2026-07-27

The AI Act's Compliance Cliff Just Got Deferred β€” Except Where It Didn't

AIPolicy🌍 Europe

Six days. That's how much runway the EU gave itself: Regulation (EU) 2026/1744 β€” the "Digital Omnibus on AI" β€” was published in the Official Journal on 24 July 2026 and entered into force on 27 July, five days before the AI Act's biggest compliance date was due to hit. It amends the Act's own timeline while that timeline was still ticking.

The deadline this was rushing to beat

The AI Act has always rolled out in stages: bans on unacceptable-risk AI and literacy duties from 2 February 2025, general-purpose AI (GPAI) model rules from 2 August 2025. 2 August 2026 was supposed to be the big one β€” the date most of the Act, including high-risk AI systems under Annex III (hiring tools, credit scoring, biometric ID), became fully enforceable. The Commission proposed deferring parts of that in November 2025; Parliament and Council reached a deal at trilogue on 7 May 2026, Parliament voted it through on 16 June, and the Council gave final approval on 29 June. Then it sat for nearly a month before publication β€” landing in the Official Journal with less than a week to spare.

What actually got pushed back

Standalone high-risk AI systems (Annex III) β€” the systems everyone was racing to certify β€” move from 2 August 2026 to 2 December 2027, a 16-month deferral. High-risk AI embedded in already-regulated products (medical devices, machinery, toys) moves from 2 August 2027 to 2 August 2028, a 12-month deferral. Two different obligations, two different amounts of extra runway β€” not a single across-the-board delay.

What didn't move at all

This is the part that gets lost in "the AI Act got delayed" headlines: Article 50 transparency obligations still apply on 2 August 2026 β€” the rules requiring disclosure when content is AI-generated or when a user is talking to a chatbot β€” alongside the Act's measures in support of innovation. That's also when enforcement itself starts, at both national and EU level, for general-purpose AI models, the Article 5 prohibitions, transparency rules, and AI literacy obligations. One carve-out on the transparency side: providers of synthetic-content systems already on the market by 2 August 2026 get an extra four months β€” until 2 December 2026 β€” to comply with the specific Article 50(2) obligation.

(Separately, and unrelated to any of this: member states are required to have at least one national AI regulatory sandbox operational by 2 August 2027 β€” a date the Omnibus didn't touch, if only because it was never part of the 2026 milestone to begin with.)

A new prohibition, on its own faster clock

The Omnibus didn't only defer things β€” it added a new Article 5 ban: AI systems built to generate non-consensual intimate imagery ("deepfake nudification") or CSAM, prohibited in three configurations β€” placing such a system on the market for that purpose, placing one on the market without reasonable safeguards against it, and a deployer using one for that purpose. Per the Commission's own implementation timeline, the prohibition doesn't take legal effect immediately β€” it starts to apply on 2 December 2026, the same date carrying the Article 50(2) transitional deadline mentioned above. Four months past the general August 2026 milestone: everything else in this piece got a multi-year reprieve; this one got a head start instead.

The AI Office's supervisory reach just widened

Under the original Act, the AI Office supervised a GPAI model and any downstream AI system built on it only when the same provider made both. The Omnibus extends that to the same provider or the same corporate group, and adds AI systems integrated into "very large online platforms" or "very large online search engines" under the Digital Services Act. It also grants the Office market-surveillance-authority powers β€” entering business premises, inspecting books and data, demanding explanations from staff. Worth being precise about what's genuinely new here: the GPAI fine regime itself β€” up to 3% of global turnover or €15M β€” was already scheduled to become enforceable from 2 August 2026 under the original Act; the Omnibus left that date alone. What it changed is who else falls under that supervision.

What to expect next

  • "Delayed" will keep getting overstated. Annex III moved 16 months; Annex I moved 12; Article 50 didn't move at all. Any post-2 August coverage that says "the AI Act was pushed back" without specifying which part is skipping the part that matters most for most deployers.
  • The CSAM/deepfake prohibition runs on the shortest clock in the package. Everything else here got deferred by a year or more; this one takes effect four months after the original August 2026 milestone, not years after it.
  • Corporate-group restructuring gets a new AI Office angle. Any group with a GPAI provider and a separately-incorporated downstream product subsidiary just lost the "different legal entity" argument for staying outside the Office's supervision.
  • Expect a similar last-week scramble before 2 December 2027. The pattern here β€” provisional agreement months out, formal adoption pushed to the wire β€” is likely how the Annex III deadline plays out too.

References: European Commission β€” AI Act Service Desk, official implementation timeline Β· NicFab β€” Regulation (EU) 2026/1744 published in the Official Journal Β· EU Artificial Intelligence Act β€” implementation timeline Β· DLA Piper GENIE β€” proposed deferral of high-risk obligations Β· Bird & Bird β€” May trilogue provisional agreement Β· Council of the EU β€” final green light, 29 June 2026 Β· Gibson Dunn β€” postponed high-risk deadlines and key changes Β· ComplianceHub.Wiki β€” the August 2, 2026 deadline that moved Β· Digital Watch Observatory β€” the AI Office's new powers

The AI Act's Compliance Cliff Just Got Deferred β€” Except Where It Didn't | Laura Martel