EU AI Act Timeline After the Omnibus: What Actually Moved
If your AI Act compliance calendar was built before August 2026, parts of it are now wrong.
Regulation (EU) 2026/1744 — the Digital Omnibus on AI — was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026, six days before the AI Act’s original high-risk deadline. It is enacted law, not a proposal, and it changes several dates that most published guidance still reports the old way.
It also gets summarised badly. The headline everyone heard was that the EU delayed the AI Act. That is half true, and the half that is false is the expensive half.
This article sets out what moved, what did not, and why the obligations that stayed put are the ones most organisations stopped watching.

Building the documentation while the dates move? The AI Act Compliance Suite covers the obligations by role — provider, deployer and GPAI model provider — with the technical documentation, the risk management file and the post-market monitoring plan already structured. €590 excl. VAT.
What moved
The deferral applies to high-risk systems, and it splits them in two.
Stand-alone high-risk systems under Annex III — AI used in employment, education, credit assessment, law enforcement and critical infrastructure — move from 2 August 2026 to 2 December 2027.
AI embedded in products already covered by EU product-safety law under Annex I moves to 2 August 2028. This is the category that matters if you make medical devices, machinery, lifts, or anything else carrying a CE mark under existing sectoral legislation.
Sixteen months for one group, two years for the other.
What did not move
This is the part that gets lost, and it is the part with a date already behind us.
| Obligation | Applies since | Changed by the Omnibus? |
|---|---|---|
| Article 5 prohibited practices | 2 February 2025 | No |
| Article 4 AI literacy | 2 February 2025 | No |
| GPAI model obligations, Articles 51–55 | 2 August 2025 | No |
| Governance provisions and penalties | 2 August 2025 | No |
| Article 50 transparency duties | 2 August 2026 | No |
| Annex III high-risk obligations | 2 December 2027 | Deferred |
| Annex I embedded high-risk obligations | 2 August 2028 | Deferred |
Article 50 transparency and AI-content-labelling duties stayed on the original 2 August 2026 schedule, along with the GPAI provider obligations that have applied since August 2025 and the Article 5 prohibitions in force since February 2025.
Read that row again. The Article 50 transparency obligations applied from 2 August 2026 and were never deferred. That date has passed.
If your organisation read “the AI Act is delayed” in May and eased off, and you operate a chatbot, a system that generates or manipulates content, or an emotion recognition or biometric categorisation system, you are late on an obligation that never moved.
The Article 50 question, answered concretely

Since this is the obligation already live and the one most organisations set aside, it is worth being specific about what triggers it. Four situations, and most organisations are in at least one without having decided that they are.
A system that interacts directly with a person. Chatbots, voice assistants, automated support agents. The person must be told they are dealing with an AI system, at the first interaction, unless it is obvious from the context. “Obvious from the context” is narrower than it sounds: a support widget branded like a person is not obvious.
A system that generates or manipulates content. Synthetic text, images, audio or video must be marked in a machine-readable way as artificially generated. This is the duty that catches marketing and content teams who never considered themselves in scope.
Deep fakes. Content that resembles real people, places or events must be disclosed as artificially generated when published, with narrow exemptions.
Emotion recognition and biometric categorisation. The people exposed to the system must be informed of its operation.
The common thread is that none of these depend on the system being high-risk. They attach to what the system does to the person in front of it, which is why the high-risk deferral leaves them untouched.
The practical test: walk through every point where your organisation’s software speaks to a customer, publishes content, or infers something about a person from their face or voice. If you cannot name who checked those against Article 50 and when, that is the gap.
What the deferral does not defer
Worth stating plainly, because “the high-risk obligations are deferred” gets read as “high-risk systems are unregulated until 2027”.
The classification still applies. A system that is high-risk under Annex III is high-risk today; what moved is the date from which the Chapter III obligations bite. The prohibitions in Article 5 apply to it regardless. If it interacts with people or generates content, Article 50 applies to it now. If it is embedded in a regulated product, the sectoral legislation — MDR, Machinery, and the rest — applies as it always did, untouched by the AI Act timeline.
There is also a supervisory dimension. Market surveillance authorities are being designated and resourced during this period, and the deferral gives them the same extra time it gives you. An authority that arrives in 2028 with three years of staffing behind it is a different proposition from one arriving in 2026 with none.
What was added
The Omnibus is not only a deferral. It introduces new prohibitions into Article 5, covering AI-generated non-consensual intimate imagery and child sexual abuse material.
A package sold as simplification that adds prohibitions is worth reading rather than summarising from a headline.
Why the deferral happened, and what it tells you
The proposal was prompted by the fact that the Act’s timely implementation has run ahead of the supporting infrastructure — the harmonised standards and Commission guidance that make the high-risk obligations operable were not ready.
That is the useful signal in the whole exercise. The deferral is an admission that the technical scaffolding is late, not that the obligations are softening. It is a deferral rather than a dismantling: the risk-based approach, the governance structure and the core obligations remain intact.
Which means the work does not get smaller. It gets the same size, later.
The trap: treating sixteen months as breathing room
The temptation with a deferral is to move the whole programme back by the same interval. Two reasons not to.
The hard part of AI Act compliance is not the documentation. It is finding every AI system in your organisation, deciding which Annex III category each falls into, and getting product and engineering to keep the inventory current as new systems ship. None of that depends on the standards being final, and none of it goes faster because you started later.
