AI Governance
The deadline you were preparing for moved. The one that arrived is different.
Reg. (EU) 2026/1744 deferred the high-risk obligations to December 2027 and August 2028, while Article 50 transparency went live 2 August 2026.
If your EU AI Act plan was built around 2 August 2026 as the date high-risk obligations bind, it is out of date — and so is a great deal of the guidance still published online.
Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026, six days before the Act's general application date. It is law, not a proposal. It amends 27 articles and five annexes, and it deferred the high-risk regime: Annex III systems now bind on 2 December 2027 and Annex I systems on 2 August 2028.
But something real did happen on 2 August 2026. Article 50 transparency obligations took effect, and the Commission and AI Office gained enforcement powers over general-purpose AI providers — requests for information, model access, recalls, and fines.
The accurate framing, and the one most content gets wrong in one direction or the other: the enforcement powers switched on; the high-risk obligations did not.
What changed
The corrections that matter
Every date below is from the Official Journal text or the Commission. If your adviser is still quoting the original timetable, ask when they last checked.
High-risk deferred by 16 months and 12 months
Annex III — employment, education, essential services, biometrics, critical infrastructure, law enforcement, migration, justice — moved from 2 August 2026 to 2 December 2027. Annex I, AI as a safety component of regulated products, moved from 2 August 2027 to 2 August 2028.
Annex I classification narrowed
The safety-component test was tightened. AI handling non-safety-related user assistance, performance optimisation, service efficiency, automation or convenience, or quality control is no longer automatically high-risk when embedded in a regulated product, unless failure creates a health or safety danger. If you were told your embedded AI was automatically in scope, re-scope it.
Article 50 transparency is live now
Tell people they are interacting with AI. Mark synthetic audio, image, video and text in a machine-readable format. Disclose deepfakes. Systems already on the market before 2 August 2026 have until 2 December 2026 for the machine-readable marking requirement.
A new prohibition arrives 2 December 2026
The omnibus added an Article 5 prohibition on generating non-consensual intimate imagery and CSAM where such output is reasonably foreseeable without significant modification and the system lacks adequate safeguards. It explicitly reaches general-purpose image and video tools.
Simplified registration reinstated
A registration duty was restored for systems a provider self-assesses as not high-risk under Article 6(3), with streamlined Annex VIII content. If you concluded you had no registration obligation, that conclusion may have expired.
The SME penalty cap is the other way round
Fines run to €35M or 7% of global turnover for prohibited practices, €15M or 3% for most other breaches. For most undertakings the cap is whichever is higher — but Article 99(6) applies whichever is LOWER for SMEs and start-ups. This is commonly reported inverted.
Questions
Frequently asked
Does the EU AI Act apply to us if we are a US company?
Quite possibly. It reaches providers placing AI systems on the EU market regardless of where they are established, deployers located in the EU, and — the provision that catches people — providers and deployers outside the EU where the system's output is used in the EU. A US SaaS product with EU customers can be in scope. Note that Article 2 was itself amended by the omnibus, so we verify scope against the consolidated text rather than against 2024-era commentary.
Does the delay mean we can stop work?
It means you can re-sequence, not stop. Three things still bite now: Article 50 transparency, the GPAI regime if you provide models, and the prohibitions that have applied since February 2025. And the deferral was granted partly because harmonised standards do not exist yet — as of mid-2026 none has been cited in the Official Journal. That is a reason the eventual work will be harder to rush, not easier.
How do we know if our system is high-risk?
Classification is the gating decision and the one worth paying to get right, because errors are expensive in both directions. It turns on Annex I and Annex III, both of which the omnibus amended. We work from the consolidated text and document the rationale, because the rationale is what you will need to show if anyone asks why you concluded you were out of scope.
Are the harmonised standards ready?
No. As of mid-2026 no harmonised standard for the AI Act had been cited in the Official Journal. EN 18286 is the closest, and Q4 2026 has been discussed as an availability target — but a target is not a citation date. Plan on the assumption that you will be demonstrating conformity without a fully settled standard to point at.
More from AI Governance
Want to know where you actually stand?
We will tell you what is in scope, what an assessor will accept, and what you do not need.