The Omnibus Moves Two AI Act Deadlines. 2 August 2026 Stays.
The Digital Omnibus pushes the AI Act's high-risk duties to December 2027 and August 2028. What stays untouched: the duties for model providers, the Article 50 transparency duties and the Commission's power to fine. What actually applies on 2 August 2026 and which decisions you should make now so that December 2027 does not force a rebuild.
Key Takeaways
- The Omnibus moves the high-risk duties for stand-alone Annex III systems to 2 December 2027 and for AI inside regulated Annex I products to 2 August 2028.
- On 2 August 2026 the Commission can fine providers of large AI models for the first time, up to 15 million euros or 3 percent of worldwide annual turnover.
- Article 50 applies from 2 August 2026. Only the marking of generated content under paragraph 2 has a grace period to 2 December 2026 for older systems.
What the delay actually moved and what it did not
On 16 June 2026 the European Parliament approved the Digital Omnibus on AI with 423 votes in favour, 57 against and 174 abstentions (HowTheyVote). The Council is due to give its final approval on 29 June. After that the text is published in the Official Journal and enters into force three days later. The Omnibus amends the AI Act, Regulation (EU) 2024/1689, along with the aviation Regulation (EU) 2018/1139 and the Machinery Regulation (EU) 2023/1230 (European Parliament).
In public perception this turned into the headline that the AI Act has been postponed. That is imprecise enough to become expensive. Two blocks of deadlines moved, both concerning high-risk systems. Everything else stands.
The point in one sentence
The Omnibus moves only the high-risk duties, while on 2 August 2026 the Article 50 transparency duties and the Commission's power to fine model providers apply unchanged.
The deadline picture after the Omnibus
The decisive change sits in the application article of the AI Act, Article 113. In practice that means two dates shifted and a lot of unchanged lines next to them. The two shifts are confirmed by the FAQ of the Commission’s AI Act Service Desk, the remaining dates come from Article 113 and the transitional provisions of the AI Act.
| Obligation block | Before | After the Omnibus |
|---|---|---|
| Stand-alone high-risk systems under Annex III | 2 August 2026 | 2 December 2027 |
| High-risk AI inside regulated products under Annex I | 2 August 2027 | 2 August 2028 |
| Duties for providers of large AI models, Chapter V | 2 August 2025 | unchanged, already in force |
| Commission’s power to fine model providers, Article 101 | 2 August 2026 | unchanged |
| Transparency duties, Article 50 | 2 August 2026 | unchanged |
| Marking of generated content under Article 50(2) for older systems | 2 August 2026 | 2 December 2026 |
| New prohibitions in Article 5 | none | 2 December 2026 |
| Models placed on the market before 2 August 2025 | 2 August 2027 | unchanged |
| At least one AI regulatory sandbox per member state | 2 August 2026 | 2 August 2027 |
| High-risk systems operated by public authorities | 2 August 2030 | unchanged |
The trigger mechanism was deleted
The Commission’s original proposal tied the delay to a condition. Deadlines were to move only as far as harmonised standards and support tools were missing, capped at 16 months for Annex III and 12 months for Annex I. That mechanism is not in the adopted text. Fixed calendar dates apply, without any condition (Gibson Dunn).
For planning purposes that matters more than it sounds. A conditional delay would have meant the deadline could slide forward again the moment standardisation delivers. A fixed date means 2 December 2027 stands, no matter how far the standards have come on that day. Anyone waiting for a second Omnibus package is planning on an assumption instead of a legal act.
Annex I was never set to 2 August 2026
One misreading persists stubbornly: AI inside regulated products under Annex I never had 2 August 2026 as its cut-off in the original AI Act. That block was always set to 2 August 2027 and the Omnibus moves it to 2 August 2028.
So anyone building medical devices, machinery or vehicle parts with an AI element never faced a 2026 deadline for the high-risk part. They now have a good two years. What they do have regardless is Article 50 and that one arrives in August.
Why 2 August 2026 is the real cut-off for model providers
The duties for general-purpose AI models, meaning the large language and image models behind the well-known assistants, sit in Chapter V of the AI Act and have applied since 2 August 2025. The Omnibus changed nothing there. What was missing for a year was enforcement: Article 101, the Commission’s power to fine model providers, was expressly excluded from early application (AI Act Explorer).
