Since 2 August 2026, the AI Act is no longer a horizon: the European AI Office and the competent national authorities have started enforcing the regulation, with the obligations on high-risk systems in their sights. The text being enforced, however, is not quite the one adopted in 2024: the "AI omnibus" regulation, proposed in November 2025 as part of the digital simplification package, was adopted in June 2026 and entered into force on 27 July — five days before the deadline. Scope clarifications, lighter documentation requirements, adjusted timelines for certain categories: the Commission has signalled its intent for an implementation that is legible and innovation-friendly, accompanied by a series of guidelines.
What is actually enforceable today
Concretely, three blocks of obligations structure the period. Prohibited practices, first, applicable for a long time now. The obligations of general-purpose model providers, next: technical documentation, copyright-compliance policy, training-data summary — with a reinforced regime for models presenting systemic risk. High-risk systems, finally, whose full regime (risk management, data governance, human oversight, robustness, logging) is entering its effective enforcement phase. For a B2B software vendor, the practical question is almost always the same: does my AI component make my product "high-risk" within the meaning of Annex III — and if not, which transparency obligations remain?
The real issue: the NIS2, CRA, GDPR, AI Act stack
Taken in isolation, each framework is manageable. The problem for European vendors is the stacking. A single software product can fall under NIS2 (because its customer is an essential entity), the Cyber Resilience Act (because it is a product with digital elements, with security-by-design and vulnerability-management requirements), the GDPR (because it processes personal data) and the AI Act (because it embeds a learning component). Four documentation logics, three incident-notification regimes, separate authorities. The only tenable strategy is the unified compliance factory: a single foundation for risk management, SBOM, logging and vulnerability handling, then declined towards each framework — rather than four parallel programmes that would exhaust any team.
A constraint that can become a selling point
There is nevertheless an offensive reading. Customers — regulated operators, the public sector, industrial players — will pass their own obligations on to their suppliers, by contract. The vendor able to provide the AI Act documentation, the SBOM required by the CRA, the GDPR guarantees and the NIS2 commitments in the tender file will turn a regulatory cost into a competitive advantage over non-European players who will discover these requirements in buyers' questions. European compliance, if industrialised early, is a barrier to entry that protects those who have cleared it.
To do before the end of the yearMap every AI component against Annex III; appoint the owner of the model documentation; unify the AI/cyber/data risk register; and follow the AI Office guidelines, which will progressively clarify what "compliance" means in practice.
The AI Act is entering the age of case law: the coming months will tell whether enforcement is as pragmatic as promised. But waiting to get started would be a misreading — the advantage will go to those who have turned the regulatory stack into a process, while their competitors experience it as an avalanche.