The EU AI Act Officially Applies, But With a Catch

As of early August 2026, the European Union's AI Act has moved from a piece of pending legislation into a body of law that companies must actually follow. TechGDPR's latest data protection digest flags this milestone, noting that the Act became applicable while its rules for high-risk AI systems remain temporarily excluded. For anyone tracking how AI regulation intersects with data privacy, this is a notable moment: the law is technically live, but one of its most consequential chapters is on hold.

The AI Act was designed around a risk-based framework. Systems are sorted into categories, from minimal risk to unacceptable risk, with obligations scaling up accordingly. High-risk AI, think systems used in hiring, credit scoring, law enforcement, or medical diagnostics, was always meant to carry the heaviest compliance burden: conformity assessments, human oversight requirements, and detailed documentation. The fact that these specific obligations are being delayed, even as the broader law takes effect, tells you something about how difficult it has been for regulators and industry to agree on implementation timelines for the toughest provisions.

Why High-Risk AI Rules Are on Pause

The delay isn't a sign that regulators have softened their stance on AI oversight. Instead, it reflects the practical reality of rolling out a law this complex. Standards bodies, national regulators, and the European Commission all needed more time to finalize the technical specifications that high-risk AI providers would be required to meet. Rather than force companies to comply with rules that weren't fully defined, the obligations tied to high-risk systems were pushed back while the rest of the Act, including provisions around prohibited practices and AI literacy, moved forward on schedule.

This staggered rollout matters for data protection professionals in particular. Many high-risk AI use cases, biometric identification, automated decision-making in employment or lending, involve substantial processing of personal data. When the compliance deadline for those systems slips, it creates a temporary gap where AI-specific safeguards aren't yet enforceable, even though GDPR obligations around the same data processing activities remain fully in force. Organizations can't treat the delay as a free pass on privacy compliance broadly, only on the AI Act's additional layer of requirements for high-risk categories.

The GDPR Connection: Privacy Still in the Frame

One of the more useful things to understand about the AI Act is that it doesn't replace GDPR, it sits alongside it. Any AI system that processes personal data, whether it's classified as high-risk or not, still has to satisfy existing data protection law: lawful basis for processing, transparency to data subjects, and safeguards against misuse. The AI Act adds sector-specific and risk-specific rules on top of that foundation.

This dual-track approach isn't unique to the EU. Data protection regimes around the world are grappling with similar questions about how to regulate new technology without leaving gaps in oversight. Zimbabwe's telecoms regulator, for instance, is preparing to actively enforce its own data protection law starting in September 2026, a shift covered in our report on POTRAZ's enforcement plans. Elsewhere, proposals like South Africa's plan to link mobile SIM registration to digital identity have raised similar concerns about how personal data gets used once it's collected, a topic we explored in our coverage of South Africa's SIM-to-ID debate. Different regions, different mechanisms, but the same underlying tension: technology moves faster than the rules meant to govern it.

What This Means For You

If you're a consumer, the immediate practical impact is limited. The EU AI Act's high-risk provisions were always aimed at the businesses and public bodies deploying AI systems, not at individual users. But the broader rollout is worth watching because it signals how seriously regulators are taking AI-driven data processing, and how much work remains before those protections are fully in place.

If you work at a company that builds or deploys AI tools touching EU users, the delay on high-risk obligations doesn't mean you can wait to prepare. Regulators have made clear the postponement is about implementation timing, not a change in direction. Getting ahead of documentation, risk assessments, and data governance now will matter once the high-risk deadlines do land.

Key Takeaways

  • The EU AI Act became applicable in August 2026, but obligations for high-risk AI systems were temporarily excluded pending finalized technical standards.
  • GDPR obligations continue to apply in full regardless of the AI Act's phased rollout, so data processing tied to AI systems still requires a lawful basis and transparency.
  • Businesses deploying AI in the EU should treat the delay as a planning window, not a compliance exemption, and continue building toward eventual high-risk requirements.
  • Watching how other jurisdictions, from Zimbabwe to South Africa, handle data protection enforcement offers useful context for how global regulatory momentum around personal data is building in parallel with AI-specific rules.