The EU AI Act Deadline That Didn't Move

The EU AI Act Deadline That Didn't Move

Hemant Goyal
Hemant Goyal
Aug 29, 2026

In July 2026 the EU deferred the AI Act's high-risk obligations to December 2027, and a lot of companies heard "AI regulation got delayed." For most of them, that reading is wrong in a way that could get expensive.

The obligations that most companies actually trigger — the transparency duties in Article 50 — took effect on schedule on 2 August 2026. They apply based on what a system does, not what risk tier it sits in. If you run a chatbot or publish AI-generated content, you're in scope today.

What actually changed

The Digital Omnibus on AI was published in the Official Journal on 24 July 2026 and entered into force on 27 July — days before the original deadline. It deferred:

  • Annex III high-risk systems (employment, credit, education): from 2 August 2026 to 2 December 2027
  • Annex I high-risk systems (AI embedded in regulated products — medical devices, lifts): to 2 August 2028
  • National regulatory sandboxes: to 2 August 2027
  • That's a real and substantial delay. If you're building an AI hiring tool or a credit scoring system, you genuinely have more time to complete conformity assessment, registration and technical documentation.

    What didn't change

    Article 50 general transparency duties. These landed on 2 August 2026 as originally scheduled, untouched by the deferral. In practice they require:

  • Disclosure when a person is interacting with an AI system — your chatbot has to say it's a chatbot
  • Labelling of AI-generated synthetic content: audio, image, video and text
  • Deepfake disclosure
  • The critical detail is that these apply by system function rather than risk tier. There's no "we're only minimal risk" exemption. A customer support bot on a SaaS product is squarely in scope, even though nothing about it is high-risk. Systems already deployed before August 2026 have a grace period to 2 December 2026 for the associated watermarking sub-obligation.

    The penalty structure

    Worth understanding because the tiers are not intuitive:

  • Prohibited practices violations (Article 5): up to €35M or 7% of global annual turnover
  • Most high-risk and GPAI violations: up to €15M or 3% of global annual turnover
  • The higher tier attaches to the prohibited-practices regime — not to the high-risk regime that got deferred.

    Does this apply to companies outside the EU?

    Probably, if your output reaches EU users in a meaningful way — through sales, access, or downstream integration. Extraterritorial reach here works similarly to GDPR: the question is where the effect lands, not where your servers are. And the AI Act doesn't replace GDPR. If you're processing personal data through an AI system, both apply.

    What to do this quarter

  • Inventory every AI system, feature and third-party AI tool you use — including the ones a team adopted without telling anyone
  • Classify each system: prohibited, high-risk (Annex I or III), limited, or minimal. Most will be limited or minimal — and still caught by Article 50
  • Check your disclosures now — does every AI-facing interface tell users they're talking to an AI?
  • Plan for the 2 December 2026 watermarking grace period if you had systems live before August
  • Don't treat the high-risk deferral as permission to stop — conformity assessment, technical documentation, quality management systems and database registration are multi-quarter programmes
  • The compliance framework angle

    ISO/IEC 42001 doesn't satisfy AI Act obligations by itself. But the risk assessments, audit trails and governance structures it requires feed directly into the technical documentation the Act demands. A 2025 compliance benchmark found 76% of organizations plan to pursue AI compliance under a framework like ISO 42001. That's why AI governance questions are showing up in procurement questionnaires long before any regulator knocks.

    One practical caution: qualified lead auditors who understand both AI systems and management-system governance are still genuinely scarce. Most teams do a gap analysis first and enter the certification queue already prepared — which saves significant time and money.

    Not sure where to start?

    Our 30-minute AI readiness call is free, focused, and actionable.