Aller au contenu
ConformiteBriefing Prioritaire

L'echeance de l'AI Act a bouge : ce qui s'applique reellement aujourd'hui

SV
Sophie Vandenberghe
Directrice conformite
9 août 2026
8 min de lecture
#AI Act#Digital Omnibus#Gouvernance de l'IA#Conformite#Reglementation europeenne#Transparence
Partager :
Conformite9 août 2026

The AI Act Deadline Moved: What Actually Applies Right Now

For two years, 2 August 2026 was the date every AI compliance roadmap was built around. It was the day the high-risk obligations of the AI Act were due to bite.

That date has moved — and a great many organisations have drawn the wrong conclusion from it.

What Changed

The Digital Omnibus on AI — Regulation (EU) 2026/1744 — was approved by the European Parliament on 16 June 2026, adopted by the Council on 29 June 2026, signed on 8 July 2026, and entered into force on 27 July 2026.

It defers the high-risk obligations:

| Category | Original date | New date | |---|---|---| | Standalone high-risk systems (Annex III) | 2 August 2026 | 2 December 2027 | | High-risk AI embedded in regulated products (Annex I) | 2 August 2027 | 2 August 2028 |

The stated rationale is to allow the harmonised standards and conformity assessment infrastructure to catch up. The obligations themselves are not weakened — they are postponed.

What Did Not Move

This is where roadmaps are going wrong. The deferral is limited to the high-risk regime. Everything else stands, and several obligations became applicable this month:

Applicable since 2 August 2026

  • Article 50 transparency obligations for providers and deployers — disclosure that a user is interacting with an AI system, that content is AI-generated, and labelling of deepfakes and emotion-recognition use

Applicable since 2 August 2025

  • General-purpose AI model obligations for providers — technical documentation, copyright policy, training-data summaries

Applicable since 2 February 2025

  • Prohibited practices — social scoring, untargeted facial-image scraping, emotion recognition in the workplace and in education, exploitation of vulnerability
  • AI literacy obligations for providers and deployers

Still coming

  • 2 December 2026 — watermarking and machine-readable marking of synthetic content under Article 50 remains on its original date

So an organisation that deployed a customer-facing chatbot, an AI-assisted screening tool, or any synthetic-media generation has live obligations today, regardless of the high-risk deferral.

The Trap in the Deferral

Three risks follow from treating December 2027 as breathing room:

1. Prohibitions are not deferred and carry the heaviest penalties. Emotion recognition in the workplace is the one that catches European employers most often — sentiment analysis in contact-centre quality monitoring is a frequent, unexamined example.

2. Transparency obligations apply to deployers, not just builders. You do not need to have trained a model to be in scope. Buying and deploying one is enough.

3. Standards work continues on the original assumptions. When the harmonised standards land, organisations that stood down their programmes will face the same workload in a shorter window, competing for the same scarce conformity assessment capacity.

What To Do With the Extra Sixteen Months

The deferral is genuinely useful — if spent on the work that was going to be hardest anyway:

Now

  1. Inventory. Most organisations still cannot list the AI systems they operate. Build the register, including embedded AI inside procured SaaS.
  2. Classify against prohibitions first. These are in force and non-negotiable. Emotion recognition and biometric categorisation deserve a specific check.
  3. Close the Article 50 gaps. Disclosure text, labelling, and the December 2026 watermarking requirement are concrete and near.
  4. Fix AI literacy. It has been an obligation since February 2025 and is commonly missed entirely.

Through 2027

  1. Provisional high-risk classification of the systems in your register
  2. Data governance and logging design — the parts that take longest to retrofit
  3. Post-market monitoring design
  4. Early engagement with notified bodies, before the queue forms

Reading the Regulation Correctly

The single most useful sentence to carry into a board conversation: the high-risk regime was postponed, the rest of the AI Act was not. An organisation that stands down its AI governance programme on the strength of the Omnibus headline is now less compliant than it was in July, not more.

Sources

AVIS // DEMANDER UNE CONSULTATION EXPERT

Besoin d'assistance opérationnelle ?

Nos analystes sont disponibles pour vous aider à mettre en oeuvre les bonnes pratiques et sécuriser votre organisation contre les menaces émergentes.

COMMS // ABONNEMENT AU FLUX D'INTELLIGENCE

Briefing reçu. Abonnez-vous pour en recevoir plus.

Recevez des briefings classifiés et des analyses de menaces directement dans votre boite de reception sécurisée.

S'abonner à la Newsletter