2026 is the year in which AI regulation moves from announcement to enforcement. The UN has presented its first independent global report on AI risks, Germany is getting a central AI supervisory authority, and the EU AI Act is postponing its strictest deadlines while remaining in place in substance. For businesses that use or develop AI, this is no longer a side issue but a question that directly affects budgets, liability and market access.
The EU AI Act applies in stages. Which obligations affect a business depends on its role, the system used and the specific use case. At the same time, data protection, internal responsibilities, AI literacy and documented human oversight are becoming more important. Businesses should therefore first take stock of the systems and use cases they operate before assessing individual deadlines in isolation.
The first global UN report on AI risks
On 26 August 2025, the UN General Assembly established two new mechanisms through Resolution A/RES/79/325: the Independent International Scientific Panel on AI and the Global Dialogue on AI Governance[1]. The panel consists of 40 scientists, selected from more than 2,600 applications from 140 countries, and is co-chaired by Yoshua Bengio (2018 Turing Award) and Maria Ressa (2021 Nobel Peace Prize)[2].
On 1 July 2026, the panel published its first “Preliminary Report”, the first independent global scientific assessment of the opportunities, risks and impacts of AI[3]. Its core message is uncomfortable: AI capabilities are developing exponentially faster than both scientific understanding and regulatory frameworks, and current safeguards cannot keep pace with the speed of development[4]. Shortly afterwards, on 6 and 7 July 2026, the first session of the Global Dialogue on AI Governance took place in Geneva, with representatives from more than 170 countries[5]. A second session is planned for May 2027 in New York.
The UN report is not a law and has no direct legal effect. It is, however, the first globally coordinated, scientifically grounded basis on which future national and regional regulation, including outside the EU, is likely to draw increasingly.
Germany is getting a central AI supervisory authority
In parallel, Germany has reorganised its national AI supervision. On 10 and 11 February 2026, the Federal Cabinet adopted the AI Market Surveillance and Innovation Promotion Act (KI-Marktüberwachungs- und Innovationsförderungsgesetz, KI-MIG) as the national act implementing the EU AI Act[6]. The Bundestag passed the act with minor amendments on 11 June 2026; at that point, approval by the Bundesrat was still pending[7].
The central supervisory authority will be the Federal Network Agency (Bundesnetzagentur), where a dedicated body is being set up: the KoKIVO, the Coordination and Competence Centre for the EU AI Act[8]. The structure is hybrid: the Federal Network Agency and its KoKIVO are responsible for AI systems outside the media sector, the state media authorities (Landesmedienanstalten) cover AI in the press, broadcasting and online media, and BaFin remains responsible for financial services on a sector-specific basis[9]. Of practical relevance for businesses: the KoKIVO offers an AI Service Desk as a central point of contact and the free “Compliance Kompass” for an initial assessment of a company's own risk class[10]. From 2 August 2026, the competent authorities can initiate initial market surveillance measures, request documents, test systems and require deficiencies to be remedied[11].
EU AI Act: same substance, postponed deadlines
The EU AI Act has been in force since 2024 and applies in stages. Article 4 and Article 5 have applied since 2 February 2025. The Digital Omnibus amended Article 4 with effect from 27 July 2026: providers and deployers must take measures to promote the AI literacy of the persons involved, but are not required to guarantee a specific level of literacy[12]. Since 2 August 2025, obligations for general-purpose AI models and key parts of the governance structure have also applied[13]. The voluntary Code of Practice for GPAI models covers transparency, copyright, and safety and security[14].
The most important change for 2026 has now been adopted. Regulation (EU) 2026/1744 was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026[15]. High-risk obligations for stand-alone systems under Annex III now apply from 2 December 2027. For high-risk AI in products that are already regulated under Annex I, the date is 2 August 2028[16].
| Obligation | Originally planned | Current status (as of July 2026) |
|---|---|---|
| AI literacy and prohibited practices | 2 February 2025 | Since 2 February 2025; Article 4 amended on 27 July 2026 |
| GPAI obligations, governance structure | 2 August 2025 | In force since 2 August 2025 |
| High-risk obligations (Annex III) | 2 August 2026 | Postponed to 2 December 2027 |
| High-risk obligations (Annex I, regulated products) | 2 August 2026 | Postponed to 2 August 2028 |
| German market surveillance begins | Not specified | From 2 August 2026 (Federal Network Agency/KoKIVO) |
Important for context: the high-risk rules have been postponed, not abolished. However, the Omnibus has also adjusted certain requirements and procedures in substance. These include the new wording on AI literacy, changes to registration and post-market monitoring, and additional simplifications for smaller companies[15]. Penalties and specific responsibilities should therefore be assessed on the basis of the consolidated legal position and the specific use case.
