The EU AI Is NOT Delayed (Just One Provision Is)

The EU’s Digital Omnibus on AI has amended the AI Act in significant ways. The headline news is that the high-risk deadline has moved from August 2026 to December 2027. In addition, the deadline for AI embedded in regulated products under the AI Act’s Annex I (e.g., medical devices, machinery, and vehicles) slips to August 2028.

Despite these postponements the AI Act’s fundamental obligations remain firmly in place.

While the delay reduces deadline pressure in some areas, it does not reduce the work firms must do to comply with rules now in force or soon to be. Firms still need to inventory AI systems, classify use cases, identify applicable obligations, establish ownership, and monitor changing guidance.

The information below helps you understand what constitutes a high-risk system under the AI Act, provides a timeline for applicability of AI Act provisions, as well as outlining some looming provisions that will have significant impacts.

The deadline delay is limited to high-risk systems, defined as follows:

  • the AI system is intended to be used as a safety component of a product, or the AI system is itself a product, covered by the Union harmonization legislation listed in Annex I; (source)
  • the product whose safety component pursuant to point (a) is the AI system, or the AI system itself as a product, is required to undergo a third-party conformity assessment, with a view to the placing on the market or the putting into service of that product pursuant to the Union harmonization legislation listed in Annex I. (source)
  • In addition to the high-risk AI systems referred to [above], AI systems referred to in Annex III shall be considered to be high-risk.

Why the EU AI Act applies to so many US firms

The EU AI Act is built to follow AI systems and their outputs. If the AI output is consumed in the EU, the AI Act binds it. This includes:

  • Shipping an AI feature to EU end users — you’re a provider placing a system on the EU market (Article 2).
  • Your EU subsidiary using a US-built internal tool — that subsidiary is a deployer located in the Union (Article 2(1)(b)).
  • EU users consuming your AI’s output, even with no EU sales — output used in the Union pulls you in (Article 2(1)(c)).
    Source

The eight Annex II areas are:

    • Biometrics
    • Critical infrastructure
    • Education and vocational training
    • Employment, workers management and access to self-employment
    • Access to essential private and public services
    • Law enforcement
    • Migration, asylum, and border control
    • Administration of justice and democratic processes

Exceptions to the Annex III high-risk categorization occur in the following circumstances:

    1. the AI system is intended to perform a narrow procedural task;
    2. the AI system is intended to improve the result of a previously completed human activity;
    3. the AI system is intended to detect decision-making patterns or deviations from prior decision-making patterns and is not meant to replace or influence the previously completed human assessment, without proper human review; or
    4. the AI system is intended to perform a preparatory task to an assessment relevant for the purposes of the use cases listed in Annex III. (source)

Here is a timeline for AI Act provisions, showing what currently applies, and what is pending.

Applicability DateProvision(s)
February 2, 2025Article 5 prohibited practices (original list); Article 4 AI literacy.
August 2, 2025General-purpose AI model obligations, Chapter V (Arts. 51–55).
August 2, 2026General application date. Article 50 transparency. Article 49 registration. National market surveillance authority powers.
December 2, 2026Two new Article 5 prohibitions (NCII/NCIM and CSAM generation). Article 50(2) machine-readable marking for generative systems already on the market before 2 Aug 2026.
August 2, 2027National regulatory sandboxes (deferred by Reg. 2026/1744).
December 2, 2027Annex III stand-alone high-risk obligations — Chapter III Sections 1, 2 and 3.
August 2, 2028Annex I embedded high-risk obligations (AI in regulated products).
August 2, 2030Article 111 transition ends for AI systems already in use by public authorities.

Upcoming deadlines to keep in mind

The December 2, 2026 deadline for compliance with the ban on AI systems that generate or manipulate non-consensual intimate images, video, audio or similar material, or child sexual abuse material (CSAM) is looming. “For providers, the prohibition extends beyond systems intended for such use to any system where such generation is a reasonably foreseeable and reproducible outcome, without requiring significant technical modification, and the system lacks reasonable and adequate technical safeguards to reliably prevent it. Providers of general-purpose image- or video-generation tools must therefore actively assess foreseeable misuse risks at the design and deployment stage.”[1]

Another December 2, 2026 deadline looms for the machine-readable watermarking obligation under Article 50(2). However, all other Article 50 obligations went into effect on August 2, 2026. They include:

  • Article 50(1) requiring interactive AI systems, including chatbots, voice assistants, and agentic AI, to inform users they are using AI at the point of interaction
  • Article 50(3) obligates those who deploy emotion recognition or biometric categorization systems to tell individuals when they are being processed by such a system.
  • Article 50(4) requires disclosure of artificial origin when deploying AI generated text or deepfakes on matters of public interest.

The complexity and dynamism of this one Act testify to the daunting task of regulatory compliance. Multiply this by municipalities, states, and countries and it’s clear why just knowing that a rule has changed is not enough. You have to orchestrate change information throughout your organization, at scale, to ensure the right people take the right steps to comply at the right time. You must not only track evolving legislation, guidance, and supervisory expectations. You have to connect them to the obligations affecting each entity, jurisdiction, and use case.

AscentAI can bring all of these different sources together, connect implementing standards and guidance to the underlying legislation, and mapping the resulting obligations across every applicable entity and jurisdiction.

HAVE QUESTIONS?  Learn more about orchestrating regulatory change throughout your organization with AscentAI.

[1] https://www.gibsondunn.com/eu-ai-act-omnibus-agreement-postponed-high-risk-deadlines-and-other-key-changes/