Key takeaways
- The Digital Omnibus (in force July 2026) moved the high-risk obligations back: stand-alone Annex III systems now 2 Dec 2027, embedded Annex I systems 2 Aug 2028.
- 2 August 2026 is still a live deadline — for Article 50 transparency, not high-risk. If your AI talks to customers or generates content, you are in scope now.
- New prohibited practices (incl. NCII/CSAM generation) apply 2 Dec 2026, with a 3-month grace on Art. 50(2) marking for legacy systems.
- "Deadline moved" is not "stand down": the transparency obligations are closer than the old high-risk date, and the extra 12–18 months on high-risk is exactly enough time to do it properly instead of in a panic.
Short version: the Digital Omnibus pushed the EU AI Act’s high-risk obligations to December 2027 and August 2028, but the Article 50 transparency rules still bite on 2 August 2026, and new prohibited practices land in December 2026. The deadline moved; the obligation that lands first did not.
For most of the last two years, every EU AI Act briefing had one number in it: 2 August 2026. That was the date the high-risk obligations were supposed to bite. We built our client roadmaps around it. Half the compliance industry did.
That date has moved. The Digital Omnibus on AI — adopted by the European Parliament on 16 June 2026, by the Council on 29 June 2026, and in force from July 2026 — re-phased the AI Act. The headline high-risk obligations were pushed back by twelve to eighteen months. But — and this is where I’ve watched people misread the news in real time — 2 August 2026 is still a live deadline. Just for a different obligation.
If you read one paragraph: the transparency rules under Article 50 still apply on 2 August 2026 and were not deferred. The high-risk documentation-and-oversight machinery moved to December 2027 and August 2028. New prohibited practices land in December 2026. “The deadline moved” is true, and “so we can stand down” is the wrong conclusion. Here’s the whole picture, and what it means for a mid-market DACH deployer.
This post supersedes our earlier guide, The EU AI Act: the 5-step plan for mid-market DACH companies, which was written against the pre-Omnibus timeline. That guide’s five-step method still holds; its dates do not. Read this one for the current schedule.
What was adopted, and when
The AI Act itself — Regulation (EU) 2024/1689 — has been in force since August 2024, on a phased timeline. Prohibited practices were banned in February 2025. General-purpose AI model rules came in during 2025. The big remaining milestone was the high-risk regime.
The Digital Omnibus is not a new law that replaces the AI Act. It’s a simplification-and-sequencing package that amends it — and amends several other files at the same time. On the AI side it does three things that matter to you:
- It re-phases the application dates, moving the high-risk obligations later and keeping the transparency obligations where they were.
- It introduces a new “small mid-cap” (SMC) category — a size band above SME — with reduced administrative burden. If you’re a mid-market company that always felt the SME carve-outs didn’t quite fit you, this is aimed at you.
- It runs alongside a data-omnibus track that touches GDPR, ePrivacy, NIS2 and the Data Act — so the same reform wave is reshaping obligations you already carry, not just the AI ones.
The adoption sequence matters for one practical reason: the dates below are settled law now, not a proposal you can bet against. Parliament in June, Council in June, in force in July. Plan against them.
The new timeline
Here is the corrected schedule. Every regulatory date we publish is checked against this — if you see an older post on our site or anyone else’s still quoting “2 August 2026” as the high-risk deadline, it predates the Omnibus.
| Date | What applies | Changed? |
|---|---|---|
| 2 Aug 2026 | Article 50 transparency obligations apply | No — not deferred |
| 2 Dec 2026 | New prohibited practices apply (incl. NCII/CSAM generation); Art. 50(2) marking/detection applies to legacy systems (3-month grace) | New |
| 2 Aug 2027 | National AI regulatory sandboxes due; Commission delegated acts for Annex I sectoral rules | — |
| 2 Dec 2027 | High-risk obligations apply to stand-alone Annex III systems | Moved from 2 Aug 2026 |
| 2 Aug 2028 | High-risk obligations apply to Annex I embedded AI systems | Moved from 2 Aug 2027 |
Two of these dates are sooner than the old high-risk cliff everyone was planning for. That’s the part that gets lost when “the deadline moved” becomes the whole story.
