What actually applied on 2 August 2026, and what did not
Short answer. The EU AI Act's high-risk deadline did not bite on 2 August 2026. The AI Omnibus entered into force on 27 July 2026 and moved Annex III high-risk obligations to 2 December 2027 and Annex I obligations to 2 August 2028. What did apply on 2 August 2026 is the rest of the Act: the transparency obligations including Article 50, the governance rules, and enforcement responsibility, now held by the AI Office and the national authorities. For an AI agent insurance buyer that split matters in one specific way. The regulator's clock moved; the underwriter's did not. Carriers writing AI cover today are still asking for governance evidence, and the sixteen months of extra time is documentation time, not a reason to stop.
Key takeaways
- The AI Omnibus entered into force on 27 July 2026. Annex III high-risk obligations now apply from 2 December 2027, Annex I obligations from 2 August 2028. Anyone still planning against a 2 August 2026 high-risk date is planning against a superseded law.
- What did apply from 2 August 2026: the transparency obligations including Article 50, the governance rules, and enforcement responsibility, which the AI Office and the national authorities have held since that date. Article 5 prohibitions and the Article 4 literacy duty have applied since 2 February 2025, the GPAI obligations since 2 August 2025. The Omnibus changed none of these.
- Existing AI-relevant insurance policies continue on their current terms until renewal. Enforcement does not retroactively change a policy already bound. The practical shift happens at the next renewal conversation, not immediately.
- The deferral did not soften underwriting. Specialist capacity kept expanding through the whole period the delay was uncertain, because specialist carriers price to operator practice rather than to regulatory dates. Armilla already requires structured governance documentation, and the two-year runway to December 2027 is the window in which a buyer can build the evidence file cheaply rather than under deadline pressure.
- The gap between well-governed and poorly governed operators is expected to widen, not premiums uniformly. Operators with a documented Article 26 operator file are positioned for stable terms; operators without one face a materially harder renewal conversation.
- The practical task list is unchanged by the deferral: confirm Annex III exposure, assemble the operator file, flag near-term renewal dates for early review, and ask your broker directly what evidence will be expected next time.
What actually applied on 2 August 2026
Regulation (EU) 2024/1689, the EU AI Act, is a Regulation, not a Directive. It does not require national transposition to take legal effect; its provisions apply directly across all Member States from the dates set out in Article 113. As originally agreed, the most consequential phase of that schedule was set to activate on 2 August 2026 for the high-risk systems listed in Annex III.
That is not what happened. The AI Omnibus entered into force on 27 July 2026 and split the schedule in two. The high-risk half moved: Annex III systems, the standalone ones covering biometrics, critical infrastructure, education, employment, migration, asylum and border control, now come into scope on 2 December 2027. Annex I systems, the high-risk AI embedded in regulated products such as lifts and toys, come into scope on 2 August 2028. The other half arrived on time: from 2 August 2026 the transparency and governance rules apply, and the AI Office and the authorities of the Member States hold responsibility for implementing, supervising and enforcing the Act.
The distinction is worth stating precisely, because a great deal of commentary through the first half of 2026 collapsed it. Nothing was cancelled. The enforcement architecture is live, the supervisory bodies are named and operating, the transparency duties on generative systems bite now, and the obligations that have applied since 2 February 2025 and 2 August 2025, the Article 5 prohibitions, the Article 4 literacy duty and the GPAI obligations under Articles 53 and 55, were never in scope of the Omnibus at all. What moved is the compliance burden on high-risk deployments, and it moved by sixteen months for Annex III.
The honest reading for a buyer is that the regulatory calendar became more generous and the insurance market did not follow it. That divergence is the substance of the rest of this article.
What does not change: policies already in force
The first and most important point for existing policyholders is what did not change on 2 August. An insurance contract is a bilateral agreement bound at a point in time on agreed terms. The EU AI Act's entry into application does not retroactively alter the terms of a policy already in force, does not create new coverage obligations for the insurer, and does not automatically trigger a mid-term review. If you hold an AI agent insurance policy, a cyber policy with an AI-relevant extension, or a professional indemnity policy covering AI-assisted services, that policy continues to operate exactly as written until its renewal date.
