Executive Summary

The word going around the industry is that the EU AI Act's high-risk provisions come into full force on August 2. The truth runs the other way. The Digital Omnibus on AI has cleared the legislative process, and the Annex III high-risk obligations — including Article 10, which requires training data to be representative, to minimize errors, and to manage bias — have been formally pushed to December 2, 2027. The notion that "the delay was only talk and never became law, so it goes ahead as scheduled" is mistaken. The delay is already law, and this blog reported that same fact in its last three pieces.

That does not make August 2 an empty date. The switches that actually flip that day are the Article 50 transparency duties — telling users they are interacting with AI and labeling AI-generated or manipulated content, including deepfakes — the Commission's power to sanction providers of general-purpose AI (GPAI), and the market-surveillance enforcement machinery. High-risk duties are "not switched on yet"; the GPAI sanction power is the opposite: "teeth growing on a rule that already existed." That asymmetry is where this piece begins.

The heart of it is a re-reading of the deferral. What Article 10 asks for is evidence of data quality, and a record that representativeness was checked, documentation that label quality was measured, and a trail of how far provenance is known are all accumulated assets that cannot be crammed together in 2027. ISO/IEC 17025 laboratory accreditation and GDPR enforcement both show the same pattern: the paperwork moves fast, but the accumulation in front of it is the real bottleneck, and quiet enforcement surges years later. So the 18-month deferral is not an exemption; it is a preparation clock.

Four numbers say first why that preparation clock is already running: the length of the deferral, the size of the fine that actually starts turning on August 2, the rate at which data quality brings AI projects down, and the gap left by organizations that have not yet started.

18 months

High-risk deferral window

2026-08-02 → 2027-12-02 · a preparation clock, not an exemption

3% of turnover

GPAI sanction cap live on Aug 2

Higher of €15M or 3% of turnover · Article 101

85%

AI projects failing on data quality

Gartner · not a problem regulation invented

78%

Organizations that haven't started compliance

As of 2026-04 · a narrowing window

1

The switches that actually flip on August 2

August 2 is often introduced as "the day the new rules begin." It is closer to the reverse. Most of what takes effect that day is a rule that already existed; what is genuinely new is the means to enforce it. Look at the three switches one by one and the character of the date becomes clear.

EU AI Act switch timeline: 2025–2028 2025-08-02 GPAI duties apply (no sanctions) 2026-08-02 Art.50 transparency + GPAI sanction power live 2026-12-02 Watermarking carve-out for existing gen-AI ends 2027-12-02 Annex III high-risk (incl. Article 10) applies 2028-08-02 Annex I high-risk (product-embedded) High-risk duties are deferred separately to 2027–2028 · what actually switches on Aug 2 is transparency + GPAI sanction power | Original Pebblous diagram
▲ What takes effect on August 2 is the Article 50 transparency duties and GPAI sanction power; the high-risk provisions (Annex III/I) are deferred separately to 2027–2028 | Original Pebblous diagram

Article 50 — the transparency duties

The first is the Article 50 transparency duties. They require disclosing to users that they are interacting with AI and labeling content that AI has generated or manipulated, deepfakes included. These duties take effect on August 2 as scheduled. The one carve-out: for generative AI already on the market, the machine-readable watermarking obligation is deferred to December 2, 2026 under the Digital Omnibus provisional agreement. In other words, what splits by provision is not "what you label" but "by when, and in what form."

Article 101 — the Commission's power to sanction GPAI providers

The second is the heart of this piece. The obligations on providers of general-purpose AI (GPAI) models — technical documentation, publishing a training-data summary, a copyright policy — have applied since August 2, 2025. What was missing was any power for the Commission (the AI Office) to fine a violation. That power comes into force precisely on August 2, 2026. The rule has been on the books for a year; the teeth are only now growing in. The cap is the higher of €15M or 3% of turnover.

The market-surveillance and AI Office enforcement structure

The third is that the investigation-and-enforcement structure of member-state market-surveillance authorities and the AI Office goes live. What switches on is not a single provision but the entire governance machine. For the first two switches to actually work, this structure has to be standing first.

It is worth making plain that these three switches are not something only European companies need to watch. Both the Article 50 transparency duties and the GPAI provider obligations apply the moment a service reaches EU users, wherever the provider is headquartered. A Korean, U.S., or Japanese company with users in the EU is squarely in scope. "We don't run a legal entity in the EU, so this doesn't touch us" is the most common misread.

Set these three beside the high-risk provisions and the true character of August 2 emerges. The table below separates what takes effect that day from what slipped to 2027. This contrast is the fact-check that runs through the whole piece.

