The EU AI Act timeline moved. What applies to you now?
Founder, Zapheron
The EU AI Act's compliance schedule changed this summer. The Digital Omnibus package deferred the obligations for standalone high-risk AI systems from August 2026 to 2 December 2027 — a genuine extension, and one that has been widely read as breathing room.
It is not, quite. The transparency obligations under Article 50 took effect on 2 August 2026 and are in force today. Most organisations I speak to have these two facts the wrong way round: they believe the whole regime slipped, when in fact the part most likely to apply to them is already live.
This piece sets out what applies now, what is coming, and how to tell which category you are in.
What actually changed?
The Digital Omnibus, which entered into force at the end of July 2026, restructured parts of the AI Act's implementation timeline. The headline change is the deferral of high-risk obligations for standalone systems listed in Annex III — the category covering employment, credit and essential services, education, biometrics and critical infrastructure — from August 2026 to December 2027.
What it did not do is defer everything. General application of the Act, including the Article 50 transparency duties, began as scheduled in August 2026.
The practical effect is a split. If you are building a CV-screening system or a credit-scoring model, you have gained roughly sixteen months. If you run a customer-facing chatbot or publish AI-generated content, you gained nothing, because your obligations started three weeks ago.
What applies right now?
Prohibited practices have been banned since February 2025. Social scoring, subliminal manipulation, and real-time remote biometric identification in public spaces are not compliance projects — they are systems you cannot deploy in the EU at all. Penalties reach €35 million or 7% of global annual turnover.
AI literacy obligations also began in February 2025. Organisations must ensure staff working with AI systems have an adequate level of understanding of them. This one is quietly widespread and quietly ignored.
General-purpose AI model rules applied from August 2025, affecting providers of foundation models rather than most deploying organisations.
Article 50 transparency duties have applied since August 2026. In practice this means: people must be told when they are interacting with an AI system rather than a human, and synthetic or AI-generated content must be identifiable as such. If you run a chatbot without disclosure, or publish generated content without marking it, this applies to you today.
What is still ahead?
2 December 2027 — obligations for standalone high-risk systems under Annex III. This is the substantial one: risk management systems across the full lifecycle, data governance and bias testing, technical documentation prepared before deployment, automatic event logging, human oversight designed into the system, conformity assessment, and registration in the EU database.
2 August 2028 — obligations for high-risk AI embedded as a safety component in products already covered by EU harmonisation legislation under Annex I: medical devices, machinery, vehicles and similar.
The distinction between those two dates matters more than it first appears. If your AI is a standalone system that makes or informs decisions about people, you are on the 2027 track. If it is a component inside a regulated physical product, you are on the 2028 track. Some organisations have both, and treating them as one programme is how deadlines get missed.
Does any of this apply to you?
Two questions determine it, and neither is about where your company is registered.
Where are the affected people? The Act applies based on where the output is used and where affected individuals are located. A Norwegian company with Estonian users is in scope. A US company serving EU customers is in scope. Being outside the EU is not, by itself, an exemption.
What is your role? Providers — organisations that develop an AI system and put it on the market — carry the heaviest obligations. Deployers, who license or purchase a system and use it in their operations, carry lighter but real ones, including informing workers where AI is used in employment contexts. Many organisations are both, for different systems, and the obligations differ per system rather than per company.
What should you do in the next ninety days?
- Inventory your AI systems. Not the strategic ones — all of them, including the vendor tools quietly embedded in HR, marketing and support. You cannot classify what you have not listed.
- Check transparency compliance first, because it is the part already in force. Every customer-facing AI interaction should disclose that it is AI. Every piece of generated content should be identifiable.
- Classify each system against Annex III. The ones that land in high-risk categories now have a December 2027 deadline and a long list of work — risk management and documentation are not tasks you start in the final quarter.
- Establish who owns this. The most common failure I see is not technical. It is that AI governance sits between legal, product and engineering and is therefore owned by nobody, until an obligation arrives with a date attached.
If you want a structured starting point, our EU AI Act Risk Classifier walks through eight questions and returns your system's likely classification, the legal basis for it, and the obligations that follow. It takes about four minutes.
One closing note, which applies to this article as much as to any tool: this is guidance, not legal advice. The Omnibus is recent, secondary interpretations of it vary, and the authoritative source is the regulation text itself. Confirm your own position with qualified counsel before making decisions on it.
Timeline verified against European Commission sources, August 2026.