The EU AI Act Just Hit Its Biggest Deadline. Here's What It Means If You Work in Paris Tech

Sun 20th Sep, 2026
General information — see our Disclaimer. Regulatory deadlines below reflect the status as of publication and are subject to change; verify current status with the European Commission before making compliance decisions.

If your startup touches hiring, credit scoring, healthcare, or education anywhere in the EU, you almost certainly fall under a law that reached its most consequential deadline this summer whether or not anyone on your team has read it. August 2, 2026 marked the point at which the majority of the EU AI Act's obligations became directly applicable, and Paris, home to a dense cluster of AI startups around Station F and beyond, is squarely in scope.

What the AI Act Actually Does

Formally Regulation (EU) 2024/1689, the AI Act entered into force in August 2024 and rolled out its obligations in phases rather than all at once. It sorts AI systems into risk tiers unacceptable, high, limited and minimal with obligations scaling directly with the classification. Prohibited practices, including social scoring and manipulative subliminal techniques, were banned starting in February 2025. General-purpose AI model obligations, covering systems like large language models, took effect in August 2025, alongside the creation of the European AI Office and national enforcement authorities.

August 2026 was the big one for most companies: high-risk systems under Annex III of the regulation think AI screening job candidates, assessing loan applications, or supporting medical diagnoses now require documented risk management, technical documentation, human oversight, and conformity assessment before being placed on the market. Penalties for the most serious violations reach €35 million or 7 percent of global turnover, whichever is higher, a ceiling that exceeds even GDPR's maximum fines.

The Twist: Some of This May Still Move

Here's what makes this a genuinely live story rather than a settled one. In November 2025, the European Commission proposed a "Digital Omnibus on AI," introducing a mechanism that ties some high-risk application dates to whether the harmonized technical standards needed to comply are actually ready. If adopted as proposed, standalone Annex III high-risk rules could be pushed to as late as December 2027, with obligations for high-risk AI embedded in regulated products medical devices, vehicles, industrial machinery potentially extending into 2028.

That proposal had not been finalized as of this article's publication date, and it could pass, change significantly, or fail entirely by the time you're reading this. Businesses that treat a possible delay as a reason to postpone compliance work are taking a real risk on an unconfirmed outcome. The AI literacy obligation and the prohibited-practices ban are already in force regardless of how the Digital Omnibus discussion resolves, and the August 2026 high-risk obligations remain the legally binding deadline unless and until an amendment is formally adopted. Check the European Commission's official AI Act page directly for the current status before making a compliance decision based on a possible delay.

Why Paris Specifically

France has positioned itself deliberately at the center of the EU's AI conversation Paris hosted the AI Action Summit in February 2025, drawing heads of state and major AI labs to the city, and French-founded AI companies have become some of the most closely watched in Europe. That visibility cuts both ways: French startups building AI products for hiring platforms, healthcare tools, or financial services are exactly the kind of high-risk use cases the regulation targets most directly, and French national authorities are among those now empowered to request technical documentation, access training data, and conduct audits.

The law's reach also extends well beyond companies physically based in the EU. Any business in San Francisco, Singapore, or anywhere else serving EU users or deploying AI systems that affect people in the EU falls within scope, with no blanket exception for research-stage products.

What Founders Should Actually Be Doing Now

Compliance specialists tracking the rollout consistently point to the same starting checklist regardless of company size: build an inventory of every AI system in use or under development, map which legal role the company holds for each one provider or deployer and classify each use case against the regulation's risk tiers rather than assuming the company as a whole is or isn't "high-risk." A customer service chatbot and an automated hiring tool sit in entirely different regulatory categories, even inside the same company.

For very early-stage startups, the practical entry point is usually simpler than it sounds: confirm whether any current or planned product function falls into a high-risk category listed in Annex III, and if so, begin technical documentation now rather than waiting for final clarity on the Digital Omnibus timeline. Waiting for perfect certainty on the compliance calendar has already left a number of companies with less runway than they expected when obligations locked in this August.

Sources: European Commission's official AI Act overview, the text of Regulation (EU) 2024/1689 on EUR-Lex, and reporting on the Digital Omnibus proposal from Startups Magazine and Leaders League.

Photo by cottonbro studio on Pexels