REGULATORY STATUS · 21 JUL 2026 Reg. (EU) 2024/1689 · amended Jul 2026

The AI Act changed three weeks ago.
Most compliance calendars are now wrong.

The Digital Omnibus moved high-risk deadlines to 2027–28 — but transparency duties still land in 12 days, and new prohibitions arrive in December. Here is exactly where the law stands, verified against the Official Journal.

IN FORCE TODAY
Prohibited practices · AI literacy · all GPAI model rules
Art. 4, 5, 50–56 · since Feb & Aug 2025
IN 12 DAYS — AUG 2
Transparency duties + GPAI enforcement — not deferred
Art. 50 incl. marking for new gen-AI · AI Office enforcement powers · penalties framework
CHANGED JUL 2026
High-risk obligations moved to Dec 2027 / Aug 2028
Digital Omnibus adopted · OJ publication expected by Jul 30 · NCII/CSAM ban Dec 2

The calendar, as amended

Struck dates superseded by the Digital Omnibus · Full timeline →
FEB 2, 2025
Prohibitions
Art. 5 banned practices; AI literacy (Art. 4).
IN FORCE
AUG 2, 2025
GPAI rules
Model obligations, systemic-risk tier, governance.
IN FORCE
AUG 2, 2026
Transparency
Art. 50 applies (marking incl. for new gen-AI). GPAI enforcement, penalties regime.
12 DAYS
DEC 2, 2026
Marking + new ban
Art. 50(2) for legacy systems; NCII/CSAM prohibition.
NEW — OMNIBUS
DEC 2, 2027
was AUG 2, 2026
High-risk (Annex III)
Full Chapter III obligations for stand-alone systems.
MOVED +16 MO
AUG 2, 2028
was AUG 2, 2027
High-risk (Annex I)
AI embedded in regulated products (devices, vehicles).
MOVED +12 MO

Briefing answers

The questions boards and leadership teams are asking this month — answered against the amended text.

Did the EU just delay the AI Act?
Partially. The Digital Omnibus (in force Jul 2026) moved high-risk obligations to Dec 2, 2027 (Annex III) and Aug 2, 2028 (Annex I products). Everything else — prohibitions, GPAI rules, and the Art. 50 transparency duties landing Aug 2, 2026 — proceeds on schedule.
What exactly applies on August 2, 2026?
Art. 50 transparency: telling people they’re interacting with AI, labelling AI-generated content, disclosing emotion recognition and biometric categorisation. Plus the governance and penalties framework. Only the machine-readable watermarking duty (Art. 50(2)) gets a grace period — to Dec 2, 2026 — and only for systems already on the market.
Does the delay mean we can pause our high-risk program?
The obligations are unchanged — only later. Conformity assessment, QMS, data governance and documentation take most organisations 12–18 months. The first harmonised standards are expected Q4 2026, which is when gap analysis against the final text can start in earnest.
We self-assessed our system as not high-risk. Anything to do?
Yes. The Omnibus reinstated registration: systems self-assessed out of high-risk classification under Art. 6(3) must still be registered in the EU database, in a lighter form. Document your reasoning — authorities can challenge it.
We’re not an EU company. Are we in scope?
Often, yes. The Act covers any provider placing a system on the EU market, and providers or deployers anywhere whose system’s output is used in the EU (Art. 2). Non-EU providers of high-risk systems also need an EU authorised representative.
What’s the realistic penalty exposure?
Up to €35M or 7% of worldwide turnover for prohibited practices; €15M / 3% for most obligations; €7.5M / 1% for misleading information (Art. 99). National authorities gain full enforcement powers Aug 2, 2026 — starting with transparency.