Skip to content
CompliancePriority Briefing

The AI Act Deadline Moved: What Actually Applies Right Now

SV
Sophie Vandenberghe
Compliance Director
August 9, 2026
8 min read
#AI Act#Digital Omnibus#AI Governance#Compliance#EU Regulation#Transparency
Share:
ComplianceAug 9, 2026

The AI Act Deadline Moved: What Actually Applies Right Now

For two years, 2 August 2026 was the date every AI compliance roadmap was built around. It was the day the high-risk obligations of the AI Act were due to bite.

That date has moved — and a great many organisations have drawn the wrong conclusion from it.

What Changed

The Digital Omnibus on AI — Regulation (EU) 2026/1744 — was approved by the European Parliament on 16 June 2026, adopted by the Council on 29 June 2026, signed on 8 July 2026, and entered into force on 27 July 2026.

It defers the high-risk obligations:

| Category | Original date | New date | |---|---|---| | Standalone high-risk systems (Annex III) | 2 August 2026 | 2 December 2027 | | High-risk AI embedded in regulated products (Annex I) | 2 August 2027 | 2 August 2028 |

The stated rationale is to allow the harmonised standards and conformity assessment infrastructure to catch up. The obligations themselves are not weakened — they are postponed.

What Did Not Move

This is where roadmaps are going wrong. The deferral is limited to the high-risk regime. Everything else stands, and several obligations became applicable this month:

Applicable since 2 August 2026

  • Article 50 transparency obligations for providers and deployers — disclosure that a user is interacting with an AI system, that content is AI-generated, and labelling of deepfakes and emotion-recognition use

Applicable since 2 August 2025

  • General-purpose AI model obligations for providers — technical documentation, copyright policy, training-data summaries

Applicable since 2 February 2025

  • Prohibited practices — social scoring, untargeted facial-image scraping, emotion recognition in the workplace and in education, exploitation of vulnerability
  • AI literacy obligations for providers and deployers

Still coming

  • 2 December 2026 — watermarking and machine-readable marking of synthetic content under Article 50 remains on its original date

So an organisation that deployed a customer-facing chatbot, an AI-assisted screening tool, or any synthetic-media generation has live obligations today, regardless of the high-risk deferral.

The Trap in the Deferral

Three risks follow from treating December 2027 as breathing room:

1. Prohibitions are not deferred and carry the heaviest penalties. Emotion recognition in the workplace is the one that catches European employers most often — sentiment analysis in contact-centre quality monitoring is a frequent, unexamined example.

2. Transparency obligations apply to deployers, not just builders. You do not need to have trained a model to be in scope. Buying and deploying one is enough.

3. Standards work continues on the original assumptions. When the harmonised standards land, organisations that stood down their programmes will face the same workload in a shorter window, competing for the same scarce conformity assessment capacity.

What To Do With the Extra Sixteen Months

The deferral is genuinely useful — if spent on the work that was going to be hardest anyway:

Now

  1. Inventory. Most organisations still cannot list the AI systems they operate. Build the register, including embedded AI inside procured SaaS.
  2. Classify against prohibitions first. These are in force and non-negotiable. Emotion recognition and biometric categorisation deserve a specific check.
  3. Close the Article 50 gaps. Disclosure text, labelling, and the December 2026 watermarking requirement are concrete and near.
  4. Fix AI literacy. It has been an obligation since February 2025 and is commonly missed entirely.

Through 2027

  1. Provisional high-risk classification of the systems in your register
  2. Data governance and logging design — the parts that take longest to retrofit
  3. Post-market monitoring design
  4. Early engagement with notified bodies, before the queue forms

Reading the Regulation Correctly

The single most useful sentence to carry into a board conversation: the high-risk regime was postponed, the rest of the AI Act was not. An organisation that stands down its AI governance programme on the strength of the Omnibus headline is now less compliant than it was in July, not more.

Sources

ADVISORY // REQUEST EXPERT CONSULTATION

Need operational assistance?

Our analysts are available to help you implement best practices and secure your organization against emerging threats.

COMMS // INTELLIGENCE FEED SUBSCRIPTION

Briefing received. Subscribe for more.

Receive classified briefings and threat analyses delivered directly to your secure inbox.

Subscribe to Newsletter