Not everyone welcomes the postponement: as early as November 2025, a coalition of more than 130 civil society organisations, including EDRi, noyb and ICCL, warned of the “biggest rollback of digital fundamental rights in EU history”, partly because of the planned redefinition of personal data[20].
The broader risk debate: from safety research to waves of lawsuits
Beyond regulation, the expert debate on AI risk also remains very much alive. Yoshua Bengio, one of the most influential AI researchers in the world, has warned that highly advanced AI systems could develop their own self-preservation goals and pose a serious risk within a decade. In June 2025, he founded the non-profit organisation LawZero with 30 million dollars in start-up funding, with the aim of developing safer, non-agentic AI architectures[21]. In early 2026, he was cautiously more optimistic in an interview with Fortune: new research, he said, points to technical approaches to addressing key safety risks[22].
At the same time, current cases show how concrete the risks already are. In 2026, xAI and Grok face at least six major lawsuits in the US and UK, as well as regulatory investigations in the EU, the UK and California, over the creation of sexualised deepfake images. An analysis by the Center for Countering Digital Hate calculated that Grok generated around three million sexualised images in just eleven days, including an estimated 23,000 depicting children[23]. In parallel, a wrongful death lawsuit is pending before a US federal court against OpenAI, alleging that design defects in GPT-4o reinforced a user's delusions[24]. Cases like these are the reason why supervisory authorities worldwide are not relying on voluntary commitments alone.
Labour market: a shift rather than a collapse
A look at the labour market reveals a more nuanced picture than the frequently cited worst-case scenario. According to the World Economic Forum's Future of Jobs Report, AI and related technologies will create around 170 million new jobs worldwide by 2030 and displace around 92 million existing ones: a net gain of 78 million, although it will largely affect different groups of people from those who are displaced[25]. According to the WEF, more than half of the global workforce will need further training over the next four years, and employees with AI skills earn 56% more on average[26]. The IMF puts the share of AI-exposed employment in advanced economies at up to 60%; so far, there has been no rise in overall unemployment, but there has been a decline in hiring rates for young people starting their careers in particularly exposed occupations[27].
Where German SMEs currently stand
According to the Bitkom AI Study 2026, the share of German companies actively using AI rose from 17% in 2024 to 41% in 2026; 48% are planning to introduce it, and only 11% explicitly reject AI[28]. There is, however, a clear gap: while more than 60% of companies with 500 or more employees already use AI, traditional SMEs below that size are lagging behind[29]. The biggest obstacles according to Bitkom: 53% cite a lack of AI skills in their teams, 41% uncertainty about data protection and 37% unclear costs[30]. It is also notable that 33% of companies report that AI is more expensive than expected, and 19% have already cut jobs as a result[31], an indication that unstructured AI use without a clear assessment of cost-effectiveness can quickly backfire.
The opportunity: putting sound practices in place early pays off
The new requirements can create a tangible advantage. Businesses that clearly document the AI systems they use, responsibilities, data flows and review processes can answer security and compliance questions from larger business customers faster and more credibly.
Legal certainty as a selling point
Businesses that know and document their AI risk class can actively use it in sales as a signal of trust, especially with larger customers that have their own compliance requirements.
Less administrative effort later
According to industry analyses, businesses that implement the GPAI Code of Practice or comparable standards early benefit from reduced effort and greater legal certainty compared with competitors that only react shortly before the deadline.
Governance shortens time to market
According to a WEF analysis, when data protection and risk assessment are built into the development process from the outset rather than added afterwards, operational risks and support costs fall noticeably.
Trust in the supply chain
Sound AI documentation helps suppliers and service providers respond transparently to the security and data protection requirements of larger business customers.
“Regulation is often seen as a brake. For businesses that put sound practices in place early, it is in fact a filter that slows down precisely those competitors that do not.”
Conclusion
The UN report makes clear that AI capabilities are growing faster than our understanding of their risks. Germany's AI supervision at the Federal Network Agency and the EU AI Act ensure that this global debate is turned into concrete, enforceable obligations, even if the strictest deadlines now lie further in the future. Businesses that use this time to document their AI use properly, build data protection in from the outset and know their own risk class will gain a lead that can no longer be made up in 2027 and 2028.