The AI Act was delayed. The parts that bind you were not.
The Digital Omnibus on AI came into force on 27 July and pushed high-risk obligations to December 2027. Six days later the transparency rules started applying anyway, and the synthetic-content grace period turns out to run backwards: the newer your deployment, the sooner you comply.
The Digital Omnibus on AI entered into force on 27 July 2026. Council adopted it on 29 June, it was signed on 8 July, published in the Official Journal on 24 July, in force three days later. Its headline effect is that the big high-risk deadline moved from 2 August 2026 to 2 December 2027.
Every summary I have read since treats that as a reprieve. Six days after it came into force, on 2 August, a set of obligations started applying regardless, and one of them has a grace period that works in the opposite direction to what people assume.
What actually moved
| Obligation | Was | Now |
|---|---|---|
| Annex III high-risk systems (standalone) | 2 Aug 2026 | 2 Dec 2027 |
| Annex I high-risk (embedded in regulated products) | 2 Aug 2027 | 2 Aug 2028 |
| Member-state AI regulatory sandboxes | 2 Aug 2026 | 2 Aug 2027 |
Two details matter more than the dates.
First, these are hard dates. The Commission's original proposal had a conditional trigger, a stop-the-clock that would start once harmonised standards were actually available. The final agreement threw that out in favour of fixed dates. If you have ever tried to build a programme plan around "whenever CEN-CENELEC finishes", you will understand why that is the single most useful thing in the instrument.
Second, Annex III is not an abstraction. It covers biometrics, employment and worker management, education, essential services, critical infrastructure and credit scoring. In other words, most of what my clients in banking, insurance and telecom actually deploy. Those teams just received sixteen extra months for conformity assessment, risk management systems, technical documentation, human-oversight design and post-market monitoring.
What did not move
Article 50 was not amended. The transparency obligations have applied since 2 August 2026:
- Article 50(1): tell people they are interacting with an AI system, unless it is obvious from the context.
- Article 50(2): providers of generative systems must mark synthetic output in a machine-readable way.
- Article 50(3): inform people exposed to emotion recognition or biometric categorisation.
- Article 50(4): disclose deepfakes, and disclose AI-generated text published on matters of public interest, unless a human took editorial responsibility for it before publication.
Alongside that, still live and unchanged: the Article 5 prohibitions and the Article 4 AI-literacy duty, both applicable since February 2025, and the Commission's enforcement powers over general-purpose models, which switched on this month. The Omnibus also added a prohibition, on AI systems that generate non-consensual intimate imagery and child sexual abuse material, with a transition to 2 December 2026.
Penalties for breaching Article 50 have been available since August 2025: up to €15M or 3% of worldwide annual turnover.
The grace period runs backwards
Here is the part nobody puts in the summary.
Article 50(2), the machine-readable marking of synthetic content, did get relief: a four-month extension to 2 December 2026. But that extension applies only to systems already on the market before 2 August 2026. A system placed on the market on or after that date complies immediately, with no grace period at all.
Read that against how teams actually behave. The organisation that shipped a generative feature last year, has it in production, has real users and the largest volume of unmarked output, gets four extra months. The team that finishes its deployment next month gets none. The relief is inversely proportional to how much output you are producing.
If you are mid-build right now, that is the single most expensive misreading available to you, because "the AI Act was delayed to 2027" and "your marking obligation started three weeks ago" are both true statements about the same regulation.
What I would do with sixteen months
Not treat it as a reprieve. The delay moved the expensive engineering, and the expensive engineering is exactly the part that gets more expensive the later you start.
Every high-risk obligation that lands in December 2027 is really a request for evidence about a system that will by then have been running for a year or two. Article 12 wants automatic logging over the system's lifetime. Article 14 wants human oversight that was designed in, not bolted on. Article 10 wants data governance you can describe. Article 72 wants post-market monitoring with a plan behind it.
Every one of those is cheap while you are building and brutal to retrofit into a live system, for the same reason that adding tests to legacy code is worse than writing them first. Sixteen months is not time off. It is the only window in which the evidence layer costs you almost nothing, and I would spend it exactly as I have argued for voice agents and long-running agents: build the audit trail while the system is still soft.
The disclosure work, meanwhile, is not a project. Article 50 is a sentence at the start of a conversation, a label on generated media, and a metadata field. If that is not shipped by now, it was never a resourcing problem.
One thing not to plan on
The other omnibus, the data one, is a different instrument and it is not law. Amendments to the GDPR and ePrivacy, including an explicit legitimate-interest basis for AI training with an unconditional opt-out, and moving cookie consent into the GDPR, are still in negotiation, with final adoption not expected before late 2026 at the earliest. The EDPB and EDPS pushed back in February, and the proposed redefinition of personal data looks unlikely to survive in the form first floated.
Anyone telling you the GDPR now permits AI training on personal data by default is describing a proposal, not a rule. I would not move a single architectural decision on it.
The pattern
Strip out the politics and the sequencing is defensible. The EU postponed the obligations that require standards, notified bodies and expensive assessment machinery that does not fully exist yet. It kept the obligations that require honesty and cost a sprint: say it is a machine, mark what the machine produced, teach your staff what they are operating.
Given a choice between those two, delaying the first is the right order. It just means the news you actually needed this month was not the delay.
Sources: Gibson Dunn on the omnibus agreement; Council's final green light, 29 June 2026; entry into force and the Article 50 timeline; DLA Piper on the deferral; Cloud Security Alliance: deferred, not cancelled; official AI Act implementation timeline; on the data omnibus, IAPP and Covington on the regulators' opinion.