AI Act Compliance Deadlines After the Omnibus Delay

Last updated: 17 July 2026. Digital Omnibus adopted 29 June 2026, awaiting publication in the Official Journal.

The AI Act compliance deadlines changed shape on 29 June 2026, when the Council gave the Digital Omnibus its final green light and moved the high-risk application dates to 2 December 2027 and 2 August 2028. What did not move matters just as much. Transparency, AI literacy and GPAI obligations keep their original dates, and the Article 99 penalty regime has been live since 2 August 2025. Every date below sits in our EU compliance deadline tracker with its legal status and an XLSX download. One boundary before we start. This article covers the EU AI Act (Regulation (EU) 2024/1689) and its 2026 Omnibus amendment, not the US Colorado AI Act (SB 24-205, replaced by SB 26-189, effective 1 January 2027), which runs on a separate timeline.

Will the EU AI Act Be Delayed?

Yes, for high-risk systems only, and the delay is adopted but not yet law. The Digital Omnibus amendment passed Parliament on 16 June 2026 and the Council on 29 June 2026, and per the Legislative Observatory the final act was signed on 8 July 2026, with the file still listed as awaiting publication in the Official Journal on 17 July 2026.

That last detail is where most coverage goes wrong. Until publication, the original 2 August 2026 date formally stands, because the amendment enters into force on the third day after it appears in the Official Journal. Working backwards, publication on 30 July 2026 puts the amendment in force on 2 August itself, the day the original deadline arrives, and publication by 29 July puts it in force a day ahead of it. The Union is racing to publish, before 2 August 2026, a law whose main effect is to move 2 August 2026, and if the Official Journal misses the window, the date the law exists to postpone applies until it appears.

Two more points the delay headlines tend to skip. The final text sets fixed replacement dates rather than the conditional trigger mechanism the Commission originally proposed, so the new deadlines will not slide further on their own. And the underlying Act is unchanged as law. It has been a directly binding regulation, no member state transposition required, since 1 August 2024. The Omnibus amends it, it does not replace it.

The Full AI Act Compliance Deadlines Table Runs From 2025 to the End of 2030

Fifteen deadlines span February 2025 to December 2030. The Omnibus moves three of them, adds two new ones, and softens the AI literacy standard without touching its date. The table reads chronologically, and the status column is the part worth checking twice, because two different legal regimes are live on the same page until the Official Journal publication.

ObligationDeadlineStatus on 17 July 2026
Prohibited practices (Article 5)2 February 2025In force
AI literacy (Article 4)2 February 2025In force, standard softened by the Omnibus
New GPAI models (Articles 51 to 55)2 August 2025In force
Penalties and governance (Chapter XII except Article 101)2 August 2025In force
General transparency (Article 50(1), (3), (4))2 August 2026Applies as originally scheduled
Watermarking, new systems (Article 50(2))2 August 2026Applies as originally scheduled, Omnibus carves out legacy systems only
GPAI fines (Article 101, per Article 113(b))2 August 2026Applies as originally scheduled
Watermarking, legacy systems (Article 50(2))2 December 2026Adopted, awaiting Official Journal
New Article 5 prohibition (CSAM and non-consensual intimate imagery)2 December 2026Adopted, awaiting Official Journal
Legacy GPAI models (Article 111(3))2 August 2027In force, unchanged
National regulatory sandboxes2 August 2027Adopted, awaiting Official Journal, moved from 2 August 2026
High-risk, Annex III standalone systems2 December 2027Adopted, awaiting Official Journal, moved from 2 August 2026
High-risk, Annex I embedded systems2 August 2028Adopted, awaiting Official Journal, moved from 2 August 2027
Legacy high-risk systems used by public authorities (Article 111)2 August 2030In force, transitional
Annex X large-scale IT systems31 December 2030In force, transitional

Every row marked “awaiting Official Journal” becomes binding on entry into force, three days after publication. The EU compliance deadline tracker holds the same dates alongside NIS2, DORA and CSRD, verified against the source acts, with the downloadable XLSX version most readers land here looking for.

2 August 2026 Still Applies to Transparency, Literacy and GPAI

The Omnibus does not touch the general transparency obligations in Article 50(1), (3) and (4), which apply from 2 August 2026 exactly as scheduled in the original Act. That is sixteen days from this article’s publication date, and it is the fact the “AI Act postponed” headlines have quietly buried.

The Omnibus buys sixteen months for high-risk systems and zero days for transparency. If your organisation runs customer-facing chatbots, publishes AI-generated content, or deploys emotion recognition or biometric categorisation, the Article 50 disclosure duties arrive on schedule. The one concession sits in Article 50(2). Systems placed on the market before 2 August 2026 get a grace period for machine-readable marking of synthetic content, running to 2 December 2026, per White & Case’s reading of the agreed text. Systems placed on the market after that date get no grace period at all.

Two other obligations are already behind you, whether or not your programme noticed. AI literacy under Article 4 has applied since 2 February 2025. The Omnibus softened it, lowering the bar from ensuring “a sufficient level” of literacy to supporting its development, and the final text rejected the Commission’s proposal to shift the duty onto member states, so it stays with providers and deployers. And GPAI obligations under Chapter V have applied since 2 August 2025, untouched by the Omnibus. Providers of models placed on the market before that date have until 2 August 2027 to comply, per Article 111(3).

