EU AI Act Deadlines Split After the AI Omnibus
The EU delayed major high-risk AI rules but kept August transparency duties, requiring affected organizations to replace one compliance date with a system-by-system map.
Pagalishor Current
Editorial desk
Published Jul 28, 2026
Updated Jul 28, 2026
11 min read
Overview
EU AI Act deadlines changed on July 27, 2026, when the AI Omnibus 2026 entered into force only days before another major deadline. It postpones the main rules for high-risk AI systems, expands some compliance relief and adjusts oversight. It does not pause the whole law. Article 50 transparency rules still begin applying on August 2, and rules for general-purpose AI models and prohibited practices are already in force.
That split is the immediate AI Act compliance problem for affected organizations. A company that heard only that Brussels delayed AI regulation could stop work on disclosures that are due now. One that ignores the extensions could spend heavily against a superseded high-risk deadline. Sound EU AI governance now requires a system inventory that separates each role, use case and obligation before teams change labels, contracts or launch plans.
The EU AI Omnibus changes two high-risk deadlines
According to the European Commission's AI Omnibus notice, two high-risk dates changed. Rules for systems listed in Annex III, including sensitive uses such as employment and law enforcement, apply from December 2, 2027. Rules for high-risk AI embedded in regulated products covered by Annex I, such as machinery, toys and lifts, apply from August 2, 2028.
Those dates replace a simpler expectation that the central high-risk regime would arrive sooner. The change responds in part to the availability of standards, guidance and conformity-assessment capacity. Businesses had warned that they could not finish technical work reliably when important support tools were incomplete.
Delay does not erase preparation. High-risk providers and deployers still need to know whether a system falls within an annex, what role each party occupies and which data, testing, documentation, human-oversight and monitoring duties may apply. The added time is valuable only if it is used to resolve classification and evidence gaps rather than restart the project a few months before the new date.
Multinational policy teams now face a version-control problem. Internal presentations, supplier questionnaires and contract templates may still cite the old calendar. A stale spreadsheet can produce either unnecessary escalation or dangerous complacency.
Every organization using the law in procurement should identify the source and revision date behind each deadline.
Article 50 transparency still starts on August 2
On the Commission's updated EU AI Act implementation timeline, Article 50 transparency rules begin applying on August 2, 2026. This is the deadline most likely to be lost inside a broad "AI Act delayed" message.
Article 50 addresses several kinds of transparency. People interacting directly with certain AI systems may need to be informed that they are dealing with AI unless the context makes that obvious. Providers of systems that generate synthetic audio, images, video or text may need technical outputs that can be detected as artificially generated or manipulated. Deployers face disclosure duties for specified deepfake and public-interest content.
Which rule applies depends on the actor and use. A model provider, application provider, professional deployer and platform operator can occupy different positions. A customer-service assistant is not automatically treated like an image generator, while editorial or artistic contexts may have particular treatment. Companies should resist turning the article into one universal badge. A separate December 2, 2026 transition appears on the timeline for certain providers of synthetic-content systems, including general-purpose systems, that were already placed on the market before August 2. It is not a six-month postponement for all transparency duties.
A label alone will not create evidence of compliance
Visible disclosure is the part a customer sees, but the operational work begins earlier. Teams must know which feature generated or transformed content, what metadata or watermarking survives export, where a notice appears and who checks that it remains visible after resizing, editing or syndication.
Marketing workflows are a useful example. A campaign may begin with a generated image, pass through an agency, enter a design tool and appear in several languages and formats. If the compliance control exists only in the first file, it can disappear before publication. The organization needs an approval trail and a rule for downstream partners, not just a sentence in an AI policy.
Customer support creates a different problem. A conversational system can hand a case to a person, call tools and retrieve account information. The notice has to be clear without misleading customers about which actions are automated or human-reviewed. Privacy, consumer-protection and sector rules still apply alongside the AI Act. A legal analysis in Cinco Dias frames the task around inventory, ownership, covered content, procedures and corporate governance. No disclosure programme works when the company cannot identify its AI systems or the people accountable for their use.