What has changed is the regulatory backdrop against which your next renewal will be priced and underwritten, and, separately, your own compliance exposure under the AI Act, which is independent of your insurance position entirely. A business can be fully AI Act non-compliant and still have a currently valid insurance policy that responds to a covered loss; conversely, a business can be diligently compliant and still find the terms of its next renewal materially different from its last one, because underwriting reflects the market's assessment of risk going forward, not a retrospective judgement on the policyholder specifically.
How underwriting is expected to shift
The obvious inference from a sixteen-month deferral is that underwriting relaxes with it. That inference is wrong, and the reason is worth understanding because it is the single most useful thing a buyer can take from this period.
An underwriter is not pricing the regulator. It is pricing the loss. A badly governed AI agent that acts on a hallucinated instruction, leaks a data set or discriminates in a hiring screen produces a claim on the day it happens, under contract law, tort, the GDPR and, from 9 December 2026, the revised Product Liability Directive, none of which moved with the Omnibus. The AI Act's Article 99 penalty regime, EUR 15 million or 3 percent of worldwide annual turnover for a qualifying deployer or provider violation on an Annex III system, is one exposure among several, and it is the one that has been pushed out to 2 December 2027. The rest arrived on schedule or was already here.
What the Act supplies to an underwriter is not primarily a penalty to insure against. It is a vocabulary and an evidence standard. Article 9 risk management, Article 10 data governance, Article 14 human oversight, Article 26 deployer duties, Article 72 post-market monitoring, Article 73 incident reporting: these describe, in a form a regulator will recognise, precisely the operator practice that separates a governable AI deployment from an ungovernable one. That is why the questions on an AI submission look the way they do, and why they did not change on 3 August 2026.
The market response continues to appear in three specific underwriting mechanics. First, governance documentation questions that were once part of a broader risk questionnaire have become gating questions, meaning a submission without a credible answer does not proceed to a quote at all rather than proceeding with a loaded premium. Armilla operates close to this model, and so do the specialist programmes written into the Lloyd's market. It is a more significant change for carriers, some of the newer SME-focused entrants among them, that had priced AI risk more permissively. See what AI insurance underwriters ask before writing a policy for the question set itself.
Second, warranty language is likely to become more common in AI-specific coverage grants. A warranty is a stricter policy mechanism than a simple disclosure question: where a policy contains a warranty that the insured high-risk AI system meets applicable regulatory obligations, a breach of that warranty can void cover for losses connected to the breach, not merely adjust the premium retrospectively. Buyers should read new and renewing AI coverage carefully for warranty language specifically, since a warranty is a materially different commitment than a statement of fact made at inception.
Third, renewal-time evidence requests are likely to become more specific and more frequently timed to coincide with the AI Act's own documentation cycle. Where a carrier previously asked generally about AI governance, it is more likely now to ask specifically whether a conformity assessment has been completed for any Annex III system, whether an Article 26 operator file exists, and whether any incident has occurred that would trigger a reporting obligation under Article 73.
What buyers should actually check, deferral or not
Four concrete actions translate this into something a buyer can act on immediately rather than waiting for a renewal notice to surface it. None of the four is made less urgent by the move to 2 December 2027, because none of them is triggered by the AI Act. They are triggered by the next renewal, which for most European buyers falls well before December 2027.
Confirm Annex III exposure. Map each AI agent your business operates against the Annex III high-risk categories: employment and workforce management, access to essential private services including credit and insurance, education, law enforcement-adjacent functions, and several others. A system outside these categories carries a lighter compliance burden and a correspondingly different insurance conversation than one inside them.
Assemble the Article 26 operator file if you have not already. This is the single document set most likely to be requested at your next renewal regardless of which carrier you use: a current risk record for the deployed system, a named individual with adequate competence assigned to human oversight, a logging practice consistent with what the system generates automatically, and a documented incident protocol. The Annex III obligation to hold it is now due on 2 December 2027 rather than 2 August 2026, which changes when a regulator can ask for it and changes nothing at all about when an underwriter will. It is the same evidence set either way, and building it against a renewal date rather than a statutory one is the cheaper order to do it in.
Flag near-term renewal dates for early review. If any AI-relevant policy, standalone AI coverage, cyber, or professional indemnity, renews in the next two quarters, initiate the governance conversation with your broker now rather than at the renewal deadline. A carrier asking new questions for the first time at the point of renewal, with no advance notice, produces worse outcomes for the buyer than the same conversation started early with time to close documentation gaps.
