The delay is real, but it is not the whole AI Act

Europe has changed the timetable for some of its most demanding AI rules.

The AI Omnibus entered into force across the European Union on 27 July. Its legal name is Regulation (EU) 2026/1744. It moves the application dates for two groups of high-risk AI systems and makes a wider set of changes to the AI Act.

Systems listed as high-risk in Annex III, including certain uses in employment, education, essential services and law enforcement, now face their main rules from 2 December 2027.

High-risk AI built into regulated products such as machinery, toys and lifts moves later still, to 2 August 2028.

That is a substantial delay. It is also easy to misread. The Omnibus does not postpone every AI Act obligation, and one important deadline is only days away.

The 2 August transparency date stays put

The European Commission's updated implementation timeline says the AI Act's Article 50 transparency rules begin on 2 August 2026.

Those rules cover situations in which people should be told they are interacting with an AI system, as well as duties around synthetic or manipulated content. The exact obligation depends on the system and how it is used.

Enforcement also starts on 2 August for the rules already in application, including general-purpose AI, prohibited practices, transparency and the revised approach to AI literacy.

Providers of certain synthetic-content systems already on the market before that date get a transition until 2 December 2026 for Article 50(2). New prohibitions on systems that generate non-consensual sexual deepfakes or child sexual abuse material start the same day.

So the useful summary is narrow: high-risk system deadlines moved. Transparency did not.

The Omnibus changes more than dates

The package also reshapes who gets lighter treatment and who watches the market.

Some measures previously limited to small and medium-sized businesses now extend to small mid-cap companies. Access to regulatory sandboxes expands, and an EU-level sandbox is planned.

The earlier general duty on organisations to ensure AI literacy has been simplified. The Commission and Member States take a stronger role in promoting literacy, while specific training duties for people operating high-risk systems remain relevant when those rules apply.

Registration is reduced for some systems used in high-risk areas when a provider concludes that the system itself is not high-risk. The AI Office receives wider oversight of certain systems built on general-purpose models and used inside very large online platforms and search engines.

The regulation also permits tightly safeguarded processing of special categories of personal data for bias detection and correction. That may help teams test discriminatory outcomes, but it also makes data governance especially important.

The Commission calls it targeted simplification

The European Commission says the Omnibus will ease compliance, support smaller companies and give businesses more legal clarity while preserving strong safety and fundamental-rights protections.

The dates and amendments are confirmed in the final regulation. The claim about the balance they create is a government judgement, not a measured outcome.

Supporters of the change can point to a clearer runway for standards, guidance and product-specific rules. A deadline is less useful when companies do not know what evidence a regulator will accept.

The other side is straightforward. People affected by high-risk systems will wait longer for the Act's full set of risk-management, documentation and oversight duties to apply.

Both can be true: implementation may become more workable, and legal protection may arrive later.

What to watch now

For companies, the first task is to stop treating the AI Act as one date. A system's category, launch date, role in the supply chain and use of synthetic content can lead to different obligations.

The immediate work is around the rules that still apply on 2 August: transparency notices, synthetic-content processes, records and responsibility for explaining who does what.

For high-risk systems, the extra time should not become empty time. Classification, data controls, human oversight and incident processes take longer to build than a final compliance memo.

Several questions remain open in practice. National authorities need enough capacity. The Commission and standards bodies need to turn legal language into usable tests. Organisations need to know when a human review is meaningful rather than decorative.

Europe has bought more time for its hardest rules. It has not removed the need to get the basics right this weekend.

Sources

  1. European Commission — AI Omnibus enters into forcePrimary Commission announcement published 27 July 2026. Source for the stated objectives, headline amendments and new application dates.
  2. EUR-Lex — Regulation (EU) 2026/1744Final legal text of the AI Omnibus, published in the Official Journal on 24 July 2026 and in force from 27 July 2026.
  3. European Commission AI Act Service Desk — Implementation timelinePrimary updated timeline used to verify which rules still apply on 2 August 2026 and the new 2026, 2027 and 2028 milestones.
  4. European Commission AI Act Service Desk — Digital Omnibus FAQPrimary implementation FAQ used to distinguish delayed high-risk duties from unchanged transparency requirements and transitional measures.