The deadline that moved
Europe moved the high-risk cliff. It did not move the rules that touch your chatbot today. Here is the map, in plain language.
For two years, one date sat circled in red in every European AI plan: August 2, 2026, the day the AI Act's high-risk regime was due to bite. Hiring tools, credit scoring, access to essential services: full obligations, conformity assessments, documentation, the works. Then, six days before that date arrived, the ground under it changed. On July 27, 2026, the Digital Omnibus entered into force as Regulation (EU) 2026/1744, and the cliff moved. Not the whole cliff, though: the part that stayed is the part most small businesses are standing on right now.
unknown nodeThis piece does one job: separate what moved from what did not, in language a founder can act on. Every date below comes from the legislative record, not from a headline.
What actually happened
The Digital Omnibus is not a rumor, a draft, or a lobbying position. It is settled, in-force law, and it got there through the full machinery. The European Commission proposed the package on November 19, 2025. The Council and the Parliament reached a provisional political agreement on May 7, 2026.
unknown nodeParliament approved the text in plenary on June 16, 2026, by 423 votes to 57, with 174 abstentions. The Council gave its final green light on June 29, 2026. The act was signed on July 8, published in the Official Journal on July 24 as Regulation (EU) 2026/1744, and entered into force three days later, on July 27.
unknown nodeWhy this matters for how you read everything else: through spring 2026 the coverage was full of "proposed," "provisional," "expected." That tense is over. The dates below are not predictions. They are the law as it stands.
What moved: two dates, not one
The deferral is the headline, and almost everyone quotes it wrong, because there is not one new deadline. There are two.
Standalone high-risk systems (the Annex III list: AI used in hiring and worker management, in credit scoring, in access to essential private and public services) were due to face the full high-risk regime on August 2, 2026. That obligation now applies from December 2, 2027. A sixteen-month deferral.
Embedded high-risk systems are AI built into products that already carry EU safety law: medical devices, machinery, toys, lifts. That is the Annex I route, and it was on a later clock, August 2027. That clock moved to August 2, 2028. Twelve months, not sixteen.
unknown nodeunknown nodeWhat did not move
Here is the part the relief coverage buried. The Article 50 transparency obligations were not deferred. They applied from August 2, 2026. As you read this, that date is already behind us.
In plain terms: if a customer talks to your chatbot, they must be able to tell they are talking to a machine. If you publish AI-generated text, images, or audio, it must be marked as such. Deepfakes must be labeled. These are not high-risk rules for banks and hospitals; they touch every business whose website has an AI assistant or whose content pipeline runs through a model. In 2026, that is most of them.
unknown nodeThere is one grace window, and it is narrow: for systems already on the market before August 2, 2026, the duty to mark AI-generated content runs from December 2, 2026. That is a few months to retrofit labels, not a reprieve.
unknown nodeAnd two whole layers of the Act never entered the negotiation at all: the obligations for general-purpose AI models have applied since August 2025, and the outright bans (social scoring, manipulative systems and the rest of the prohibited-practices list) have applied since February 2025. Nothing in the Omnibus touched either.
The relief nobody is reading
The Omnibus did not only move dates. It created a category most founders have not heard of yet: the "small mid-cap," a company with fewer than 750 employees and up to €150 million in turnover (or a balance sheet up to €129 million). Firms in that band, and the small and medium enterprises below it, get a materially lighter regime: simplified technical documentation, a quality-management system proportionate to their size, reduced penalty caps, and priority access to regulatory sandboxes.
unknown nodeThe sandbox picture moved too. Member states now have until August 2027, a year longer than before, to stand up national AI sandboxes, and the Act adds an EU-level sandbox run by the AI Office. For a small company, a sandbox is the one place where you can test a borderline system with the regulator watching instead of waiting.
unknown nodeThe wrong lesson
The tempting reading of all this is: we got away with it: park the file until 2027. That is the one mistake the new timeline actually punishes.
A delay is not a cancellation. The high-risk regime was deferred, not dropped; the definitions did not change; the December 2027 date is now as fixed as the August 2026 date used to look. And sixteen months is shorter than it sounds once you subtract the time it takes to answer suppliers' questionnaires, chase documentation from the vendors whose models you build on, and untangle which of your tools even fall on the Annex III list.
unknown nodeThe move that costs almost nothing now and a great deal later is an inventory. One page per system: what the AI does, in one sentence. Who owns it: a name, not a department. What data goes in and what comes out. And what it may never do, written down. That single register answers the transparency duties you owe today, tells you instantly whether December 2027 concerns you, and is the first document any lawyer, auditor, or enterprise customer will ask for. Mapping your systems while the deadline is far is cheap. Reconstructing the map in the last quarter of 2027 is not.
Compliance is legibility
Everything we publish circles one claim: machines can only act on what they can clearly read, and that now cuts in two directions. Outside your company, AI assistants recommend the brands the web has made legible. Inside it, the new law asks for exactly the same discipline: know what your AI does, write it down, put a name on it. The register that satisfies a regulator and the clarity that gets you cited by a machine are the same habit. The businesses that treat the moved deadline as sixteen months of silence will do the work twice; the ones that write it down once will find that the document was never really for Brussels.
If you want to see how legible your own business already is to the machines that answer your customers' questions, you can measure it at /signal-index/ or write to us at /contact/.
unknown nodeunknown nodeunknown nodeunknown nodeunknown nodeunknown nodeunknown node