2026-07-27

The AI Act's Compliance Cliff Just Got Deferred — Except Where It Didn't

AIPolicy🌍 Europe

Six days. That's how much runway the EU gave itself: Regulation (EU) 2026/1744 — the "Digital Omnibus on AI" — was published in the Official Journal on 24 July 2026 and entered into force on 27 July, five days before the AI Act's biggest compliance date was due to hit. It amends the Act's own timeline while that timeline was still ticking.

The deadline this was rushing to beat

The AI Act has always rolled out in stages: bans on unacceptable-risk AI and literacy duties from 2 February 2025, general-purpose AI (GPAI) model rules from 2 August 2025. 2 August 2026 was supposed to be the big one — the date most of the Act, including high-risk AI systems under Annex III (hiring tools, credit scoring, biometric ID), became fully enforceable. The Commission proposed deferring parts of that in November 2025; Parliament and Council reached a deal at trilogue on 7 May 2026, Parliament voted it through on 16 June, and the Council gave final approval on 29 June. Then it sat for nearly a month before publication — landing in the Official Journal with less than a week to spare.

What actually got pushed back

Standalone high-risk AI systems (Annex III) — the systems everyone was racing to certify — move from 2 August 2026 to 2 December 2027, a 16-month deferral. High-risk AI embedded in already-regulated products (medical devices, machinery, toys) moves from 2 August 2027 to 2 August 2028, a 12-month deferral. Two different obligations, two different amounts of extra runway — not a single across-the-board delay.

What didn't move at all

This is the part that gets lost in "the AI Act got delayed" headlines: Article 50 transparency obligations still apply on 2 August 2026 — the rules requiring disclosure when content is AI-generated or when a user is talking to a chatbot — alongside the Act's measures in support of innovation. That's also when enforcement itself starts, at both national and EU level, for general-purpose AI models, the Article 5 prohibitions, transparency rules, and AI literacy obligations. One carve-out on the transparency side: providers of synthetic-content systems already on the market by 2 August 2026 get an extra four months — until 2 December 2026 — to comply with the specific Article 50(2) obligation.

(Separately, and unrelated to any of this: member states are required to have at least one national AI regulatory sandbox operational by 2 August 2027 — a date the Omnibus didn't touch, if only because it was never part of the 2026 milestone to begin with.)

A new prohibition, on its own faster clock

The Omnibus didn't only defer things. It added a new Article 5 ban on AI systems built to generate non-consensual intimate imagery ("deepfake nudification") or CSAM. The prohibition covers three configurations: placing such a system on the market for that purpose, placing one on the market without reasonable safeguards against it, and a deployer using one for that purpose. Per the Commission's own implementation timeline, the prohibition doesn't take legal effect immediately — it starts to apply on 2 December 2026, the same date carrying the Article 50(2) transitional deadline mentioned above. That is four months past the general August 2026 milestone: everything else in this piece got a multi-year reprieve; this one got a head start instead.

The AI Office's supervisory reach just widened

Under the original Act, the AI Office supervised a GPAI model and any downstream AI system built on it only when the same provider made both. The Omnibus extends that to the same provider or the same corporate group, and adds AI systems integrated into "very large online platforms" or "very large online search engines" under the Digital Services Act. It also grants the Office market-surveillance-authority powers — entering business premises, inspecting books and data, demanding explanations from staff. Worth being precise about what's genuinely new here: the GPAI fine regime itself — up to 3% of global turnover or €15M — was already scheduled to become enforceable from 2 August 2026 under the original Act; the Omnibus left that date alone. What it changed is who else falls under that supervision.

Update — July 30: the Commission publishes the how-to, two days before the deadline

The part of the Act this post said didn't move now has its instruction manual. Ahead of the 2 August application date, the Commission has published its guidelines on the Article 50 transparency obligations, alongside a Code of Practice on Transparency of AI-generated Content — the voluntary companion document, in the same mould as last year's GPAI Code of Practice, that lets providers demonstrate compliance by signing up to an agreed implementation rather than inventing their own.

