[nonimo]
ES Download soon

The EU AI Act's big deadline is 2 August. Does it touch you?

The EU’s AI Act entered into force in August 2024, but it applies in stages. The stage arriving on 2 August 2026 is the big one: the bulk of the regulation starts applying, including the obligations for high-risk AI systems listed in the Act’s Annex III, things like AI used in recruitment, credit scoring, education and access to essential services.

Why an Australian organisation should care at all

Three reasons, in descending order of urgency.

You sell into the EU, or process Europeans’ data. The Act can reach organisations outside Europe when the output of an AI system is used in the EU. If that is you, this deadline belongs on your compliance calendar next to the GDPR work you already did.

Your tools are global. The vendors behind the AI tools your staff use ship one product worldwide. Changes they make for European compliance, more transparency about AI-generated content, more documentation, tend to arrive for everyone.

Australia is moving in the same direction. The government has been consulting on AI guardrails for two years, and the reformed Privacy Act has already sharpened penalties and individual rights. The EU timeline is a preview of the questions an Australian regulator, insurer or enterprise client will eventually ask you: what AI do you use, for what, and what controls are on.

What the Act does not fix

Here is the part that matters for daily work: the AI Act regulates AI systems, who may build them, deploy them and under what documentation. It says very little about the oldest problem in the room, which is an employee pasting a client’s file into a chatbot. That was already a privacy problem under the GDPR in Europe and the Privacy Act here, long before the AI Act, and it remains one after 2 August.

A written AI policy does not stop it, because the moment of risk is a paste into a browser tab. That is the moment Nonimo works on: names, IDs and case numbers are masked on the computer, before the text leaves, and your organisation gets a monthly record showing the control was on. If a client or regulator asks how you govern AI use, that record is a better answer than a PDF nobody reads.

This is a plain-language summary, not legal advice. For how the AI Act applies to your organisation specifically, ask your privacy adviser.