The EU AI Act's deadline moved to 2027. Yours didn't

The EU AI Act's deadline for high-risk AI systems has moved from August 2, 2026 to December 2027. Read that as a reason to relax, though, and you're setting yourself up for an expensive surprise.

The change comes from the Digital Omnibus on AI, the first serious amendment to Regulation (EU) 2024/1689 since it took effect in 2024. It has now completed the full process: the European Parliament backed it on June 16, 2026, the Council of the EU gave final sign-off on June 29, the text was signed on July 8, it was published in the Official Journal on July 24, and it entered into force on July 27, 2026.

What moved is the timing of the heavy machinery. High-risk obligations now arrive in two later waves:

Standalone high-risk systems under Annex III, the use-based bucket that covers recruitment tools, credit scoring, and systems used in education, law enforcement and border control, shift from August 2, 2026 to December 2, 2027.

High-risk AI baked into already-regulated products under Annex I, think medical devices, machinery and lifts, shift to August 2, 2028.

These are the obligations that soaked up most of the boardroom oxygen: risk management under Article 9, data governance, technical documentation, human oversight, conformity assessment and post-market monitoring. All of it pushed back.

So it would be easy to conclude the pressure is off. It isn't.

So it would be easy to conclude the pressure is off. It isn't.

August 2 still matters, and it reaches more of you

The Omnibus delayed the high-risk regime. It left the transparency rules alone, and it left general-purpose AI alone. From August 2, 2026, two things go live that touch far more organisations than the high-risk rules ever will.

First, the Article 50 transparency obligations become enforceable. Like GDPR, the Act reaches past the EU's borders: the duties attach to the AI system and its users, not to where you're headquartered. A US or Gulf company serving EU customers is as exposed as a business in Berlin.

Second, GPAI enforcement kicks in. The EU AI Office, the body inside the European Commission that supervises general-purpose AI, gets its teeth, and national market surveillance authorities across all 27 member states can start investigating and fining.

Article 50 isn't a single rule. It's four duties, and they land on different actors:

  • Article 50(1), chatbot and assistant disclosure. If your system talks to people, you have to tell them they're dealing with a machine, right at the start, not somewhere in the terms and conditions. Agentic AI acting on a user's behalf is covered too.
  • Article 50(2), synthetic content marking. AI-generated or edited text, images, audio and video have to carry a machine-readable marker so other platforms can detect they're synthetic. In practice this points at C2PA Content Credentials, the provenance standard the Commission's own Code of Practice holds up as the example.
  • Article 50(3), emotion recognition and biometric categorisation. Deploy one of these and you have to tell the people it's being used on.
  • Article 50(4), deepfakes and public-interest text. Anything realistic enough to pass as genuine has to be labelled, even without intent to deceive. AI-written text on matters of public interest needs a flag as well, unless a human genuinely edited it and owns the result. A quick skim doesn't clear the bar.

Many companies get this wrong. You are responsible for following the rules whether you built the AI system or bought it from another provider. Even if the platform adds its own label, you still have to meet your legal obligations. If you don't, you could face fines of up to €15 million or 3% of your global annual turnover, whichever is higher, enforced by regulators in any EU member state.

There is one exception. If a generative AI tool was already on the market before August 2026, providers have until 2 December 2026 to meet the Article 50(2) requirement for adding machine-readable labels to AI-generated content. This is a limited grace period, not a delay for all Article 50 rules. The European Commission's Transparency Code of Practice, published on 10 June 2026, offers helpful guidance, but following it is optional. The legal requirements in Article 50 are still mandatory.

The compliance calendar, at two speeds

The cleanest way to hold this in your head: the AI Act now runs on two clocks.

  • August 2, 2026 (unchanged): Article 50 transparency obligations enforceable, GPAI enforcement live, market surveillance authorities in all 27 member states able to investigate and fine.
  • December 2, 2026: machine-readable marking under 50(2) for generative tools already on the market before August, plus the new Article 5 prohibitions, including AI-generated non-consensual intimate imagery and child sexual abuse material.
  • December 2, 2027: high-risk obligations for standalone Annex III systems.
  • August 2, 2028: high-risk obligations for Annex I embedded systems.

That gap between the clocks is the whole point. The deadline that moved affects fewer businesses than the one that held.  If you run a customer-facing chatbot or generate marketing content, your first real encounter with the AI Act lands next month, not in 2027.

Postponed isn't the same as gone

Two things matter here before anyone reroutes the compliance budget.

The deferral is now settled law, not a promise. With the Omnibus in force as of July 27, 2026, the revised dates are binding and the earlier uncertainty about whether they would apply has gone. That cuts both ways: there's no longer any ambiguity to hide behind, and no version of the timeline in which the high-risk obligations simply disappear.

And the architecture of the Act hasn't budged. The risk tiers, the governance model, the classification logic, the substance of the obligations, none of it was ever on the table. High-risk duties were postponed, not deleted. The Omnibus even keeps a registration step for systems you've classified as not high-risk, with lighter Annex VIII information requirements but the underlying assessment still documented, a reminder that "not high-risk" never meant "nothing to do."