Most organisations underestimate their AI system count by half. The tools people signed up for individually, the AI features switched on inside software you already licence, and the model behind a supplier’s service all count. An hour spent asking around fills more gaps than a week of writing.
The obligations that stayed put are already live. Your inventory is what tells you whether any of your systems falls under Article 50. Without it you cannot answer the question, let alone comply.
What to do in the next month
- Correct your compliance calendar. If it says Annex III high-risk from 2 August 2026, it is wrong. If it says Annex I from 2 August 2027, it is wrong.
- Check Article 50 against your systems now. It is the only high-visibility obligation currently enforceable that most organisations deprioritised. Interaction with a person, synthetic content, emotion recognition, biometric categorisation — those are the triggers.
- Build or refresh the AI system inventory, with the role you hold for each system: provider, deployer, importer, distributor. The role decides which obligations attach, and it can change without the system changing — modifying a bought system substantially can move you from deployer to provider.
- Classify each system against Annex III and Annex I. The deferral gives you time to do this properly; it does not give you a reason to skip it.
- Keep the GPAI work moving if you build on foundation models. Articles 51–55 have applied since August 2025 and the Omnibus does not touch them.
Where ISO 42001 fits, and where it does not
If you are building the machinery rather than reading about it, what an AI governance framework consists of sets out the documents and records, and how ISO 42001 compares with ISO 27001 shows what transfers if you already hold one.
If you already hold ISO 27001 and are wondering how much of it counts toward an AI management system, the mapping between the two answers that without quoting a percentage.
Certification to ISO/IEC 42001 does not discharge AI Act obligations. The Act is law; the standard is voluntary, and conformity with the Act is assessed against the Act.
What the standard does is build the machinery the Act’s obligations run on: the system inventory, the impact assessment, the risk process, the technical documentation, the information given to users, the incident channel. An organisation that has implemented ISO 42001 has most of the operational apparatus the Act asks for and still has to demonstrate conformity separately.
Put differently: the standard makes the work repeatable. It does not make it unnecessary. If you want the detail of what an AI management system involves, the readiness checklist and what certification does and does not prove cover it.
What this means by organisation type
The deferral lands differently depending on what you build and where you sit in the chain.
| If you are | What changed for you | What to do now |
|---|---|---|
| A provider of a stand-alone high-risk system under Annex III | Sixteen months more, to 2 December 2027 | Use the time on inventory and classification, which do not depend on the standards |
| A manufacturer with AI inside a CE-marked product | Two years more, to 2 August 2028 | Nothing changes under your sectoral regulation; the AI Act sits on top of it |
| A deployer of somebody else’s high-risk system | The same deferral, but your obligations were always lighter | Confirm what the provider has committed to give you, in writing |
| A GPAI model provider | Nothing. Articles 51–55 have applied since August 2025 | Keep working through the Code of Practice and the systemic risk thresholds |
| An organisation running a chatbot or generating content | Nothing. Article 50 applied from 2 August 2026 | This is the one to check this week |
| An organisation that thought it was out of scope | Possibly nothing, but verify | Most organisations underestimate their AI system count by half |
The last row is the one worth dwelling on. The AI tools people signed up for individually, the AI features switched on inside software you already licence, and the model behind a supplier’s service all count toward scope. None of them appear in a procurement report.
Frequently asked questions
Is the AI Act delayed? Partly. The high-risk obligations under Annex III moved to 2 December 2027 and those under Annex I to 2 August 2028. Nothing else moved. The prohibitions, the AI literacy duty, the GPAI obligations and the Article 50 transparency duties are all on their original dates.
Do the transparency obligations still apply from 2 August 2026? Yes. They were never deferred, and that date has now passed.
Is the Omnibus in force, or still a proposal? In force. Regulation (EU) 2026/1744 was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. Guidance published before then describes a provisional political agreement, not the enacted text.
Does the deferral apply to our medical device software? If the AI is a safety component of a product regulated under Annex I legislation, the applicable date is 2 August 2028. That is the later of the two, and it does not change your obligations under the sectoral regulation itself, which continue as before.
Have the penalties changed? No. Up to €35 million or 7% of worldwide annual turnover for prohibited practices, up to €15 million or 3% for most other infringements, and up to €7.5 million or 1% for supplying incorrect information to authorities.
Should we slow down? The work that takes longest — the inventory and the classification — does not depend on the deferred obligations or on the standards being finalised. Organisations that use the extra time to do that properly will find the rest straightforward. Organisations that pause will do the same work later, with less margin.
Where this leaves you
The Omnibus is the EU acknowledging that its original timeline outran the market’s ability to comply with the hardest parts. That is a reasonable thing for a legislator to do, and it does not change what compliance eventually requires.
The lesson worth carrying is not that a deadline moved. It is that a compliance calendar built on headlines rather than on the text will be wrong in both directions — relaxed where it should be urgent, and urgent where there is now time.
If you are building the underlying documentation, what AI Act compliance involves in practice covers the obligations by role.
The AI Act Compliance Suite contains the documents the Regulation asks for, organised by the role you hold rather than by article number — because the obligations that apply to you depend on whether you are the provider, the deployer, or both for different systems. €590 excl. VAT.
If your AI sits inside a CE-marked product, the deferral to 2 August 2028 gives you room to build the management system underneath it properly: the ISO 42001 Compliance Suite covers that layer. How conformity assessment actually works for that category covers what the Digital Omnibus changed in Article 43 itself, not just the date around it.