Item In force 2026-08-02 (no delay) Deferred
Article 50 transparency duties Mostly applies as scheduled
Article 50 machine-readable watermarking (existing generative AI) Deferred to 2026-12-02
GPAI sanction power (Commission, Article 101) Actually enforceable from Aug 2
Market-surveillance / AI Office investigation & enforcement structure Live
Annex III high-risk (incl. Article 10) Formally deferred to 2027-12-02
Annex I high-risk (product-embedded, medical devices, etc.) Deferred to 2028-08-02

The size of the fine is worth pinning down too. The "3% of turnover for violations" that circulates in coverage points in the right direction but attributes it wrongly. EU AI Act fines split into three tiers. What actually starts biting at 3% on August 2 is not Tier 2 but the GPAI Article 101 power the Commission enforces directly; the Article 10 violations that sit inside Tier 2's 3% are moot for now, because the obligation itself is deferred to 2027, so real penalties come only after that.

Tier Cap Applies to In force
Tier 1 €35M / 7% of turnover Article 5 prohibited-practice violations From 2025-02-02
Tier 2 €15M / 3% of turnover Provider/deployer obligations, Article 50 transparency, Article 10 data governance violations, etc. Penalties chapter in force, but Article 10 obligation deferred to 2027-12
Tier 3 €7.5M / 1% of turnover Supplying incorrect or incomplete information to authorities From 2025-08-02
GPAI-specific (Article 101) €15M / 3% of turnover GPAI provider obligation violations — enforced directly by the Commission Sanction power from 2026-08-02

For a large provider the fixed €15M cap is effectively a floor. Plug in 3% of turnover and the scale changes. On FY2025 revenue, Alphabet's would run to roughly $12.1B (about $402.8B in revenue) and Microsoft's to roughly $8.5B (about $281.7B). The real deterrent comes from the turnover percentage, not the fixed amount. That math, though, is for the giants. For SMEs and startups the reverse applies: the lower of the fixed cap or the turnover percentage (Article 99(6), the so-called "SME exception"). For the same violation, the direction of the burden flips with company size. For the record, "1.5%" is a figure that appears nowhere. It is an error repeated in secondary sources; the correct number for supplying incorrect information is 1% (Tier 3).

2

Why, and where, high-risk was deferred

The premise going around is that "there was talk of a delay, but it never became law, so the rules go ahead as scheduled." That sentence is exactly inverted. The delay did not stop at discussion. It became law. The law is called the Digital Omnibus on AI.

The legislative record is clear. The European Parliament adopted it on June 16, 2026; the Council approved it on June 29; signature followed on July 8. Multiple law-firm analyses — Gibson Dunn, Jones Walker, Licentium — confirm the same timeline. Under this amendment, the obligations on standalone Annex III high-risk AI (including Article 10 data governance) were formally deferred to December 2, 2027, and the product-embedded Annex I high-risk category to August 2, 2028.

Digital Omnibus legislative steps: 3 done, publication pending Parliament adopts ✓ 2026-06-16 Council approves ✓ 2026-06-29 Signature ✓ 2026-07-08 OJ publication pending Adoption, approval, and signature are done — the one remaining variable is Official Journal publication | Original Pebblous diagram
▲ The Digital Omnibus has cleared adoption, approval, and signature; only Official Journal publication remains for official effect | Original Pebblous diagram

One variable remains. For this deferral schedule to take official effect, the Digital Omnibus must be published in the Official Journal. Adoption and approval are done; only publication is pending. So this piece treats "high-risk has been deferred" as settled fact, and "the date the Official Journal publication lands" as the one remaining procedural variable.

Why does the correction matter? This blog already reported, in its last three pieces (June 19, June 25, July 13), that "high-risk = confirmed deferral to December 2027." Running the original premise would have been a factual error reversing our own coverage, an internal contradiction on our own site. Timeline consistency is a basis for trust.

One further amendment is worth adding. The Digital Omnibus also reworked Article 10's exception for processing special-category sensitive data for the purpose of detecting and mitigating bias. Checking for bias requires sensitive attributes such as demographics, and this amendment tidies up the legal basis for handling exactly that data. We examined what this amendment implies in detail in our July 4 piece on the sensitive-data exception.

3

What the "evidence" in Article 10 really is

Read Article 10 for the first time and it looks like an unfamiliar demand: training, validation, and test data must be "relevant, sufficiently representative, and to the best extent possible free of errors and complete"; bias must be examined and mitigated; gaps in the data must be identified. But this list is not a standard regulation invented from scratch. It is closer to regulatory language draped over a problem industry has repeatedly named as the leading cause of AI failure.

The numbers say as much. Gartner estimates that 85% of AI projects fail due to poor data quality or a lack of relevant data, and that only 12% of organizations have data of "AI-ready" quality. Google Research's "Data Cascades" study reports that 92% of practitioners in high-stakes domains experienced data problems propagating downstream and compounding at least once, and 45% more than once. Thin representativeness and label errors were breaking projects long before regulation pointed at them.

