Skip to content
Home Blog Compliance & Architecture

Two Deadlines Moved, Three Did Not. Filing the AI Act Under December 2027 Means Missing August 2, 2026.

The Digital Omnibus pushes high-risk obligations for standalone Annex III systems to December 2, 2027 and for embedded Annex I products to August 2, 2028. What stays untouched: the GPAI obligations, the Article 50 transparency duties, and the Commission's power to fine. An inventory of what actually goes live on August 2, 2026 - and which architecture decisions have to be made now so that December 2027 does not force a migration.

Fabian Weiss, founder of FW Delta Fabian Weiss
Jun 19, 2026 14 Min Read

Key Takeaways

  • Regulation (EU) 2026/1744 moves Chapter III Sections 1 to 3 for standalone Annex III systems to December 2, 2027 and for embedded Annex I systems to August 2, 2028.
  • On August 2, 2026 the Commission's power to fine GPAI providers under Article 101 takes effect, with a ceiling of 15 million euros or 3 percent of worldwide annual turnover.
  • Article 50 applies from August 2, 2026; only the synthetic content marking duty in paragraph 2 has a transition to December 2, 2026 for systems placed on the market earlier.

What the delay actually moved and what it did not

The Digital Omnibus on AI was adopted as Regulation (EU) 2026/1744 of July 8, 2026. It amends Regulation (EU) 2024/1689, the AI Act itself, along with Regulation (EU) 2018/1139 on aviation safety and the Machinery Regulation (EU) 2023/1230. It was published in the Official Journal on July 24, 2026 and entered into force on the third day after that, meaning July 27, 2026 (nicfab).

The path there was short. The European Parliament approved on June 16, 2026 with 423 votes in favour, 57 against and 174 abstentions, out of 654 votes cast and 64 non-participations (HowTheyVote). The Council gave final approval on June 29, 2026, procedure file 2025/0359(COD), ordinary legislative procedure without a further reading (Council of the EU, nicfab on the Council adoption).

In public perception this turned into the headline that the AI Act has been postponed. That is imprecise enough to become expensive. Two blocks of deadlines moved, both concerning high-risk systems. Everything else stands.

Deadline Reality

Article 113 point (b) of the AI Act brings Chapter XII into application from August 2, 2025, expressly with the exception of Article 101. That exception expires on August 2, 2026. From that day the Commission can impose fines on providers of GPAI models of up to 15 million euros or 3 percent of worldwide annual turnover, whichever is higher. The Omnibus changed none of this.

The deadline picture after the Omnibus

The decisive change sits in the application article. Article 1 point 40 of Regulation (EU) 2026/1744 recasts Article 113 of the AI Act. In practice that means two dates shifted and a lot of unchanged lines next to them.

Obligation blockBeforeNowStatus
Standalone high-risk systems, Art. 6(2) and Annex III (Chapter III Sections 1 to 3)02.08.202602.12.2027moved
High-risk systems embedded in regulated products, Art. 6(1) and Annex I02.08.202702.08.2028moved
GPAI obligations, Chapter V, Art. 51 to 5602.08.202502.08.2025already in force
Commission’s power to fine GPAI providers, Art. 10102.08.202602.08.2026unchanged
Transparency obligations, Art. 5002.08.202602.08.2026unchanged
Synthetic content marking, Art. 50(2), for legacy systems-02.12.2026transition
New prohibitions, Art. 5(1) points (ba) and (bb)-02.12.2026new
GPAI models placed on the market before 02.08.202502.08.202702.08.2027unchanged
At least one AI regulatory sandbox per member state, Art. 57(1)02.08.202602.08.2027moved
High-risk systems operated by public authorities02.08.203002.08.2030unchanged

The sources for the two high-risk shifts are the FAQ section of the Commission’s AI Act Service Desk and the timeline analysis by the Future of Privacy Forum. Sandboxes and the GPAI legacy date come from the same analysis, the public authority date from the Modulos reading of the Official Journal text.

The trigger mechanism was deleted

The original Commission proposal tied the delay to a condition. Deadlines were to move only as far as harmonised standards and support tools were missing, capped at 16 months for Annex III and 12 months for Annex I. That mechanism is not in the final text. Fixed calendar dates apply, without any condition (Gibson Dunn, Modulos).

