Blog
EU AI Act 2026: Why companies need a sovereign AI infrastructure on OpenShift now
Large parts of the EU AI Act have applied since 2 August 2026 - but not quite as originally planned. With the "Digital Omnibus on AI", signed on 8 July 2026, the EU pushed back the deadlines for high-risk AI systems considerably. Here’s what applies now and what’s still to come.
What actually took effect on 2 August 2026
Unchanged - and not postponed - are the transparency obligations under Art. 50: AI-generated content must be labelled, and chatbots and deepfakes disclosed. These obligations apply to virtually any company using AI-assisted customer communication, content generation or chat features.
The postponed deadlines for high-risk AI
- 2 December 2027: obligations for high-risk systems under Art. 6(2) in conjunction with Annex III - e.g. AI in recruitment, education, creditworthiness assessment, or access to essential services.
- 2 August 2028: obligations for high-risk systems under Art. 6(1) in conjunction with Annex I - AI as a product or safety component of regulated products.
Why the time gained is no reason to sit back
The Digital Omnibus buys companies time - not an all-clear. Those who start now to inventory their AI systems, classify them by risk category and build governance structures won’t be under time pressure in 2027. Those who wait will end up doing that groundwork later, under exactly the pressure the deadline shift was meant to relieve.
The link to a sovereign AI infrastructure
The closer an AI application gets to high-risk territory - hiring decisions, credit scoring, customer assessment - the more traceability matters: which data went in, which model was used, who accessed what and when. On rented cloud infrastructure running proprietary, third-party-operated models, that’s only partially provable. A self-operated AI platform built on open standards - a container platform such as OpenShift as the operating foundation, combined with an open language model in your own data centre - gives companies back the control and auditability a later conformity assessment will need. That’s exactly the approach behind our Private AI offering: your own infrastructure instead of a black box, with clear responsibilities from day one.
Sources: DataGuard (2026), TÜV Consulting "Digital Omnibus on AI" (2026), Goldright EU AI Act guide (2026).
Next step
Questions about this topic?
We’ll help you assess what’s relevant for your environment – no sales pitch.
Book an initial consultation