High-Risk Deadlines Move to 2 December 2027 and 2 August 2028

Once the Omnibus is published, standalone high-risk systems under Annex III must comply from 2 December 2027, and high-risk systems embedded in regulated products under Annex I from 2 August 2028. Which of those dates is yours, or whether either applies at all, depends entirely on classification, and our AI Act risk classifier walks through the Annex III and Annex I tests in a few minutes.

The delay has a cause worth knowing, because it explains why the extra time is less generous than it looks. The Commission set itself a 2 February 2026 deadline to publish classification guidelines under Article 6, missed it, and released draft high-risk guidelines on 19 May 2026, with the consultation running to 23 July 2026 and final guidance expected by the end of the year. The postponement exists because the interpretive machinery companies need to comply was not ready. Our read is that the sixteen months are for the standards bodies as much as for you, and waiting for the final guidelines to start classification spends the buffer on the wrong side of the desk.

The Omnibus also redraws the edges of the high-risk regime. Products under the Machinery Regulation are exempted from direct application of the AI Act. And the SME relief provisions extend to the new small mid-cap category. Under the Commission definition that covers companies with fewer than 750 employees and either annual turnover up to €150 million or a balance sheet total up to €129 million, around 38,000 companies EU-wide. Parliament and the Council have provisionally agreed to raise those thresholds to 1,000 employees and €200 million turnover or €172 million balance sheet total in the separate small mid-cap legislation, but that agreement is not yet formally adopted. If your organisation sits anywhere near either set of numbers, the category is worth a check before you budget for full-regime compliance.

Who Needs to Comply With the EU AI Act?

The Act binds providers, deployers, importers, distributors, product manufacturers and authorised representatives, together called operators, including those outside the EU where the system’s output is used in the EU. Scope is the question to settle before any deadline matters, because Article 2 carves out more than the enforcement headlines suggest.

Explicitly outside the Act sit systems used exclusively for military, defence or national security purposes (Article 2(3)), activity limited to scientific research and development (Article 2(6)), pre-market research and testing, though testing in real world conditions stays inside the Act (Article 2(8)), and personal, non-professional use by individuals (Article 2(10)). Free and open-source systems are exempt under Article 2(12) unless they are high-risk or fall under Article 5 or Article 50, an exception large enough that open-source is not the escape route it is sometimes sold as. The Act follows the product-regulation model and creates only limited individual rights, a complaint right under Article 85 and a right to an explanation of individual decision-making under Article 86, and it leaves the GDPR fully intact per Article 2(7). AI models that are not general-purpose, which includes many classical machine learning models, carry no model-level obligations of their own.

Fines Reach €35 Million and Have Applied Since 2 August 2025

Breaching an Article 5 prohibition carries fines of up to €35 million or 7% of total worldwide annual turnover, whichever is higher, per Article 99(3), and the penalty chapter has applied since 2 August 2025 with one carve-out. Article 113(b) holds back the GPAI fining power in Article 101 until 2 August 2026, so the enforcement plumbing predates every deadline the delay coverage discusses except the one aimed at model providers.

The remaining tiers cover most of the compliance programme. Breaches of the main operator obligations, including provider duties under Article 16, deployer duties under Article 26 and the Article 50 transparency rules, run to €15 million or 3% per Article 99(4). Supplying incorrect or misleading information to authorities runs to €7.5 million or 1% per Article 99(5). GPAI providers sit under a separate regime in Article 101, capped at €15 million or 3% and applicable from 2 August 2026. One figure still circulating in older summaries, a 7% tier quoted as 6%, comes from a draft-era text and does not match the adopted Act. And Article 99(6) reverses the usual logic for SMEs and start-ups, for whom the lower of the two amounts applies, not the higher. The full tier structure, with who fines whom and under which national arrangements, is in our AI Act fines guide.

Classification Is Work You Can Finish Before the Official Journal Lands

The single decision that sets your deadline is classification, and nothing about it depends on when the Omnibus is published. An inventory of each AI system your organisation builds, deploys or procures, mapped against Annex III and Annex I, tells you whether your date is 2 December 2027, 2 August 2028, or neither, and it is work the draft guidelines already support.

The rest of the sequence follows from the table above. Anything with transparency touchpoints, chatbots, synthetic content, emotion recognition, needs its Article 50 work finished by 2 August 2026, with machine-readable marking for pre-existing systems by 2 December 2026. Providers of GPAI models placed on the market before 2 August 2025 hold a 2 August 2027 date under Article 111(3). Organisations under 750 employees with turnover below €150 million fit the current small mid-cap definition, and the provisionally agreed rise to 1,000 employees and €200 million would widen it further, so the thresholds belong in the scoping file before the budget is set. Then one calendar entry. When the Official Journal publication lands, expected by 30 July 2026, the pending rows in the table become binding three days later, and that is the moment to re-verify, not before.

RegDossier

Making EU compliance almost enjoyable. Almost.

EU regulatory updates in your inbox every two weeks. Free.

Get the next briefing

Similar Posts