What Actually Took Effect on 2 August 2026: The EU AI Act After the Digital Omnibus
Dr. Abeer Alshammari · Published 8/18/2026
For most of 2026 the conversation about the EU AI Act has circled a single question: is the high-risk deadline still real? As of 2 August, the answer is settled, and it is more nuanced than either the "everything has been delayed" or the "nothing has changed" reading suggests.
What the Digital Omnibus actually moved
The European Commission proposed the Digital Omnibus on 19 November 2025 as a simplification package touching the GDPR, the AI Act and the Product Liability Directive. The AI component was endorsed by the European Parliament on 16 June 2026 by 423 votes to 57, with 174 abstentions, and received final Council approval on 29 June 2026.
Its practical effect is a deferral of the high-risk regime. Obligations for stand-alone Annex III high-risk systems -- the employment, education, creditworthiness, essential services and law enforcement use cases -- now apply from 2 December 2027, a slip of sixteen months. High-risk AI embedded in products already regulated under Annex I moves to 2 August 2028, a slip of twelve months.
What became enforceable anyway
Article 50 was deliberately excluded from the deferral and applied on schedule from 2 August 2026. It places transparency duties on providers and deployers regardless of risk classification: people must be told when they are interacting with an AI system rather than a human; synthetic audio, image, video and text must be marked in a machine-readable format as artificially generated; deepfakes must be disclosed; and individuals must be informed when they are subject to emotion recognition or biometric categorisation. Breach exposes an organisation to fines of up to EUR 15 million or 3 percent of total worldwide annual turnover, whichever is higher.
The second change is quieter and, for anyone building on foundation models, more consequential. Obligations for general-purpose AI model providers took effect on 2 August 2025, but providers were given a one-year adjustment period before the Commission could act on them. That period closed on 2 August 2026. The AI Office can now request technical documentation, conduct its own model evaluations, demand compliance and risk-mitigation measures up to market restriction and recall, and impose fines.
Why a deferral is not a reprieve
The most common misreading is treating a moved date as a cancelled obligation. It is not. The Annex III requirements -- risk management systems, data governance, technical documentation, logging, human oversight, accuracy and robustness testing -- do not compress well. They depend on knowing which systems you operate, who is accountable for each, and what data flows through them. Organisations that used the original deadline pressure to build that inventory are now sixteen months ahead. Those that paused will rediscover in late 2027 that the discovery phase alone takes two quarters.
There is also a scoping trap. Article 50 does not care whether a system is high-risk. A customer service chatbot, an internal drafting assistant whose output gets published, a marketing tool that generates synthetic imagery -- none of these are Annex III systems, and all of them are in scope today. The deferral moved the part of the Act most organisations had budgeted for and left untouched the part most had ignored.
The governance reading
This is a familiar pattern in regulatory design and worth naming: the obligations that get deferred are the expensive ones with visible compliance programmes attached, and the obligations that survive are the ones that look like disclosure. Disclosure obligations are cheap to legislate and hard to operationalise, because they require you to know, system by system, where AI touches a person. Very few organisations have that map.
The control that matters here is not a policy document. It is an AI system register that records, for each deployed system, whether it interacts with people, whether it generates content that reaches the public, who the provider is, and which disclosure obligation attaches. That register is also the input to the Annex III work in 2027, which is why building it now is the efficient sequence rather than the cautious one.
Three things worth doing this quarter
First, inventory every AI system that produces output a person sees, and record whether the required disclosure is actually in place. Second, confirm with your general-purpose model providers what they are doing about machine-readable marking of synthetic content, because your Article 50 position depends on capabilities you may not control. Third, keep the Annex III programme funded and running on its original design assumptions, and treat December 2027 as a delivery date rather than a distant one.
The deadline moved. The work did not.
Try it yourself
An interactive CyberAbeer experience for this topic is in development.
Coming soon