Few pieces of legislation have caused as much confusion in recent months as the AI Act. The reason is simple: six days before the big deadline, the EU postponed the most important obligations — but not all of them. Anyone who read the news only halfway either believes nothing applies now, or is preparing for requirements that still have eighteen months to run. Both lead to wrong decisions.
What has applied since 2 August 2026
The transparency obligations under Article 50 of Regulation (EU) 2024/1689 are in force, with no transition period. Anyone operating an AI system that people interact with directly must disclose it. In practice: a chatbot in customer service, a voice agent on the hotline, an AI-supported assistant in a recruitment process — in every case the person at the other end must be able to tell that no human is answering.
Also in force are the rules for providers of general-purpose AI models and the list of prohibited practices. And the enforcement machinery is in place: breaches of the transparency rules carry substantial fines.
What the Digital Omnibus postponed
Die Amending Regulation (EU) 2026/1744 of 8 July 2026 postpones the full high-risk obligations: standalone high-risk systems under Annex III — AI in recruitment, credit decisions or critical infrastructure, for example — need to be fully compliant only by 2 December 2027. For AI embedded in regulated products the date is 2 August 2028.
The postponement was not a political retreat but a concrete implementation problem: the harmonised technical standards and the conformity assessment infrastructure were simply not ready in time. Companies would have been obliged to comply with something nobody could have assessed.
Why “postponed” does not mean “done”
In the conversations I have had since July, one sentence comes up again and again: “Then we will pick it up in the next planning cycle.” That is risky for two reasons.
First: the work to be done between now and December 2027 is not documentation. It is finding out which AI systems are running in the organisation at all. In most organisations I see, that list does not exist — not because nobody wanted to keep one, but because AI has long been bought by business units rather than by IT. A reliable inventory takes months, not weeks.
Second: risk classification is the precondition for everything else. Only once it is settled whether a system falls under Annex III at all can you say which deadline applies. Many companies are not affected — but do not know it, and tie up capacity in preparations they do not need. Others are affected and have no idea.
The three questions that come before compliance
Before any governance document is written, a management board should be able to answer three questions:
- Which AI systems are running here — including the ones nobody ordered? Including the tools employees use on their own initiative.
- Which risk class does each of them fall into? Without that classification, every deadline is just a number in the calendar.
- Who decides when it is contested? Governance fails less often for lack of rules than for lack of accountability.
What I recommend to leadership teams
The postponement is a gift to everyone who uses it as preparation time — and a trap for everyone who books it as a reprieve. The difference will not show in 2027 but already now: whoever starts the AI inventory gains something on the side that has nothing to do with compliance. Namely clarity about where value is actually created in the organisation — and where tools have merely been licensed.
That is exactly the point at which regulation stops being a nuisance and starts being useful.
Sources
- Regulation (EU) 2024/1689 — AI Act, version of 13 June 2024, EUR-Lex
- Regulation (EU) 2026/1744 — amending regulation of 8 July 2026, EUR-Lex
This article offers a professional assessment and does not replace legal advice. The EU AI Act is an evolving regulation; the publications of the European Commission and the competent national authority are authoritative.