The EU AI Act’s high-risk deadline moved. Its transparency deadline did not. If you read a headline about the EU AI Act being delayed and eased off your compliance program, you are three days late on a set of obligations that carry penalties of up to 15 million euros or 3% of global turnover.
Here is the precise split. The Digital Omnibus — Regulation (EU) 2026/1744, published in the Official Journal on July 24, 2026 and in force since July 27 — pushed high-risk AI obligations under Article 6(2) and Annex III from August 2, 2026 to December 2, 2027. For AI embedded in products already regulated by EU product-safety law — medical devices, machinery, toys — the new date is August 2, 2028. That is genuine relief, and it is narrow.
What did not move: Article 50 transparency obligations and the Commission’s general-purpose-AI enforcement powers took effect on schedule, August 2, 2026. They have been live since Sunday.
What our earlier coverage got right, and what changed
In April we published our prior coverage of the EU AI Act’s August deadline, which told readers that August 2, 2026 was the hard date for high-risk system compliance and cited penalties up to 35 million euros for prohibited practices. The classification framework, the risk categories, and the extraterritorial reach in that post all still hold. The prohibited-practice bans have been enforceable since February 2025 and were never in scope for delay.
What changed is the timing of the high-risk regime — the conformity assessments, the technical documentation, the EU database registration. If your compliance plan was built around an August 2, 2026 high-risk cutoff, you now have until December 2, 2027, or August 2, 2028 for embedded-product AI.
That is the correction. The rest of this post is about the mistake the correction invites.
Why did Brussels delay the high-risk rules?
The technical standards were not ready. CEN and CENELEC had not finalized the harmonized standards that translate the Act’s requirements into testable criteria, and most member states had not stood up functioning enforcement authorities. Regulating against unfinished instructions produces inconsistent enforcement, so the Commission bought sixteen months. Orrick, Gibson Dunn, Freshfields, National Law Review, and Digital Applied all reached the same reading in late July: the extension is about implementation readiness, not a retreat from the Act.
That distinction matters because it tells you what will not be delayed again. Transparency obligations need no harmonized standard — the requirement is that people know they are dealing with AI. There is nothing for a standards body to specify, so there was nothing to wait for.
The three exposures that went live August 2
Conversational agents. If a customer-facing chatbot, voice agent, or phone assistant interacts with anyone in the EU, that person must be informed they are interacting with an AI system. Not buried in a terms-of-service page — disclosed at the point of interaction, in a way a reasonable person notices. This is the single most common exposure, because nearly every business that deployed an agent in the last two years deployed a customer-facing one.
Synthetic media. AI-generated or AI-manipulated image, audio, and video content must be marked as artificially generated. Marketing teams producing synthetic product imagery, AI voiceovers, or generated video are inside this obligation today, and marketing is typically the function furthest from the compliance team.
AI-generated text on matters of public interest. Published text about public-interest topics must be disclosed as AI-generated unless it has undergone human review with an identified person or organization taking editorial responsibility. Content operations running AI-drafted articles without a named human editor are exposed.
Add the GPAI dimension: the Commission’s enforcement powers over general-purpose AI models are now active, which pushes obligations down the supply chain toward the businesses building on top of foundation models.
What should a business do this week?
Inventory every AI system that touches an EU user, confirm each one discloses its nature at the point of interaction, and assign a named owner to the December 2, 2027 high-risk track. Transparency compliance is usually a matter of interface copy and content policy — days of work, not quarters. The high-risk work is a program. Treat them as separate efforts with separate deadlines, because they are.
The inventory is the part most businesses skip, and it is the part that determines whether the rest is possible. You cannot disclose what you do not know you operate. Shadow deployments — the marketing team’s content generator, the support team’s trial chatbot, the sales team’s outbound voice agent — are precisely the systems nobody registered and nobody is monitoring. The governance structures that make AI agents auditable exist for this reason, and an August 2026 deadline is an unusually good excuse to build them.
The real risk is standing down
Two failure modes are available right now, and the second is more likely than the first.
The first is over-compliance: pouring resources into high-risk conformity work on an obsolete timeline while easier obligations go unmet. Wasteful, but not dangerous.
The second is the one the headlines are manufacturing. “EU AI Act delayed” reads as permission to disband the working group, defer the budget, and revisit in 2027. Businesses that do this will be non-compliant on transparency — the cheapest, most visible, most easily audited obligation in the entire Act. A regulator does not need a technical audit to find a chatbot that fails to identify itself. They need a browser.
There is also a compounding cost. Sixteen extra months sounds generous until you remember what high-risk compliance requires: documented data governance, meaningful human oversight, continuous monitoring, defensible conformity assessment. Organizations that let the program go cold in August 2026 will restart it in mid-2027 with the same amount of work and less time. The same discipline that carries an AI pilot into reliable production is what carries a compliance program across a moved deadline — steady operational ownership, not deadline-driven sprints.
The bottom line
The delay is real, narrow, and specific: high-risk obligations move to December 2, 2027, or August 2, 2028 for embedded-product AI. Everything else runs on the original schedule, and transparency duties plus GPAI enforcement have been live since August 2, 2026. Penalties for what remains enforceable are up to 15 million euros or 3% of global annual turnover.
The businesses in trouble twelve months from now will not be the ones that misread the high-risk deadline. They will be the ones that heard “delayed” and stopped reading.
If you are running AI agents into EU markets and want a clear-eyed read on which obligations bind you today versus which ones you have until 2027 to satisfy, that separation is exactly the kind of audit we run.