AI Agent Governance for SMBs: What August 2 Actually Changes
August 2 is in every compliance newsletter — and just before the deadline, Brussels postponed the high-risk rules to late 2027. So it's all moot? Exactly wrong. What actually applies to SMBs running AI agents, and the one-page governance minimum.
From August 2, 2026 the EU AI Act's transparency duties and penalty framework apply, while the high-risk obligations were postponed to December 2027 via the omnibus package — and the AI literacy duty has been in force since February 2025. For SMBs running AI agents, a one-page minimal set covers the essentials: tool register, data residency, named owners, human-in-the-loop points, audit trail, training evidence, and output control on critical paths.
August 2, 2026 has been sitting in every compliance newsletter for months: the EU AI Act becomes "fully applicable." And shortly before the date, Brussels postponed the high-risk obligations to December 2027 via the omnibus package. The common reaction in smaller companies: exhale, shelve the topic again.
That's the wrong conclusion — for two reasons. First, the part that matters most has been in force for a while. Second, AI agent projects aren't dying of regulation right now; they're dying of missing governance. Let's take it in order. (Upfront: this is a practitioner's read, not legal advice.)
What actually applies when
The timeline, without the legalese:
- Since February 2025: prohibited practices are banned, and the AI literacy duty applies — if you deploy AI, you must demonstrably train your staff. That covers practically every company using agents or assistants.
- Since August 2025: governance rules for the large foundation models (GPAI) — the providers' problem, not yours, but it shapes which models you can buy with a clear conscience.
- From August 2, 2026: the rest of the regulation becomes applicable, including transparency duties (users must know they're interacting with AI; AI-generated content must be labeled) and the penalty framework.
- Postponed to December 2027: the obligations for high-risk use cases (hiring, critical infrastructure, education, justice …) — via the omnibus decision. Postponed, not scrapped.
For a typical SMB using agents for support, documents, code, or back-office work, that means: most of the duties that concern you apply today or from this summer. The 2027 postponement covers the heavy cases — and anyone operating there needs the extra time anyway.
What actually kills agent projects
Gartner predicted as early as mid-2025 that over 40 percent of agentic AI projects will be cancelled by the end of 2027 — because of rising costs, unclear business value, and missing risk controls. Not because of Brussels.
It matches what I see in DACH companies: the agent gets introduced because pressure from above is high. Three months later, nobody knows which tools are actually in use, what data they see, or who answers for the output. Then an incident happens — a data leak, a wrong answer to a customer, an agent with too many permissions — and the project is politically dead.
Governance isn't the brake on AI speed. It's what makes AI speed survivable. The same logic as with AI-generated code: the control layer decides whether it holds or tips over.
The minimal set: governance on one page
No framework, no committee, no 60-page policy. This fits on one page and covers the essentials for most SMBs:
- Tool register. Which AI tools and models are approved, and which data classes may go in (public / internal / personal)? A living document, not a PDF buried in the intranet.
- Data residency settled. Where do model and data run — EU, Switzerland, US? Is a data processing agreement in place? For personal data this isn't AI-Act extra credit; it's GDPR duty.
- Owners named. One named owner per agent use case. "IT" is not a name.
- Human-in-the-loop points defined. Where does a human decide, always — payments, outbound customer communication, personnel decisions, production code?
- Audit trail. Logs: which agent did what, when, with which data. Without it, every incident is unexplainable — and every compliance question unanswerable.
- Training evidence. The AI literacy duty has applied since February 2025. A documented half-day training per role is enough to start — zero documentation is not.
- Output control on critical paths. Agent output that goes external or changes systems passes review. Spot checks are fine where the risk is small.
The Swiss angle — and advantage
Switzerland isn't in the EU: the AI Act doesn't apply directly here. But it reaches extraterritorially — serve customers in the EU market or deliver AI output into it, and you're in scope. For Swiss SMBs that means: you need the minimal set above either way.
And there's the other side of the coin: Swiss- or EU-hosted models, clean data residency, and a solid audit trail are currently a selling point in DACH B2B. "We can document what our AI does with your data" wins deals against vendors who can't.
What you can do this week
Build item 1: the tool register. One hour with your team leads, one table — tool, model, hosting region, allowed data classes, owner. You will almost certainly find two things: a tool nobody knew about, and a data class that should never have gone in. That's exactly what the register is for.
And if you want agents in production but the architecture, audit trail, and data residency aren't there yet: that's precisely the kind of engagement we take on — AI and agent architecture, auditable and CH/EU-hosted. Write to hire@halvic.ch.
Frequently asked questions
What does the EU AI Act require from August 2, 2026?
From that date the remaining parts of the regulation become applicable, including transparency duties — users must know they are interacting with AI, and AI-generated content must be labeled — plus the penalty framework. Prohibited practices and the AI literacy training duty have already applied since February 2025, and GPAI governance rules for model providers since August 2025.
Were the EU AI Act high-risk rules postponed?
Yes. Shortly before the August 2, 2026 date, Brussels postponed the obligations for high-risk use cases — hiring, critical infrastructure, education, justice — to December 2027 via the omnibus package. Postponed, not scrapped. For a typical SMB using agents for support, documents, code, or back-office work, most relevant duties apply today or from summer 2026 regardless.
Does the EU AI Act apply to Swiss companies?
Not directly — Switzerland is not in the EU. But the Act reaches extraterritorially: if you serve customers in the EU market or deliver AI output into it, you are in scope. Swiss SMBs therefore need the same minimal governance set — and clean data residency plus a solid audit trail is currently a selling point in DACH B2B deals.
Why do AI agent projects fail in companies?
Gartner predicted in mid-2025 that over 40 percent of agentic AI projects will be cancelled by end of 2027 — because of rising costs, unclear business value, and missing risk controls, not regulation. The typical pattern: an agent gets introduced under pressure, nobody tracks which tools see which data or who owns the output, and the first incident kills the project politically.