General-purpose AI obligations already apply before the new deadlines
Since 2024, the EU AI Act has applied in stages. Prohibited practices and the general AI literacy framework began applying in February 2025.
Rules for providers of general-purpose AI models and the EU-level governance structure began applying in August 2025. The 2026 Omnibus does not return those areas to a blank slate.
For companies buying a foundation model through an API, the provider's obligations do not replace the buyer's responsibilities. A deployer still needs to understand the intended use, human review, access controls and the effect of connecting the model to internal data or consequential decisions. Contracts should allocate documentation and incident duties instead of assuming the vendor carries the whole law.
Model customization complicates the role map. Fine-tuning, retrieval, tool integration and repackaging can change what an organization provides to customers. Legal classification should follow what the company actually does, not the brand printed on the underlying model.
Open models require the same caution. Access to weights does not remove downstream duties. It changes where technical information, evaluation and control responsibilities may sit. Teams need a product-level view that joins model origin, modifications, distribution and use.
Smaller companies gain relief, not an exemption
Selected simplified approaches previously reserved for small and medium-sized enterprises now extend to small mid-cap companies. The Commission says this can make documentation and other duties more proportionate for a larger group of businesses. Proportionate does not mean optional: eligibility needs to be checked, and the simplified route still has to satisfy its conditions. A growing company can cross a threshold or belong to a group whose size changes the analysis.
Registration is streamlined for systems used in high-risk areas when the particular task is not considered high risk. Affected Article 6(3) systems remain registered in the EU database, but the required Annex VIII information is simplified. The change does not let a provider relabel a consequential task as ordinary, so the classification rationale remains important.
AI literacy changes are another source of confusion. The Omnibus places a stronger promotional role on the Commission and Member States and simplifies the earlier company-facing requirement, while training expectations remain relevant for high-risk deployers. Sensible organizations will keep role-based training because staff cannot apply disclosure, review and escalation rules they do not understand.
AI Office oversight follows system reach, not company size
AI Office oversight expands to certain systems built on general-purpose models and systems embedded in very large online platforms and search engines. The Commission presents this as a way to reduce fragmented supervision when one model or platform crosses borders and services.
Centralization may give providers a clearer institutional counterpart, but it does not remove national authorities. Enforcement still involves EU and Member State bodies depending on the obligation and system.
Companies need a regulatory map that matches product reach, establishment and affected markets.
Interaction with other EU rules is also clarified, while procedures for conformity-assessment bodies are streamlined. An AI system can sit inside a product already governed by safety legislation, while its data processing engages privacy law and its customer presentation engages consumer rules.
No internal AI committee can merge those regimes by declaration. Engineering evidence, data-governance records, product safety work and public disclosures have to agree. A model card that promises one use while marketing promotes another creates a governance failure before a regulator asks a question.
Sandboxes and bias testing gain guarded pathways
Broader access to regulatory sandboxes and a planned EU-level sandbox are part of the reform. Sandboxes can help companies test interpretations with supervisors, particularly when a novel system does not fit cleanly into existing examples.
They are not a safe harbour for uncontrolled deployment. Real-world testing still needs a defined purpose, safeguards and a path for stopping or repairing the test. Users should not carry hidden risk merely because the provider calls a release experimental.
Strong sandbox candidates have a narrow question and measurable evidence. A healthcare developer may need to test workflow integration while keeping clinical decisions with qualified staff. An employer may need to evaluate whether a ranking tool creates disparate outcomes before it affects applicants. "Testing the product" is too vague to support meaningful oversight.
Companies should also plan for exit. A successful test needs production controls, ownership and monitoring. An unsuccessful test needs deletion, incident handling and a decision about affected participants. Treating a sandbox as a permanent pilot simply moves compliance debt into live operations.
A guarded pathway now permits processing of special categories of personal data when necessary for detecting and correcting bias. This addresses a recurring conflict: teams may need sensitive attributes to discover discrimination but privacy law restricts how those attributes are handled.
