Back to Blog
EU AI Act

The EU AI Act's high-risk deadline moved. Here's what still applied on 2 August 2026.

Published 26 August 20265 min readBy EmberHound

The Digital Omnibus deferred the Annex III high-risk obligations to December 2027. Article 50 transparency was not deferred. A plain reading of what is live now, what moved, and the dates that are closer than they look.

On 27 July 2026, six days before the EU AI Act's most-anticipated deadline, Regulation (EU) 2026/1744 - the Digital Omnibus on AI - entered into force. It defers the Chapter III requirements for high-risk AI systems classified under Article 6(2) and Annex III from 2 August 2026 to 2 December 2027, and for systems classified under Article 6(1) and Annex I, where AI is embedded in products already covered by EU product-safety law, to 2 August 2028.

Most coverage stopped at 'the deadline moved'. The deferral is narrower than that reading suggests, and 2 August 2026 stayed a live compliance date for a set of obligations that apply to organisations of every size and every risk tier.

The Digital Omnibus deferred the high-risk deadlines. It did not defer Article 50 transparency, and it did not remove the Article 5 prohibitions or the Article 4 AI literacy duty, both of which have applied since 2 February 2025.

What actually applied on 2 August 2026

Article 50 sets transparency duties that attach to how a system interacts with people rather than to its risk classification. Two of the four sit with providers and two with deployers, which is the distinction most summaries skip:

DutyArticleFalls on
Telling people they are interacting with an AI system, unless it is obvious50(1)Provider
Marking synthetic audio, image, video and text in a machine-readable format50(2)Provider
Informing people exposed to emotion recognition or biometric categorisation50(3)Deployer
Disclosing deepfake content as artificially generated or manipulated50(4)Deployer

If you buy a chatbot and run it under the vendor's name, 50(1) is the vendor's duty. Put your own name or trademark on it and the Article 3(3) definition of provider can make the duty yours, because a provider is whoever places the system on the market under their own name. That test is separate from Article 25, which moves the provider role only for high-risk systems. Worth checking before assuming Article 50 is somebody else's problem.

What moved and what didn't

ObligationOriginal datePosition after the Omnibus
Prohibited practices (Article 5)2 February 2025In force, and extended
AI literacy (Article 4)2 February 2025In force, wording softened
General-purpose AI model obligations2 August 2025In force, unchanged
Transparency (Article 50)2 August 2026In force, not deferred
High-risk, Annex III standalone (Article 6(2))2 August 2026Deferred to 2 December 2027
High-risk, product-embedded (Article 6(1), Annex I)2 August 2027Deferred to 2 August 2028

What lands before December 2027

The Omnibus left a nearer set of dates that got much less attention than the headline deferral. Both fall in December 2026, and both are worth a diary entry now:

  1. 1Providers of generative systems placed on the market before 2 August 2026 must meet the Article 50(2) machine-readable marking requirement. Systems placed on the market from 2 August 2026 had to comply immediately, so this transitional window covers only what was already out there.
  2. 2Two prohibited practices added by the Omnibus take effect: AI systems generating non-consensual intimate imagery, and systems generating child sexual abuse material. There is no exemption for systems already on the market.
We state that milestone as 'December 2026' rather than a specific day on purpose. The European Commission's own policy page gives the month without a day, and the day quoted in secondary summaries has not been checked against Article 113 in the Official Journal text. Treat it as month-precision until you have read the source yourself.

What the extra sixteen months are for

Sixteen months sounds generous until you count what has to happen inside them. The deferred Chapter III obligations cover risk management, data governance, technical documentation, logging, human oversight, and accuracy. For deployers, Article 26 adds using the system per the provider's instructions, assigning competent and trained people to oversee it, monitoring its operation, and retaining automatically generated logs for at least six months.

None of that can start until you know which systems you run and how each one classifies. Most organisations cannot yet produce that list. Classification under Article 6 and Annex III is the gating step for everything downstream, and it is not a task that compresses into a final quarter.

Does this reach you outside the EU?

The Act applies to providers placing AI systems on the EU market wherever they are established, and to deployers established in the EU. It also reaches providers and deployers outside the EU where the output produced by the system is used in the EU. For a UK business the practical test is usually whether you have EU customers, EU staff, or EU-facing outputs, not where the servers sit.

The UK has not adopted an equivalent statute. If you operate in both, the AI Act is likely to be the higher bar and the one that sets the shape of your programme.

What to do in the next quarter

  1. 1Confirm your role for each system. Deployer and provider carry very different obligations, and Article 25 can move you between them without you doing anything you would think of as building an AI system.
  2. 2Check Article 50 against what you are running now. It applies today, and the deployer duties on deepfakes and on emotion recognition are the ones organisations most often have live without having noticed.
  3. 3Build the system inventory. Every deferred obligation attaches per system, so the list is the prerequisite for all of them.
  4. 4Document your AI literacy measures. The duty has applied since February 2025 and no deferral touched it.
  5. 5Screen each system against Annex III. December 2027 is the deadline for compliance, not the date to begin classifying.
This post describes the regulation as published. It is not legal advice, and the Omnibus amends text that many summaries still quote in its original form. Check the consolidated text or take advice before relying on a classification decision.

Where data discovery fits

Article 26(4) requires deployers to ensure input data is relevant and sufficiently representative for the system's intended purpose, to the extent they control that data. Article 26(9) points deployers at their GDPR data protection impact assessment obligations, using the information the provider supplied. Both questions assume you know what data reaches the system. Where personal data arrives from file shares, mailboxes and endpoints that nobody catalogued, neither has an answer yet - the same gap that makes Article 30 records incomplete and access requests slow.

Sources & references

  1. Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (AI Act) - EUR-Lex
  2. Regulation (EU) 2026/1744 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 (Digital Omnibus on AI) - EUR-Lex
  3. Regulation (EU) 2024/1689 - consolidated text as at 27 July 2026 - EUR-Lex
  4. AI Act - regulatory framework for artificial intelligence - European Commission

Related resources

Want more of this in Google?

See what personal data your endpoints are hiding

EmberHound scans your devices for GDPR and PCI data automatically - no manual discovery required.

Your cookie choices

We use cookies to run this site, measure how it is used, and to advertise on other platforms. You can accept or refuse each purpose separately.

Keeps you signed in and remembers this choice. Always on.

Google Analytics, Sentry and Vercel. Which pages are used, and what breaks.

LinkedIn, X and Meta pixels, loaded through Google Tag Manager.

Cookie policy