Two Deadlines Moved, Three Did Not. Filing the AI Act Under December 2027 Means Missing August 2, 2026.
The Digital Omnibus pushes high-risk obligations for standalone Annex III systems to December 2, 2027 and for embedded Annex I products to August 2, 2028. What stays untouched: the GPAI obligations, the Article 50 transparency duties, and the Commission's power to fine. An inventory of what actually goes live on August 2, 2026 - and which architecture decisions have to be made now so that December 2027 does not force a migration.
Key Takeaways
- Regulation (EU) 2026/1744 moves Chapter III Sections 1 to 3 for standalone Annex III systems to December 2, 2027 and for embedded Annex I systems to August 2, 2028.
- On August 2, 2026 the Commission's power to fine GPAI providers under Article 101 takes effect, with a ceiling of 15 million euros or 3 percent of worldwide annual turnover.
- Article 50 applies from August 2, 2026; only the synthetic content marking duty in paragraph 2 has a transition to December 2, 2026 for systems placed on the market earlier.
What the delay actually moved and what it did not
The Digital Omnibus on AI was adopted as Regulation (EU) 2026/1744 of July 8, 2026. It amends Regulation (EU) 2024/1689, the AI Act itself, along with Regulation (EU) 2018/1139 on aviation safety and the Machinery Regulation (EU) 2023/1230. It was published in the Official Journal on July 24, 2026 and entered into force on the third day after that, meaning July 27, 2026 (nicfab).
The path there was short. The European Parliament approved on June 16, 2026 with 423 votes in favour, 57 against and 174 abstentions, out of 654 votes cast and 64 non-participations (HowTheyVote). The Council gave final approval on June 29, 2026, procedure file 2025/0359(COD), ordinary legislative procedure without a further reading (Council of the EU, nicfab on the Council adoption).
In public perception this turned into the headline that the AI Act has been postponed. That is imprecise enough to become expensive. Two blocks of deadlines moved, both concerning high-risk systems. Everything else stands.
Article 113 point (b) of the AI Act brings Chapter XII into application from August 2, 2025, expressly with the exception of Article 101. That exception expires on August 2, 2026. From that day the Commission can impose fines on providers of GPAI models of up to 15 million euros or 3 percent of worldwide annual turnover, whichever is higher. The Omnibus changed none of this.
The deadline picture after the Omnibus
The decisive change sits in the application article. Article 1 point 40 of Regulation (EU) 2026/1744 recasts Article 113 of the AI Act. In practice that means two dates shifted and a lot of unchanged lines next to them.
| Obligation block | Before | Now | Status |
|---|---|---|---|
| Standalone high-risk systems, Art. 6(2) and Annex III (Chapter III Sections 1 to 3) | 02.08.2026 | 02.12.2027 | moved |
| High-risk systems embedded in regulated products, Art. 6(1) and Annex I | 02.08.2027 | 02.08.2028 | moved |
| GPAI obligations, Chapter V, Art. 51 to 56 | 02.08.2025 | 02.08.2025 | already in force |
| Commission’s power to fine GPAI providers, Art. 101 | 02.08.2026 | 02.08.2026 | unchanged |
| Transparency obligations, Art. 50 | 02.08.2026 | 02.08.2026 | unchanged |
| Synthetic content marking, Art. 50(2), for legacy systems | - | 02.12.2026 | transition |
| New prohibitions, Art. 5(1) points (ba) and (bb) | - | 02.12.2026 | new |
| GPAI models placed on the market before 02.08.2025 | 02.08.2027 | 02.08.2027 | unchanged |
| At least one AI regulatory sandbox per member state, Art. 57(1) | 02.08.2026 | 02.08.2027 | moved |
| High-risk systems operated by public authorities | 02.08.2030 | 02.08.2030 | unchanged |
The sources for the two high-risk shifts are the FAQ section of the Commission’s AI Act Service Desk and the timeline analysis by the Future of Privacy Forum. Sandboxes and the GPAI legacy date come from the same analysis, the public authority date from the Modulos reading of the Official Journal text.
The trigger mechanism was deleted
The original Commission proposal tied the delay to a condition. Deadlines were to move only as far as harmonised standards and support tools were missing, capped at 16 months for Annex III and 12 months for Annex I. That mechanism is not in the final text. Fixed calendar dates apply, without any condition (Gibson Dunn, Modulos).
