The EU AI Act's New Deadlines: What Changed and What Still Applies Right Now
The most dangerous sentence in European tech right now is: “The AI Act got delayed, so we can deal with it later.”
Half of it is true. On 29 June 2026, the Council gave its final green light to the Digital Omnibus package, rescheduling the AI Act’s most demanding obligations. The 2 August 2026 cliff that companies spent two years dreading is gone.
The other half is where companies will get hurt. Several obligations are already in force, one lands this December, and the delayed deadlines arrive faster than most compliance programs can be built. Here is the timeline as it actually stands.
What changed
The Digital Omnibus moved the application dates for high-risk AI systems:
| Obligation | Old date | New date |
|---|---|---|
| Standalone high-risk AI systems (Annex III: biometrics, employment, credit scoring, critical infrastructure, public services) | 2 Aug 2026 | 2 Dec 2027 |
| High-risk AI embedded in regulated products (Annex I: medical devices, machinery, toys and similar) | 2 Aug 2027 | 2 Aug 2028 |
| Transparency obligations for AI-generated and AI-manipulated content | 2 Aug 2026 | 2 Dec 2026 |
Note the last row: transparency obligations were delayed by only a few months, not years. If your product generates text, images, audio or video, or runs chatbots that users might mistake for humans, 2 December 2026 is your date. That’s less than five months away.
The package also postponed the requirement for Member States to establish AI regulatory sandboxes (to August 2027) and added new prohibitions on AI-generated non-consensual intimate imagery and child sexual abuse material, applying from December 2026.
What did NOT change and applies today
Prohibited AI practices (in force since February 2025). Social scoring, exploitative manipulation, untargeted facial-image scraping, and emotion recognition in workplaces and schools (with narrow exceptions). These remain banned now, with the Act’s highest penalty tier attached.
AI literacy obligations (in force since February 2025). If your staff operates or uses AI systems, you must ensure a sufficient level of AI literacy. Quietly ignored by many companies, and one of the easiest gaps for a regulator or litigant to point at.
General-purpose AI model obligations (in force since August 2025). If you build or substantially fine-tune GPAI models, transparency, documentation and copyright-policy duties already apply.
Why “we’ll start in 2027” is a losing strategy
Enterprise procurement doesn’t wait for regulators. AI governance questionnaires are already standard in enterprise deals. Your buyers’ legal teams will ask about your AI Act posture in 2026 regardless of when enforcement begins, and “we haven’t started” loses deals today.
High-risk compliance takes 12 to 18 months to build properly. Risk management, data governance, technical documentation, human oversight, conformity assessment. For a startup, December 2027 is roughly one funding cycle away.
Investors have learned to ask. AI Act exposure now shows up in due-diligence checklists. A credible classification memo is cheap insurance against a valuation haircut.
The delay rescheduled, it did not deregulate. Companies betting on repeal are betting their EU market access on a political long shot.
What to do this quarter
- Classify your systems now. Prohibited, high-risk, limited or minimal. Everything else in your compliance plan depends on this single legal determination, and it’s where DIY goes wrong most often.
- If you touch generative AI, prepare for 2 December 2026. Marking AI-generated content, disclosing chatbots, deepfake labelling: scope it now, ship it by autumn.
- Cover the obligations already in force. An AI-literacy training record and a prohibited-practices screening memo are days of work, not months.
- If you’re plausibly high-risk, start the gap assessment in 2026. Being ready early makes “AI Act ready” a differentiator in enterprise sales long before it’s an obligation.
- Document your reasoning. Whatever you conclude, write it down. A considered, dated position is worth a great deal with regulators, customers and investors alike.
The bottom line
The Digital Omnibus bought companies time. Time is only an advantage for the companies that use it.
Mike Nimród is an IT and data protection lawyer (AIGP, CIPT, CIPP) and researcher at Corvinus University of Budapest. If you want a clear answer on how the AI Act applies to your product, from a human and not a prompt, get in touch.