Concretely, what applies from Saturday: systems that interact with people must disclose that the user is talking to an AI; providers of generative systems must mark AI-generated or manipulated content in a machine-readable way; deepfakes and AI-generated text published on matters of public interest must be labelled; and people exposed to emotion-recognition or biometric-categorisation systems must be told. The one transitional softening, noted above, still stands: synthetic-content systems already on the market by 2 August get until 2 December 2026 for the machine-readable marking duty specifically.

The Code of Practice is not launching into a void: the Commission published alongside it a first list of more than 180 organisations that have already signed — meaning the voluntary compliance vehicle arrives with meaningful industry uptake on day one, the same pattern that made last year's GPAI code effective in practice.

The same date switches on enforcement, and the press release lays out an architecture more distributed than "the AI Office takes over." Three bodies split the transparency and prohibited-practices rules: the AI Office covers AI systems offered by the same provider as the underlying GPAI model, plus systems integrated into very large online platforms and search engines designated under the DSA — exactly the widened scope the Omnibus section above describes; national competent authorities cover every other AI system; and the European Data Protection Supervisor covers AI used by the EU institutions themselves. Article 50 violations carry fines up to €15M or 3% of worldwide annual turnover, whichever is higher. The Commission pointedly notes that effective enforcement "will also depend on Member States ensuring that national competent authorities are properly designated and adequately resourced" — which is as close as a press release comes to admitting that several aren't yet.

For GPAI providers, the obligations that become enforceable are the ones the systemic-risk debate has circled all year: documentation to authorities and downstream providers, a copyright policy, and a published summary of training content. The most advanced models are additionally answerable for large-scale risks the Commission now lists explicitly: CBRN, loss of control, cyber offence, harmful manipulation, and threats to fundamental rights. Two of those — "risks to European cybersecurity" and "AI acting outside human control" — are singled out as having "recently drawn public attention," which reads as a direct nod to this summer's jailbreak-driven Fable 5 suspension and the cyber-model wave.

The enforcement machinery comes with people and tools attached. A Scientific Panel of 60 independent AI experts has held its first meeting, and the AI Office has appointed Professor Alessandro Abate (Oxford; formerly Stanford, SRI and TU Delft) as Lead Scientific Adviser. Abate is a specialist in the safety, verification and control of AI-enabled systems — a telling choice of discipline for an office whose hardest future calls will be about exactly that. Three reporting channels also open: a public Complaint Tool, a confidential Whistleblower Tool for insiders and — most interestingly given the year's distillation fights — a dedicated channel for downstream providers building on GPAI models to report the model providers themselves. The EU has, in effect, built an official mechanism for the K3-style disputes this blog has been covering to become regulatory complaints rather than tweets.

Two things are worth reading into the timing. The guidelines are interpretive, not legislative — they arrived weeks before the obligations they interpret, which continues the Act's most consistent implementation pattern: the binding text lands years ahead, the practical meaning arrives at the last possible moment. And the sequencing sharpens the point this post led with: the EU deferred the hard part (high-risk conformity, to December 2027) while holding the line on the visible part. From Saturday, the AI Act that most Europeans will actually encounter is a labelling law — the chatbot that tells you it's a chatbot, the image marked as generated — and that part shipped on schedule, guidelines, signatories and all.

What to expect next

  • "Delayed" will keep getting overstated. Annex III moved 16 months; Annex I moved 12; Article 50 didn't move at all. Any post-2 August coverage that says "the AI Act was pushed back" without specifying which part is skipping the part that matters most for most deployers.
  • The CSAM/deepfake prohibition runs on the shortest clock in the package. Everything else here got deferred by a year or more; this one takes effect four months after the original August 2026 milestone, not years after it.
  • Corporate-group restructuring gets a new AI Office angle. Any group with a GPAI provider and a separately-incorporated downstream product subsidiary just lost the "different legal entity" argument for staying outside the Office's supervision.
  • Expect a similar last-week scramble before 2 December 2027. The pattern here — provisional agreement months out, formal adoption pushed to the wire — is likely how the Annex III deadline plays out too.