

For most companies, the EU AI Act has been easy to put off. It was a big, complicated law from Brussels, and the deadlines felt far away. That changed this spring. In a few weeks, Germany set out how it will enforce the Act at home, and the EU softened some of its toughest parts. If you are rolling out AI or building agentic workflows, the takeaway is simple: the rules are no longer abstract, and they affect your plans now. digital-strategy.ec.europa
This is where most of our projects begin. Before we talk about which model or which tool, we make sure the setup is legally sound and ready to scale. That is our "Strategic Foundation" phase. The recent changes make that groundwork both more urgent and a lot clearer. aiact-akademie
What already applies
The Act came into force in August 2024 and switches on in stages. The bans on the riskiest uses — things like certain social-scoring systems and emotion recognition at work or in schools — have applied since early 2025. Rules for general-purpose AI models followed in August 2025. The big date everyone watched was 2 August 2026, when most of the remaining rules were set to apply. ypog
One rule is easy to miss but applies to everyone: the AI literacy duty under Article 4, in force since February 2025. It simply means the people using AI need to understand what they are doing with it. There is no size threshold — a large corporation and a three-person team are both covered. This is why our academy starts with people, not licences. A licence does not create change, and it does not meet Article 4. A team that understands its tools is more productive, and compliant by default. artificialintelligenceact
What Germany just built
For a long time, Germany had not said who would actually enforce the Act — a gap that risked action from the European Commission. That changed on 11 February 2026, when the Federal Cabinet approved the draft KI-MIG (the AI Market Surveillance and Innovation Promotion Act). It names the supervising authorities, their powers, and the penalties, and is now moving through parliament — given the EU deadlines, likely fast. advisori
Germany chose not to build a new agency. Instead, the Bundesnetzagentur (Federal Network Agency) becomes the central authority, while existing regulators keep their areas — BaFin for finance, the state media authorities for journalism, and so on. So the first practical step for any company is simple: find out which authority covers your specific use case, because it can differ. The draft also lets high-risk systems be tested under controlled conditions — a regulatory sandbox. That maps directly onto our "Sandbox & Prototyping" phase: a safe environment, a proof of concept, real-world validation, now with a clear legal basis. ovidiusuciu
The Bundesnetzagentur has also opened an AI Service Desk — a single place where companies can ask how the Act applies to them. It even includes a "compliance compass" to check whether your systems are in scope. Think of it as an early on-ramp, not a hotline for emergencies. bundesnetzagentur
What changed in Brussels
The bigger news came on 7 May 2026. Parliament and the Council agreed on the Digital Omnibus on AI — a set of targeted changes meant to cut red tape without dropping the risk-based approach. It is not formally adopted yet, but the direction is clear and, for once, pragmatic. orrick
Three things matter most.
First, more time. High-risk systems under Annex III — AI used in hiring, education or insurance — now apply from 2 December 2027 instead of summer 2026. AI built into physical products like medical devices or machinery has until 2 August 2028. That is roughly 16 extra months to get ready. verifywise
Second, real relief for smaller firms. The simplified rules, once limited to the smallest companies, now cover all SMEs and "small mid-caps" of up to about 750 employees and €150 million in revenue. That means lighter documentation, standard templates, fairer fines, and easier access to sandboxes. jdsupra
Third, a clearer line on risk. AI that only assists a user or improves performance — and whose failure creates no safety or health risk — is no longer automatically "high-risk" just because it sits inside a regulated product. Genuinely safety-critical AI, like in a medical device, still is. ieu-monitoring
Two more points. The duty to label or watermark AI-generated content moves to 2 December 2026, while other transparency rules still start in August 2026. And lawmakers added a new ban on AI that creates non-consensual intimate images or child sexual abuse material. "Simplification" here means cutting needless burden — not weakening real protection. reneweuropegroup
What it means for your transformation
The honest read: the pressure on the exact date has eased, but the standard for doing it well has not. More time and less paperwork reward the companies that treat compliance as part of the design, not a last-minute scramble. That is how we work. In the assessment phase, we classify the risk of your planned AI and confirm which authority applies before anything goes live. In the sandbox phase, we test, now with the broader testing options behind us. In the rollout, we combine the global hyperscalers with European providers like IONOS, Hetzner, OVHcloud and Open Telekom Cloud, so GDPR and the AI Act become part of the architecture instead of a brake on it. pwc
One question stays open. The detailed European standards that explain exactly how to meet the high-risk requirements are not ready yet. That is the biggest unknown left in the timeline — and a good reason to start now: take stock of the AI systems you already use, lean on the Bundesnetzagentur's Service Desk, and get your team up to speed. digitalcompliance.snellman
The message from Berlin and Brussels is the same. The rules are real, the deadlines now favour those who plan ahead, and the advantage goes to companies that treat transformation and compliance as one roadmap, not two. Building that bridge between business and tech is what we do.
Sources and further reading
European Commission – AI Act overview: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
AI Act Article 4 (AI literacy), consolidated text: https://artificialintelligenceact.eu/article/4/
YPOG – "Art. 4 AI Act: The underestimated challenge on the road to AI": https://www.ypog.law/en/insight/art-4-ai-act
AIACT Akademie – "AI Act Implementation Law: Germany's AI Oversight Approved": https://www.aiact-akademie.de/en/news/ai-act-implementation-law-german-cabinet-ai-oversight
Advisori – German AI Act implementation (KI-MIG) analysis: https://www.advisori.de/en/blog/ki-mig-decided-what-the-ai-act-implementation-act-means-for-companies
Bundesnetzagentur – AI Service Desk: https://www.bundesnetzagentur.de/SharedDocs/Pressemitteilungen/EN/2025/20250703_KI_ServiceDesk.html
Bundesnetzagentur – Innovation and AI regulatory sandboxes: https://www.bundesnetzagentur.de/EN/Areas/Digitalisation/AI/05_Innovation/start.html
Orrick – "EU's Digital Omnibus on AI: 7 Key Changes You Need to Know": https://www.orrick.com/en/Insights/2026/05/EUs-Digital-Omnibus-on-AI-7-Key-Changes-You-Need-to-Know
Gibson Dunn – "EU AI Act Omnibus Agreement — Postponed High-Risk Deadlines and Other Key Changes": https://www.gibsondunn.com/eu-ai-act-omnibus-agreement-postponed-high-risk-deadlines-and-other-key-changes/
VerifyWise – "EU AI Act omnibus: what changed on 7 May 2026 and what to do": https://verifywise.ai/blog/eu-ai-act-omnibus-what-changed
Renew Europe – "AI Omnibus deal puts an end to 'nudifiers'": https://www.reneweuropegroup.eu/news/2026-05-07/ai-omnibus-deal-puts-an-end-to-nudifiers
European Commission press corner – "EU agrees to simplify AI rules": https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1024
The EU AI Act Gets Real in Germany: What the New Rules Mean for Your AI Plans
June 1, 2026
Felix Felix – Digital Development Manager @spyke