Academically, too, this requirement is already something measurable. The arXiv paper "Data Bias Profiles for the EU AI Act" formalized dataset representativeness into quantitative metrics aligned with the Article 10 requirements, and follow-on work extended it into sampling bias, deployment bias, and structural bias. Why representativeness matters is proven by cases that have become classics. Gender Shades showed that facial-recognition accuracy diverges sharply by skin tone and gender; audits of LAION-5B showed that large-scale web-crawled data carries demographic bias. A flaw at the data stage is not a simple error. It transfers into bias in the model's internal representations. That is exactly why Article 10 governs the data stage.

And here is where the core thesis of this piece emerges. What Article 10 asks for is not data but evidence about data: a record that representativeness was checked, documentation that a label error rate was measured, a trail showing bias was examined and mitigated, a lineage of how far the provenance is known. These forms of evidence share one property. Once the model is fully trained, they cannot be produced retroactively. Try to reconstruct provenance lineage and bias examination after training is done, and the reconstruction itself becomes a red flag to an auditor.

Evidence is not manufactured — it accumulates ① Data collection ② Labeling ③ Bias check ④ Model training Provenance record Label quality record Bias review record Training-data summary Accumulated evidence = a byproduct of the pipeline (can't be produced retroactively) ✗ Reconstructing after training → a red flag to the auditor
▲ The evidence Article 10 requires must accumulate as a byproduct while the pipeline runs; reconstructing it after training is itself a red flag | Original Pebblous diagram

Evidence is not manufactured; it accumulates. What Article 10 requires is an accumulated asset that has to be left behind as a byproduct while the pipeline runs, and that character decides the next chapter's conclusion in advance. The deferral is not an exemption; it is the time to start that accumulation.

This connects to, yet differs from, the angle we took in our July 13 report. That piece laid out "the specific audit-trail items a labeling workflow leaves behind"; this one focuses on "why that trail is an accumulated asset that cannot be produced retroactively."

4

The deferral is a preparation clock, not an exemption

"It's been pushed to 2027, so we can leave it alone for now." This is the most common misread of the deferral. The previous chapter's conclusion — that evidence is an accumulated asset that cannot be produced retroactively — knocks it down at once. Eighteen months is not a break; it is lead time. And this structure is not a quirk unique to the EU AI Act. Two different regimes show exactly the same pattern.

Parallel one — ISO/IEC 17025 laboratory accreditation

Consider the ISO/IEC 17025 accreditation that testing and calibration bodies obtain. For an accreditation body such as Korea's KOLAS, the official processing time from application to accreditation is roughly 90 business days. But the preparation that comes before it — building the quality-management system, documenting procedures, running an internal audit — takes an industry-average of about 12 months. The administrative processing itself is fast; the real bottleneck is the accumulation in front of it. The paperwork clears in three months, but building the state the paperwork is meant to prove takes a year.

Stage Duration Character
Building a new quality-management system ~12 months on average Accumulation (the real bottleneck)
Accreditation body processing (application → accreditation) ~90 days Administrative processing (fast)

Parallel two — the surge that followed GDPR's "quiet"

GDPR has already shown why regulatory silence should not be misread as harmlessness. For the first two years after it took effect in May 2018, fines were sporadic. The turning point was 2023. Cumulative fines surged that year alone — including the €1.2B the Irish supervisory authority levied on Meta. As of January 2026, cumulative GDPR fines had reached €7.1B, more than 60% of it imposed after 2023. By contrast, the EU AI Act's penalties chapter has been in force since August 2, 2025, yet as of May 2026 there is still not a single imposed case. Overlay the GDPR trajectory and the safer reading of this silence is not harmlessness but the period in which enforcement infrastructure is being built.

GDPR cumulative fines: a surge after the quiet €7.1B cumulative (as of 2026-01) 2018–2022 Quiet early years Under 40% of total 2023–2026 Surge phase 60%+ of total (turn: 2023) Contrast: EU AI Act penalties chapter in force since 2025-08, zero cases as of 2026-05
▲ GDPR fines stayed quiet for its first two years, then surged from 2023 — why regulatory silence should not be read as harmlessness | Original Pebblous diagram

Both parallels point the same way. Article 10 evidence, ISO 17025 accreditation, and GDPR enforcement all prove the same structure from different angles: "the administration is fast but the accumulation is slow," or "acceleration follows the quiet." Read the deferral as anything other than lead time and the bill comes due in 2027.

The real-world state of readiness backs the warning. As of April 2026, 78% of organizations had not yet started meaningful compliance measures. The cost of preparing is not symbolic either. CEPS estimates €193,000–€330,000 to build a new quality-management system and about €71,400 a year to maintain it (the widely cited "€400,000" is that original figure miscomputed by a different body). For the 78% who haven't started, the 18 months is a window already narrowing. Why separating data provenance and standing up audit traceability now is urgent is something we also covered in our piece on the high-risk deferral and data governance.

