The Clock Didn't Stop: What the 2026 Digital Omnibus Actually Delays, and What's Already Live
“The EU AI Act was delayed” is the most expensive misreading in circulation. Regulation (EU) 2026/1744 moved some high-risk dates. It did not pause the Act, and it did not touch the duties already in force.
MikeFounder & developer
4 min read
- AI governance
- EU AI Act
- Compliance
AI governance
“The EU AI Act was delayed” is the sentence I hear most, and it is the one most likely to leave you exposed. It was not delayed. Parts of Chapter III were. The rest of the clock kept time.
Regulation (EU) 2026/1744, the Digital Omnibus on AI, was signed on 8 July 2026, published in the Official Journal on 24 July, and entered into force on 27 July. It amends the AI Act (Regulation (EU) 2024/1689). It does not repeal it. If your plan was to wait until “the delay” ran out, you need to know which delay you mean.
What actually moved
The headline change is the high-risk regime in Chapter III, Sections 1 to 3.
For stand-alone systems classified as high-risk under Article 6(2) and Annex III (recruitment tools, credit scoring, education, insurance pricing, the list that catches ordinary operators), the application date moved from 2 August 2026 to 2 December 2027.
For AI systems that are safety components in products already regulated under Annex I (medical devices, machinery, vehicles, toys), the date moved from 2 August 2027 to 2 August 2028.
Providers and deployers of high-risk systems intended for public authorities have until 2 August 2030 to bring those systems into line, under the amended Article 111.
National AI regulatory sandboxes, originally due by 2 August 2026, now have until 2 August 2027.
Those extra months are real. They do not pause the statute. Anyone with an Annex III system in the building already has a project start date.
What did not move
This is the part a headline leaves out.
Article 5, the ban on prohibited practices, has applied since 2 February 2025. Social scoring, untargeted scraping of facial images to build a recognition database, emotion recognition in the workplace or education in most cases, real-time remote biometric identification in public spaces except the narrow law-enforcement exceptions: still banned. The Omnibus added two more entries, for AI systems that generate non-consensual intimate imagery and AI-generated child sexual abuse material. Those two apply from 2 December 2026. They do not loosen the bans that have been live for eighteen months.
Chapter V, general-purpose AI models (Articles 51 to 55) has applied since 2 August 2025. Transparency documentation, copyright policy, a summary of training content, and the extra duties for models presumed to carry systemic risk above 10^25 FLOPs of training compute: still live. Models already on the market before 2 August 2025 have until 2 August 2027. The Omnibus did not push Chapter V.
Article 50 (transparency) applies from 2 August 2026, eleven days before this post. If a system interacts directly with a person, that person must know they are talking to a machine unless it is obvious. Deepfakes and certain public-interest text must be labelled. Providers of generative systems must mark synthetic output so it can be detected. The one concession is a grace period: systems already on the market before 2 August 2026 have until 2 December 2026 to meet the Article 50(2) machine-readable marking duty. Systems launched on or after 2 August comply from day one. Chatbot disclosure and deepfake labelling were not given that grace.
The AI Office's enforcement powers over GPAI providers also switch on with the 2 August 2026 general application date. The scaffolding is going up, not coming down.
This does not give you relief if…
If you are running a prohibited practice, the Omnibus is irrelevant. Article 5 is not in the deferred chapter. A “we thought the Act was delayed” file will not help you.
If you deploy a chatbot, a voice agent, or a public-facing generator into the EU market, or one whose output is used there, Article 50 is already your problem. Being a UK company does not take you out. Article 2 was not narrowed.
If you provide a general-purpose model, you have been on the clock since August 2025. The high-risk delay is not your delay.
If your only AI is a staff Copilot used to draft emails, you are probably not in Annex III. You may still have Article 4 literacy duties (in force since 2 February 2025, rewritten by the Omnibus from a duty of result into a duty of effort) and GDPR duties that never depended on the AI Act at all.
What the extra months are for
Sixteen months on Annex III is not a holiday. Building a defensible file (inventory, classification rationale, data lineage, oversight design, logging) is a two-to-three quarter job in a mid-sized operation, and it competes with everything else on the roadmap. December 2027 is the date the obligations apply, not the date you start.
The full dated table, live versus deferred, with citations, sits in the library: EU AI Act: Timeline & Current Status. That page is the one that will be revised when the next instrument moves a date. This post makes the case; the table holds the dates.
The dangerous sentence is “the AI Act was delayed.” The accurate one is: Chapter III high-risk duties for Annex III systems apply from 2 December 2027; Article 5, Chapter V, and Article 50 do not wait for that date. Plan against the second sentence.
If this is live in your operation, talk to us.