IThe one-line version, if you only read one paragraph
High-risk conformity work got a 16-month reprieve; transparency did not. And this is enacted law, not a proposal you can wait out. The Digital Omnibus on AI — Regulation (EU) 2026/1744 — was published in the Official Journal on July 24, 2026 and entered into force on July 27, 2026, six days before the original deadline it was rewriting. That timing matters. The deferral was locked in before August 2, so nobody had to comply with the old Annex III date even for a week — but nobody got a pass on the parts that stayed put, either.
IIWhat got pushed: the Digital Omnibus deferral
The deferral runs on two tracks, depending on where the high-risk system lives. Secure Privacy's breakdown lays out both:
Here's the part that gets misread: the requirements themselves were not softened. The obligations for high-risk systems — risk management, data governance, human oversight, documentation — are all still coming. Only the start date moved. Parliament co-rapporteur Arba Kokalari put the political spin bluntly: "we are pressing the pause button on the AI Act and we are reducing red tape." The pause is real. The red-tape reduction, on the high-risk regime, is mostly a matter of timing.
aHow we got here: from proposal to enacted law in about eight months
For an EU legislative process, this was a sprint. Per Secure Privacy, the sequence ran: the European Commission published the proposal on November 19, 2025 → a first trilogue on April 28, 2026 failed to reach agreement → a provisional political deal was struck on May 7, 2026 → the Council gave its final green light on June 29, 2026 → and the text hit the Official Journal on July 24, 2026. EU Executive Vice-President Henna Virkkunen framed the deal this way: "Our businesses and citizens want two things from AI rules. They want to be able to innovate and feel safe. Today's agreement does both." The honest read is that dates in this regime can move fast and late — which is exactly why treating any deadline as final is a mistake.
IIIWhat did NOT get delayed: Article 50 transparency rules went live on schedule
This is the section most teams get wrong. Article 50's transparency obligations took effect on August 2, 2026, exactly as originally planned, and were left out of the Omnibus deferral entirely. National market surveillance authorities can enforce them from that date.
In plain terms, that means: if a user is interacting with an AI system, they have to be told. AI-generated and deepfake content has to be labeled. And the deployer-side duties — disclosure for emotion-recognition and biometric-categorization systems, plus deepfake labeling — came with no grace period at all and have applied since August 2, 2026, according to Morgan Lewis.
The key mental model: transparency applies by function, not by risk tier. It doesn't care whether your system is "high-risk" under Annex III. If it talks to people or generates content, it's likely in scope — Annex III delay or not.
aThe one exception: watermarking gets a short grace period
Exactly one piece of Article 50 got breathing room. The machine-readable marking requirement — Article 50(2), the watermarking obligation — got a short runway for generative AI systems that were already on the market before August 2, 2026. Morgan Lewis notes those providers have until December 2, 2026 to comply: a four-month extension, and notably shorter than the six-month grace period the Commission originally floated. Anything placed on the market on or after August 2, 2026 has to comply immediately. There's no grace period for new systems.
IVNew rule that snuck in: the ban on AI 'nudifiers' and CSAM
The Omnibus didn't only push dates back — it added a new prohibition. Per the Council of the EU, Article 5's list of prohibited practices now bans AI systems used to generate non-consensual intimate imagery — so-called "nudifiers" — and child sexual abuse material. It takes effect on December 2, 2026, the same day as the watermarking deadline. And because it's an Article 5 prohibition, it sits in the harshest enforcement tier there is.
VWhat the penalties actually look like now
The fine structure stays steeply asymmetric. Prohibited practices are punished far harder than everything else. Here's how the tiers stack up, per Cooley:
The takeaway: the transparency rules that just went live carry the same €15M / 3% exposure as most high-risk violations. "Only transparency" is not a small line item.
VITwo smaller changes worth knowing about
A couple of quieter provisions matter if you're already operating systems in the EU.
Grandfathering. High-risk systems lawfully placed on the market before the new applicability dates can keep running without retrofitting or fresh certification — provided the design is unchanged. The catch is the reset clause: the moment a system is "substantially modified," the clock starts over and full obligations attach.