What still lands on 2 August 2026: Article 50, in practice
Article 50 is the transparency layer. It’s short, it’s cheap to comply with, and it applies to a huge share of the AI that mid-market companies actually run. It was not touched by the Omnibus. It applies on 2 August 2026.
In plain terms, four obligations:
- AI you interact with must say so. A chatbot, a voice agent, an AI phone line — the person on the other end must be able to tell they’re dealing with a machine, unless it’s obvious. If you run a support bot on your site, that’s you.
- Synthetic media must be marked as machine-readable. Text, images, audio and video your systems generate must be marked so downstream tools can detect them. This is the machine-readable marking obligation under Art. 50(2) — the part with a three-month grace for legacy systems, landing 2 December 2026.
- Deepfakes must be labelled to the viewer. If you generate or manipulate image, audio or video content that resembles real people, places or events, it has to be disclosed as artificially generated.
- Emotion-recognition and biometric-categorisation systems must inform the people exposed to them.
If your AI never faces a customer, a partner or the public — a demand-forecasting model that only feeds an internal planner, say — Article 50 largely passes you by. But be honest about “internal.” An AI that drafts customer emails, scores inbound leads that then get a human-sounding auto-reply, or generates marketing copy is facing outward.
What moved to 2027 / 2028 — and why “stand down” is the wrong read
The high-risk regime is the heavy one: technical documentation, data governance records, human-oversight design, logging, post-market monitoring, conformity assessment. That’s what moved.
- Stand-alone Annex III systems — the classic high-risk use cases like AI in recruitment, credit scoring, or access to essential services — now apply from 2 December 2027 (from 2 August 2026).
- Annex I embedded systems — AI that’s a safety component of a product already regulated under EU product law (machinery, medical devices, and so on) — now apply from 2 August 2028 (from 2 August 2027).
Twelve to eighteen extra months. I understand the temptation to close the folder. Three reasons not to:
One: the sooner obligations don’t care about the high-risk date. Transparency (Aug 2026) and expanded prohibited practices (Dec 2026) are both ahead of where the high-risk work now sits. If you filed the whole AI Act under “2026 problem” and then heard “deadline moved to 2027,” you’ve now got two obligations quietly overdue while you relax.
Two: high-risk compliance is retrofit-expensive. The documentation and logging obligations are painful to bolt on after a system is live and unpainful to design in. If you’re building or procuring an Annex III system in 2026 — a new applicant-tracking model, a credit engine — the extra time is a gift for doing it right, not a reason to build it non-compliant and fix it later. Retrofitting audit-grade logging onto a running model is the single most expensive mistake we see.
Three: procurement runs ahead of the law. Enterprise buyers and DACH public-sector tenders already put AI Act readiness in their RFPs. We watched deals turn on it in Q1 2026, well before any high-risk date. Your customers’ compliance calendars are stricter than the regulation’s.
The revised 5-step plan for mid-market DACH deployers
The method from our original guide survives the Omnibus intact — only the sequencing changes, because transparency is now the near-term forcing function, not high-risk. Same five steps, re-pointed at the real dates.
- 01
Inventory every AI system — and flag what faces outward
Catalogue every AI system you use, build, or embed: commercial tools (ChatGPT Enterprise, Copilot, Salesforce Einstein), custom models, ML inside existing software, third-party APIs. For each, record one new field the Omnibus makes urgent: does it interact with, or produce content for, a customer, partner, or the public? That flag drives your Article 50 exposure. Most mid-market companies find 5–15 systems when they actually look.
⏱ 1–2 weeks
- 02
Close Article 50 first
For every outward-facing system, add the transparency measures: bot disclosure, synthetic-content marking, deepfake labelling, emotion-recognition notice. This is the 2 August 2026 obligation and it is cheap — do it now while it is the binding date, not after. Machine-readable marking for legacy systems has until 2 December 2026, but do it in the same pass.
⏱ 1–2 weeks
- 03
Classify for risk — and check the prohibited list
Classify each system by risk tier using Annex III for high-risk domains. Then check it against the prohibited practices, which expand on 2 December 2026 to include new categories such as NCII/CSAM generation. Prohibited beats everything: a banned use is not a documentation problem, it is a stop-now problem. When in doubt on high-risk, classify higher.
