On August 2, now days away, the EU AI Act reaches the date its drafters designed as the moment of general applicability, and the European hosting industry arrives at it in a state of well-earned confusion. On June 29 the Council gave final approval to the Digital Omnibus on AI, the simplification package that postpones the regulation’s most feared obligations, the high-risk regime, to December 2027 and beyond. Much of the industry heard that as “the AI Act is delayed.” It is not. What was delayed is one chapter of it.

August 2 still switches on the Commission’s power to fine general-purpose AI model providers up to 3 percent of global turnover, still activates the transparency obligations for every newly placed AI system that talks to humans or generates content, and still marks the start of member-state enforcement, ready or not, and mostly not: by mid-June, only nine of twenty-seven member states had fully designated the authorities meant to do the enforcing, and six had designated none at all. For European hosts and cloud providers, who have spent two years building AI inference products and wrapping them in the sovereignty flag, the question of which obligations land on whom on August 2 is no longer academic. It determines whether “sovereign AI hosting” is a sales pitch or a regulatory category. And the answer differs sharply depending on what, exactly, a host sells.

Key facts, the AI Act as of July 2026

  • What the omnibus changed: standalone high-risk (Annex III) obligations move from August 2, 2026 to December 2, 2027; product-embedded high-risk (Annex I) to August 2, 2028; national sandboxes to August 2027
  • What August 2, 2026 still activates: Article 101, the Commission’s power to fine GPAI model providers up to €15M or 3 percent of worldwide turnover; Article 50 transparency for AI systems placed on the market from that date; the AI Office’s power to verify GPAI compliance and order corrective measures
  • The penalty ladder (Article 99), in force since August 2025: €35M or 7 percent for prohibited practices, €15M or 3 percent for most violations, €7.5M or 1 percent for misleading regulators
  • The hosting boundary: selling raw GPU capacity creates no AI Act role; selling hosted model APIs can, and a fine-tune using more than one-third of the original model’s training compute makes the modifier a GPAI provider under the Commission’s guidelines
  • New in July: the Commission adopted its final Article 50 transparency guidelines on July 20, thirteen days before the duties they interpret become enforceable; a voluntary code of practice on marking AI-generated content closes its initial signatory window on July 27
  • Enforcement readiness is thin: by mid-June 2026, 9 of 27 member states had fully designated their AI Act authorities, 12 were partway there, and 6 had designated none

What the Omnibus Actually Rescheduled

The Digital Omnibus on AI is narrower than its reputation, and it reached the finish line barely ahead of the deadline it was rescuing:

  • November 19, 2025: proposed by the Commission
  • May 7, 2026: agreed in trilogue
  • June 16: endorsed by Parliament
  • June 29: adopted by the Council
  • July 8: signed; at press time it was still waiting for the Official Journal publication that has to come before the end of July for the new deadlines to bind ahead of August 2

That last gap is a piece of administrative suspense that says something in itself about how close to the wire this rescue arrived. The package’s centerpiece is timing relief for the high-risk regime: providers of standalone high-risk systems in Annex III (hiring tools, credit scoring, biometric systems and the rest) now have until December 2, 2027, and high-risk AI embedded in regulated products until August 2, 2028. It also postpones the member-state sandbox obligation to August 2027, shortens the grace period for marking already-marketed synthetic-content systems to December 2, 2026, and adds a new prohibition, applying from this December, on AI tools for non-consensual intimate imagery.

What it conspicuously does not touch: the GPAI chapter that has applied since August 2025, the penalties framework in force since the same date, and the two things arriving on August 2, 2026, namely Commission enforcement powers over GPAI model providers under Article 101 and the Article 50 transparency duties for newly placed systems. Anyone in the industry who filed the omnibus under “AI Act delayed two years” should reread it with counsel: the delay is real for high-risk deployers; it is close to irrelevant for infrastructure and model providers.

One chapter moved, the rest holds. Source: Regulation (EU) 2024/1689, Art. 113; Digital Omnibus on AI.

Where the Hosting Industry Actually Sits

The AI Act regulates AI systems and models, not computers, and that distinction is the industry’s most important legal fact. A host selling raw GPU instances, Hetzner selling dedicated GPU servers, OVHcloud selling public-cloud GPU capacity, is none of the Act’s regulated roles: not a provider (it develops no system and markets none under its name), not a deployer, not a distributor. Compute is out of scope, full stop, and the American neoclouds’ European business runs through exactly that door. The exposure begins one layer up, and it escalates in three steps.

Step one: hosting other people’s models. Serving third-party open-weight models behind an API, as OVHcloud AI Endpoints does with more than forty models, as Scaleway’s Generative APIs do with Mistral, Llama and Qwen from Paris, as IONOS’s AI Model Hub does from its own certified data centers, and as T-Systems’ AI Foundation Services do with more than fifteen LLMs. This, per the Commission’s July 2025 GPAI guidelines, does not in itself make the host a GPAI provider; the model’s originator keeps that role. But it does put the host in the value chain Article 25(4) formalizes, supplying “tools, services, components” to downstream providers, with written-agreement duties when a customer’s system is high-risk.

Step two: branding. A host that offers a model, or an AI website builder, chatbot, or support agent, under its own name and trademark is a provider of that system, with Article 50 duties from August 2: users must be told they are talking to a machine, and generated content must be machine-readably marked. Nearly every AI site-builder this industry has launched since 2024, and this publication has counted many, crosses that line by design.

Step three: modification. Fine-tune an open model using more than one-third of the original’s training compute, or rebrand it as your own, and you have become a GPAI model provider yourself, with the full documentation, copyright-policy and transparency apparatus that role carries, enforceable by the Commission from August 2. For essentially every host, step three is a line to stay behind deliberately; no hosting-scale fine-tune approaches a third of a frontier model’s training compute, which is precisely why the threshold is workable as a bright-line rule.

