The EU’s AI law took effect Sunday, minus the part everyone feared. That part has a new date.

For two years, August 2, 2026 was the date circled in every AI compliance calendar in Europe: the day the EU AI Act’s rules for high-risk systems, the category that includes credit scoring and hiring tools, were supposed to bite. The date arrived on Sunday. The rules did not.

Six days earlier, the EU’s Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force after a spring of negotiation, and it moved the high-risk deadlines: obligations for stand-alone high-risk systems listed in Annex III now apply on December 2, 2027, and for high-risk AI embedded in regulated products on August 2, 2028. Gibson Dunn’s analysis of the deal lists recruitment and credit scoring among the categories affected. The postponement was pitched as pragmatism: the technical standards firms need in order to comply were not ready.

What did happen on Sunday matters just as much, because the parts that took effect are the parts that touch everyone, not just the builders of high-risk systems. And if your instinct is that a European law is somebody else’s problem, hold that thought for three paragraphs.

What actually switched on August 2

Two things, broadly.

The first is transparency. Under Article 50, providers of AI systems that generate synthetic audio, images, video, or text must ensure outputs are “marked in a machine-readable format and detectable as artificially generated or manipulated.” People interacting with an AI system must be told they are dealing with one, unless that is obvious from context (the statute’s actual standard is a person “reasonably well-informed, observant and circumspect,” which is more faith than some vendors extend to their users). Deployers of deepfakes must disclose them. And one clause lands close to home if your firm publishes anything: deployers of an AI system generating text “published with the purpose of informing the public on matters of public interest” must disclose that the text was artificially generated. Systems already on the market before August 2 get a grace period on the marking obligation, until December 2, 2026, per the omnibus. The rest is live.

For practitioners, the marking rule has a practical edge: machine-readable means detectable. As those markers spread through the tools, AI-drafted content stops being invisible, to clients, to platforms, and to anyone who bothers to check. A firm that quietly ships AI-written deliverables without disclosure is acquiring a technical problem on top of an ethical one.

The second is the enforcement machinery itself. The market surveillance framework became applicable on Sunday, and with it the enforcement powers of the AI Office, the body the EU set up in 2024 to police the law. That creates an odd but deliberate sequence, one close observers have flagged: the supervisors take their posts more than a year before the high-risk obligations they will supervise become enforceable. Europe, in other words, did not cancel the hard part. It seated the referees first and pushed kickoff to late 2027.

Why accounting is written into this law

Look at what Annex III actually classifies as high-risk, because two of its categories sit inside ordinary accounting and firm life.

One: “AI systems intended to be used to evaluate the creditworthiness of natural persons or establish their credit score,” with a carve-out for fraud-detection tools. If your practice, or your client’s finance function, uses AI to assess whether an individual gets credit, that is not a gray area in Europe. It is named.

Two: hiring and workforce management. Systems used for “the recruitment or selection of natural persons,” including filtering applications and evaluating candidates, and systems that make decisions about promotion, termination, task allocation, or monitoring performance. Every firm that lets an AI tool rank resumes is described in that sentence, and so is every workforce-analytics dashboard that scores staff productivity.

Classification, to be clear, is only the label. The substance sits in the delayed sections: the full high-risk regime that providers and deployers will owe by December 2027, from risk management to the human-oversight requirement we return to below. The label survived the omnibus untouched. The homework moved.

Then comes the reach. Article 2 applies the law not only to EU firms but to “providers and deployers of AI systems that have their place of establishment or are located in a third country, where the output produced by the AI system is used in the Union.” A Toronto or Chicago firm running AI-assisted work whose output is used in the EU is not automatically outside this law because its office is. The mechanics of enforcement across borders will take years to settle, but the text is not subtle about intent.