For planning purposes that matters more than it sounds. A conditional delay would have meant the deadline could slide forward again the moment standardisation delivers. A fixed date means December 2, 2027 is no longer negotiable, regardless of the state of harmonised standards on that day. Anyone waiting for a second Omnibus package is planning against an assumption instead of a legal act.
Annex I was never set to August 2, 2026
One misreading persists stubbornly: AI embedded in regulated products under Article 6(1) and Annex I never had August 2, 2026 as its cut-off in the original AI Act text. That block was always set to August 2, 2027, and the Omnibus moves it to August 2, 2028 (AI Act Service Desk, Article 113).
So anyone building medical devices, machinery or vehicle components with an AI element never faced a 2026 deadline for the high-risk part. They now have a good two years. What they do have regardless is Article 50, and that one arrives in August.
Why August 2, 2026 is the real cut-off for GPAI providers
The obligations for general purpose AI models in Chapter V, meaning Articles 51 to 56, have applied since August 2, 2025. The Omnibus changed nothing here (Commission). What was missing for a year was enforcement: Article 101, the Commission’s power to fine GPAI providers, was expressly excluded from the early application of Chapter XII (Article 113, AI Act Explorer).
That exception now expires. From August 2, 2026 a set of obligations that has been binding for twelve months becomes enforceable by fine for the first time. On top of that comes a shift in competence: the AI Office gains exclusive competence for AI systems built on a GPAI model from the same provider, together with investigative powers, on-site inspections, commitments and fines (Gibson Dunn).
The GPAI Code of Practice is the instrument along which the market has sorted itself. The Commission’s signatory list shows 23 companies as of April 23, 2026, among them OpenAI, Anthropic, Google, Microsoft, Amazon, IBM, Mistral AI, Cohere, ServiceNow, Aleph Alpha, Black Forest Labs, Almawave, Fastweb, LINAGORA, Bria AI, Pleias and Writer (Commission). Two deviations are instructive. xAI signed only the safety and security chapter and has to demonstrate transparency and copyright compliance by other means. Meta publicly declined to sign in July 2025, arguing that the code creates legal uncertainty and goes beyond the scope of the AI Act (Euronews).
For you as an integrator this has one practical consequence. Whether your model provider signed the code, and for which chapters, determines which evidence you receive from them and which you have to produce yourself. That is a procurement question, not a legal one, and it belongs in the contract before the model goes into production.
A second date in this block: providers of GPAI models placed on the market before August 2, 2025 have to reach compliance by August 2, 2027 (Future of Privacy Forum).
Article 50 hits companies that build no models at all
Article 50 governs transparency obligations and applies from August 2, 2026. The Omnibus did not touch that date (AI Act Service Desk, Gibson Dunn).
There is exactly one qualification. The marking obligation for synthetic content in Article 50(2) applies to systems placed on the market before August 2, 2026 only from December 2, 2026. That is a four-month transition, anchored through Article 111(4). Paragraphs 1, 3 and 4 apply without any transition from August 2, 2026, and systems newly placed on the market after that day have to comply from day one (Latham & Watkins, nicfab).
This is the point where the delay becomes irrelevant for most companies. A customer portal with a chat assistant, a marketing workflow with image generation, a support tool that drafts replies automatically: none of these is necessarily a high-risk system, but all of them touch Article 50. The penalty range for breaches of Article 50 goes up to 15 million euros or 3 percent of worldwide annual turnover, with SMEs and start-ups facing the lower of the two figures (Article 99).
That makes the distinction between legacy and new system a data field, not a gut feeling. If you do not record per system when it was placed on the market, you can neither claim the four-month transition nor prove it.
The new prohibition from December 2, 2026
The Omnibus adds points (ba) and (bb) to Article 5(1). Prohibited are AI systems for generating non-consensual intimate imagery of real persons and child sexual abuse material. Applicable from December 2, 2026, with a penalty range of up to 35 million euros or 7 percent of worldwide annual turnover (nicfab, Modulos).
The technically decisive clause sits in the liability formula. It also bites where the generation is a reasonably foreseeable and reproducible result without sufficient safeguards. So no intended purpose in the datasheet is required. It is enough that your system can do it, that someone reaches it reproducibly, and that you built no effective barrier.