⏱ 1 week
- 04
Build high-risk documentation and oversight — on the new clock
For Annex III systems, you now have until 2 December 2027; for Annex I embedded systems, 2 August 2028. Use the runway to design documentation, data-governance records, human-oversight workflows, and logging into the system rather than bolting them on. If you are building or buying a high-risk system in 2026, make compliance a build requirement now — retrofitting later is the expensive path.
⏱ Scaled to system; start at design time
- 05
Stand up monitoring and keep the inventory live
Set up logging, drift and performance monitoring, incident reporting, and periodic reclassification. Your inventory is not a one-time document — new tools arrive monthly and each one re-opens the Article 50 question. Assign an owner (usually whoever runs data protection or IT compliance today) with the mandate and the time to keep it current.
⏱ Ongoing; setup 1–2 weeks
If you’re a small mid-cap under the new SMC definition, watch for the reduced-burden provisions as the Commission’s implementing detail lands — lighter documentation and reporting than the full regime, aimed squarely at companies your size. It doesn’t exempt you from the core obligations; it right-sizes them.
What to do in the next 30 days
You don’t need a governance programme this month. You need four moves:
- Run the inventory. One spreadsheet, every AI system, one column for “faces a customer/partner/public.” A day of work with the right people in the room. Everything else keys off it.
- Fix your bots and generated content for Article 50. Wherever an AI talks to someone or makes content that reaches someone, add the disclosure. This is the 2 August 2026 obligation and the fastest win on the list.
- Screen for prohibited use. Cross-check your inventory against the prohibited practices, including the December 2026 additions. If anything lands there, escalate it today — this is the one category where “later” isn’t an option.
- Re-date your roadmap. If any internal plan, board deck, or vendor contract still says “high-risk compliance by August 2026,” correct it to 2 December 2027 (Annex III) or 2 August 2028 (Annex I). Wrong dates in a roadmap cause both false panic and false calm.
The Omnibus didn’t let anyone off the hook. It moved the biggest obligation to a saner date and left the cheap, near-term ones exactly where they were. The companies that read it as “we’re done until 2027” are the ones that’ll miss August.
Where you actually stand
If you’re not sure whether your AI use is outward-facing, high-risk, or brushing against the prohibited list, that’s the whole question — and it’s answerable in an afternoon with the right inventory. Oleks builds the technical controls and logging; I handle the classification and the compliance framework. Between us we cover both the paperwork and the infrastructure that makes it real.
// SOURCES
- Regulation (EU) 2024/1689 (AI Act) — full text and guidance — European Commission, 2024
- Digital Omnibus — simplification of EU digital rules — European Commission, 2026
- AI Act Explorer — topic-indexed reference — Future of Life Institute, 2024
Frequently asked questions
Did the EU AI Act high-risk deadline change?
Yes. The Digital Omnibus, adopted by Parliament on 16 June 2026 and Council on 29 June 2026 and in force from July 2026, moved the high-risk obligations back. Stand-alone Annex III high-risk systems now apply from 2 December 2027 (from the previous 2 August 2026), and Annex I embedded high-risk systems from 2 August 2028 (from the previous 2 August 2027).What still applies on 2 August 2026?
Article 50 transparency obligations. These were NOT deferred. If you deploy a chatbot, a voice agent, an emotion-recognition system, or you generate synthetic text, images, audio or video, users must be told they are interacting with or looking at AI. That date holds.What is the Digital Omnibus?
A package of simplification and sequencing changes to EU digital law. On AI it re-phases the AI Act's application dates and introduces a new 'small mid-cap' (SMC) category with reduced administrative burden. It also touches GDPR, ePrivacy, NIS2 and the Data Act on a parallel data-omnibus track.Does the moved deadline mean mid-market companies can wait?
No. Two things are due sooner than the old high-risk date: Article 50 transparency (2 Aug 2026) and the expanded prohibited practices (2 Dec 2026). The extra time on high-risk is there to let you build documentation and oversight properly, not to postpone starting. Procurement teams already ask for AI Act readiness in RFPs regardless of the legal date.
Was this helpful?