Most coverage of the EU AI Act in July 2026 carried the same headline: the high-risk deadline has been delayed. That is true. It is also the least useful sentence you could take away from it.
Two obligations did not move. One has been enforceable since August 2, 2026. The other lands on December 2, 2026, which is under three months from now. If your business puts AI-generated text, images, audio or video in front of anyone in the European Union, that second date is the one on your calendar.
Here is what actually changed, what did not, and which parts apply to a company that has never built an AI model in its life.
The Instrument: Regulation (EU) 2026/1744
The Digital Omnibus on AI was published in the Official Journal of the European Union on July 24, 2026, and entered into force on July 27, 2026, as Regulation (EU) 2026/1744. It amends the AI Act (Regulation (EU) 2024/1689) along with the EU’s aviation and machinery regulations.
The timing was deliberate. It landed six days before the AI Act’s general application date of August 2, 2026, which the recitals cite as the reason for the unusually fast entry into force.
What it did was narrow: it moved four application dates. It created no new derogations for the obligations themselves.
What Moved, and What Did Not
| Obligation | Original date | Now |
|---|---|---|
| High-risk systems under Annex III (standalone) | 2 August 2026 | 2 December 2027 |
| High-risk AI embedded in Annex I regulated products | 2 August 2027 | 2 August 2028 |
| National AI regulatory sandboxes | 2 August 2026 | 2 August 2027 |
| Article 50(2) marking, for generative systems already on the market | 2 August 2026 | 2 December 2026 |
| Article 50 transparency duties | 2 August 2026 | Unchanged — live now |
| Prohibited practices (Article 5) | 2 February 2025 | Unchanged |
| General-purpose AI model obligations | 2 August 2025 | Unchanged |
Read that table twice. The delay applies to the heaviest compliance machinery: conformity assessments, quality management systems, technical documentation, CE marking, database registration. Those requirements were not softened. They were postponed, and only for high-risk classifications.
Everything a normal business is likely to touch stayed where it was.
Article 50 Is the Part That Reaches Ordinary Companies
Article 50 covers transparency, and it applies to deployers as well as providers. In plain terms, it requires that people be told when they are dealing with a machine, and that synthetic content be marked as synthetic.
That sweeps in a lot of businesses that would never describe themselves as AI companies:
- A retailer running a customer service chatbot on its EU storefront.
- An agency producing AI-generated images or voiceovers for a client’s European campaign.
- A publisher using AI to draft or illustrate articles read in the EU.
- A recruiter using an AI tool that interacts directly with candidates.
None of those is a high-risk system in the Annex III sense. All of them sit inside Article 50, and Article 50 has been enforceable since August 2.
December 2, 2026: Three Dates Converge
That one day carries three separate items.
Legacy generative systems must comply with Article 50(2). Providers of AI systems generating synthetic audio, image, video or text that were placed on the market before August 2, 2026 were given until December 2 to implement machine-readable marking. If you shipped a generative feature in 2025, this is your date, not August.
Two new prohibitions take effect. The Omnibus added categories to Article 5 covering AI systems that generate or manipulate realistic non-consensual intimate material depicting identifiable people, and systems connected to child sexual abuse material. Prohibited practices carry the Act’s steepest penalties.
The transition window closes. After December 2, the distinction between legacy and new generative systems disappears for transparency purposes.
The Quieter Changes Worth Knowing
Three amendments got almost no coverage but change real compliance work.
A new Article 42(3) creates a presumption of conformity: high-risk systems within the scope of the Cyber Resilience Act that meet its Article 12(1) conditions are deemed to satisfy the AI Act’s cybersecurity requirements under Article 15. That removes a duplicate assessment for products caught by both regimes.
The Commission is now required to ask European standardisation bodies, without undue delay, to develop deliverables that let companies comply with the AI Act and Annex I sectoral law together rather than twice.
And the AI literacy duty was softened. It was never the hardest obligation, but it was the one most likely to be quietly ignored.
Why the Delay Happened
The official reasoning is about readiness, not retreat. Harmonised technical standards for high-risk systems were not finished, and neither was the enforcement infrastructure at member state level. Asking companies to demonstrate conformity against standards that do not exist yet is not a workable ask.
Industry groups had lobbied for more time and got it. Civil society organisations argued the postponement weakens a regime that took years to negotiate. Both readings are defensible, and the regulation itself takes no position: it moves dates and leaves the substance intact.
What it does not support is the interpretation that spread fastest, which is that the AI Act has been shelved. It has not. Regulatory pressure on digital platforms in Europe and the UK has been building steadily, as the UK’s proposed overnight social media restrictions for teenagers showed earlier this year.
What to Do Before December
- Inventory your AI touchpoints. Not your models — your points of contact with EU users. Chatbots, generated copy, generated imagery, synthetic voice, AI-assisted screening.
- Check your disclosures. Does a user interacting with your bot know it is a bot, before they type anything?
- Check your marking. Article 50(2) is about machine-readable marking of synthetic content, not just a visible caption. Ask your vendor what they emit, in writing.
- Separate your calendars. August 2026, December 2026, August 2027, December 2027 and August 2028 are five different tracks. Treating them as one project is how the December date gets missed.
- Do not unwind your high-risk work. The requirements are identical; only the deadline moved. Teams that disbanded their programmes in July will rebuild them in 2027 at higher cost.
Common Questions
Does this apply to a company outside the EU? The Act reaches providers and deployers whose systems are placed on the EU market or whose output is used in the EU. Practical enforcement against a foreign business depends heavily on circumstances, much as it has with GDPR.
Are we a provider or a deployer? A provider develops the system; a deployer uses it professionally. Importing or distributing an AI system into the EU market can make you a provider. The distinction changes which obligations apply.
What are the penalties? They are tiered, with prohibited practices at the top of the scale. The Act’s maximum figures reach into the tens of millions of euros or a percentage of global annual turnover, depending on the breach.
Where This Stands
Information here is current as of September 5, 2026. Regulation (EU) 2026/1744 is in force and its dates are settled, but implementing acts, Commission guidance and harmonised standards are all still being produced, and any of them can change how the obligations are applied in practice.
The useful reframe is this. The Omnibus did not reduce what Europe expects from AI systems. It rescheduled the hardest part and left the part that touches the most companies exactly where it was. If you only track one date from this article, track December 2.