For planning purposes that matters more than it sounds. A conditional delay would have meant the deadline could slide forward again the moment standardisation delivers. A fixed date means December 2, 2027 is no longer negotiable, regardless of the state of harmonised standards on that day. Anyone waiting for a second Omnibus package is planning against an assumption instead of a legal act.

Annex I was never set to August 2, 2026

One misreading persists stubbornly: AI embedded in regulated products under Article 6(1) and Annex I never had August 2, 2026 as its cut-off in the original AI Act text. That block was always set to August 2, 2027, and the Omnibus moves it to August 2, 2028 (AI Act Service Desk, Article 113).

So anyone building medical devices, machinery or vehicle components with an AI element never faced a 2026 deadline for the high-risk part. They now have a good two years. What they do have regardless is Article 50, and that one arrives in August.

Why August 2, 2026 is the real cut-off for GPAI providers

The obligations for general purpose AI models in Chapter V, meaning Articles 51 to 56, have applied since August 2, 2025. The Omnibus changed nothing here (Commission). What was missing for a year was enforcement: Article 101, the Commission’s power to fine GPAI providers, was expressly excluded from the early application of Chapter XII (Article 113, AI Act Explorer).

That exception now expires. From August 2, 2026 a set of obligations that has been binding for twelve months becomes enforceable by fine for the first time. On top of that comes a shift in competence: the AI Office gains exclusive competence for AI systems built on a GPAI model from the same provider, together with investigative powers, on-site inspections, commitments and fines (Gibson Dunn).

The GPAI Code of Practice is the instrument along which the market has sorted itself. The Commission’s signatory list shows 23 companies as of April 23, 2026, among them OpenAI, Anthropic, Google, Microsoft, Amazon, IBM, Mistral AI, Cohere, ServiceNow, Aleph Alpha, Black Forest Labs, Almawave, Fastweb, LINAGORA, Bria AI, Pleias and Writer (Commission). Two deviations are instructive. xAI signed only the safety and security chapter and has to demonstrate transparency and copyright compliance by other means. Meta publicly declined to sign in July 2025, arguing that the code creates legal uncertainty and goes beyond the scope of the AI Act (Euronews).

For you as an integrator this has one practical consequence. Whether your model provider signed the code, and for which chapters, determines which evidence you receive from them and which you have to produce yourself. That is a procurement question, not a legal one, and it belongs in the contract before the model goes into production.

A second date in this block: providers of GPAI models placed on the market before August 2, 2025 have to reach compliance by August 2, 2027 (Future of Privacy Forum).

Article 50 hits companies that build no models at all

Article 50 governs transparency obligations and applies from August 2, 2026. The Omnibus did not touch that date (AI Act Service Desk, Gibson Dunn).

There is exactly one qualification. The marking obligation for synthetic content in Article 50(2) applies to systems placed on the market before August 2, 2026 only from December 2, 2026. That is a four-month transition, anchored through Article 111(4). Paragraphs 1, 3 and 4 apply without any transition from August 2, 2026, and systems newly placed on the market after that day have to comply from day one (Latham & Watkins, nicfab).

This is the point where the delay becomes irrelevant for most companies. A customer portal with a chat assistant, a marketing workflow with image generation, a support tool that drafts replies automatically: none of these is necessarily a high-risk system, but all of them touch Article 50. The penalty range for breaches of Article 50 goes up to 15 million euros or 3 percent of worldwide annual turnover, with SMEs and start-ups facing the lower of the two figures (Article 99).

That makes the distinction between legacy and new system a data field, not a gut feeling. If you do not record per system when it was placed on the market, you can neither claim the four-month transition nor prove it.

The new prohibition from December 2, 2026

The Omnibus adds points (ba) and (bb) to Article 5(1). Prohibited are AI systems for generating non-consensual intimate imagery of real persons and child sexual abuse material. Applicable from December 2, 2026, with a penalty range of up to 35 million euros or 7 percent of worldwide annual turnover (nicfab, Modulos).

The technically decisive clause sits in the liability formula. It also bites where the generation is a reasonably foreseeable and reproducible result without sufficient safeguards. So no intended purpose in the datasheet is required. It is enough that your system can do it, that someone reaches it reproducibly, and that you built no effective barrier.

