The EU AI Act's August 2026 Deadline Moved. Three Things Landed Anyway.
The high-risk obligations slipped to December 2027, but Article 50 transparency, a new prohibition, and the AI Office's new powers all took effect on schedule.
On 2 August 2026, the EU AI Act's rules for high-risk AI systems were finally supposed to bite. Two years of preparation pointed at that date.
They didn't bite. Five days earlier, Regulation (EU) 2026/1744, the "Digital Omnibus on AI", entered into force and moved the deadline by roughly eighteen months.
If you spent the last year building toward August, you have more time than you thought. If you're now wondering whether you can put the whole thing down, that's the part worth reading.
What moved
The high-risk obligations, the ones covering AI in hiring, education, biometrics, migration, and access to essential services, got pushed:
| Category | Was | Now |
|---|---|---|
| Stand-alone high-risk systems (Annex III) | 2 August 2026 | 2 December 2027 |
| High-risk AI embedded in regulated products (Annex I) | 2 August 2027 | 2 August 2028 |
This isn't a proposal or a provisional agreement any more, which is worth saying because plenty of coverage still describes it that way. The Omnibus was published in the Official Journal on 24 July 2026 and entered into force on 27 July. It is law.
What didn't move
Three things landed anyway, and they're the ones more likely to touch a small software business than the high-risk regime ever was.
Article 50 transparency applies now. If someone is interacting with an AI system, or looking at AI-generated content, they have to be able to know that. This is the obligation most likely to catch an ordinary product: a chat interface, generated images, synthetic voice. It did not get deferred. The watermarking requirement in Article 50(2) has a grace period for systems already on the market, until 2 December 2026, but the broader disclosure duty is live.
A new prohibition was added. The Omnibus prohibits AI systems that generate or manipulate non-consensual intimate imagery and child sexual abuse material. It's written to catch systems where that output is a reasonably foreseeable and reproducible result without significant technical modification, not only systems built for it. There's a transitional period to 2 December 2026.
The AI Office got teeth. It now holds exclusive supervisory responsibility for certain systems built on general-purpose AI models, and for AI integrated into the very large platforms and search engines already regulated under the Digital Services Act. Enforcement moved up a level rather than out to twenty-seven national regulators.
Why the delay happened, honestly
The official framing is simplification, and giving industry room to comply with standards that weren't finished. Both are true. The harmonised standards that high-risk compliance depends on genuinely weren't ready, and a deadline you cannot actually meet is not a deadline. It's a trap.
It's also true that the pressure to delay was loud, and came from companies with a great deal to lose. Both things can be true at once. I'd rather say that plainly than pick the flattering half.
What I'd actually do with the extra time
Here's my problem with treating this as a reprieve.
If your product only handles people's data carefully because a regulation was about to force it, then the regulation moving means your users just lost eighteen months of protection they were going to get. Nothing about the risk changed on 27 July. Only the paperwork date did.
The version of this that survives regulatory whiplash is architectural. If personal data is encrypted on someone's device and you hold no key, a compliance deadline sliding doesn't alter what you can be compelled to hand over, or what a breach of your servers can expose, because the answer was already nothing. That's the bet StarkVault is built on, and it's why I don't find deadline news especially load-bearing.
Compliance is a floor that keeps moving. Build above it and you stop having to track where it went.
What to check this month
- If your product generates content or talks to users, work out whether Article 50 applies to you. That one is live now, not in 2027.
- If you've been treating August 2026 as your compliance date, re-plan against 2 December 2027, but don't quietly cancel the work.
- If you were relying on the deadline to justify a privacy investment internally, you'll need a better argument. Try the one where you never hold the data.
The deadline moved. Whether that matters depends entirely on why you were building toward it.
