The EU AI Act's compliance calendar changed on July 27, 2026, when the Digital Omnibus on AI — Regulation (EU) 2026/1744 — entered into force. Transparency rules for chatbots and AI-generated content apply now (since August 2, 2026). The high-risk regime for standalone Annex III systems — hiring tools, credit scoring, education, critical infrastructure — moved from August 2026 to December 2, 2027. AI embedded in regulated physical products got until August 2, 2028. Both deferred dates are fixed calendar dates: the proposal's clause letting the Commission pull them forward once standards were ready did not survive into the final text.
If a guide you're reading still says "high-risk obligations apply from August 2, 2026," it was written before the Omnibus and is now wrong. This page reflects the law as it stands in August 2026, with primary sources linked throughout.
Last verified: August 10, 2026. This is general information for business planning, not legal advice — for decisions about your specific obligations, talk to counsel qualified in EU law.
The new EU AI Act timeline at a glance
| Date | What applies | Status |
|---|---|---|
| July 27, 2026 | Digital Omnibus (Regulation (EU) 2026/1744) in force; AI Act timeline amended | In force |
| August 2, 2026 | Article 50 transparency: disclose AI interaction, label deepfakes and AI-generated content, notify on emotion recognition and biometric categorization | In force |
| December 2, 2026 | Machine-readable marking for generative AI systems already on the market before August 2, 2026 (end of the 4-month grace period); new prohibitions on nudification and CSAM-generation apps | Upcoming |
| December 2, 2027 | Standalone high-risk AI systems under Annex III: employment, education, credit assessment, law enforcement, critical infrastructure | Deferred (was Aug 2, 2026) |
| August 2, 2028 | High-risk AI embedded in regulated products: medical devices, machinery, toys | Deferred (was Aug 2, 2027) |
What is the Digital Omnibus on AI?
The Digital Omnibus is an EU regulation, first proposed by the European Commission on November 19, 2025, that amends the AI Act to fix a practical problem: the harmonized standards, national authorities, and conformity-assessment bodies that high-risk AI compliance depends on weren't ready. Rather than enforce rules nobody could yet comply with, the EU deferred the high-risk regime and simplified several obligations. It was published in the Official Journal as Regulation (EU) 2026/1744 and entered into force on July 27, 2026.
Three things it did not change are worth stating plainly, because the deferral headlines bury them:
- The substance of high-risk obligations is unchanged. Risk management, technical documentation, human oversight, and conformity assessment are all still coming — only the date moved.
- Transparency obligations were not deferred. They apply now.
- General-purpose AI model rules continue on their existing track.
Which EU AI Act rules apply right now?
Since August 2, 2026, Article 50 transparency obligations are live. If your business serves EU users, you must today: tell people when they are interacting with an AI system (chatbots, voice agents); clearly label deepfakes and AI-generated content; and inform people when emotion-recognition or biometric-categorization systems are used on them. Penalties for transparency violations run up to €15 million or 3% of worldwide annual turnover, whichever is higher.
One nuance most coverage misses: generative AI systems that were already on the market before August 2, 2026 have a four-month grace period — until December 2, 2026 — for the machine-readable marking requirement (the technical watermarking layer, as distinct from the visible labeling). New systems don't get that grace.
In practice, for a small or mid-size business this means three checks you should run this quarter:
- Chatbot and voice-agent disclosure. Every customer-facing AI touchpoint needs a clear "you're talking to an AI" signal. If you run an AI assistant on your site, this is a copy change, not a project.
- AI-content labeling. If you publish AI-generated images, audio, or video to EU audiences, they need clear labeling — and your tooling needs to support machine-readable marking by December.
- Vendor inventory. You can't disclose what you don't know you run. List every AI system in your stack, what it does, and who its provider is. This same inventory is the first artifact you'll need for 2027 anyway.
Which deadlines moved to December 2, 2027?
The compliance date for standalone high-risk AI systems under Annex III moved from August 2, 2026 to December 2, 2027 — a 16-month deferral. Annex III covers AI used in employment and worker management (CV screening, promotion decisions), education (exam scoring, admissions), credit assessment and essential services, law enforcement, migration, and critical infrastructure.
If you use an AI tool to screen job applicants or score loan applications for EU subjects, you are (or your vendor is) in this bucket. The obligations — risk management systems, data governance, technical documentation, logging, human oversight, conformity assessment — did not get lighter. You got time.
December 2, 2027 is a fixed date — and even much of the post-Omnibus coverage gets this detail wrong. The Commission's November 2025 proposal tied the deferral to the availability of harmonized standards, with a mechanism to pull the date forward once those standards were ready, and analyses written during the negotiation — including Gibson Dunn's read of the provisional agreement — describe that pull-forward clause. It did not survive. The final regulation sets fixed calendar dates with no stop-the-clock mechanism and no early trigger (Orrick's final-text analysis; AI Act Blog). If a guide tells you the deadline can spring forward the moment a standard is published, it is describing the draft, not the law.
A fixed date is not a license to idle, though. Sixteen months is a short runway once vendor lead times and the still-unfinished harmonized standards enter the math — and the substance of the obligations didn't shrink while the date moved.
What about AI embedded in physical products?
High-risk AI that is a safety component of products already regulated under EU product law — medical devices, machinery, toys, lifts — now has until August 2, 2028 (extended from August 2027). If you're a software-only business, this bucket mostly matters when you sell into manufacturers: expect their procurement teams to start pushing AI Act clauses into contracts well before 2028.
What is newly banned?