The Commission opened formal DSA proceedings against X over Grok on January 26, 2026; Ofcom opened proceedings under the Online Safety Act on January 12, 2026. The Center for Countering Digital Hate documented more than three million sexualised images in under two weeks, over 23,000 of them depicting apparent minors (Tech Policy Press). On March 26, 2026 the Rechtbank Amsterdam ordered X and xAI to stop Grok's undressing feature in the Netherlands, with a penalty of 100,000 euros per day per defendant and proof of compliance within ten working days (Tech Policy Press).
Anyone embedding an image or video model into a product therefore has a build task from December 2026, not a policy task. A sentence in the terms of use is not a safeguard. An input and output check that blocks and logs reproducible circumventions is one. That is a matter for security architecture, not for the legal notice.
Which architecture decisions have to be made now
Sixteen months sit between August 2, 2026 and December 2, 2027. That is enough time to build the high-risk obligations into normal operations, and clearly too little to start them as a project in the summer of 2027. The decision being made now is not whether you become compliant, but whether compliance is a by-product of the release process or a separate programme with its own migration.
Classification belongs in a data field, not a document
The deadlines hang on three properties per system: the classification under Annex III or Annex I, the contact with Article 50, and the date of placing on the market. Maintain that in a spreadsheet and you have a snapshot from the last audit. Keep it as a versioned artefact next to the code and you have a snapshot from the last deployment.
# ai-inventory/credit-prescreening.yml
system: credit-prescreening
version: "3.4.1"
placed_on_market: "2026-05-14" # before 02.08.2026 -> transition possible
role: provider
classification:
annex_iii: true # Art. 6(2) -> Chapter III from 02.12.2027
annex_i_product: false # Art. 6(1) -> would be 02.08.2028
gpai_upstream:
provider: "model-vendor-x"
code_of_practice: ["safety_security", "transparency", "copyright"]
article_50:
paragraph_1: true # from 02.08.2026, no transition
paragraph_2: false # marking of synthetic content
paragraph_3: false # from 02.08.2026, no transition
paragraph_4: false # from 02.08.2026, no transition
grandfathering:
substantial_modification: false # true ends the exemption
last_reviewed: "2026-07-27"
eu_database:
registration_required: true
registered: false
From this record the applicable cut-off can be computed instead of researched. The Article 50(2) transition is the only case where the date of placing on the market changes the result:
from datetime import date
CUTOFFS = {
"annex_iii": date(2027, 12, 2), # Chapter III Sections 1 to 3
"annex_i": date(2028, 8, 2),
"article_50": date(2026, 8, 2),
"article_5": date(2026, 12, 2), # new prohibitions (ba) and (bb)
}
def applicable_from(system: dict) -> dict:
c, due = system["classification"], {}
if c["annex_iii"]:
due["chapter_iii"] = CUTOFFS["annex_iii"]
if c["annex_i_product"]:
due["chapter_iii"] = CUTOFFS["annex_i"]
for para in ("paragraph_1", "paragraph_3", "paragraph_4"):
if c["article_50"][para]:
due[f"art_50_{para}"] = CUTOFFS["article_50"]
if c["article_50"]["paragraph_2"]:
# Four-month transition only for systems placed on the market earlier
due["art_50_paragraph_2"] = (
date(2026, 12, 2)
if system["placed_on_market"] < CUTOFFS["article_50"]
else CUTOFFS["article_50"]
)
return due
Grandfathering is a release decision
High-risk systems already on the market before the new cut-off dates stay exempt as long as they are not substantially modified. For high-risk systems operated by public authorities, August 2, 2030 applies regardless (Modulos).
