Welcome to Between the Hype. A biweekly newsletter on where enterprise systems and AI actually intersect. Not the keynote version. The version you need when you’re back at your desk on Monday.
If you’ve got “2 August 2026 — EU AI Act high-risk deadline” sitting in a risk log somewhere, change it. Last month the EU moved it. The high-risk obligations most enterprises have been scrambling to hit now land in December 2027, not this August. But a different set of duties still starts on 2 August, and that’s the one to act on now.
If you run HR, finance, credit, or any AI that touches decisions about people — inside SAP, Oracle or Microsoft — this changes both your compliance clock and your budget sequencing. Two things to get right: what actually applies next month, and what you now have until the end of 2027 to do properly instead of in a panic.
What changed
The EU’s “Digital Omnibus” amended the AI Act’s timeline. The European Parliament approved it in mid-June and the Council gave final adoption on 29 June 2026; it now awaits publication in the Official Journal (until then, confirm before you rely on the new dates). This is not the blanket “stop-the-clock” pause that was lobbied for and rejected. It’s a targeted deferral to fixed new dates.
The dates that matter now
Live today (since February 2025): the outright bans and the AI-literacy duty. Worth a check — emotion recognition in the workplace is prohibited, so if anyone’s pitched you “employee sentiment analysis,” that’s a today problem, not a 2027 one.
Still on for 2 August 2026: the transparency rules (Article 50). You have to tell people when they’re dealing with an AI (chatbots), and label AI-generated or synthetic content and deep fakes. Watermarking of content already on the market gets until 2 December 2026.
Moved to 2 December 2027 (from this August): the heavy high-risk obligations — HR screening, credit scoring, insurance pricing, and the rest of Annex III.
Moved to 2 August 2028: high-risk AI built into physical products.
Classify your AI systems: the 5-minute pass
1. Tier every system. Prohibited → High-risk (an Annex III use case) → Limited (transparency only) → Minimal (no obligations).
2. The Annex III list that catches most enterprises. Recruitment and HR decisions (screening, promotion, termination, task allocation, performance monitoring); creditworthiness and credit scoring (fraud detection is excluded); life and health insurance pricing; access to essential services. If a system does one of these, it’s high-risk.
3. Apply the get-out (Article 6(3)). An Annex III system isn’t high-risk if it only does a narrow, procedural task and doesn’t replace human judgment — unless it profiles people, in which case it always is.
4. Fix your role. Using vendor AI as-is makes you a deployer. You become a provider — and inherit the heavier obligations — if you badge it as your own, substantially modify it, or fine-tune or re-purpose it into a high-risk use. Fine-tuning a vendor model can flip you from deployer to provider.
5. Know the exposure. Prohibited-practice breaches, up to €35M or 7% of global turnover; high-risk and transparency breaches, up to €15M or 3%; bad information to regulators, €7.5M or 1%. SMEs and start-ups are capped at the lower figure, not the higher.
What it means for you, specifically
If you’re outside the EU: you’re likely still in scope. The Act reaches non-EU providers and deployers when an AI system is placed on the EU market or its output is used in the EU. A US-headquartered firm screening EU job applicants, or scoring EU customers, is caught. “We’re not an EU company” is not the exemption people assume it is.
If you’re inside the EU: you’re a deployer for most vendor AI, and the deployer duties — human oversight, logging, informing workers and affected people — attach to your high-risk systems when that layer applies in December 2027. The transparency duties attach in August 2026.
If you sit on the board: two questions for the next risk review. Do we have a complete inventory of our AI systems, each with an owner and a risk tier? And who is accountable for the August 2026 transparency duty? At up to 7% of global turnover, this is a board-level number, not an IT footnote.
If you’re the practitioner: you own the register and the classification. Treat the deferral as build time, not idle time — sixteen months is exactly enough to do it properly, and only if you start now. The one thing to ship before August is the AI-disclosure labelling.
The bottom line
The fine is not the real risk. The real risk is finding out in 2027 that you’ve got forty AI features already live across SAP, Copilot and Oracle and no one can say which are high-risk or who owns them. Classification is a half-day workshop now. It’s a fire drill later. The reprieve is only a gift if you spend it building the register — system, use case, tier, role, owner — rather than parking the topic for sixteen months.
Do this next month: make sure anything customer- or employee-facing that runs on AI actually says so. That’s the one duty that didn’t move.
General information, not legal advice. The new dates bind only once the Digital Omnibus is published in the Official Journal, so confirm before you rewrite the policy.
Between the Hype goes out every other week, on where enterprise systems and AI actually intersect. If it was useful, forward it to whoever owns your AI rollout.
Dive deeper: platform-by-platform guides
Everything mentioned above — the embedded capabilities, the activation steps, the honest limitations — is covered in detail in my practitioner guides. Each one walks through what’s actually available today, how to enable it, and where the gaps are.
SAP AI Guide
Joule across IBP, FI/CO, and MM — what works, what doesn’t, how to enable it.
Microsoft AI Guide
Copilot in Dynamics 365 Finance, SCM, and Microsoft 365 — capabilities and activation.
Oracle AI Guide
50+ Fusion Cloud agents across Finance, SCM, and HCM — what’s shipping today.
Executive overview: the strategic decisions that matter →
Between the Hype
A biweekly newsletter on where enterprise systems and AI actually intersect. Not the hype. The reality.
Subscribe on LinkedIn →