Ask directly what evidence will be expected next time. Brokers and carriers are themselves adjusting their submission requirements in real time following this deadline. The most direct way to avoid surprises is to ask the specific question rather than assume continuity with your last renewal: what governance evidence will you expect from us at the next renewal, and has that changed since our last submission.
What this means for the certification and evidence layer
The connection between AI Act compliance documentation and insurance underwriting evidence has been a consistent theme across this network, and 2 August 2026 is the point at which that connection stops being anticipatory and becomes operational. An Article 26 operator file, a completed conformity assessment record, and a structured certification assessment such as the one offered through Agent Certified are not three separate documentation exercises. They draw on substantially the same evidence: system purpose and scope, training data governance, risk assessment findings, human oversight mechanisms, and incident response procedures. Building one evidence file that satisfies the regulator, the insurer, and any enterprise counterparty asking for AI assurance is materially more efficient than maintaining three separate ones, and it is the practical response to a deadline that has now, after eighteen months of anticipation, actually arrived.
Frequently asked questions
Frequently asked questions
Did the EU AI Act high-risk deadline take effect on 2 August 2026?
No. The AI Omnibus entered into force on 27 July 2026, six days before the deadline, and moved the high-risk obligations. Annex III high-risk systems now come into scope on 2 December 2027, and Annex I high-risk systems embedded in regulated products on 2 August 2028. What did apply from 2 August 2026 is the rest of the Act: the transparency obligations including Article 50, the governance rules, and enforcement responsibility, which the AI Office and the national authorities have held since that date. Article 5 prohibitions and the Article 4 AI literacy duty have applied since 2 February 2025 and the GPAI obligations since 2 August 2025, none of which the Omnibus changed.
How does EU AI Act enforcement change AI agent insurance underwriting?
Carriers are expected to move from optional governance questions to conditional underwriting for high-risk deployments, making evidence of Article 26 operator file compliance a condition of quoting or a warranty attached to the policy. A warranty breach can void cover for the connected loss, a materially different position from a rating factor that only affects premium.
Does my existing AI insurance policy still respond now that enforcement has begun?
Existing policies continue on their agreed terms until renewal; enforcement does not retroactively alter a policy already in force. Insurers pricing renewals after 2 August 2026 are more likely to ask directly about conformity assessment and Article 26 operator file status, and may propose new warranty language. Review your policy's renewal date against this shift rather than assuming current terms are unaffected indefinitely.
Does AI Act enforcement affect insurance premiums?
The direction of travel is a widening gap between well-governed and poorly governed operators rather than a uniform increase. Carriers that already price on governance documentation, Armilla among them, are expected to apply that differential more strictly as the Act's enforcement machinery becomes operational. Documented operators are positioned for stable terms; undocumented ones face higher premiums or tighter conditions. The deferral of the Annex III date to 2 December 2027 buys documentation time, not a reprieve: underwriters price the deployment in front of them, not the calendar.
What should an AI agent insurance buyer do in the 90 days after 2 August 2026?
Confirm Annex III high-risk exposure and conformity assessment status. Assemble the Article 26 operator file: risk record, named human oversight, logging schedule, incident protocol. Flag any AI-relevant policy renewing in the next two quarters for early governance review. Ask your broker directly what evidence will be expected at the next renewal.
References
- Regulation (EU) 2024/1689. EU AI Act. Articles 9-17, 26, 50, 70, 99, 113. OJ L, 12 July 2024.
- European Commission. AI Omnibus enters into force, 27 July 2026. Annex III high-risk obligations apply from 2 December 2027, Annex I from 2 August 2028. digital-strategy.ec.europa.eu (checked 17 August 2026).
- European Commission. Regulatory framework for AI: application timeline. From 2 August 2026 the AI Office and the authorities of the Member States are responsible for implementing, supervising and enforcing the AI Act. digital-strategy.ec.europa.eu (checked 17 August 2026).
- EU AI Act Member State transposition and enforcement status, tracked at agentliability.eu.
- Armilla Insurance Services. Affirmative AI Liability Insurance, underwritten by certain underwriters at Lloyd's. armilla.ai (checked 17 August 2026).
- Artificial Intelligence Underwriting Company (AIUC). AIUC-1 standard: 51 requirements, 130 controls, six pillars. aiuc.com (checked 17 August 2026).
- Directive 2024/2853. Revised Product Liability Directive. OJ L, 18 November 2024. Applicable from December 2026.