The EU AI Act timetable after the Digital Omnibus: what actually applies, and when

  • August 5, 2026

In July 2026 the European Union rewrote the AI Act’s compliance calendar, and most organisations drew the wrong conclusion from it. The Digital Omnibus on AI - Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force from 27 July 2026 - deferred the Act’s Annex III high-risk obligations by sixteen months. It did not defer everything. The transparency duties many compliance calendars had quietly deprioritised took effect on 2 August 2026, exactly as originally scheduled.

The result is that many AI compliance plans are now wrong in both directions at once: relaxed about duties that have already landed, and braced for obligations that have moved. Here is the corrected picture.

What the Digital Omnibus changed

Two deferrals matter most. The high-risk obligations for standalone systems under Annex III - the categories covering areas such as employment, credit, essential services and law enforcement - moved from 2 August 2026 to 2 December 2027. Obligations for AI embedded in products already regulated under Annex I sectoral legislation moved from 2 August 2027 to 2 August 2028. Both are unconditional calendar dates. The Commission’s November 2025 proposal would have tied them to the readiness of supporting standards; the adopted text dropped that mechanism, and commentary written against the earlier draft is still in circulation.

What did not move is just as important. The Act’s general application date of 2 August 2026 stood, and with it the Article 50 transparency duties: informing people when they interact with an AI system, labelling deepfakes, disclosing AI-generated text published to inform the public, and marking synthetic content. One narrow concession applies. The machine-readable marking duty in Article 50(2) has a transition to 2 December 2026 - but only for generative systems already placed on the market before 2 August 2026. It does not cover systems placed on the market since that date, and it does not touch the deployer duties in Article 50(4). Separately, the Article 4 AI literacy duty was amended rather than deferred: it is now a duty to take measures supporting the development of AI literacy rather than to guarantee a level of it, and it has applied in that form since 27 July 2026.

The corrected timetable at a glance

DATE

STATUS

WHAT IT COVERS

2 Aug 2026

Already in force

General application of the Act, including the Article 50 transparency duties - AI interaction disclosure and content marking.

2 Dec 2026

Transition ends, new bans start

Article 50(2) content-marking transition closes for systems already on the market. Two new Article 5 prohibitions also take effect: AI-generated non-consensual intimate imagery and child sexual abuse material.

2 Dec 2027

Deferred deadline

High-risk obligations for standalone Annex III systems - the deadline most programmes were originally built around.

2 Aug 2028

Final stage

Obligations for AI embedded in products regulated under Annex I.

 

What is already live: the Article 50 reality check

If your organisation runs customer-facing chatbots or assistants, generates content that reaches the public, or deploys AI that interacts with people in ways they might not recognise as AI, transparency duties apply to you now. The practical questions are simple to ask and surprisingly hard to answer: which of your systems are in scope, is disclosure consistent across every journey, and could you evidence compliance if a regulator, journalist or complainant asked this month?

The uncomfortable prerequisite hiding inside those questions: you cannot evidence transparency across systems you have not inventoried. Most organisations discover, on inspection, that their list of customer-facing AI is incomplete - which turns a disclosure exercise into a discovery exercise first.

What the deferral does not mean

Sixteen months is a window, not a reprieve. Three reasons not to bank the delay: first, high-risk obligations are demanding - risk management systems, data governance, technical documentation, human oversight, logging - and they rest on foundations that take time to build, starting with a trustworthy inventory. Second, the EU calendar is not the only one moving; US state legislation continues to arrive, and sectoral regulators and insurers are already asking for AI inventories without waiting for Brussels. Third, organisations that used the original deadline to win internal urgency now face a harder budget conversation - the programmes that survive the deferral are the ones that convert “compliance deadline” into “governance capability” while the window is open.

Done in order - inventory, ownership, lifecycle, evidence - the window is comfortably enough time to build AI governance properly, once. It is not enough time to do it twice. One date in the adopted text is easy to miss: high-risk systems already in use by a public authority must be brought into compliance by 2 August 2030 regardless of when they were placed on the market.