That exemption is not a gift, it is a constraint. It holds exactly as long as the system stands still. A model swap, a new intended purpose, an expanded user group: any of these can end the exemption, and it ends the moment the release ships, not the moment someone thinks about it. If you want to use grandfathering, you have to decide it deliberately per system and anchor it in the change process. If you want to keep developing, you are better off planning for the full set of obligations right away.
| Decision | If it is made now | If it waits until mid-2027 |
|---|---|---|
| Classification as a versioned data field | Every change to model, role or purpose triggers a reassessment | Manual inventory whose result is stale on the day it is submitted |
| Technical documentation out of the build | Documentation is an artefact of the release process | Documentation becomes a project with its own budget and deadline |
| Quality management for AI systems | Runs inside the existing process | A second process alongside the existing one, with friction |
| Registration in the EU database | Data points fall out of the inventory | Data points are collected from scattered sources |
| Grandfathering or continued development | Deliberate decision per system, documented | A routine release ends the exemption unnoticed |
| Operational evidence from production | A defensible history exists by the cut-off date | The first years of operation cannot be reconstructed |
The registration duty in the EU database stays, by the way. Annex VIII Section B loses exactly two data points (Modulos). Anyone hoping the filing would disappear has gained two fields.
In practice this is two integrations: the inventory into the release process, so that no version ships without a classification, and the inventory into continuous observation of the models in use, so that a provider swap does not silently trigger a reassessment.
Who gets relief and who leaves the scope
Two changes affect not the deadlines but the perimeter.
First, the SME relief measures are extended to small mid-caps. Latham & Watkins puts the covered group at up to 750 employees and 150 million euros in annual revenue; the underlying Recommendation (EU) 2025/1099 defines small mid-caps as companies with fewer than 750 employees and at most 150 million euros in annual turnover or 129 million euros in balance sheet total. The scope: simplified guidance and documentation templates, sandbox access, and a cap on the mid-tier fines at the lower of the percentage or the fixed amount (Modulos). Sandbox access carries its own deadline though: member states only have to have at least one AI regulatory sandbox operational by August 2, 2027, a year later than originally foreseen.
Second, AI-enabled machinery no longer falls directly under the AI Act but is covered sectorally through the Machinery Regulation (EU) 2023/1230 (European Parliament). For machinery manufacturers this is the most far-reaching change in the package, because it reopens the question of which legal act applies before the question of the deadline even arises.
What you need to decide this week
The delay is real, and it is narrowly bounded. Three decisions do not tolerate postponement.
First: a complete list of every AI system in use, with the date it was placed on the market and a classification against Article 50. Not against Annex III, that can wait until 2027. Against Article 50, because it applies in a matter of weeks. Without that list you do not know which of your systems may even claim the transition to December 2026.
Second: an inventory of which model providers you use and which chapters of the Code of Practice they signed. That determines which evidence is supplied to you and which you have to produce yourself.
Third: per high-risk candidate, a documented decision between freezing and continued development. Both are defensible. What is not defensible is drifting between the two through a routine release.
Everything else can be built in sixteen months, provided it grows inside the systems rather than beside them. Wait instead, and you will build the same systems again in 2027, only under time pressure. If you want to see what an inventory and a release gate look like in an existing landscape, talk to us.
Sources
- EUR-Lex: Regulation (EU) 2026/1744
- Commission: AI Act Service Desk, FAQ
- Commission: Regulatory framework for AI
- Commission: GPAI Code of Practice, signatories
- Council of the EU: Final green light, 29.06.2026
- European Parliament: Legislative Train, Digital Omnibus on AI
- EUR-Lex: Recommendation (EU) 2025/1099 on the definition of small mid-cap enterprises
- HowTheyVote: Plenary vote, 16.06.2026
- AI Act Explorer: Article 113
- AI Act Explorer: Article 99
- AI Act Explorer: Enforcement of Chapter V
- nicfab: Digital Omnibus on AI in the Official Journal
- nicfab: Council adoption
- Future of Privacy Forum: AI Act Implementation Timeline
- Gibson Dunn: Omnibus Agreement, Postponed High-Risk Deadlines
- Latham & Watkins: AI Act Update
- Sidley: Provisional Agreement to Delay Key Obligations
- DLA Piper: Deferral of High-Risk AI Obligations
- Law and Technology: Regulation 2026/1744 in the Official Journal
- Modulos: EU AI Act Omnibus Now Law
- Tech Policy Press: Proceedings against Grok and X
- Tech Policy Press: Rechtbank Amsterdam ruling
- Euronews: Meta will not sign the code
Technical analyses for decision makers
New posts on SaaS economics, AI architecture, compliance and owned infrastructure.
I would like to receive analyses and updates from FW Delta by email in future. I can withdraw my consent at any time. Further information is available in the privacy policy.
No spam. Unsubscribe at any time. Privacy notice