5

Turning evidence into organizational discipline

One line in the industry commentary captures the situation exactly: "Regulators don't tell you which vendor to buy. They expect you to show up with the evidence you can actually produce on request." That sentence defines the character of regulatory readiness. What an auditor wants is not a particular tool but a state in which, the moment a request arrives, you can answer by opening a record rather than reconstructing one.

That state is not completed by buying a single product. Records of checking representativeness, of measuring label quality, and of provenance lineage and bias examination have to remain standing as byproducts of the pipeline and stay accessible on request at any time. This is a question of organizational discipline before it is a question of tooling: the habit of keeping data quality in a continuously auditable state, of making evidence-readiness the default of operations.

The priority within that discipline splits by whether you are a GPAI provider or a high-risk deployer. If you are a GPAI provider, the documentation and transparency obligations already have teeth from August 2, so the deadline is now. If you are preparing a high-risk system, accumulating Article 10 evidence is lead time toward 2027. The gap between organizations that mistook the deferral for an exemption and downed tools, and those that used it as a measurement window, only grows harder to close as the deadline approaches.

Editor's Note. Pebblous watches this topic because the "evidence of data quality" that regulation has begun to demand overlaps precisely with the question DataClinic has aimed at — how to prove, through diagnosis, that a dataset is representative and has been checked for bias. Regulation deciding to govern the data stage is close to a regulatory endorsement of our repeated claim that "data quality determines model quality." As a practical instance of the discipline that keeps this diagnosis and documentation continuously auditable, Pebblous's AI-Ready Data pipeline, DataClinic, and AADS sit alongside a testing quality-management system built on ISO/IEC 17025 (accredited-laboratory recognition in preparation). This does not replace labeling or regulatory advice; it stands in the adjacent seat of diagnosing data quality.

The switches on August 2 are not the ones you think. What flips on is the transparency duties and the GPAI sanction power, and high-risk has quietly begun its countdown toward the 2027 deadline. Read that countdown as a reprieve and you have slack; read it as a preparation clock and you have lead time. The larger picture — the regulatory embodiment of data sovereignty — continues at the Sovereign AI hub. Thank you for reading.

R

References

This piece was written by cross-checking the primary regulatory texts, law-firm analyses, academic papers, and industry statistics below. The deferral schedule is anchored to the Digital Omnibus (European Parliament adoption 2026-06-16, Council approval 06-29, signature 07-08, Official Journal publication pending).

Legislation & primary regulation / law-firm analysis

  • 1.EU AI Act, Article 99 — Penalties. Link
  • 2.EU AI Act, Article 101 — Fines for GPAI Providers. Link
  • 3.EU AI Act, Annex III — High-risk categories. Link
  • 4.Gibson Dunn, "EU AI Act Omnibus Agreement — Postponed High-Risk Deadlines and Other Key Changes" (2026). Link
  • 5.Jones Walker LLP, "Yes, August 2 Still Matters" (2026). Link
  • 6.Licentium, "EU AI Act Article 50 Transparency Obligations Enter Application on 2 August 2026." Link

Academic — representativeness, dataset bias, documentation

  • 7."Data Bias Profiles for the EU AI Act and Beyond," arXiv:2507.08866 (2025) — directly tied to the Article 10 representativeness requirement. Link
  • 8.Buolamwini & Gebru, "Gender Shades: Intersectional Accuracy Disparities in Commercial Gender Classification," FAT* 2018. Link
  • 9.Sambasivan et al., "Everyone Wants to Do the Model Work, Not the Data Work: Data Cascades in High-Stakes AI," ACM CHI 2021. Link
  • 10.Gebru et al., "Datasheets for Datasets," arXiv:1803.09010 (2018; CACM 2021). Link

Industry & statistics (cost, readiness, enforcement)

  • 11.CEPS, "Clarifying the Costs for the EU's AI Act" — new QMS €193K–330K. Link
  • 12.Google Research, "Data Cascades in Machine Learning" — 92% of practitioners affected. Link
  • 13.Kiteworks, "GDPR Fines Hit €7.1 Billion" — the enforcement delay-then-acceleration pattern. Link
  • 14.appliedAI Institute, "AI Act: Risk Classification of AI Systems from a Practical Perspective" (2023, secondary citation). Link

※ The large-GPAI-provider revenue used in the fine calculations draws on Alphabet's and Microsoft's official FY2025 results (SEC filings). AI-governance market-size figures are not cited in the body, as definitions and scope vary too widely across research firms. The ISO/IEC 17025 and accreditation-body durations are a synthesis of general international practice and official accreditation-body guidance, and do not indicate any specific organization's acquisition date.