
Loading

Loading
We use strictly necessary cookies to run this site, and analytics cookies to understand how it's used. See our Privacy Policy for details.
The EU AI Act's August 2026 deadline didn't hold as originally written. What the Digital Omnibus actually delayed, what didn't change, and where things head next.
The EU AI Act was supposed to reach full application on August 2, 2026. It didn't, not because enforcement stalled, but because the EU itself decided the original timeline was moving faster than organizations, and in some cases the EU's own standards bodies, could actually keep up with. Our earlier piece on who regulates AI across the EU, UK, and Gulf covers the law as originally structured, this one covers what actually changed since, and where the direction of travel points next.
EU co-legislators reached a provisional agreement on the Digital Omnibus on May 7, 2026, and Parliament voted it through in plenary on June 16, 2026. The practical effect is a genuine, substantial delay to the AI Act's high-risk obligations, not a minor technical adjustment. Standalone high-risk systems under Annex III, the category covering employment, credit scoring, and education, now have until December 2, 2027, sixteen months later than the original date. Systems embedded in already-regulated products under Annex I, like medical devices and machinery, move from August 2027 to August 2028. The national regulatory sandbox deadline moved too, from August 2026 to August 2027.
EU AI Act high-risk obligations, original vs. revised
This is the part worth being precise about, because it's easy to read "delay" as "the law got weaker" across the board, and that's not accurate. Prohibited AI practices and the general-purpose AI model obligations that already took effect in August 2025 are unaffected by the omnibus. A new prohibition, covering AI that generates non-consensual intimate images and CSAM, takes effect December 2, 2026, on schedule. The delay is specifically targeted at the high-risk classification system's compliance machinery, not the law's enforcement teeth for the practices it already considers unacceptable.
The General-Purpose AI Code of Practice, published on the Commission's website in July 2025 after a multi-stakeholder drafting process, is the main tool GPAI providers use to demonstrate compliance, but following it is explicitly optional, other paths to compliance remain open. Its own legal force is still conditional: the Code only takes effect once the Commission formally approves it through an implementing act under Article 56(6) of the AI Act, and an implementing act legally cannot amend or supplement the underlying regulation itself. The practical upshot for any organization relying on the Code is to track that approval status directly rather than assume voluntary guidance has already become binding.
The pattern across 2026 is recalibration, not deregulation, toward what standards bodies and national authorities can realistically deliver on time. Coverage of the omnibus negotiations is explicit that the new high-risk dates are tied to the actual availability of harmonized technical standards and Commission guidelines, not an arbitrary new calendar date, meaning further adjustment is plausible if those standards slip again. For a multi-region organization, the operating assumption worth adopting is that the EU's framework will keep evolving on a rolling basis for at least another year, which argues for building an AI governance program around the underlying risk-management discipline, not a specific compliance date that may move again.
Whichever exact date eventually applies to your specific system, the control work underneath it doesn't change, know what AI systems you're actually running, classify their real risk level honestly, and document the human oversight and technical controls around them. Our EMEA Compliance Map tracks the underlying data-protection regimes these AI rules sit alongside across 27 European countries plus the UAE, Saudi Arabia, and Qatar, and our Cybersecurity Consulting team can help map which of these shifting obligations actually applies to your specific deployment today, not just where the law is eventually headed.
Tell us about your environment and goals, we'll help you scope the right engagement.