Disclaimer: This article is best-effort research based on public sources available as of October 2026. Details in this area change quickly, so verify facts against the primary sources listed at the end before acting. This is insight, not legal advice. Regulatory content here has not been legally confirmed and should be checked with qualified counsel and the official text.

The EU AI Act’s timeline changed in 2026. The AI Digital Omnibus, a package of targeted amendments, postponed the obligations for high-risk AI systems that were due to start on August 2, 2026. According to law-firm summaries, EU institutions reached a provisional agreement on May 6, 2026. Usercentrics reports that the European Parliament adopted the text on June 16, the Council on June 29, and that it entered into force on July 27, 2026, after publication in the Official Journal.

Many organizations heard “the AI Act was delayed” and relaxed. That reading is wrong in an expensive way. Only some obligations moved. Others already apply, and one set began in August 2026. This article lays out the calendar as reported and suggests how to use the time that was actually gained.

The new calendar

Timeline of EU AI Act application dates after the Digital Omnibus, from February 2025 to August 2028
Figure 1. EU AI Act application dates after the Digital Omnibus, as reported in mid-2026. Confirm against the official text.
  • February 2, 2025: Prohibited AI practices and the AI literacy requirement began to apply.
  • August 2, 2025: Obligations for providers of general-purpose AI models began.
  • August 2, 2026: Article 50 transparency obligations apply, including disclosure that people are interacting with AI and labeling of certain AI-generated content.
  • December 2, 2026: The machine-readable marking requirement under Article 50(2) applies to generative AI systems that were already on the market before August 2, 2026. The new ban on AI systems that generate non-consensual intimate imagery or child sexual abuse material also applies from this date.
  • December 2, 2027: Obligations for stand-alone high-risk systems listed in Annex III, such as AI used in employment, credit scoring and access to essential services.
  • August 2, 2028: Obligations for high-risk AI embedded in products already covered by EU product safety law under Annex I.

What moved, and what did not

Comparison of EU AI Act obligations moved later by the Digital Omnibus and obligations that did not move
Figure 2. The Omnibus moved high-risk deadlines. Prohibitions, general-purpose AI duties and transparency obligations stayed on schedule.

Beyond the dates, law firm Orrick summarized several other changes in the final text. Among them: a new “small mid-cap” category that extends some relief to companies with fewer than 750 employees or below set turnover and balance-sheet thresholds; a clearer legal basis for processing special category personal data to detect and correct bias, subject to strict necessity and safeguards; a narrower definition of “safety component”; and stronger supervisory powers for the EU AI Office over AI systems built on general-purpose models and those integrated into very large online platforms.

One detail is easy to miss. Usercentrics notes that the watermarking grace period only covers generative AI systems placed on the market before August 2, 2026. Systems placed on the market on or after that date get no grace period and must comply with Article 50(2) from launch. If your organization shipped a new generative feature in the EU this autumn, check this now.

Three mistakes to avoid

Treating the delay as a pause. High-risk compliance is a large program: risk management systems, data governance, technical documentation, logging, human oversight, accuracy and robustness testing, and for many providers a conformity assessment. Organizations that start in mid-2027 will not finish by December 2027. The extra time is best used to build these capabilities properly, not to postpone them.

Ignoring transparency duties. Article 50 obligations are already live. Customer-facing chatbots, synthetic media and AI-generated text published on matters of public interest are the common triggers. These are often owned by marketing, customer service and product teams that do not think of themselves as part of an AI compliance program.

Forgetting the deployer role. Many organizations assume the AI Act is mainly a problem for AI vendors. Deployers of high-risk systems, such as employers using AI in hiring, carry their own obligations, including human oversight, monitoring and, in some cases, impact assessments. Buying a compliant product does not make its use compliant.

A practical plan for the next 15 months

  1. Refresh your AI inventory by role. For each system, record whether you are provider, deployer, importer or distributor, and whether it falls under Annex III, Annex I, Article 50 or none. Our research on AI regulations includes a Regulatory Exposure Path for this mapping.
  2. Close Article 50 gaps now. Confirm AI interaction disclosures and content labeling for every customer-facing system. Check whether any generative system launched after August 2, 2026 needs machine-readable marking already.
  3. Use a management system as the backbone. ISO/IEC 42001 and the NIST AI Risk Management Framework give structure that maps well to many AI Act requirements. See frameworks and standards.
  4. Plan high-risk work as a 2027 program. Set milestones for documentation, testing and oversight design through the first half of 2027, leaving time for review before December 2, 2027.
  5. Push requirements to vendors. Update contracts so AI suppliers provide the documentation, logs and change notices you need as a deployer. Our vendor AI risk research covers how.
  6. Track harmonized standards. The Omnibus directed the Commission toward unified technical standards. These will shape what “compliant” means in practice, so assign someone to watch them.

The bottom line

The Omnibus bought time for high-risk systems, nothing more. Prohibitions, general-purpose AI obligations and transparency duties are already in force, and new market entries get no watermark grace. Organizations that use the extra 16 months to build durable risk management, documentation and oversight will reach December 2027 in good shape. Those that wait will face the same work under far more pressure.

Related research: AI Governance, Risk and Compliance, AI risk assessment and AI audit and assurance.

Sources

  • Orrick, “EU AI Act Update: Digital Omnibus Finalizes 8 Compliance Changes,” July 2026. orrick.com
  • Gibson Dunn, “EU AI Act Omnibus Agreement: Postponed High-Risk Deadlines and Other Key Changes,” 2026. gibsondunn.com
  • Usercentrics, “EU AI Act Deal: Digital Omnibus Now in Force,” 2026. usercentrics.com