The AI Act deadlines are now settled: what changed, and what to do next
21 July 2026 · 6 min

The EU has finished a long argument about its own timetable. On 24 July 2026 the Digital Omnibus on AI was published in the Official Journal as Regulation (EU) 2026/1744, and it entered into force on 27 July 2026. For most of the past year the story was "dates may move." That story is over. The dates moved, and they are now fixed in law.
Here is the short version for compliance and finance leaders. The hardest obligations, the ones for high-risk AI, were pushed back. The obligations that were already live, the bans and the transparency rules, stayed where they were. The penalties did not change. If your firm relaxed because "it all got delayed," that reading is wrong, and it is worth correcting this week.
What actually moved
High-risk AI is the part most banks, insurers and asset managers care about. Credit scoring, insurance pricing for life and health, and hiring tools all sit in the high-risk category. The original date for these standalone systems was 2 August 2026. It is now 2 December 2027. High-risk AI that is built into a regulated product, for example inside a device already covered by EU safety law, moves to 2 August 2028.
One detail matters here. The Commission's first proposal made the new high-risk date conditional. It would only apply once standards and support tools were ready. The final law dropped that condition and set plain calendar dates instead. So you are not planning against a moving target anymore. December 2027 means December 2027.
What did not move
Two things stayed exactly where they were, and this is where firms get caught out.
First, the prohibited practices. The Article 5 bans have applied since 2 February 2025. Social scoring, certain biometric categorisation, and manipulative systems that exploit vulnerabilities are off limits now, not later. The Omnibus added one new ban, on AI that produces child sexual abuse material or non-consensual intimate images, with a short transition to 2 December 2026. Breaching a ban carries the top penalty.
Second, the transparency rules. The Act's general application date is still 2 August 2026. From that day you have to tell people when they are dealing with an AI system, and you have to disclose AI-generated content. There is one narrow exception. The duty to mark AI-generated content in a machine-readable way has a grace period to 2 December 2026. Everything else in this bucket lands in August.
General-purpose AI models are also unchanged. Those obligations have applied since 2 August 2025, and the Commission's power to enforce them applies from 2 August 2026.
The literacy rule got softer, not gone
Article 4, the staff AI literacy duty, has been live since 2 February 2025. The Omnibus reworded it. Before, firms had to "ensure" a sufficient level of AI literacy. Now they have to support it, judged against people's roles, training, and the context they work in. The law even spells out that you do not have to guarantee any specific level for any individual.
Read that as relief on wording, not a reason to stop. The duty still exists. If a regulator asks how your staff understand the AI tools they use, "we did nothing because it was softened" is a poor answer. Basic training, a simple policy, and a record of who was trained still do the job.
The penalties are the same
Nothing about the Omnibus touched the fines. The ceilings remain up to 35M euros or 7% of global annual turnover for banned practices, up to 15M euros or 3% for most other breaches, and up to 7.5M euros or 1% for giving regulators incorrect information. The delay to high-risk rules does not buy you a discount on the bans or the transparency duties.
So what should a regulated firm do now
Treat the extra time as runway, not as a pause. Four practical steps.
One, split your inventory by date. Separate the AI you use into three lists: anything that could touch a prohibited practice, anything customer-facing that triggers transparency in August 2026, and anything high-risk that now has until December 2027. The first two lists are urgent. The third is a project you can plan properly.
Two, close the August 2026 transparency gap first. Check every chatbot, every automated customer message, and every place you publish AI-generated text or images. Confirm the disclosures are in place before 2 August 2026. Diarise the machine-readable marking work for 2 December 2026.
Three, use the high-risk runway for real conformity work. December 2027 sounds far away, but the work is heavy: risk management, data governance, human oversight, technical documentation, and for many finance uses a fundamental-rights impact assessment. Start the credit and insurance models now, because those are the ones on the Annex III list.
Four, keep the literacy programme going. Light training, a short internal policy, and a record of attendance. It satisfies the softened Article 4 and it makes every other step easier, because staff who understand the tools spot the risks.
The headline for a board is simple. The EU did not weaken the AI Act. It rescheduled the hardest part and left the rest in place. Firms that read the delay as permission to stop will meet the same rules in 2027 with less time and more exposure. Firms that use the runway will be ready early and calm about it.
Sources
- https://digital-strategy.ec.europa.eu/en/news/ai-omnibus-enters-force
- https://www.consilium.europa.eu/en/press/press-releases/2026/06/29/artificial-intelligence-council-gives-final-green-light-to-simplify-and-streamline-rules/
- https://www.gibsondunn.com/eu-ai-act-omnibus-agreement-postponed-high-risk-deadlines-and-other-key-changes/
- https://www.freshfields.com/en/our-thinking/blogs/technology-quotient/eu-ai-act-unpacked-34-the-final-digital-omnibus-on-ai-key-amendments-to-the-a-102nber
- https://www.stibbe.com/publications-and-insights/ai-act-reloaded-what-the-latest-ai-act-changes-mean-in-practice
- https://www.dlapiper.com/en-us/insights/publications/2025/08/latest-wave-of-obligations-under-the-eu-ai-act-take-effect