← All episodes
Episode 17 · Making Sense of AI ·13:31 ·July 21, 2026

The EU AI Act Rules Everyone Thinks Got Delayed — and the Ones Taking Effect Anyway

Everyone read 'the EU AI Act got delayed' and relaxed. But the rules that bite land August 2 anyway — and the same illusion runs from Washington to Seoul to the Gulf. Where AI regulation actually stands in 2026, and where it's heading.

The Promise

  • The binding rules are boring and specific — transparency, documentation, human oversight — which makes them something an organization can prepare for rather than fear.
  • The EU's risk-tiered model is being copied from Latin America to South Korea, so one honest governance effort can satisfy many jurisdictions at once.
  • Cybersecurity already walked this exact path — from 'not my problem' to a standing board responsibility — which gives AI governance a proven playbook to follow.
PROMISE RISK
Balanced

The Risk

  • One industry survey this spring found 78% of organizations had done nothing to prepare, and the August 2 general-purpose AI obligations don't wait for them.
  • The headline 'delay' only moved the high-risk rules. The parts that reach almost every AI system you already run took effect on schedule.
  • The US rollback can't legally execute while 100+ state AI laws bind companies right now — 'deregulation' is a headline, not something your compliance team can rely on.

The delay that wasn’t

Everyone read one headline — “the EU AI Act got delayed” — and relaxed. That’s the part that doesn’t matter. The delay moved the high-risk rules, the ones that make noise. It left untouched the obligations that reach almost every AI system your organization already runs. Those take effect on August 2, 2026, whether or not anyone put the date on the calendar. One industry survey this spring found 78% of organizations had done nothing to prepare. The deadline didn’t wait for them.

The same illusion, everywhere

Step back from Europe and the pattern repeats on every continent. The US announced a rollback that can’t legally execute — while more than 100 state AI laws bind companies right now. Canada’s comprehensive bill died in Parliament, and EU-style laws are rising across Latin America to fill the space. South Korea’s AI Act is already live. China runs a labeling regime. The UAE built an office that uses AI to help draft the laws themselves. The binding rules are almost never the ones making headlines. The quiet ones are the ones that bite.

Where this ends: the boardroom

If you want to know where AI regulation is heading, look at cybersecurity. Twenty years ago it was a technical problem two levels down from the board. Today it’s a standing agenda item with personal liability attached. AI governance is walking the same path, and faster. The destination is already known and the playbook already exists. The risk is the interval — the stretch where the rules are binding, the enforcers are named, and most organizations are still treating August like a theory.