Executive summary
Two AI compliance stories landed in the same week and point in opposite directions if you only read the headlines. In Brussels, June's Digital Omnibus agreement pushed the EU AI Act's high-risk compliance deadlines out by sixteen to twenty-four months - but Article 50 transparency duties, GPAI enforcement powers and the Act's penalty regime all took effect exactly on schedule on 2 August, unaffected by the delay applied elsewhere. In Washington, Executive Order 14409 hit its own 1 August deadline to stand up a frontier AI model review framework that its own text insists creates no licensing requirement, no mandatory pre-clearance and no legal obligation on any developer to participate - while critics point out the framework carries enough unpublished access criteria and competitive pressure to function like one anyway. Read separately, these look like Europe tightening and America staying hands-off. Read together, the actual pattern is more specific: both regimes are, right now, enforcing the parts that are cheapest to verify and least dependent on classification judgement, while leaving the harder structural questions for later.
This paper sets out a practical readiness framework built around that reality. It argues for four things: treating "in force" and "in the news" as different categories that require separate tracking; building AI vendor due diligence questions around what a vendor's own frontier model has or hasn't gone through, on both sides of the Atlantic; avoiding the trap of reading either government's use of "voluntary" or "delayed" as a signal to deprioritise governance work generally; and building a compliance calendar that survives the fact that both regimes have already shown a willingness to move their own dates.
1. What is actually binding today, versus what is coming
Precision matters more than usual here because both regimes moved multiple provisions at once, on different tracks. On the EU side, Article 50's transparency duties - disclosing AI interaction to users, labelling AI-generated content and marking deepfakes - are live now, alongside the Commission's enforcement powers over general-purpose AI models and the Act's full penalty regime. None of that required the high-risk compliance date to arrive, because none of it depends on the harder classification work of determining whether a given system counts as high-risk under Annex III. The provisions that did move - standalone Annex III systems to 2 December 2027, AI embedded in already-regulated products to 2 August 2028 - are the ones that require exactly that classification and conformity-assessment work, which is also the work most enterprise AI governance programmes find hardest to do quickly.
On the US side, the frontier model review framework required by Executive Order 14409 has no compliance date for developers at all, because the order does not compel developer participation in the first place. What it does have is an 1 August deadline for the government's own working group - Treasury, the NSA, CISA, in consultation with NIST - to have a classified benchmarking process and a voluntary submission channel actually built. That's a materially different kind of deadline: it obligates an agency to finish building a process, not a company to comply with one. Enterprises tracking "1 August" in a compliance calendar without that distinction risk either over-reading US urgency that isn't there yet, or under-reading EU obligations that already are.
2. The verifiability pattern explains both regimes' sequencing
A regulator with limited enforcement capacity, on either side of the Atlantic, will rationally start with the obligations it can check by simply using the product. Is a chatbot labelled as a chatbot. Is synthetic content marked as synthetic. Did a developer submit a frontier model for review, or decline to. All three are binary, observable facts. High-risk classification under the EU AI Act, by contrast, requires a case-by-case judgement about a system's actual use context - the kind of determination that takes real regulatory capacity to make correctly at scale, which is exactly the machinery both the Digital Omnibus delay and the US framework's vagueness are implicitly buying time to build. Enterprises should read the current sequencing as regulators front-loading what they can verify cheaply, not as a signal about how seriously either regime intends to eventually enforce the harder parts.
3. Voluntary frameworks still belong in vendor due diligence
The absence of a legal requirement to participate in the US frontier model review framework does not mean participation is irrelevant to your own AI vendor risk assessment. Public critiques of the framework have already flagged that roughly 100 organisations sit on an undisclosed approved-access list, with no published eligibility criteria and no disclosed appeals process for a developer who disagrees with a determination. That opacity is a reason to ask your vendors more directly what they've done, not a reason to treat the question as unanswerable. A vendor's willingness to disclose whether its frontier models have gone through voluntary government review, and under what terms, is itself a useful signal about that vendor's broader transparency posture - independent of whether the review itself is legally required.
4. A moved deadline is information, not a reprieve
Both regimes have now demonstrated, within weeks of each other, that headline AI compliance dates are negotiable once the underlying political or administrative pressure shifts. The EU moved a deadline it had already fixed once. The US built a framework whose central definition - what counts as a "covered frontier model" - remains unpublished nearly two months after the order's own internal deadline passed. Enterprises that respond to either fact by deprioritising governance work are making the same mistake in both directions: treating a moved or vague deadline as evidence the underlying issue no longer matters, when it more often means the enforcement mechanism is still being built rather than abandoned. The safer posture is to keep the underlying classification and documentation work moving on a timeline your own team controls, so that whichever date eventually holds firm, you're not building the evidence base for it under pressure.
Practical framework checklist
The following translates the four principles above into decisions a compliance or AI governance programme can act on now.
- Maintain separate tracking for "legally binding today," "binding on a fixed future date" and "voluntary but market-pressured" - collapsing these into one compliance calendar is where most of the current confusion originates.
- Confirm today whether any AI system you provide or deploy in the EU triggers Article 50 disclosure duties, independent of your high-risk classification timeline - that obligation is live now regardless of company size or sector.
- Add a standing question to AI vendor due diligence: has this vendor's frontier model gone through the US voluntary review framework, the EU's GPAI Code of Practice obligations, both, or neither, and what was disclosed about the outcome.
- Continue EU high-risk classification and documentation work against the new fixed dates - 2 December 2027 and 2 August 2028 - without treating either date as licence to pause the work entirely.
- Review your compliance calendar quarterly rather than annually while both regimes remain this fluid - a framework built around dates fixed in June 2026 has already needed revision twice by August.
- Brief leadership on the distinction between "voluntary" and "optional in practice" explicitly - competitive and reputational pressure can produce near-universal participation in a framework with no legal force behind it at all.
Risks and how to manage them
The most common failure mode is treating either government's framing at face value without checking what it actually obligates. A team that reads "high-risk deadline delayed" as "the EU AI Act doesn't matter until 2027" will miss live Article 50 obligations that a regulator can act on today with minimal effort. A team that reads "voluntary" as "irrelevant to compliance planning" will miss the due diligence value of knowing whether a vendor's frontier model went through review at all. A second failure mode is assuming today's compute thresholds and access criteria will hold - both regimes have shown a willingness to change scope and dates within a single year, and a framework built around today's specifics will need revisiting sooner than a typical governance cycle expects. A third is treating US and EU obligations as a single combined timeline; they run on entirely different legal mechanisms and will not move together, so a delay in one carries no information about the other.
Conclusion
Neither regime went quiet in the first week of August 2026, whatever the headline read. The EU enforced exactly the obligations it could verify cheaply while buying time on the harder classification work. The US built the scaffolding for a review framework it insists carries no legal force, while leaving enough undefined that market pressure may end up doing more work than the statute never will. Enterprises that track what's actually binding today, keep vendor due diligence current on both frameworks, and treat every "delayed" or "voluntary" label as information rather than permission to stop will be the ones not scrambling when either government, as both have already shown they're willing to do, moves the next date. For a facilitated review of where your AI governance programme actually stands against both regimes as they exist today, contact sales@halfteck.com.