One year after the EU AI Act took effect, two camps have formed among the companies it applies to. One group read the fine print, understood exactly what changed and what didn’t, and moved on with confidence. The other heard “delay” and stopped paying attention entirely.

Only one of those camps is right. And if you’re not sure which one you’re in, that’s worth fixing before a regulator makes the distinction for you.

We sat down with our Data Protection Officer, Rui Serrano, to walk through the EU AI Act’s four risk tiers, what the July 2026 Omnibus actually pushed back, and the obligations that are already fully enforceable today, delay or no delay. It’s a sharper, more specific conversation than most of what’s out there on this topic, and it covers ground a lot of companies are quietly getting wrong.

▶ Watch the full episode: In/Sight: EU AI Act Explained

What you’ll learn in this episode:

  • Where your AI use falls among the four risk tiers, minimal, limited, high risk, or forbidden, and why that classification depends on how you use a tool, not just which tool it is
  • What the Omnibus really delayed (three specific dates: December 2026, December 2027, and August 2028) and the one distinction most companies are missing about what it didn’t touch
  • Why “the deadline moved” is the wrong takeaway for most organizations, and what’s already required starting from August 2026
  • The one-line test Serrano uses to explain AI risk classification that’s stuck with everyone who’s heard it

Watch the full conversation, or catch it on Spotify!

InSight SPOTIFY

Not sure where your organization stands?

Insight Assurance independently evaluates EU AI Act readiness, including classification rationale, documentation, evidence, and control alignment. Contact us to talk with the professionals at Insight Assurance.