Skip to content
Home Blog Compliance & Architecture

The Omnibus Deferred the High-Risk Duties. Something Still Applies on 2 August, and to Almost Everyone.

The Digital Omnibus has been in force since 27 July 2026 and pushed the AI Act's high-risk obligations back. Almost every headline reads deferral. Article 50 is not covered by it and applies from 2 August 2026, six days after the deferral entered into force.

Fabian Weiss, founder of FW Delta Fabian Weiss
Jul 29, 2026 14 Min Read

Key Takeaways

  • Regulation (EU) 2026/1744 of 8 July 2026 was published in the Official Journal on 24 July and entered into force on 27 July 2026.
  • High-risk obligations now apply from 2 December 2027 for stand-alone systems and from 2 August 2028 for those embedded as safety components in products already covered by sectoral legislation.
  • Article 50 is not amended by the Omnibus and applies from 2 August 2026. A limited grace period runs to 2 December 2026 for the marking duty under Article 50(2), for systems placed on the market before 2 August 2026.

What the Omnibus deferred and what it did not

Regulation (EU) 2026/1744 of 8 July 2026 amends the AI Act along with Regulations (EU) 2018/1139 and (EU) 2023/1230. It was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026, three days later.

The substantive core of the coverage was the new timeline for high-risk systems. Those obligations now apply from 2 December 2027 for stand-alone systems and from 2 August 2028 for those embedded as safety components in products already covered by sectoral legislation. That is a substantial deferral, and for manufacturers of high-risk systems it is the most important news of the year.

For everyone else the most important news is different: Article 50 was left untouched.

The transparency obligations apply from 2 August 2026. Six days after the deferral everyone wrote about entered into force. Anyone who read the coverage as “the AI Act has been postponed” has missed a deadline landing within days.

Two dates, six days apart

27 July 2026: the Digital Omnibus enters into force and moves the high-risk duties to 2027 and 2028.
2 August 2026: Article 50 applies. Unchanged, undeferred, for providers and deployers.

This is not legal advice

This text reflects the state of the published legal acts and the official interpretive guidance. Whether and how a duty applies to your specific system depends on classifications that require qualified assessment. What is written here does not replace that assessment. It is meant to trigger it.

What Article 50 requires

The European Commission’s guidance divides the obligations into four cases. Notably, two of them fall on providers and two on deployers, meaning companies that develop nothing and merely use a system.

Paragraph 1, direct interaction, falls on providers. People must know they are interacting with an AI system, unless this is obvious. The notification has to happen from the start of the first interaction, in a clear and distinguishable manner.

Paragraph 2, marking of generated content, falls on providers. Synthetic audio, image, video and text content must carry machine-readable marks that allow detection as AI-generated or manipulated. For systems placed on the market before 2 August 2026, the Commission notes a limited grace period to 2 December 2026, and only for this marking duty.

Paragraph 3, emotion recognition and biometric categorisation, falls on deployers. Anyone operating such systems must inform the natural persons exposed to them of their operation.

Paragraph 4, AI-generated text in the public interest, falls on deployers. Text published to inform the public on matters of public interest must be labelled as AI-generated, unless it underwent human review or editorial control.

The penalty range for breaches of provider and deployer obligations reaches 15 million euros or three percent of total worldwide annual turnover, whichever is higher.

Why this affects more companies than expected

The common assumption is that the AI Act concerns AI providers. But paragraphs 3 and 4 fall on deployers, and a deployer under the regulation is any company using an AI system under its own authority, outside purely personal activity.

That captures a lot of unremarkable everyday cases. A chat window on a website that is not immediately recognisable as automated. An assistant on the service line. Texts on a company blog covering matters of public interest that were machine-generated. Systems inferring mood from camera images, which happens in retail spaces and event venues more often than the operators realise.

None of these cases requires that you trained a model yourself. Deployment is enough.

The part that is architecture, not law

The four duties share a technical precondition that is rarely discussed: you have to know which AI systems are in use in your organisation, who uses them, what they output and where that output goes.

The question sounds trivial and is trivial in almost no company. Over the last two years, AI features did not arrive through the door of IT procurement. They arrived as feature extensions to tools already in use. A CRM gets text suggestions, a ticketing system gets summaries, an editorial tool gets a draft generator. Nobody made a procurement decision, because it was not a procurement. It was an update.

The practical consequence for the coming weeks is therefore not legal but inventory work:

  1. Which systems in use generate content or interact with people? Including features that arrived as an update to existing tools.
  2. Which of those emit something outward? To customers, to the public, to applicants.
  3. Where does marking already exist, and where are you relying on the vendor to apply it?
  4. Who decides internally when a vendor newly activates an AI feature? If the answer is nobody, that is the actual finding.

Point four is the one that matters beyond this deadline. Deadlines come and go, and the next legal act will be cut differently again. What remains is whether an organisation knows what happens inside its systems, or re-establishes it from scratch every time.

Why deferrals are the wrong planning basis

The Omnibus is the second major correction to the AI Act’s timeline. For the manufacturers concerned it is genuine relief, and it would be unfair to play that down.

It still makes a poor planning basis. A deferral is not a repeal. It moves a requirement into a year in which other requirements also fall due. Booking the reprieve as time gained and pausing the work leaves you facing the same task in 2027 with less runway and more concurrency.

The same pattern shows up with the Cyber Resilience Act, whose reporting duties bite on 11 September 2026, fifteen months before the security requirements apply in full. There too the pulled-forward duty is the organisational one, and there too many plan backwards.

We covered the earlier deferral in detail elsewhere. The observation from then still holds: with every report of a postponement, it pays to check precisely which article was moved and which was not. The answer is rarely in the headline.

What makes sense in the next few days

The 2 August deadline can no longer be addressed with a project. What it allows is an honest inventory, and that is useful even when it stays incomplete.

  • Build the inventory, even roughly. A list with twelve entries beats a perfect list that does not exist.
  • Customer-facing cases first. Chat, assistants, published text. That is where the duty is most immediate and the implementation simplest.
  • Ask vendors what they do about marking. For paragraph 2 the duty sits with the provider of the system. Whether your supplier meets it is a question you have to ask, not one that answers itself.
  • Do not overextend the grace period to 2 December 2026. According to the Commission guidance it covers only the marking duty under paragraph 2 and only systems placed on the market before 2 August. Everything else applies immediately.
  • Let lawyers do the legal classification. In particular, whether a specific system falls under paragraph 3 is not something to decide in passing.

The point behind the deadline

At its core Article 50 asks for something that fits in one sentence: people should know when they are dealing with a machine. It is one of the few rules in this field you can consider right even without a regulation behind it.

The practical effort almost never sits in the marking itself. A notice in a chat window is half an hour of work. The effort sits in knowing where the machines are in the first place. That capability is not a compliance task but a question of running your systems, and it pays off independently of any deadline.

How to build automation so it stays traceable which step runs on a model and which runs deterministically is described on our process automation page. The deadlines will keep moving. The question of whether you know what your system does will not.

Newsletter

Research for technical decisions

New reports, benchmarks and technical analyses on SaaS economics, AI engineering and owned infrastructure.

Original research Public sources No sales mail

By subscribing you receive new analyses and updates from FW Delta by email. You can withdraw your consent at any time. Further information is available in the privacy policy.

Newsletter

Research for technical decisions

New reports, benchmarks and technical analyses on SaaS economics, AI engineering and owned infrastructure.

Original research Public sources No sales mail

By subscribing you receive new analyses and updates from FW Delta by email. You can withdraw your consent at any time. Further information is available in the privacy policy.