Policy & Regulation

The high-risk deadline that moved: what the EU AI Act actually required on 2 August 2026

EU AI ActRegulationComplianceDigital OmnibusEnforcement
Hype level
5.0

For two years, 2 August 2026 was the date every AI compliance roadmap pointed at. It was the day the EU AI Act’s obligations for high-risk systems — risk management, data governance, technical documentation, human oversight, conformity assessment — were scheduled to bite. Vendors sold readiness programs against it. Law firms wrote countdown alerts. That date has now passed, and the high-risk regime did not start.

It was deferred by Regulation (EU) 2026/1744, the “Digital Omnibus on AI,” dated 8 July 2026, published in the Official Journal on 24 July and in force from 27 July — six days before the deadline it moved. The obligations for standalone high-risk systems under Annex III now apply from 2 December 2027. For high-risk AI embedded in regulated products under Annex I, the date is now 2 August 2028, pushed back from 2 August 2027. Something did apply on 2 August 2026, and it is not nothing. But it is not what the roadmaps said.

This is worth recording carefully, because regulatory timelines are the one part of the AI debate where the claim and the resolution are both matters of public record. There is no benchmark dispute here, no eval methodology to argue about. A regulation either applies on a date or it does not.

What the omnibus changed

The deferral was not a surprise so much as a slow-motion one. The Commission published its AI simplification proposal in November 2025. A provisional political agreement was reached on 6 May 2026 and confirmed by the Council the following week, per Gibson Dunn’s summary of the agreed text. The final regulation was signed 8 July and published 24 July.

The amendment operates on Article 113 of the AI Act — the article that sets the staggered application dates. The substance of Chapter III, Sections 1 to 3 was not gutted; the obligations still exist in the same form. What moved was when providers have to meet them. The stated justification is procedural rather than philosophical: harmonised standards, the technical documents against which conformity is actually assessed, were not ready, and national competent authorities were not in place.

Both of those are verifiable, and both were visible well before the omnibus. The AI Act required Member States to designate their notifying and market surveillance authorities and single points of contact by 2 August 2025. In a briefing published 18 March 2026, the European Parliament’s Members’ Research Service reported that the Commission’s list “comprised eight single contact points, out of 27.” Seven months past a statutory deadline, fewer than a third of Member States had completed the most basic step in the enforcement chain. A high-risk regime commencing in August 2026 would have commenced into a supervisory vacuum in most of the single market.

The omnibus also did more than shift dates. It expanded the AI Office’s role, giving it investigation and inspection powers and exclusive competence over general-purpose AI where the model and the system come from the same developer — a consolidation that matters for the frontier labs specifically, since it routes them to Brussels rather than to 27 national regulators. And it added a prohibition on AI-generated non-consensual intimate imagery and child sexual abuse material, with a transitional period running to 2 December 2026.

What did apply on 2 August

The transparency layer landed on schedule. Article 50 obligations now apply: providers must disclose when a person is interacting with an AI system, and deployers must disclose deepfakes and inform people subject to emotion recognition or biometric categorisation. Machine-readable marking of synthetic content is also required, though systems already on the market got a grace period to 2 December 2026 before the marking obligation bites.

That grace period is the detail most likely to be misread. “Article 50 applies from August” and “your existing product must be watermarking today” are different statements, and the second one is wrong for systems placed on the market before the date. Providers building new systems do not get the extension.

Two other tranches were already live and remain so. The Article 5 prohibitions on unacceptable-risk practices — social scoring, certain biometric categorisation, manipulative techniques — have applied since 2 February 2025. Obligations for general-purpose AI model providers have applied since 2 August 2025, with the one-year grace period for signatories of the GPAI Code of Practice running out on 2 August 2026, as Norton Rose Fulbright’s data protection team laid out in July.

So the accurate summary of 2 August 2026 is: disclosure duties began, the GPAI grace period ended, and the compliance-heavy conformity regime for high-risk systems moved out by sixteen to twenty-four months depending on the annex.

The enforcement machinery is still behind the calendar

An obligation that applies is not the same as an obligation that is enforced. Article 50 enforcement is decentralised — it runs through national market surveillance authorities, not through the AI Office. That is the same authority infrastructure the Parliament’s own researchers found to be substantially undesignated in March 2026.

This produces a predictable asymmetry. The first enforcement actions will come from the Member States that built capacity early, which means the effective regulatory temperature will vary by jurisdiction long before it converges. Companies operating across the EU will face a compliance floor set by their most active regulator rather than by Brussels, which is roughly the opposite of what a harmonising regulation is meant to do.

For anyone tracking claims about the AI Act, this matters more than the headline dates. Between 2024 and 2026, the Act was described in industry commentary as both an imminent innovation-killer and a paper tiger. The record now supports a narrower reading: the Act is real, its obligations are real, and its timetable has proven negotiable when implementation infrastructure was not ready. That is a claim about institutional capacity, not about regulatory intent.

What this predicts about the 2027 and 2028 dates

The obvious question is whether December 2027 and August 2028 are firmer than August 2026 was. The honest answer is that we do not know yet, but there are observable indicators rather than vibes.

The binding constraint the omnibus cited was harmonised standards. CEN-CENELEC’s work on the standards underpinning conformity assessment is the load-bearing dependency: if those are published with enough lead time for providers to test against them, the 2027 date has a mechanism for holding. If they are not, the same argument that justified this deferral will be available again, and it will have precedent behind it.

The second indicator is authority designation. The count of Member States with functioning market surveillance authorities is public and countable. If it moves from single digits toward the mid-twenties over the next year, the enforcement story changes materially. If it does not, a December 2027 start date describes a legal fact and not an operational one.

The third is the political economy. This deferral was packaged as “simplification,” and it arrived alongside a broader European push on competitiveness. A precedent now exists for moving AI Act dates through an amending regulation on roughly a six-month legislative cycle. Whether that becomes a one-off or a pattern is the thing to watch, and it is the sort of question that gets answered by counting, not by arguing.

What changes the picture going forward

For compliance teams, the practical read is that the work does not go away, but the sequencing does. Documentation, data governance, and risk management systems built for an August 2026 deadline are not wasted; they are early. The teams that will be exposed are the ones that treat sixteen extra months as permission to stop, because the 2027 obligations are the same obligations with a longer runway and — if standards arrive late — potentially a much more compressed real preparation window than the calendar implies.

For anyone reasoning about AI regulation more broadly, the useful lesson is about what kind of claim a legislative date is. It is a commitment made years in advance by an institution that does not control the technical and administrative prerequisites for keeping it. The AI Act’s prohibitions arrived on time. Its transparency duties arrived on time. Its most operationally demanding regime did not, and the reason was not lobbying pressure alone but the absence of the standards and authorities required to make compliance assessable at all.

That distinction is worth keeping. “The EU delayed the AI Act” is a headline that flattens a specific, documented failure to build enforcement capacity into a story about political will. The record supports the narrower version: the deadline moved because the machinery behind it was not finished, and the machinery being unfinished was measurable and public more than a year before anyone moved the date.