Permission is not a reason to collect everything. The data should be necessary for a defined test, access should be limited and retention should be justified. Synthetic or proxy data can sometimes reduce exposure, though it may also hide real-world patterns.
Bias work needs more than a single aggregate score. Performance can vary across language, disability, age, region and other contexts. The relevant groups depend on the system and decision. A hiring tool and an identity-verification tool do not share one fairness checklist.
Results also need an owner. Detecting a disparity without changing the model, threshold, workflow or available appeal does not reduce harm. Product and legal teams should agree in advance what result triggers remediation or blocks release.
The new deepfake prohibition deserves precise reading
One new prohibition covers systems that generate non-consensual sexually explicit and intimate content or child sexual abuse material. The Commission timeline places the new prohibitions from December 2, 2026, while the enacted text appears in Regulation (EU) 2026/1744.
This is stronger than a transparency rule. A disclosure cannot cure prohibited conduct. Providers need prevention, abuse detection, reporting and enforcement controls that match the severity of the risk.
That provision should not be diluted into a general argument about all synthetic media. Lawful creative, satirical and accessibility uses raise different questions from non-consensual sexual imagery. Policy and product controls should preserve that distinction while acting decisively against abuse.
Platforms and tool providers also need to coordinate. A generator can block a request, a hosting service can remove material and an identity or provenance system can support investigation. No single layer is sufficient when content moves across services.
Procurement teams need a new date matrix
For immediate use, attach a date matrix to the AI inventory. For each system, record the business owner, provider, deployer, affected users, countries, potential annex classification, transparency duties, model origin and current control evidence.
Then map deadlines by obligation. August 2, 2026 is the transparency and enforcement checkpoint for applicable rules. December 2 brings the transition for specified existing synthetic-content systems and the new prohibitions. December 2, 2027 is the Annex III high-risk date. August 2, 2028 is the Annex I product-embedded date.
Supplier contracts should match that matrix. Ask who produces technical documentation, who preserves detection signals, who reports incidents and how material model or feature changes are communicated. A warranty that merely says "AI Act compliant" is difficult to test and may become stale after an update.
Renewal dates matter too. A provider that cannot meet a 2027 requirement may need replacement well before the deadline because migration and validation take months. Procurement is therefore part of compliance design, not a final administrative step.
Four questions organize that matrix. What is the system and which role does the organization play? Which provision applies on which date? What records show the control works? What happens when the model, vendor or use expands?
Mixing those questions produces common errors. A team may decide a system is not high risk and wrongly conclude that no transparency duty applies. It may add a disclosure and assume that data, copyright or consumer obligations are solved. It may evaluate one model version while automatic updates change behaviour.
A controlled release process can keep the answers aligned. Material changes should trigger reclassification, testing and communication. The threshold for "material" needs concrete examples: a new decision function, a new user group, a new data source or a change from advice to automated action.
Documentation should be useful to operators rather than written only for an audit. A support lead needs to know when to disclose automation and escalate a case. A marketer needs rules for synthetic media. An engineer needs detection and logging requirements. Governance becomes real when each person can act on it.
EU AI Act deadlines now reward disciplined scoping
After the Omnibus, EU AI Act deadlines no longer form a single staircase that every system climbs together. High-risk rules gain more time while immediate transparency work and already applicable provisions remain in place. That makes disciplined scoping more valuable than broad compliance slogans.
Executives should ask for a dated inventory and an obligation map, not a percentage-complete dashboard. Percentages hide whether the unfinished work belongs to an August disclosure or a 2028 product assessment. The risk follows the missed duty, not the project-plan colour.
Used well, the extra time can improve quality. Standards can mature, conformity bodies can prepare and companies can test controls instead of producing hurried documents. But a delay that becomes inactivity will recreate the same bottleneck under a new date.
August 2 is the immediate checkpoint for Article 50 transparency. Affected companies should verify what customers and audiences will see, whether synthetic outputs retain detection signals and whether the evidence survives across agencies and platforms. After that, the longer high-risk timetable should be used to build controls that can withstand product change—not as proof that the AI Act disappeared.