AI Policy - 6 min read - 4 August 2026

Brussels moved the EU AI Act's biggest deadline by 16 months. Read what didn't move before you relax.

Back in the spring, law firms were telling US companies to treat 2 August 2026 as the date the EU AI Act's high-risk obligations became real. In June, the Digital Omnibus agreement quietly pushed that date to December 2027. This week, three other parts of the Act - transparency duties, GPAI enforcement powers and the penalty regime - landed exactly on schedule anyway.

In April, Holland & Knight was warning US companies to prepare for a possible August 2026 compliance deadline under the EU AI Act's high-risk provisions - Articles 9 through 17 for providers, Article 26 for deployers, covering systems used in areas like recruitment, credit scoring and law enforcement. That deadline no longer exists in the form the warning described. On 16 June, the European Parliament gave final approval to the Digital Omnibus amendments, and according to Gibson Dunn's analysis of the agreement, the Commission's original conditional trigger for high-risk enforcement was scrapped in favour of two new fixed dates: standalone Annex III high-risk systems now have until 2 December 2027, and AI embedded in already-regulated products under Annex I gets until 2 August 2028. Sixteen months of runway, in one legislative move, for the obligations that most enterprise AI governance programmes had been building toward.

What stayed exactly where it was

The instinct after news like that is to file the whole Act under "later." That would be a mistake, because the Digital Omnibus didn't touch everything with an August 2026 date attached to it. Article 50's transparency duties - disclosing to users when they're interacting with an AI system, labelling AI-generated content, marking deepfakes - stayed on the original schedule and took effect on 2 August as planned, with only the watermarking-specific requirement under Article 50(2) getting a four-month grace period for systems already on the market. The Commission's enforcement powers over general-purpose AI models went live the same day, as did the Act's penalty regime. None of that required a fixed high-risk compliance date to matter - it applies the moment an organisation is deploying or providing an AI system that talks to, or about, a real person.

The Omnibus made two other changes worth knowing even if they don't carry an immediate deadline. Gibson Dunn's summary notes a new prohibition under Article 5 on AI systems that generate non-consensual intimate imagery or child sexual abuse material, with its own transitional period running to 2 December 2026 - and a restructuring of oversight that gives the EU AI Office "exclusive competence" over general-purpose AI cases where the same company built both the underlying model and the system running on top of it, alongside new investigative and enforcement powers for the Office itself. Member states also picked up an extra year, to August 2027, to stand up the regulatory sandboxes the Act promises as a lower-friction path for companies testing AI systems under supervision.

Why the sequencing is the actual story

We wrote in July about the Commission's Action Plan on Cybersecurity and AI, which arrived three weeks ahead of GPAI Code of Practice obligations and read, at the time, as Brussels front-loading scrutiny before the heavier high-risk machinery switched on. What's actually happened is closer to the opposite of what that timing implied: the heaviest compliance lift got pushed out by well over a year, while the lighter-weight, disclosure-focused obligations - the ones that cost far less to implement and are far easier for a regulator to check by simply using the product - went ahead unchanged. That's not a retreat from enforcement. It's the EU choosing to start with the obligations it can actually verify at scale - is a chatbot labelled as a chatbot, is synthetic media marked as synthetic - while giving itself, and industry, more time on the harder classification and conformity-assessment work that high-risk designation demands. For a compliance team that had high-risk conformity assessments on this quarter's roadmap, that work can reasonably move down the list. For anyone assuming the whole Act just went quiet for a year, Article 50 says otherwise, and it's the provision a regulator can act on with the least effort.

What the delay is not

It's worth being precise about what the Digital Omnibus didn't do. It didn't repeal the high-risk provisions, exempt any sector from them, or signal that they won't eventually bind - it moved fixed dates that were already fixed once before. Enterprises that paused high-risk classification work entirely on the strength of this news are trading a compliance deadline they could see clearly for one that arrives with sixteen months' less warning if Brussels decides, as it just demonstrated it's willing to do, to hold this new date firm. The safer read is that the classification and documentation work doesn't need to finish by December 2027 - it needs to be underway well before it, on a timeline your own team controls rather than one set by how close the next deadline is.

  • Confirm today whether any AI system you provide or deploy in the EU triggers Article 50 disclosure duties - that obligation is live now, independent of high-risk status or company size.
  • Re-baseline your high-risk classification work against the new fixed dates - 2 December 2027 for standalone Annex III systems, 2 August 2028 for AI embedded in regulated products - without treating either as licence to stop the work entirely.
  • If your AI system marks or generates synthetic media, plan for the Article 50(2) watermarking grace period ending 2 December 2026, not the later high-risk dates.
  • Check whether your GPAI model provider also runs the system built on top of it - the AI Office's new exclusive-competence rule changes who you'd actually be dealing with in an enforcement action.
  • Treat the Omnibus as a rescheduling, not a reprieve - a body that has already moved this deadline once has shown it's willing to hold the next one, and documentation built now is documentation you won't be building under pressure in 2027.

A delayed deadline is still useful information, but only if you're precise about which deadline actually moved. If you want help mapping which of your AI systems fall under Article 50 today versus which ones have genuine runway to 2027 or 2028, email sales@halfteck.com.

Explore more resources

Browse our full library of enterprise cloud, software, data and AI content.

View all resources