The EU AI Act's big deadline moved. Half the internet hasn't noticed.

The AI Omnibus pushed high-risk obligations to December 2027 and August 2028, while the transparency rules landed on schedule. What applies now, and why so many guides are out of date.

By Yash Malviya

Published

European Union flags waving outside the European Parliament in Strasbourg
Photo: Tim Diercks / Pexels

What actually changed this summer

The EU spent two years telling companies that 2 August 2026 was the day the AI Act's high-risk regime would bite. Then, days before the deadline, the calendar moved. The AI Omnibus, formally Regulation (EU) 2026/1744, entered into force on 27 July 2026 and rewrote the Act's timetable. Stand-alone high-risk systems under Annex III, the list covering hiring and recruitment tools, credit scoring, education, access to essential services, law enforcement and border management, now have until 2 December 2027. AI embedded in products that already carry EU safety regimes, the Annex I set spanning machinery, medical devices, toys and lifts, moved out to 2 August 2028.

That is a sixteen-month reprieve on the obligations most software companies were sweating: risk management systems, data governance, technical documentation, logging, human oversight and registration in the EU database. The Commission sells the package as simplification rather than retreat, and paired the delays with lighter documentation duties for SMEs and, newly, for small mid-cap companies.

What is already law today

Read past the headlines about delay and the striking fact is how much of the Act is simply in force. The banned-practices list, including social scoring by public authorities, has applied since 2 February 2025. Obligations for general-purpose AI model providers have applied since 2 August 2025. And the piece that landed on schedule this August is the one most consumer products actually touch: Article 50 transparency. Systems that interact with people must disclose that they are AI, and synthetic media and deepfakes must be labelled. The Commission's AI Office also holds enforcement powers over general-purpose model providers as of 2 August 2026.

The Omnibus even added law while subtracting deadlines. It wrote a new prohibition into Article 5, banning AI systems that generate non-consensual intimate imagery or child sexual abuse material, with a transition that ends on 2 December 2026. The same date closes a four-month watermarking grace window for systems that were already deployed before this August. Anyone filing the Omnibus under "Brussels went soft" has not read it.

“Our businesses and citizens want two things from AI rules. They want to be able to innovate and feel safe. Today's agreement does both. With simpler and innovation-friendly rules, we make it easier to innovate without lowering the bar on safety.”

Henna Virkkunen, Executive Vice-President for Tech Sovereignty, Security and Democracy, European Commission press release IP/26/1024, 7 May 2026
Businesswoman sitting at desk reviewing contract with legal documents and newspaper
The transparency rules landed on schedule. The high-risk obligations moved to December 2027 and August 2028. Photo: https://kaboompics.com/ / Pexels

The internet has not caught up

Here is the practical problem: much of what ranks in search for the AI Act was written before late July, and it confidently tells you things that are no longer true. In one afternoon of research for this piece we found current-looking compliance guides still presenting 2 August 2026 as the binding high-risk deadline. Even the specialist resources disagree on details: the Future of Life Institute's AI Act tracker logs the Omnibus as entering into force on 31 August, while the Commission's own announcement says 27 July.

When sources conflict, dates beat prose. The regulation number is 2026/1744, the consolidated text lives on EUR-Lex, and any undated page that treats August 2026 as the high-risk deadline was written in a different legal reality. This is exactly why our regulation tracker attaches a source link and a verified-on date to every row. A compliance date without a date-of-checking is a rumour with a citation.

Sixteen months is a schedule, not a pardon

If you build or deploy Annex III systems for the EU market, December 2027 sounds distant and is not. The high-risk file takes quarters, not weeks: risk management that actually runs, training-data governance you can evidence, logs you retain, oversight a human can genuinely exercise, and registration at the end of it. Deployers carry duties as well as vendors, including oversight arrangements and informing affected people. Start with an inventory of which systems plausibly land in Annex III, then gap-analyse against the file you would need to show a regulator, and let the deferral absorb the engineering rather than the procrastination.

Member states also now have until August 2027 to stand up regulatory sandboxes, which are worth watching if you want supervised room to test.

The nearer risk surface is the part nobody delayed. If your product talks to people, generates media, or ships a general-purpose model, your obligations are current, and as of August the AI Office has the powers to make that point.

Our take

Brussels blinked on timing, not on direction. The high-risk regime survived intact and dated, the ban list grew, and the transparency rules arrived on schedule with an enforcer attached. Companies reading the delay as a pardon will spend late 2027 discovering how much of the file cannot be built in a quarter. Use the sixteen months. And check the date on anything you read about this law, including this article: it was accurate on the day in the byline, which is why it, and every row of our regulation tracker, carries one. The same week the compliance calendar moved, the price of frontier AI moved too: see what the GPT-6 price cuts actually mean.

Frequently asked questions

What did the AI Omnibus change about the EU AI Act's timeline?

The AI Omnibus, formally Regulation (EU) 2026/1744, entered into force on 27 July 2026 and rewrote the Act's timetable. Stand-alone Annex III high-risk systems, the list covering hiring, credit scoring, education and access to essential services, now have until 2 December 2027, moved from 2 August 2026. AI embedded in products under Annex I, such as machinery, medical devices and toys, moved out to 2 August 2028.

Which parts of the AI Act are already law today?

The banned-practices list, including social scoring by public authorities, has applied since 2 February 2025, and obligations for general-purpose AI model providers have applied since 2 August 2025. Article 50 transparency duties took effect on schedule on 2 August 2026, requiring systems that interact with people to disclose they are AI and synthetic media to be labelled. The Commission's AI Office also holds enforcement powers over general-purpose model providers as of 2 August 2026.

Did the Omnibus only delay obligations, or add any?

It added law while subtracting deadlines. It wrote a new prohibition into Article 5 banning AI systems that generate non-consensual intimate imagery or child sexual abuse material, with a transition that ends on 2 December 2026. That same date also closes a four-month watermarking grace window for systems that were already deployed before this August.

Why are so many online compliance guides out of date?

Much of what ranks in search for the AI Act was written before late July 2026, so it still presents 2 August 2026 as the binding high-risk deadline, which is no longer true. Even specialist resources disagree: the Future of Life Institute's tracker logs the Omnibus entering into force on 31 August, while the Commission's own announcement says 27 July. The article advises trusting dated sources, noting the regulation number is 2026/1744 and the consolidated text lives on EUR-Lex.

If the high-risk deadline moved to 2027, is there time to relax?

The article calls the sixteen-month move a schedule, not a pardon. The high-risk file takes quarters, not weeks: risk management that actually runs, training-data governance you can evidence, logs you retain, oversight a human can genuinely exercise, and registration at the end of it. Deployers carry duties as well as vendors, and member states have until August 2027 to stand up regulatory sandboxes.

Sources

What each one is, and whose it is.

  1. 1

    AI Omnibus enters into force, European Commission (July 27, 2026)

    Press report
  2. OtherIndependent of the vendor
  3. 3

    High-level summary of the AI Act (post-Omnibus timeline), Future of Life Institute / artificialintelligenceact.eu

    DocumentationIndependent of the vendor
  4. 4

    EU agrees to simplify AI rules to boost innovation and ban 'nudification' apps, European Commission (press release IP/26/1024) (May 7, 2026)

    Press report