That exception now expires. From 2 August 2026 a set of duties that has been binding for twelve months becomes enforceable by fine for the first time, up to 15 million euros or 3 percent of worldwide annual turnover. On top of that comes a new competence: the Commission’s AI Office takes over supervision of AI systems built on a model from the same provider, with investigative powers and fines (Gibson Dunn).
The Code of Practice for model providers is the instrument along which the market has sorted itself. The Commission’s signatory list shows more than twenty companies, among them OpenAI, Anthropic, Google, Microsoft, Amazon, IBM, Mistral AI and Aleph Alpha. Two deviations are instructive. xAI signed only the safety and security chapter and has to demonstrate transparency and copyright compliance by other means. Meta publicly declined to sign in July 2025, arguing that the code creates legal uncertainty and goes beyond the AI Act (Euronews).
If you build a model into your product, this has one practical consequence. Whether your model provider signed the code and for which chapters determines which evidence you receive from them and which you have to produce yourself. That is a purchasing question and it belongs in the contract before the model goes live.
A second date in this block: providers of models placed on the market before 2 August 2025 have to catch up by 2 August 2027.
Article 50 hits companies that build no models at all
Article 50 governs transparency duties and applies from 2 August 2026. The Omnibus did not touch that date (AI Act Service Desk).
There is exactly one qualification. The marking duty for generated content in Article 50(2) applies to systems placed on the market before 2 August 2026 only from 2 December 2026. That is a four-month transition. Paragraphs 1, 3 and 4 apply without any transition from 2 August 2026. Systems newly placed on the market after that day have to comply with everything from day one.
This is the point where the delay becomes irrelevant for most companies. A customer portal with a chat assistant, a marketing workflow with image generation, a support tool that drafts replies: none of these is necessarily a high-risk system, but all of them touch Article 50. Fines for breaches of Article 50 go up to 15 million euros or 3 percent of worldwide annual turnover. For small and medium-sized companies the lower of the two applies (Article 99).
That makes the distinction between old and new system a data field, not a gut feeling. If you do not record per system when it was placed on the market, you can neither use the four-month transition nor prove it.
The new prohibition from 2 December 2026
The Omnibus adds two new prohibitions to Article 5. Banned are AI systems that generate intimate imagery of real people without their consent or child sexual abuse material. The prohibitions apply from 2 December 2026. The fine range goes up to 35 million euros or 7 percent of worldwide annual turnover (Gibson Dunn).
The technically decisive clause sits in the wording of the ban. It also bites where the generation is a reasonably foreseeable and reproducible outcome and the provider has not built in adequate safeguards. So no intended purpose in the datasheet is required. It is enough that your system can do it, that someone reaches it reproducibly and that you built no effective barrier.
Where the prohibition comes from
The Commission opened proceedings under the Digital Services Act against X over Grok on 26 January 2026. The UK's Ofcom opened proceedings under the Online Safety Act on 12 January 2026. The Center for Countering Digital Hate estimates that Grok generated around three million sexualised images in under two weeks, over 23,000 of them depicting apparent minors (Tech Policy Press). On 26 March 2026 the Amsterdam court ordered X and xAI to stop the undressing feature in the Netherlands, with a penalty of 100,000 euros per day (Tech Policy Press).
Anyone building an image or video model into a product therefore has a build task from December 2026, not a policy task. A sentence in the terms of use is not a safeguard. A check on input and output that blocks and logs reproducible workarounds is one. That is a matter for security architecture, not for the legal notice.
Which decisions have to be made now
Sixteen months sit between 2 August 2026 and 2 December 2027. That is enough time to build the high-risk duties into normal operations and clearly too little to start them as a project in the summer of 2027. The decision being made now is not whether you meet the requirements, but whether that happens as a by-product of the normal release process or as a separate programme with its own rebuild.
Classification belongs in a data field, not a document
The deadlines hang on three properties per system: the classification under Annex III or Annex I, the contact with Article 50 and the date the system was placed on the market. Maintain that in a spreadsheet and you have a snapshot from the last audit. Keep it as a versioned file next to the code and you have a snapshot from the last release.