Where the Prohibition Comes From

The Commission opened formal DSA proceedings against X over Grok on January 26, 2026; Ofcom opened proceedings under the Online Safety Act on January 12, 2026. The Center for Countering Digital Hate documented more than three million sexualised images in under two weeks, over 23,000 of them depicting apparent minors (Tech Policy Press). On March 26, 2026 the Rechtbank Amsterdam ordered X and xAI to stop Grok's undressing feature in the Netherlands, with a penalty of 100,000 euros per day per defendant and proof of compliance within ten working days (Tech Policy Press).

Anyone embedding an image or video model into a product therefore has a build task from December 2026, not a policy task. A sentence in the terms of use is not a safeguard. An input and output check that blocks and logs reproducible circumventions is one. That is a matter for security architecture, not for the legal notice.

Which architecture decisions have to be made now

Sixteen months sit between August 2, 2026 and December 2, 2027. That is enough time to build the high-risk obligations into normal operations, and clearly too little to start them as a project in the summer of 2027. The decision being made now is not whether you become compliant, but whether compliance is a by-product of the release process or a separate programme with its own migration.

Classification belongs in a data field, not a document

The deadlines hang on three properties per system: the classification under Annex III or Annex I, the contact with Article 50, and the date of placing on the market. Maintain that in a spreadsheet and you have a snapshot from the last audit. Keep it as a versioned artefact next to the code and you have a snapshot from the last deployment.

# ai-inventory/credit-prescreening.yml
system: credit-prescreening
version: "3.4.1"
placed_on_market: "2026-05-14"        # before 02.08.2026 -> transition possible
role: provider

classification:
  annex_iii: true                     # Art. 6(2) -> Chapter III from 02.12.2027
  annex_i_product: false              # Art. 6(1) -> would be 02.08.2028
  gpai_upstream:
    provider: "model-vendor-x"
    code_of_practice: ["safety_security", "transparency", "copyright"]
  article_50:
    paragraph_1: true                 # from 02.08.2026, no transition
    paragraph_2: false                # marking of synthetic content
    paragraph_3: false                # from 02.08.2026, no transition
    paragraph_4: false                # from 02.08.2026, no transition

grandfathering:
  substantial_modification: false     # true ends the exemption
  last_reviewed: "2026-07-27"

eu_database:
  registration_required: true
  registered: false

From this record the applicable cut-off can be computed instead of researched. The Article 50(2) transition is the only case where the date of placing on the market changes the result:

from datetime import date

CUTOFFS = {
    "annex_iii":  date(2027, 12, 2),   # Chapter III Sections 1 to 3
    "annex_i":    date(2028, 8, 2),
    "article_50": date(2026, 8, 2),
    "article_5":  date(2026, 12, 2),   # new prohibitions (ba) and (bb)
}

def applicable_from(system: dict) -> dict:
    c, due = system["classification"], {}

    if c["annex_iii"]:
        due["chapter_iii"] = CUTOFFS["annex_iii"]
    if c["annex_i_product"]:
        due["chapter_iii"] = CUTOFFS["annex_i"]

    for para in ("paragraph_1", "paragraph_3", "paragraph_4"):
        if c["article_50"][para]:
            due[f"art_50_{para}"] = CUTOFFS["article_50"]

    if c["article_50"]["paragraph_2"]:
        # Four-month transition only for systems placed on the market earlier
        due["art_50_paragraph_2"] = (
            date(2026, 12, 2)
            if system["placed_on_market"] < CUTOFFS["article_50"]
            else CUTOFFS["article_50"]
        )

    return due

Grandfathering is a release decision

High-risk systems already on the market before the new cut-off dates stay exempt as long as they are not substantially modified. For high-risk systems operated by public authorities, August 2, 2030 applies regardless (Modulos).

That exemption is not a gift, it is a constraint. It holds exactly as long as the system stands still. A model swap, a new intended purpose, an expanded user group: any of these can end the exemption, and it ends the moment the release ships, not the moment someone thinks about it. If you want to use grandfathering, you have to decide it deliberately per system and anchor it in the change process. If you want to keep developing, you are better off planning for the full set of obligations right away.

