Share with your CISO
The EU’s AI Act regulatory framework is now actively phasing into enforcement, with prohibited practices live since February 2025, General-Purpose AI model rules binding since August 2025, and full high-risk system compliance deadlines landing in December 2027 and August 2028 after the AI Omnibus simplification passed in July 2026. The framework bans eight AI practices outright, imposes strict pre-market obligations on high-risk deployments across sectors from HR to credit scoring, and requires GPAI providers to disclose training data sources and pass systemic-risk assessments.
What this means for your business
Any enterprise operating AI systems in the EU right now sits inside a compliance clock that is already ticking on some obligations and accelerating on others. The August 2025 GPAI rules are not future risk, they are current exposure. Companies deploying foundation models, whether building on OpenAI, Anthropic, or open-weight alternatives, need to verify that their providers have filed the required training-data summaries and completed systemic-risk assessments. If a provider hasn’t, the deployer’s legal insulation is thinner than most legal teams currently assume.
The AI Omnibus simplification deserves a hard read rather than a sigh of relief. Yes, it pushed certain high-risk deadlines to 2027 and 2028 and extended SME-style documentation relief to small mid-caps. But it also centralized oversight authority in the AI Office, meaning enforcement will be more consistent and less gameable across member states than early observers expected. The addition of an outright ban on AI nudification apps signals that the Commission is willing to expand the prohibited list, not contract it. Compliance architecture built only to today’s prohibited list is already incomplete.
The decision that will separate well-positioned enterprises from reactive ones isn’t whether to comply, it’s whether compliance infrastructure gets built into the AI procurement and deployment workflow now or bolted on in 2027 under deadline pressure. The GPAI Code of Practice is voluntary today but functions as an advance signal of what mandatory standards will look like. Organizations that treat it as optional are effectively choosing to pay a premium for certainty later, after the standards harden into law.
Concept deep-dive: Systemic Risk (GPAI)
The AI Act labels a General-Purpose AI model as carrying “systemic risk” when its capabilities or deployment scale could produce harms that propagate across multiple sectors simultaneously, think of it as the difference between a fire in one building and a failure in the city’s power grid. The threshold is currently pegged to compute used in training. Models above it face mandatory risk assessment, incident reporting, and adversarial testing obligations before EU deployment, creating a two-tier compliance burden that splits the foundation model market structurally.
Based on reporting from AI Act | Shaping Europe’s digital future, originally published 2026-07-24 03:00:00.