A pragmatic sequence for the window

  • Now: establish the register. Discover what AI actually runs - models, agents, datasets, prompts, MCP servers - and reconcile it with the services it supports. Every later obligation consumes this inventory.
  • Now: sweep customer-facing AI for Article 50 exposure and standardise disclosure - this duty is live, and the transition for in-market content marking closes in December 2026.
  • Next: assign owners and risk-classify priority assets against the Act’s categories, so the systems heading for Annex III obligations are identified two years before the deadline, not two months.
  • Then: build the evidence habit - approvals, classifications and controls generated as live records, so December 2027 is a report, not a fire drill.

Frequently asked questions

Did the Digital Omnibus delay the whole EU AI Act?

No. It deferred the high-risk obligations (Annex III to December 2027; Annex I-embedded to August 2028). General application and the Article 50 transparency duties took effect on 2 August 2026 as scheduled. Note also that Regulation (EU) 2026/1744 is the AI file only. The wider Digital Omnibus covering GDPR, ePrivacy and the Data Act is a separate piece of legislation still in negotiation, and conflating the two is the most common error in circulation.

We are a UK business - does any of this apply to us?

The Act has extraterritorial reach: it can apply where AI systems are placed on the EU market or their outputs are used in the EU. Many UK enterprises are in scope for parts of their estate, and UK sectoral regulators are asking parallel questions on their own timetables. Scope analysis is worth doing properly - this article is general information, not legal advice.

What should we do first?

Inventory. Every obligation - transparency, high-risk, documentation - presupposes you know what AI you run. If your inventory is a spreadsheet, start there; the gap between the spreadsheet and the discoverable truth is usually the first material finding.

Building that inventory as a live, owned, evidenced record rather than a spreadsheet is exactly what ServiceNow AI Control Tower is for, and it is where we now spend most of our time with clients. 

How do we find out how exposed we are?

Kaptius runs a free half-day Pre-Flight Check: a structured assessment of your AI estate including your regulatory position, producing a one-page heat map and the five exposures that should worry you.

Disclaimer: Date-sensitive content. Last verified 5 August 2026 against Regulation (EU) 2026/1744 (Official Journal, 24 July 2026). Verify every date against the Official Journal / official Commission sources at publication and on a quarterly refresh cycle. This article is general information, not legal advice.

-------------------------------------------------------------------------------------------------------------------------------

Kaptius helps enterprises turn AI governance from a compliance scramble into an operating capability, on ServiceNow AI Control Tower. Start with a Pre-Flight Check - half a day, no fee, one page of findings - or read our guide to the six-week AI register. 

Curated Reads

Understanding-TPSM-The-Future-Of-Tech-Service-Management
Understanding TPSM: The Future Of Tech Service Management
Technology Provider Service Management (TPSM) is a strategic solution that integrates customer care and operations teams. It focuses on streamlining service delivery and, hence, enabling technology providers to deliver exceptional customer experiences. Here is a brief guide to what you need to know about it.

 

A Paradigm Shift Scaling Your Tech Business With ServiceNow TPSM
A Paradigm Shift: Scaling Your Tech Business With ServiceNow TPSM
Modern businesses need to focus on agility. This is especially true of tech businesses as these operate in a particularly fast-moving environment. Scalability is a key part of agility. Here is a quick guide to how ServiceNow's Technology Provider Service Management solution (TPSM) can help make it easier to scale your business.

 

Streamlining-Service-Management-Delivery-With-ServiceNow-TPSM
Streamlining Service Management & Delivery With ServiceNow TPSM
ServiceNow's Technology Provider Service Management (TPSM) is a solution designed to facilitate effective service delivery and management in the technology sector.  It hosts a range of specialised tools and features that address common pain points they face.  Here is a brief guide to how implementing TPSM can help you and your business.