The Sovereignty Sales Pitch Meets Its Own Regulation

There is an irony in the timing that European strategy teams should sit with. The European hosts’ AI products are marketed on jurisdiction: OVHcloud’s “sovereign cloud” framing, Scaleway’s “your data remains yours, and only in Europe,” IONOS’s AI Model Hub with its GDPR and Gaia-X badging. That positioning, which we analyzed in the EU sovereign-cloud context, has been commercially effective precisely because European buyers price regulatory certainty. August 2 tests whether the sellers price it too. A sovereign-AI offer that cannot show its Article 50 marking implementation, its value-chain agreements, and its model-documentation flow-through is selling compliance it has not built, days before the framework it invokes becomes enforceable, and with no excuse of missing guidance: the Commission published its final transparency guidelines, all fifty-one pages of them, on July 20.

The competitive read cuts both ways. Done properly, compliance becomes the product: the host that ships inference with the transparency plumbing, the marking APIs, and the documentation pack ready-made is selling its customers their own August 2 readiness, a genuinely differentiated offer against US hyperscalers whose model partners signed the Code of Practice but whose enterprise customers still carry their own deployer duties. Done cynically, the sovereignty label becomes a liability magnet, because a regulator looking for an early, legible enforcement case may find a European provider that advertised compliance easier to make an example of than an American one that never claimed it. The Act’s fine ladder has applied since last August; what August 2 adds is the machinery and the political moment.

The Asymmetry and the Calendar

The strategic backdrop is a widening transatlantic asymmetry. While the EU pressed ahead with its enforcement build-out, Washington spent the year pushing in the opposite direction: a December 2025 executive order creating an AI Litigation Task Force to challenge state AI laws, and a March 2026 White House framework urging Congress to preempt them, which Congress has so far declined to do. There is still no comprehensive US federal AI statute. For hosting companies operating on both sides, the practical consequence is that AI-product compliance is becoming a European fixed cost with no American equivalent. Whether that cost nets out as burden or as barrier-to-entry depends on execution: the hosts that measure their compliance costs early will be the ones able to price them.

The Sovereignty Sales Pitch Meets Its Own Regulation

There is an irony in the timing that European strategy teams should sit with. The European hosts’ AI products are marketed on jurisdiction: OVHcloud’s “sovereign cloud” framing, Scaleway’s “your data remains yours, and only in Europe,” IONOS’s AI Model Hub with its GDPR and Gaia-X badging. That positioning, which we analyzed in the EU sovereign-cloud context, has been commercially effective precisely because European buyers price regulatory certainty. August 2 tests whether the sellers price it too. A sovereign-AI offer that cannot show its Article 50 marking implementation, its value-chain agreements, and its model-documentation flow-through is selling compliance it has not built, days before the framework it invokes becomes enforceable, and with no excuse of missing guidance: the Commission published its final transparency guidelines, all fifty-one pages of them, on July 20.

The competitive read cuts both ways. Done properly, compliance becomes the product: the host that ships inference with the transparency plumbing, the marking APIs, and the documentation pack ready-made is selling its customers their own August 2 readiness, a genuinely differentiated offer against US hyperscalers whose model partners signed the Code of Practice but whose enterprise customers still carry their own deployer duties. Done cynically, the sovereignty label becomes a liability magnet, because a regulator looking for an early, legible enforcement case may find a European provider that advertised compliance easier to make an example of than an American one that never claimed it. The Act’s fine ladder, 35 million euros or 7 percent for prohibited practices, 15 million or 3 percent for the bulk of violations, has applied since last August; what August 2 adds is the machinery and the political moment.

The Asymmetry and the Calendar

The strategic backdrop is a widening transatlantic asymmetry. While the EU pressed ahead with its enforcement build-out, Washington spent the year pushing in the opposite direction: a December 2025 executive order creating an AI Litigation Task Force to challenge state AI laws, and a March 2026 White House framework urging Congress to preempt them, which Congress has so far declined to do. There is still no comprehensive US federal AI statute. For hosting companies operating on both sides, the practical consequence is that AI-product compliance is becoming a European fixed cost with no American equivalent. Whether that cost nets out as burden or as barrier-to-entry depends on execution: the hosts that measure their compliance costs early will be the ones able to price them.

Nine of twenty-seven have the authorities the Act assumes. Source: artificialintelligenceact.eu national implementation tracker, June 17, 2026.

The immediate calendar is short:

  • Before August 2: confirm which offerings are systems versus components, verify no product crosses the branding or fine-tune lines unintentionally, paper the Article 25(4) agreements into AI-product terms of service, and read the July 20 transparency guidelines against every customer-facing AI feature. Providers that want to be on the initial signatory list of the content-marking code of practice have until July 27.
  • Before December 2, 2026: content-marking for anything already on the market, and the new intimate-imagery prohibition, which for hosts is an acceptable-use-policy and abuse-desk question.
  • Before December 2, 2027: the high-risk regime returns for the customers, not the infrastructure, which makes it a sales opportunity dressed as a deadline.

The omnibus bought the industry’s customers seventeen months. It bought the industry itself days.

About the Data

Every date and figure above was checked against the primary texts, Articles 3, 25, 50, 99, 101 and 113 of the AI Act via EUR-Lex, the Commission’s guidelines, and the Council’s adoption release, read alongside law-firm analyses, and re-verified on July 23, 2026, including the omnibus’s still-pending Official Journal status. Enforcement-readiness figures are the artificialintelligenceact.eu tracker’s, as of June 17. Product descriptions come from the providers’ own pages, re-checked the same day. This is analysis, not legal advice; the Official Journal text, once published, governs over any summary of it.