Skip to main content
Back to Blog
Compliance

September 3, 2026

Arelis AI

7 min read

What Still Lands on 2 August 2026 — and What Doesn't

The Digital Omnibus moved the high-risk deadline to December 2027, and a lot of teams heard 'the AI Act is delayed'. Three sets of obligations did not move. Here is what actually applies in August, and what it means for your roadmap.

What Still Lands on 2 August 2026 — and What Doesn't

When the Digital Omnibus pushed the high-risk deadline from August 2026 to December 2027, a lot of programmes quietly went back to sleep. In the conversations we have had since, the summary most teams are working from is some version of "the AI Act got delayed by sixteen months."

That is half the picture, and the missing half has a date on it.

Three sets of obligations did not move. One of them applies to almost every company shipping a customer-facing AI feature in the EU, whether or not anything in the estate is high-risk.

What moved

Regulation (EU) 2026/1744 — the Digital Omnibus on AI — deferred the high-risk regime:

| Category | Was | Now | | --- | --- | --- | | Annex III stand-alone high-risk systems | 2 August 2026 | 2 December 2027 | | Annex I high-risk embedded in regulated products | 2 August 2027 | 2 August 2028 |

Annex III is the list most people mean when they say "high-risk": employment and worker management, credit scoring, education, essential private and public services, biometrics, law enforcement, migration, justice. If you are building or deploying one of those, you have gained roughly sixteen months.

The Omnibus also narrowed the scope. An AI component that merely assists a user or optimises performance, without creating a health or safety risk, now falls outside the high-risk classification. Some systems that were in scope last year are not in scope today.

What did not move

1. Article 50 transparency — 2 August 2026

This is the one that catches people. Article 50 is not about risk classification at all. It applies to AI systems by virtue of what they do, not how dangerous they are:

  • Systems that interact with people must make clear that the person is dealing with an AI, unless that is obvious from context.
  • Emotion recognition and biometric categorisation systems must inform the people exposed to them.
  • Synthetic content — audio, image, video or text generated or manipulated by AI — must be machine-readably marked as artificially generated.
  • Deep fakes must be disclosed as such.

If you run a support chatbot, a generative feature inside a product, an AI voice agent, or anything that produces synthetic media for EU users, Article 50 is your August 2026 deadline. It does not matter that your system is not high-risk. Most systems subject to Article 50 are not.

There is one narrow concession: a four-month grace period, to 2 December 2026, applies to the machine-readable marking requirement for systems already on the market. The broader duty to disclose is unaffected.

2. General-purpose AI obligations — already in force

Provider obligations for general-purpose AI models under Articles 51–56 have applied since 2 August 2025. They did not move, because they were already live. If you fine-tune, distribute or substantially modify a general-purpose model, you may be a provider under these rules — a status a surprising number of teams have not checked.

3. Prohibited practices — already in force

The Article 5 prohibitions have applied since February 2025 and remain active. The Omnibus in fact added to them: a new prohibition covering so-called nudifier applications and the generation of child sexual abuse material, with a transitional period running to 2 December 2026.

Prohibitions are not a compliance programme you schedule. They are a line you are already on the wrong side of, or not.

Why this matters more than the sixteen months you gained

A delayed deadline is only useful if you know which deadline moved.

The pattern we keep seeing is an organisation that classified its AI estate in 2025, found nothing in Annex III, concluded it was out of scope, and stopped. That conclusion was about high-risk. It said nothing about Article 50 — and Article 50 is precisely the obligation that attaches to the customer-facing generative features most companies have shipped since.

The practical exposure is also different in kind. High-risk compliance is a documentation, testing and conformity-assessment programme measured in quarters. Article 50 compliance is mostly interface and provenance work: disclosure in the right place, at the right moment, and durable marking of what your systems generate. Smaller, but it touches product surfaces rather than a compliance repository, which means it needs engineering time on a roadmap that was probably re-planned on the assumption that nothing was due until 2027.

What to do in the next quarter

  1. Re-inventory against Article 50, not Annex III. The question is not "is this high-risk" but "does a person interact with it, or does it generate content." Those are different filters over the same estate, and the second one usually returns more systems than teams expect.
  2. Decide where disclosure lives. At first contact, not buried in terms. For voice agents, before the conversation starts. Write it down as a product decision, because you will be asked to evidence it.
  3. Sort out content marking. Machine-readable provenance for anything your systems generate. If you rely on a model provider's marking, confirm in writing what they actually emit and whether it survives your pipeline.
  4. Check whether you are a GPAI provider. Fine-tuning and redistribution can move you into that category. This obligation has been live for over a year.
  5. Keep the high-risk programme warm. December 2027 is not far for conformity assessment, and the narrowed scope means last year's classification should be re-run rather than assumed. Re-running it is cheaper than restarting it in 2027.

The shape of the thing

The Omnibus was widely read as a retreat. It is better read as a re-sequencing: the heavy conformity machinery slid right, and the obligations that shape how people encounter AI stayed exactly where they were.

If your programme is currently paused until 2027, the useful question is not whether you are ready for high-risk. It is whether the AI features you have already shipped tell the people using them what they are talking to.

This article reflects the position following the adoption of Regulation (EU) 2026/1744. It is general information about the regulation's timeline, not legal advice — obligations depend on your role as provider or deployer and on the systems you operate. Arelis AI helps teams inventory their AI estate against the Act and evidence what they find.

Back to Blog
AI Assistant