Why it matters
  • Lead. August 2, 2026 was the scheduled enforcement date for the EU AI Act’s most consequential provisions — but a Digital Omnibus agreement reached in May quietly moved those obligations to December 2027.
  • Fact. The postponement, agreed by the European Council, Parliament, and Commission on May 7, covers Annex III high-risk AI applications including biometric identification, law enforcement tools, employment screening, and border control systems.
  • Stake. Companies with GPAI (general-purpose AI model) obligations face live enforcement from August 2; companies deploying high-risk systems have until December 2027 — but legal advisers warn that 16 months is barely enough time to complete the required conformity assessments.

What Passed — and What Did Not

August 2 was always the headline date in EU AI Act compliance calendars. It marked the point at which the regulation’s obligations for “high-risk” AI systems — the applications most directly affecting individuals’ rights, livelihoods, and physical safety — were supposed to become binding under Annex III.

Annex III covers AI systems used in biometric identification and categorisation, critical infrastructure, education and vocational training, employment and HR processes, essential public and private services, law enforcement, migration and border control, and the administration of justice. These categories include facial recognition systems, automated CV-screening tools, predictive policing platforms, and AI-assisted credit scoring — the applications that civil liberties groups and regulators have watched most closely since the AI Act was first proposed in 2021.

According to legal analysis published by Gibson Dunn and Reed Smith contemporaneously with the August 2 deadline, the political agreement known as the “Digital Omnibus” — reached between the European Council, European Parliament, and European Commission on May 7, 2026 — postponed all Annex III obligations to December 2, 2027. Annex I obligations, covering AI embedded in regulated products such as medical devices, lifts, and machinery, were moved even further, to August 2, 2028.

What Is Live From August 2

The Omnibus deal left two enforcement categories intact. First, general-purpose AI model (GPAI) obligations — the requirements that took effect for providers of large AI models available in the EU — were not subject to the postponement. Transparency requirements, capability evaluations, and incident reporting obligations for GPAI providers entered full effect on August 2, as this site reported. Second, the prohibition on banned AI practices — including real-time biometric surveillance in publicly accessible spaces and AI-enabled social scoring by public authorities — was similarly unaffected by the Omnibus deal.

The practical result is a bifurcated enforcement timeline: GPAI providers and banned-practice prohibitions are live; high-risk deployers and providers have 16 more months.

Why the Delay Was Agreed

The Omnibus deal reflected pressure from industry groups and several member states who argued that companies — particularly small and mid-size enterprises — were not prepared to meet the August 2026 deadline. The European AI Office, which took on GPAI oversight responsibility in 2025, also acknowledged that the conformity assessment infrastructure for Annex III systems was not operational in time for full August enforcement. Critics, including digital rights organisations, argued the postponement undermined the law’s credibility at exactly the moment when AI deployment in high-stakes sectors was accelerating.

What Companies Need to Do Now

Legal advisers at firms including Holland and Knight have flagged that December 2027 is not as distant as it appears. Completing a conformity assessment for a complex high-risk AI system — including risk management documentation, data governance reviews, technical documentation, and in some cases third-party audits — typically requires 12 to 18 months of preparation. Companies deploying Annex III systems that have not yet started their compliance programmes are effectively at or beyond the limit of what is achievable before the new deadline.

The postponement does not affect companies’ obligations to prepare; it affects the date on which non-compliance becomes subject to fines of up to €30 million or 6% of global annual turnover. For US companies with EU-facing products, the bifurcation also creates a near-term planning obligation: the GPAI rules that apply now may affect model selection and deployment architecture in ways that interact with the high-risk rules coming in 2027.