And there is the quieter channel, the one that got GDPR clauses into every engagement letter on earth: vendors. The platforms accountants use are global. They will not build one compliant version for Europe and a separate noncompliant one for everyone else; they will build to the strictest market and ship it everywhere. Machine-readable marking of AI-generated content, disclosure defaults, documented human oversight: expect these to arrive in your tools regardless of where you practice, the way privacy settings did. When we wrote about CLA training its own model with Digits last week, we noted the firm’s 120-plus locations span the US, UK, and Europe. Firm-owned models and European offices now come with a regulatory calendar attached.

The sequencing, read correctly

There are two honest readings of the delay, and both hold a real insight.

The industry reading is that this is realism. You cannot certify systems against harmonized standards that do not exist yet, and a deadline that arrives before the standards do produces paperwork theater, not safety. Sixteen extra months to do it properly is a favor to everyone, including the people the law protects.

The skeptical reading is that the EU blinked under pressure, and that a rule which keeps moving stops being a deadline and starts being a suggestion. On this reading, the delay teaches every regulated industry that lobbying works, and the credit-scoring model that misjudges someone in 2026 will do so without consequence for another year and a half.

Our take sits between them, anchored to the part nobody delayed. The supervisory apparatus is live now. The transparency duties are live now. The classification of credit scoring and hiring AI as high-risk survived the omnibus untouched; only the date moved. Regulators who spend sixteen months staffed, empowered, and watching before their biggest obligations kick in tend to arrive at that kickoff with opinions. Firms betting the delay becomes a repeal are making a bet about European politics with their compliance budget.

What it means for you

If you practice in the UK or the EU, or serve clients who do: you now have a real date and a known list. Spend some of the sixteen months on an inventory: which tools in your stack, or your clients’ stacks, touch individual creditworthiness or hiring decisions, and which vendor contracts say anything about who carries the AI Act obligations. Ask every vendor with EU exposure for its AI Act roadmap in writing. The firms that did this early for GDPR spent 2018 calmly.

If you are in North America with no EU footprint: your exposure runs through Article 2 if your output crosses the Atlantic, and through your vendors either way. The tools you use will grow marking, disclosure, and oversight features built for Brussels, and the diligence questions your insurers and larger clients ask will borrow the EU’s vocabulary. High-risk is about to become a term of art in procurement everywhere. None of this requires becoming an EU lawyer. It requires knowing which of your tools and outputs cross that line, and having the vendor’s answer on file.

If advisory is part of your practice, there is also a service line taking shape here. EU-exposed clients will need exactly what accountants are good at: an inventory of AI uses, a map of which ones touch the named categories, and vendor answers in writing. Someone is going to bill for that work. It might as well be the profession that already holds the client’s trust.

And if your firm uses AI to screen candidates or score credit anywhere in the world: the largest regulatory bloc on the planet has now put those uses on its named list. That designation will echo in liability arguments, underwriting questionnaires, and client expectations long before any EU inspector calls.

The bottom line

Buried in the delayed section of this law is Article 14, which requires high-risk AI systems to be built so “that they can be effectively overseen by natural persons during the period in which they are in use.” Oversight, the article says, exists to prevent the risks that remain “despite the application of other requirements.” Strip the legal language and you get a familiar idea: every other safeguard can be engineered, and the last one is a person. Readers of the KPMG episode already know what happens when that safeguard is skipped. Regulators keep arriving, jurisdiction by jurisdiction, at the same conclusion this newsletter starts from: AI can do the work. It cannot sign the work. Europe just wrote the signature requirement into statute and gave everyone sixteen months to get ready. The firms that treat human oversight as their operating model, rather than their compliance burden, will not need the extension.

Footnote

Footnote is an independent publication. It is not professional accounting, tax, or legal advice, and it is not EU legal advice; the AI Act’s application to any specific firm or tool depends on facts and counsel we cannot assess from here. Our summary is based on the regulation texts and analyses linked above, current as of August 4, 2026, and the omnibus reform is recent enough that interpretations are still settling. Statements of law are simplified; talk to qualified counsel before acting. We have no consulting relationships with any company named in this article.