Skip to content
AIPIA, Italian AI Professionals Association
First AI course in English — twelve editions in Italy
New

International membership is open: join AIPIA from any country.

Become a member for €24/year
AI Act anniversary

EU AI Act, two years on: what has actually changed, and what comes next

Two years after entry into force, the EU AI Act has reshaped AI compliance practice, regulatory engagement, and corporate governance across the European market and beyond. A stock-take of what changed and what remains to work through.

AI AIPIA Scientific-Technical Committee (STC)
  • EU AI Act
  • retrospective
  • regulation
  • compliance

Two years after entry into force on 1 August 2024, the European Union’s Artificial Intelligence Act has moved from regulatory aspiration to operational reality for a significant share of the global AI sector. The prohibited-practice provisions have been applicable since February 2025; the general-purpose AI (GPAI) obligations have been in effect since August 2025; the major substantive obligations land on 2 August 2026, weeks from the publication of this article.

This piece takes stock of what the AI Act has actually changed and what remains genuinely uncertain or unresolved. It is written for practitioners and decision-makers who need to plan for the rest of 2026 and beyond.

What has visibly changed

Five concrete shifts in AI practice are now visible in European and globally connected markets.

Corporate AI governance has matured rapidly. Two years ago, “AI governance” in most organisations meant ad-hoc oversight by a senior leader plus ISO 27001 controls. Today, mid-sized and large organisations operating in the EU market typically have named AI governance functions, AI inventories, risk-classification processes, technical documentation templates, post-deployment monitoring procedures, and incident-response playbooks. ISO 42001 adoption has accelerated. The governance maturity gap between organisations that started in 2023 and those still beginning is substantial.

The GPAI conversation has stabilised. When the regulation entered into force, the operational scope of GPAI obligations was genuinely unclear. The Code of Practice negotiated under Article 56, published in mid-2025, gave providers a concrete compliance pathway. Major non-EU GPAI providers, including the leading frontier-model labs, have engaged with the Code and adapted their disclosures, training-data documentation, copyright opt-out respect, and systemic-risk management accordingly.

Conformity assessment has become a real industry. Notified bodies, internal compliance teams, third-party AI auditors, and specialised consultancies have built capacity around AI Act conformity assessment. The market for AI audit and conformity services in the EU is now multiple billions of euros annually and growing through 2026 as the high-risk obligations take effect.

The professional associations have shifted role. Organisations like AIPIA, IEEE, and national professional bodies have moved from offering general AI ethics training to providing operational AI Act compliance support, conformity-assessment readiness programmes, and credential pathways tied to specific competencies. The European Digital Credential network has expanded substantially.

EU AI Office has emerged as a key institutional actor. The European AI Office, established within the Commission to enforce GPAI obligations and coordinate national authorities, has become an operational regulator in less than two years. Guidance documents, investigations, working groups, and stakeholder dialogue from the AI Office have shaped day-to-day compliance practice across the GPAI provider landscape and beyond.

What remains uncertain

Three areas where the AI Act remains genuinely unresolved.

High-risk classification edge cases. Annex III categories are broad in some places and narrow in others. Whether a specific AI application falls within “essential services”, “employment”, or “education and vocational training” can be ambiguous. Guidance from the Commission, the AI Office, and the European Artificial Intelligence Board has clarified some boundaries but left others open. Cases will shape interpretation through enforcement.

Article 6(3) “non-substantial” derogation. The provision allowing organisations to declassify Annex III systems where the AI does not pose significant risk of harm to health, safety, or fundamental rights is a meaningful operational lever, and its application is disputed. Conservative legal advice typically treats the derogation narrowly; commercial pressure pushes toward broader application. The Commission’s emerging guidance is sharpening the criteria.

Extraterritorial enforcement against non-EU organisations. The regulation applies to organisations established outside the EU placing AI on the EU market. Enforcement could run through cooperation with non-EU authorities, through EU-based authorised representatives, or through market-access mechanisms. How effectively it will work remains to be tested in practice. Substantial extraterritorial enforcement has not yet occurred.

What has surprised practitioners

Some elements have played out differently from initial expectations.