What to record per system
- Name, version and the date the system was placed on the market
- Role: provider or deployer
- Classification: Annex III, Annex I or neither
- Which model sits behind it and which chapters of the code its provider signed
- Which paragraphs of Article 50 are touched
- Whether the system is frozen or under continued development
- Whether registration in the EU database is required and whether it is done
From this record the applicable cut-off can be derived instead of researched every time. The Article 50(2) transition is the only case where the market entry date changes the result.
Grandfathering is a release decision
High-risk systems already on the market before the new cut-off dates stay exempt as long as they are not substantially modified. For high-risk systems operated by public authorities 2 August 2030 applies regardless.
That exemption is not a gift, it is a constraint. It holds exactly as long as the system stands still. A model swap, a new intended purpose, an expanded user group: any of these can end the exemption and it ends the moment the new version goes live, not the moment someone thinks about it. If you want to use grandfathering, you have to decide it deliberately per system and anchor it in the change process. If you want to keep developing, you are better off planning for the full set of duties right away.
| Decision | If it is made now | If it waits until mid-2027 |
|---|---|---|
| Classification as a versioned data field | Every change to model, role or purpose triggers a reassessment | Manual inventory whose result is stale on the day it is submitted |
| Technical documentation out of the build | The documentation is produced as part of the release | The documentation becomes a project with its own budget and deadline |
| Quality management for AI systems | Runs inside the existing process | A second process alongside the existing one, with friction |
| Registration in the EU database | The entries fall out of the inventory | The entries are collected from scattered sources |
| Grandfathering or continued development | Deliberate decision per system, documented | A routine release ends the exemption unnoticed |
| Operational evidence from production | A defensible history exists by the cut-off date | The first years of operation cannot be reconstructed |
The registration duty in the EU database stays, by the way. The Omnibus only removes some entries from the reporting scope. Anyone hoping the filing would disappear has gained a few fields.
In practice this is two integrations: the inventory into the release process, so that no version ships without a classification and the inventory into continuous observation of the models in use, so that a provider swap does not silently trigger a reassessment.
Who gets relief and who leaves the scope
Two changes affect not the deadlines but the perimeter.
First, the relief measures for small and medium-sized companies are extended to small mid-caps. The underlying Recommendation (EU) 2025/1099 defines them as companies with fewer than 750 employees and at most 150 million euros in annual turnover or 129 million euros in balance sheet total. The relief covers simplified templates for technical documentation, access to regulatory sandboxes and a cap on the mid-tier fines at the lower of the two values. Sandbox access carries its own deadline though: member states only have to have at least one sandbox operational by 2 August 2027, a year later than originally planned.
Second, AI-enabled machinery no longer falls directly under the AI Act’s high-risk rules. The requirements are to be carried over into the Machinery Regulation (EU) 2023/1230 instead (European Parliament). For machinery manufacturers this is the most far-reaching change in the package, because it reopens the question of which legal act applies before the question of the deadline even arises.
What you can check now
The delay is real and it is narrowly bounded. Three things do not tolerate postponement.
First: a complete list of every AI system in use, with the date it was placed on the market and a classification against Article 50. Not against Annex III, that can wait until 2027. Against Article 50, because it applies in a matter of weeks. Without that list you do not know which of your systems may even use the transition to December 2026.
Second: an inventory of which model providers you use and which chapters of the Code of Practice they signed. That determines which evidence is supplied to you and which you have to produce yourself.
Third: per high-risk candidate, a documented decision between freezing and continued development. Both are defensible. What is not defensible is drifting between the two through a routine release.
Everything else can be built in sixteen months, provided it grows inside the systems rather than beside them. Wait instead and you will build the same systems again in 2027, only under time pressure. If you want to see what an inventory and a release gate look like in an existing landscape, talk to us.
Not legal advice
This text reflects the state of the text adopted by Parliament and the Commission's guidance. Only the version published in the Official Journal is binding. Whether and how a duty applies to your system depends on classifications that need a legal review.
Research for technical decisions
New reports, benchmarks and technical analyses on SaaS economics, AI engineering and owned infrastructure.
Original research Public sources No sales mail
By subscribing you receive new analyses and updates from FW Delta by email. You can withdraw your consent at any time. Further information is available in the privacy policy.