Back to Guides
Guide16 September 2026

Has the EU AI Act Passed and What Does It Mean for Your Business?

Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.

In this guide
  1. Key takeaways
  2. Did the EU AI Act actually pass?
  3. When did the Act become generally applicable?
  4. What are the key implementation milestones?
  5. What does the Digital Omnibus amendment change?
  6. Which obligations apply to my organization today?
  7. How is the Act enforced?
  8. What should I do next?
  9. Where can I find more detailed guidance?

Key takeaways

Did the EU AI Act actually pass?

Yes - the EU AI Act was formally adopted by the European Parliament and Council on 13 June 2024 and became law as Regulation (EU) 2024/1689. It entered into force on 1 August 2024, making the legislation legally binding.

When did the Act become generally applicable?

The regulation started applying to AI systems placed on the EU market or used in the Union on 2 August 2026. That date marks the point when all providers must adhere to the full set of obligations, unless specific provisions have earlier entry dates.

What are the key implementation milestones?

MilestoneWhat happenedDate
Adoption of the AI Act (Regulation (EU) 2024/1689)Formal parliamentary and council approval13 June 2024
Entry into forceLaw becomes active, but not yet generally applicable1 August 2024
General applicabilityObligations apply to AI placed on the EU market2 August 2026
Prohibited - practice rules (Art. 5) and AI - literacy dutiesFirst enforceable provisions2 Feb 2025
Transparency obligations (Art. 50)Provider must publish model information2 Aug 2025
General - purpose AI model obligationsNew requirements for large foundation models2 Aug 2025
High - risk obligations (stand - alone)Deadline for compliance2 Dec 2027
High - risk obligations (product - embedded)Deadline for compliance2 Aug 2028
Digital Omnibus amendmentPostponed high - risk deadlines, added bans (e.g., nudifier, CSAM)27 July 2026

What does the Digital Omnibus amendment change?

The amendment, published on 24 July 2026 and effective 27 July 2026, does not repeal the AI Act. It mainly postpones high - risk compliance dates and adds new prohibited practices such as nudifier tools and child - sexual - abuse - material generation. The core framework and enforcement mechanisms remain unchanged.

Which obligations apply to my organization today?

How is the Act enforced?

National AI Offices and the EU AI Office monitor compliance. They can issue fines up to 6 % of annual turnover for serious breaches, similar to GDPR penalties. Enforcement actions typically start after the general applicability date, but earlier penalties can be applied for prohibited practices.

What should I do next?

  1. Inventory your AI systems - identify any that are placed in the EU market or used by EU customers.
  2. Classify risk - determine if any fall under the high - risk category defined in Annex II.
  3. Check prohibited practices - verify none of your systems perform activities listed in Art. 5.
  4. Prepare documentation - create model - cards, data - governance records, and AI - literacy training plans.
  5. Plan for deadlines - schedule compliance work to meet the 2 Dec 2027 and 2 Aug 2028 high - risk deadlines.

Where can I find more detailed guidance?


This article reflects the latest publicly available information as of September 2026.

Free security scan

See what's actually exposed on your site.

Decloak's free scan runs in about 15 seconds, no account required, and covers:

  • HTTP/TLS security posture
  • JavaScript CVEs
  • Exposed Supabase/Lovable/Base44 misconfigurations
  • AI-written executive summary