DecisionIf it is made nowIf it waits until mid-2027
Classification as a versioned data fieldEvery change to model, role or purpose triggers a reassessmentManual inventory whose result is stale on the day it is submitted
Technical documentation out of the buildDocumentation is an artefact of the release processDocumentation becomes a project with its own budget and deadline
Quality management for AI systemsRuns inside the existing processA second process alongside the existing one, with friction
Registration in the EU databaseData points fall out of the inventoryData points are collected from scattered sources
Grandfathering or continued developmentDeliberate decision per system, documentedA routine release ends the exemption unnoticed
Operational evidence from productionA defensible history exists by the cut-off dateThe first years of operation cannot be reconstructed

The registration duty in the EU database stays, by the way. Annex VIII Section B loses exactly two data points (Modulos). Anyone hoping the filing would disappear has gained two fields.

In practice this is two integrations: the inventory into the release process, so that no version ships without a classification, and the inventory into continuous observation of the models in use, so that a provider swap does not silently trigger a reassessment.

Who gets relief and who leaves the scope

Two changes affect not the deadlines but the perimeter.

First, the SME relief measures are extended to small mid-caps. Latham & Watkins puts the covered group at up to 750 employees and 150 million euros in annual revenue; the underlying Recommendation (EU) 2025/1099 defines small mid-caps as companies with fewer than 750 employees and at most 150 million euros in annual turnover or 129 million euros in balance sheet total. The scope: simplified guidance and documentation templates, sandbox access, and a cap on the mid-tier fines at the lower of the percentage or the fixed amount (Modulos). Sandbox access carries its own deadline though: member states only have to have at least one AI regulatory sandbox operational by August 2, 2027, a year later than originally foreseen.

Second, AI-enabled machinery no longer falls directly under the AI Act but is covered sectorally through the Machinery Regulation (EU) 2023/1230 (European Parliament). For machinery manufacturers this is the most far-reaching change in the package, because it reopens the question of which legal act applies before the question of the deadline even arises.

What you need to decide this week

The delay is real, and it is narrowly bounded. Three decisions do not tolerate postponement.

First: a complete list of every AI system in use, with the date it was placed on the market and a classification against Article 50. Not against Annex III, that can wait until 2027. Against Article 50, because it applies in a matter of weeks. Without that list you do not know which of your systems may even claim the transition to December 2026.

Second: an inventory of which model providers you use and which chapters of the Code of Practice they signed. That determines which evidence is supplied to you and which you have to produce yourself.

Third: per high-risk candidate, a documented decision between freezing and continued development. Both are defensible. What is not defensible is drifting between the two through a routine release.

Everything else can be built in sixteen months, provided it grows inside the systems rather than beside them. Wait instead, and you will build the same systems again in 2027, only under time pressure. If you want to see what an inventory and a release gate look like in an existing landscape, talk to us.

Sources

Note on sourcing: The full text of Regulation (EU) 2026/1744 could not be retrieved via EUR-Lex; the ELI identifier itself is verified. The article mapping (Article 1 point 40 as the provision amending Article 113 of the AI Act) comes from secondary sources, not from our own reading of the Official Journal text. The Council press release of 29.06.2026 returns HTTP 403 on direct retrieval; date and subject are evidenced through the title, the URL and several independent secondary sources, but the wording was not verified first-hand. On the transition period for synthetic content marking, one source states three months rather than four; the four-month figure (02.08.2026 to 02.12.2026) is carried by the majority of sources. The number of GPAI Code of Practice signatories varies by reference date; only the Commission list as of 23.04.2026 is reproduced here. The small mid-cap thresholds come from Recommendation (EU) 2025/1099; a higher definition proposed by Parliament in February 2026 for a different omnibus package (1,000 employees, 200 million euros turnover, 172 million euros balance sheet total) does not concern the AI Act and is not used here. Only the version published in the Official Journal is legally binding. This article does not constitute legal advice; for the classification of your specific systems, consult qualified counsel.
Newsletter

Technical analyses for decision makers

New posts on SaaS economics, AI architecture, compliance and owned infrastructure.

I would like to receive analyses and updates from FW Delta by email in future. I can withdraw my consent at any time. Further information is available in the privacy policy.

No spam. Unsubscribe at any time. Privacy notice

Newsletter

Technical analyses for decision makers

New posts on SaaS economics, AI architecture, compliance and owned infrastructure.

I would like to receive analyses and updates from FW Delta by email in future. I can withdraw my consent at any time. Further information is available in the privacy policy.

No spam. Unsubscribe at any time. Privacy notice