It also added new prohibitions and widened the AI Office's reach over general-purpose AI providers. And a handful of quieter changes are now confirmed: the AI literacy duty under Article 4 was softened to a "take measures" standard rather than a guaranteed level of competence, though deployers of high-risk systems still face specific training duties under Article 26(2); Member States now have until August 2, 2027 to stand up their regulatory sandboxes; and the legal basis for processing special-category data to detect and correct bias was widened to all AI systems, under a strict-necessity test. Postponement, lighter paperwork, and a longer regulatory arm, all in the same amendment. That isn't a retreat.

Why the extra time is worth having

The urge to delay compliance efforts underestimates how long this work really takes.

The high-risk rules got pushed back for a concrete reason. The infrastructure needed to comply with them, the harmonised standards (the first AI-specific one, prEN 18286, is still working through the pipeline), the notified-body capacity, the official guidance, simply wasn't ready. That's also why the work is hard. That's also why the work is hard: a defensible risk management system, Annex IV technical documentation, a lifecycle evidence trail, conformity assessment, post-market monitoring. None of that fits inside a single quarter, and plenty of teams that called August 2026 achievable were already stretched thin.

The extra sixteen months doesn't shrink the job. It gives you a fair shot at doing it right.

A word on shortcuts, since they come up in every planning meeting. An AI management system standard like ISO/IEC 42001 is a genuinely useful foundation and gets you moving on governance, but it doesn't stand in for the Act's per-system conformity assessment, CE marking or EU database registration, and neither does the NIST AI RMF. Frameworks give you a running start. They don't cross the finish line for you.

The organisations that come out ahead are the ones using this window to turn AI governance from a fire drill into something that just runs. Teams building now will be audit-ready. Teams waiting for 2027 will be caught unprepared.

From AI inventory to audit-ready proof, without the manual grind

This is the point where readiness stops being paperwork and becomes an operation.

Holistic AI's EU AI Act readiness solution runs the whole journey as an agentic workflow instead of a checklist someone fills in by hand. Rather than asking your team to read the regulation and interpret it system by system, the platform works the assessment for you, start to finish:

  • Discovery and inventory: It surfaces every AI system in the business, built in-house, bought in, or hiding inside a third-party tool as shadow AI, and pulls them into one register.
  • Role and risk classification: For each system it figures out what you are (provider, deployer, importer or distributor) and where it sits on the risk pyramid, because your obligations depend on both.
  • Obligation mapping and gap analysis: It lays out what each system owes, checks that against what you've already done, and gives you a readiness score you can act on.
  • Role-specific assessments across the map: provider high-risk and limited-risk paths, deployer transparency and Fundamental Rights Impact Assessments under Article 27, importer and distributor duties, and the authorised-representative requirement for providers of GPAI models or high-risk systems.
  • Mitigation and evidence: It hands back specific fixes for each gap and builds the audit-grade evidence chain to prove them, ready for a conformity assessment or a regulator's questions.

Work that usually swallows a governance team for months folds into a repeatable pipeline, one that keeps itself current as the rules, and the dates, keep moving.

The bottom line

The timeline changed. The obligations didn't disappear, they rescheduled. Transparency rules and GPAI enforcement start August 2, 2026 regardless. High-risk duties land in December 2027 and August 2028. And with the Omnibus now in force, the revised schedule is fixed rather than pending. Use the extra time to build. Don't use it as permission to delay.

See where your AI systems actually stand. Explore Holistic AI's EU AI Act Readiness Assessment

Frequently asked questions

Is the EU AI Act delayed?

Partly. The Digital Omnibus, in force from 27 July 2026, pushed the high-risk obligations back — standalone Annex III systems to 2 December 2027 and embedded Annex I systems to 2 August 2028. The Article 50 transparency rules and general-purpose AI enforcement still start on 2 August 2026. For most organisations, the nearest deadline hasn't moved at all.

What are the Article 50 transparency obligations?

Four disclosure duties. Tell people when they're talking to a chatbot (50(1)), mark AI-generated or edited content in machine-readable form (50(2)), notify anyone subject to emotion recognition or biometric categorisation (50(3)), and label deepfakes and AI-written public-interest text (50(4)). They fall on providers and deployers and apply from 2 August 2026.

Does the EU AI Act apply to companies outside the EU?

Yes. Like GDPR, it has extraterritorial reach. If your AI system is placed on the EU market, or its output is used in the EU, you're in scope, even with no EU entity of your own.

What's the difference between a provider and a deployer?

A provider develops an AI system or puts it on the market. A deployer uses one under its own authority. You can be both at once, for different systems, and your deployer duties apply whether you built the tool or licensed it from someone else.

What are the penalties for non-compliance?

Up to 35 million euros or 7% o global annual turnover for prohibited practices, and up to 15 million euros or 3% for high-risk and transparency breaches, whichever figure is higher under each category. National market surveillance authorities handle enforcement.

This article is for general information only and isn't legal advice. For your organisation's specific obligations, talk to qualified counsel.

End-to-End AI Governance, Enterprise Clarity

Get a demo
Stay informed with the Latest News & Updates
By clicking “Accept”, you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts. View our Privacy Policy for more information.