The Omnibus added two prohibited practices with real enforcement teeth, applying from December 2, 2026: AI systems that generate or manipulate non-consensual intimate imagery ("nudification" apps), and systems for generating child sexual abuse material. These are bans, not compliance regimes — there is no path to operating them lawfully in the EU.
The small mid-cap (SMC) relief almost nobody has noticed
Buried in the Omnibus is a new company category that changes the compliance math for mid-size businesses: the small mid-cap, or SMC — a company with fewer than 750 employees and either annual turnover up to €150 million or a balance sheet total up to €129 million (the EU definition).
Under the amended AI Act, the simplified compliance measures that previously applied only to SMEs are extended to SMCs. Per the Morgan Lewis analysis of the June 2026 agreement and Orrick's summary of the final text, that package includes simplified technical documentation templates, more proportionate quality-management expectations, priority access to regulatory sandboxes, and tailored penalty caps. If your company sits between "too big for SME relief" and "nowhere near enterprise compliance budgets" — say, 300 employees and €80M revenue — you just qualified for a lighter regime that most compliance write-ups don't mention yet, because the category didn't exist when they were written.
One caution: a separate EU legislative file (the "Omnibus IV" company-law package) is negotiating a different small mid-cap definition with higher thresholds. For AI Act purposes, the numbers that matter are the ones above. Not sure which category you are? Start with our SMC vs SME definitions guide; for the full relief list and how to use it, see the small mid-cap AI Act exemptions guide.
The other sleeper change: a lawful way to bias-test your AI
Alongside the deadlines, Regulation 2026/1744 rewrote Article 10(5) of the AI Act into something genuinely new: a legal basis to process special categories of personal data — health, ethnicity, religion, sexual orientation, and the rest of GDPR Article 9 — solely to detect and correct bias in AI models and systems. The original provision covered only providers of high-risk systems and was replaced before it ever produced legal effect; the rewritten basis reaches beyond high-risk providers (Orrick).
The conditions are strict, and they read like a checklist you can hand your engineering team:
- Processing must be strictly necessary — allowed only where bias detection and correction cannot be effectively achieved with other data, including synthetic or anonymized data.
- The data must be protected with state-of-the-art, privacy-preserving security measures, including pseudonymization.
- Access must be strictly controlled and documented, and the data must not be transmitted or transferred to other parties.
- The data must be deleted once the bias is corrected or when it reaches the end of its retention period.
Two nuances worth naming. First, this creates no obligation to bias-test anything — it removes a GDPR blocker for teams that want to. Second, it resolves a genuine catch-22 for anyone running hiring or screening AI: proving a CV-screening agent doesn't discriminate requires exactly the demographic data GDPR told you not to hold. The IAPP's analysis of the original exception shows how narrow the old, high-risk-only version was; the amended version gives you a lawful path — with the safeguards spelled out — to start building the fairness evidence your December 2027 obligations will ask for.
Does the EU AI Act apply to a business outside the EU?
Yes, potentially. The AI Act applies not only to companies established in the EU but also to providers placing AI systems on the EU market and to situations where an AI system's output is used in the EU. A US agency running an AI chatbot that serves EU visitors, or selling an AI screening tool an EU customer uses on EU candidates, is in scope. Physical location is not the test — where the system and its output land is.
What should an SME actually do before December 2027?
The deferral is an opportunity to do this in planned quarters instead of a panic sprint. The sequence that makes sense for most small and mid-size businesses:
- Now — inventory and disclose. Build the AI system inventory, fix Article 50 disclosures on every customer-facing AI touchpoint, and confirm your generative tooling can do machine-readable marking by December 2, 2026.
- Next two quarters — classify. Map each system in your inventory against Annex III. Most SME automation (internal workflow agents, support triage, content operations) is not high-risk — knowing which of your systems are and aren't changes your budget by an order of magnitude.
- 2027 — close the gap on what's actually high-risk. For the systems that are in Annex III scope: risk management, documentation, human oversight, logging. If you qualify as an SME or SMC, use the simplified documentation route.
- Throughout — demand audit trails from vendors. Whoever builds your AI systems should be able to show you what the system did and why, per interaction. That's not just compliance hygiene; it's how you establish accountability when an AI system makes an expensive mistake. It's also how we build AI agents at PxlPeak — permissions, activity logs, and human handoff are part of the architecture, not an add-on — alongside the broader compliance posture work that GDPR-era requirements already demand.
If you're trying to work out which of these buckets your automation ideas fall into before you build anything, that's a conversation we have with clients weekly — our AI agents hub covers the architecture side, or talk to us about your specific stack.
Sources
- Regulation (EU) 2026/1744 — Official Journal text (July 24, 2026)
- European Commission — AI Omnibus enters into force (July 2026)
- Modulos — EU AI Act Omnibus Published: New Deadlines (July 2026)
- European Commission — Digital Omnibus on AI regulation proposal (November 2025)
- K&L Gates Cyber Law Watch — EU Digital Omnibus on AI Enters Into Force (July 31, 2026)
- Gibson Dunn — EU AI Act Omnibus Agreement: Postponed High-Risk Deadlines (2026 — covers the provisional agreement; the pull-forward clause it describes was dropped from the final text)
- Orrick — EU AI Act Update: Digital Omnibus Finalizes 8 Compliance Changes (July 2026)
- AI Act Blog — The Digital Omnibus and the postponement of high-risk obligations to December 2027 (2026)
- IAPP — The AI Act's debiasing exception to the GDPR (2024 — the original, high-risk-only Article 10(5))
- Morgan Lewis — EU Approves Delays and Other Amendments to Certain EU AI Act Obligations (June 2026)
- EUR-Lex — Commission Recommendation on the definition of small mid-cap enterprises