Compliance
The EU AI Act in 2026: What Actually Applies Now, After the Digital Omnibus
The AI Act's most demanding obligations, for high-risk systems, were due on 2 August 2026. Regulation (EU) 2026/1744 pushed them back to December 2027 and August 2028. Transparency duties did not move. Here is what is actually binding today.
Regulation (EU) 2024/1689, the EU AI Act, entered into force on 1 August 2024. It applies in stages. Prohibited practices and AI literacy duties took effect on 2 February 2025. Obligations on general-purpose AI models, governance structures and penalties took effect on 2 August 2025.
The next milestone, the obligations for high-risk AI systems under Chapter III of the regulation, was due on 2 August 2026. It did not happen on that date. On 24 July 2026, the Digital Omnibus on AI, Regulation (EU) 2026/1744, was published in the Official Journal and entered into force three days later, six days before the original deadline.
What moved, and what did not
The omnibus defers the high-risk obligations in two steps. Standalone high-risk systems listed in Annex III, covering uses such as recruitment, workers' management, creditworthiness assessment, biometrics and education, now fall under Chapter III from 2 December 2027 instead of 2 August 2026. High-risk systems embedded in regulated products under Annex I, such as medical devices or machinery, move to 2 August 2028.
- Prohibited practices under Article 5, in force since 2 February 2025, unchanged.
- General-purpose AI model obligations, transparency documentation and systemic risk assessment for the largest models, in force since 2 August 2025, unchanged.
- Article 50 transparency duties, disclosing AI interaction and marking synthetic content, applied as scheduled on 2 August 2026 and were not deferred.
- A new prohibition on AI tools generating non-consensual intimate imagery or child sexual abuse material, added by the same omnibus, applies from 2 December 2026.
Why the delay does not mean the absence of exposure
A deferred obligation is not a cancelled one. Organisations placing an AI system on the EU market, wherever they are established, including Swiss and other non-EU providers, remain bound by the obligations already in force: banned practices, transparency toward users interacting with an AI system, and, for providers of general-purpose models, documentation and risk assessment. The eighteen extra months granted for high-risk systems are preparation time, not exemption time.
1 août 2024
entry into force of the EU AI Act
2 déc. 2027
new date for Annex III high-risk obligations
2 août 2028
new date for Annex I product-integrated high-risk obligations
2 août 2026
Article 50 transparency duties, unchanged, already applicable
The classification question every organisation using AI still has to answer
Regardless of the calendar, the AI Act requires every provider or deployer to classify each AI system it builds or uses: prohibited, high-risk, limited-risk with transparency duties, or minimal-risk. That classification exercise, and the evidence behind it, is what a buyer, an insurer or an investor will ask for well before December 2027. The postponement moved the compliance deadline. It did not move the due diligence one.
“The organisations that already know which of their AI systems is high-risk, and why, are not the ones the omnibus was written to protect.”
— Aegryn
Aegryn Advisory supports organisations in classifying their AI systems under the EU AI Act, documenting governance and risk assessment, and certifies the outcome under the CIFSO Security & Sovereignty dimension, ahead of the moment a buyer, insurer or regulator asks for proof.
This article was written with the assistance of artificial intelligence and reviewed under Aegryn editorial responsibility. In accordance with Article 50 of the EU AI Act, we assume editorial responsibility for this content.
Insights Aegryn
Recevez chaque semaine les analyses Aegryn — M&A, valorisation, tech, CIFSO.
Ready to submit your asset or access the catalogue?
