Skip to main content
Straife
Abstract network of connected nodes

Deferred, Not Cancelled: What August 2 Still Requires Under the EU AI Act

Straife

Liliana Bakayoko

August 5, 2026

Regulation (EU) 2026/1744 — the Digital Omnibus on AI — was published in the Official Journal on July 24, 2026 and entered into force on July 27, six days before the AI Act's original high-risk compliance deadline.

The headline is a deferral. Obligations for standalone high-risk AI systems under Annex III move from August 2, 2026 to December 2, 2027. Obligations for AI embedded in products already covered by EU product-safety law under Annex I move to August 2, 2028.

The headline is also the least useful part of the regulation, because August 2, 2026 was not cancelled. It arrived, and it switched things on.

What Took Effect on August 2

The Article 50 transparency obligations applied in full from the original date and were not deferred. In practical terms that means four things became legally required this month for systems placed on the EU market:

Disclosure that a user is interacting with an AI system rather than a person, where that would not otherwise be obvious. Marking of synthetic content — audio, image, video, and text generated or manipulated by AI — in a machine-readable format. Notification to individuals subject to emotion recognition or biometric categorisation systems. And labelling of deep fakes, with disclosure that the content has been artificially generated or manipulated.

The Omnibus provides one accommodation: systems already on the market before August 2 have a four-month transitional period, until December 2, 2026, to implement machine-readable watermarking for AI-generated content.

The general-purpose AI obligations that took effect in 2025 remain in force. The Article 5 prohibitions on unacceptable-risk practices remain in force. Nothing about the deferral touches either.

The Deferral Trap

The predictable organisational response to a fifteen-month extension is to stand down the high-risk readiness programme and redeploy the people. This is a mistake with a specific, foreseeable failure mode.

High-risk conformity work is not linear. It requires a complete inventory of AI systems and their classification, a quality management system, technical documentation, data governance and training-data provenance records, human oversight design, accuracy and robustness testing, post-market monitoring, and — for many Annex III systems — engagement with a notified body whose capacity is finite.

That last constraint is the one that bites. If a substantial share of the affected population pauses now and restarts in mid-2027, they will converge on the same conformity assessment infrastructure at the same moment, and the queue will not clear before December 2027. The organisations that stay in motion will be assessed. The ones that paused will be explaining themselves.

There is also a documentation problem that worsens with delay. Training-data provenance, design rationale, and testing records are far easier to assemble while the people who built the system are still available and still remember. Reconstructing them eighteen months later is materially harder and produces weaker evidence.

A Revised Compliance Calendar

  • Now: Confirm Article 50 compliance for every deployed system — chatbot disclosure, synthetic content marking, emotion recognition notices, deep fake labelling. This is a present legal obligation, not a future one.
  • By December 2, 2026: Complete machine-readable watermarking for pre-existing systems relying on the transitional period.
  • Through 2026: Finish the AI system inventory and Annex III classification. Most organisations still cannot produce a defensible list of the AI systems in use across the business, including those embedded in vendor products.
  • 2027: Complete quality management system build-out, technical documentation, and conformity assessment engagement for Annex III systems, working backward from December 2, 2027 rather than forward from today.
  • Continuous: Renegotiate vendor contracts to allocate AI Act obligations explicitly. Deployers carry duties they cannot discharge without provider cooperation, and standard commercial terms do not currently provide it.

The Bigger Picture

It is tempting to read the Omnibus as evidence that Europe is retreating from AI regulation under competitiveness pressure. The text does not support that reading.

The prohibitions stand. The transparency regime is now live. The general-purpose AI obligations are in force. The high-risk framework is intact and has moved by fifteen months, not been withdrawn. What changed is the timetable, and it changed because the supporting infrastructure — harmonised standards, notified body capacity, national supervisory authorities — was not ready to carry the original one.

That distinction has a practical consequence. A deferral driven by implementation capacity rather than political reversal is unlikely to repeat, because the reasons for it are being actively addressed. Organisations planning on a second extension are betting against the direction of the file.