Voluntary compliance has been substantial. The AI Pact, the Commission’s voluntary early-compliance scheme, attracted over 200 organisations including many global tech companies and major EU industrial groups. Voluntary commitments have been more substantive than many anticipated, and have informed mandatory compliance practice.

SMEs have been more engaged than expected. Early commentary worried that AI Act compliance would crush SME AI innovation. The reality has been mixed: some SMEs have indeed struggled with documentation and conformity burdens, but others have used SME-specific provisions effectively and integrated compliance into product development from the start. The compliance-cost-vs-innovation balance remains genuinely contested.

Non-EU GPAI providers have engaged substantively. When the regulation entered into force, some commentary predicted that major non-EU AI labs would either ignore the EU market or withdraw selectively rather than comply. The actual response has been notably constructive: engagement with the GPAI Code of Practice, adaptation of disclosure and risk-management practices, and designation of EU points of contact.

National authorities have been slower than expected. The AI Act requires designation of competent national authorities by August 2025. Several member states have been late; others have designated but under-resourced their authorities. Operational enforcement capacity at member-state level is uneven and will need investment through 2027.

What comes next

Three milestones structure the next eighteen months.

2 August 2026: The bulk of substantive obligations apply. High-risk system providers must comply with risk management, data governance, technical documentation, transparency, human oversight, accuracy and robustness, conformity assessment, and post-market monitoring. Deployers face their own obligations on use, oversight, log retention, and, for public bodies and select private actors, fundamental rights impact assessments. Enforcement becomes meaningfully operative.

2 August 2027: High-risk AI embedded in regulated products under Annex I, including machinery, medical devices, vehicles, and toys, becomes fully enforceable. This second wave brings substantial industrial sectors into full AI Act scope and triggers further conformity assessment workload.

Continuous secondary legislation. Delegated acts, implementing acts, and harmonised standards will continue to flow from the Commission and from European standardisation organisations through 2027 and beyond. Practitioners should expect rolling updates rather than a single stable regulatory state.

What AIPIA observes

AIPIA’s vantage point rests on accredited membership of the European AI Alliance, working channels with the European AI Office, training programmes covering AI Act compliance, and working groups on operational implementation. From that position, three observations stand out.

The organisations doing well are those that started early and treated AI Act compliance as a multi-year corporate-governance investment, not a project. They have integrated AI governance into their operating model rather than running it as a side activity.

The organisations facing the largest difficulties are those that delayed engagement until 2025 or 2026 and are now compressing what should have been a two-year work programme into twelve or six months. Resource cost is materially higher; risk of gaps is materially higher.

The organisations getting most strategic value from compliance are those that have used the process to mature broader AI capability: better data governance, clearer model lifecycle management, sharper risk and ethics literacy across the workforce. AI Act compliance and AI capability turn out to be largely the same thing built differently.

The next two years of AI Act implementation will continue to shape practice. The extraterritorial test, the high-risk wave, the standards consolidation, and case law development will all unfold through 2027. Practitioners who continue to invest in competency, governance, and credentials will be best placed for what comes after the August 2026 milestone.

Frequently asked questions

Has the AI Act delayed AI adoption in Europe?

The early evidence is mixed and largely anecdotal. Some organisations have delayed specific high-risk deployments pending guidance clarity. Others have accelerated AI investment to integrate compliance ahead of the August 2026 deadline. Net effect on adoption rate is hard to measure cleanly; the regulatory effect is real but distinguishable from underlying technology and market dynamics.

Have non-EU organisations actually complied with the AI Act?

Major non-EU GPAI providers have engaged with the Code of Practice and substantially adapted their disclosure and risk-management practices. Other non-EU organisations vary widely: some have built dedicated compliance functions; others have not yet engaged seriously. Enforcement to date has been limited; the substantive test of extraterritorial enforcement remains ahead.

What is the next milestone?

2 August 2026: most provisions of the regulation apply, including the bulk of high-risk system obligations. 2 August 2027: high-risk AI embedded in regulated products under Annex I becomes fully enforceable. These dates anchor the next compliance cycles.

Get this analysis in your inbox

AIPIA briefings on EU AI policy, the European AI Credential, and cross-border AI practice. Membership gives access to deeper member-only briefings and working-group output.