The machinery carve-out. The Omnibus moved the Machinery Regulation from Annex I Section A to Section B, which means most AI-embedded machinery now only has to meet the sector-specific Machinery Regulation rather than the AI Act's full high-risk regime. The same package also pushed back the deadline for Member States to stand up at least one national AI regulatory sandbox to August 2, 2027.
VIIThe full compliance timeline, in order
One consolidated view, so you can see where the two tracks sit relative to everything else. The pre-2026 dates are per Cooley's timeline:
Worth flagging: the Commission only adopted its official Guidelines on the Article 50 obligations on July 20, 2026 — 13 days before the rules took effect. Practical interpretation landed almost at the buzzer. That's the pattern to plan around.
VIIIWhat this means if you're building or funding AI right now
Here's my honest verdict. The deferral bought real runway on the expensive, slow part — high-risk conformity assessments, documentation, human-oversight design. If that was your 2026 fire drill, you now have until December 2027, and that's genuine relief.
But the obligations that are live today are the ones almost everyone actually touches. Transparency and deepfake-labeling apply by function, not risk tier — so most generative AI products are already in scope regardless of the Annex III delay. If you ship a chatbot, a content generator, or anything that produces synthetic media, the disclosure and labeling duties are on you now, not in 2027.
One softer-landing option worth knowing: the voluntary Code of Practice on Transparency of AI-generated Content, published in June 2026. By the end of July 2026, roughly 190 companies had signed on, and signatories get a degree of presumption of conformity and a friendlier enforcement posture than non-signatories. For GPAI and content-labeling posture, it's a reasonable place to start.
At the studio, this is the kind of moving-target problem I build around — I run an AI systems studio and consultancy that helps funds and companies wire compliance and disclosure into the products they're already shipping, rather than bolting it on after an alert lands. It ties into how I think about structuring a company for AI in 2026: the obligations that apply by function belong inside your build, not in a quarterly review. And if you're weighing whether to staff this internally, it's the same math as what a $10K/month build-vs-buy retainer actually replaces — someone has to own the moving parts, and the parts here move fast.
IXKeeping track of what changes next
The Omnibus is the clearest proof yet that this regulation is still settling — a deadline everyone tracked for a year moved six days before it landed. Re-reading law-firm alerts every month is a bad use of anyone's time, and "I read the Act once" doesn't count as staying current.
That's why I built the EU AI Compliant tracker at euaicompliant.com. The core reference is freely accessible — the consolidated law with amendment diffs, an obligations database mapped by role and deadline, an enforcement map across all 27 national authorities, and a regulatory radar for what's coming next — with extended features and team accounts on paid tiers. Every citation is verified against the Official Journal, with a last-verified date on every page, so you're reading the law, not another AI-generated summary of it. And if you'd rather have it wired into your own stack, that's something the studio can set up and operate.
XFAQ
What does EU AI Compliant actually track? The full Act — 113 articles, 180 recitals, 13 annexes — with amendment diffs so you can see what changed and when. On top of that: an obligations database, a JTC 21 standards tracker with citation status, an enforcement map across all 27 national authorities with penalty bands, and a radar for upcoming changes like the Omnibus itself.
How do you keep it current? Every citation is verified against the Official Journal and carries a last-verified date, with direct citations to EUR-Lex. No hallucinated obligations — if it's on the page, it traces back to the primary source.
Is it built for legal teams or engineering teams? Both, really. It's aimed at in-house counsel, compliance teams, and the AI providers who have to operate under the law. Obligations are mapped by role — provider, deployer, or importer — so a compliance lead and a builder can each filter down to what applies to them.
Does it cover transparency and GPAI too, or just high-risk? All of it. Obligations are mapped by role, risk class, and deadline — so the Article 50 transparency duties and GPAI provider obligations are in there alongside the Annex III high-risk regime, not treated as an afterthought.
What does it cost, and can you set it up for us? The reference layer is freely accessible; extended features and team accounts sit on paid tiers. If you want it wired into your fund's or company's exact stack and operated alongside everything else, that's available through the build-and-operate retainer.
— Michael Rouveure