CustomLabs
Insights

What Actually Moved in the EU AI Act's 2026 Deadline Change

On 24 July 2026, the EU published Regulation (EU) 2026/1744, the “Digital Omnibus on AI,” amending the AI Act (Regulation (EU) 2024/1689). It entered into force three days later, on 27 July 2026. The headline read almost everywhere was “the AI Act got delayed.” That’s true for one specific set of obligations and false for most of the rest, and the difference matters if you’re deciding what to build first.

This is a factual summary of one regulation’s changes, not legal advice. If a specific deadline changes what your organization has to do, that’s a question for counsel, not for a consultancy’s insight page.

On sourcing, since this page is asking you to trust some dates: the pre-amendment text of Article 113 quoted below comes from the Commission’s own AI Act Service Desk. The amended dates were each checked across several independent summaries, which agreed on all of them. Where those summaries disagreed, as they did on the original Annex I date, the parent act’s own text settled it. The EUR-Lex link at the foot is the authoritative version, and it’s there so you can check this against it rather than take our word for it.

What moved

Chapter III, Sections 1 to 3 of the AI Act cover the core high-risk obligations: conformity assessment, technical documentation, risk management, human oversightHuman oversight is a checkpoint where a person can meaningfully approve, reject, or intervene. design, and the rest of the compliance package a high-risk AI systemA high-risk AI system is one classified as carrying enough decision impact to trigger heavier compliance. has to carry. Article 113, as amended, now sets two different dates for two different kinds of high-risk system:

  • 2 December 2027 for AI systems classified as high-risk under Article 6(2) and Annex III — the stand-alone category covering things like biometrics, critical infrastructure, employment screening, and credit scoring.
  • 2 August 2028 for AI systems classified as high-risk under Article 6(1) and Annex I — systems embedded in products already covered by other EU product-safety law, like machinery or medical devices.

The two legs never shared a start date, and the two deferrals aren’t the same size. Annex III sat on the Act’s general application date of 2 August 2026, so it moved by roughly sixteen months. Annex I already had a later date of its own. Point (c) of the original Article 113 reads:

Article 6(1) and the corresponding obligations in this Regulation shall apply from 2 August 2027.

So the embedded leg moved by twelve months, and it keeps the one-year lead over Annex III that it always had. Plenty of summaries are getting this wrong in one direction or the other, usually by asserting both legs started on the same day. One provision rides along outside the deferral: Article 6(5), covering the Commission’s guidelines on how classification itself works, was carved out and kept on its own schedule.

The reason is practical rather than political: the harmonised standards, common specifications, and national conformity-assessment bodies these obligations depend on weren’t going to be ready in time, and forcing the original date would have meant applying a compliance regime the supporting infrastructure couldn’t yet support.

What didn’t move

Everything else that had already taken effect stayed in effect, and two dates that were still ahead stayed where they were.

  • The Article 5 prohibited-practices regime has applied since 2 February 2025, as part of Chapters I and II. That date is untouched. The Article 5 list actually grew: two new prohibitions, covering AI systems that generate non-consensual intimate imagery and AI-generated child sexual abuse material, were added and apply from 2 December 2026.
  • General-purpose-AI obligations have applied since 2 August 2025. Nothing in this amendment touches that provision.
  • The Article 50 transparency duties — labelling AI-generated content, disclosing AI involvement — still land on 2 August 2026 for new systems. What’s new is a grace period for systems already on the market before that date: providers get until 2 December 2026 to bring existing systems into compliance with Article 50(2), instead of needing to be ready on day one.
  • The AI-literacy duty in Article 4 kept its 2 February 2025 date too, though the obligation itself was softened elsewhere in the same regulation, from requiring providers and deployers to “ensure” AI literacy among their staff to requiring them to “take measures to support” it. Deployers are the larger group there, and the one most readers of this page will fall into.

So the practical shape is: the two deadlines that moved were already the latest and the most procedurally heavy in the Act. The ones already in force, and the one due in a few weeks, did not move at all.

The engineering read

None of this changes what’s worth building. A deferred deadline is a reason to sequence work differently, not a reason to skip it, because almost everything Chapter III eventually asks a high-risk system to produce is also what a customer’s procurement team, a diligence process, or your own incident response asks for on a much shorter clock than any regulator’s.

A system register with a named owner, a versioned release that ties prompt, model, index and tools together, a log that can reconstruct a specific past decision, and a system card procurement can read without you in the room: none of that depends on whether your system ends up classified as high-risk under Annex III, and all of it answers a question someone will ask well before December 2027. The six surfaces on the governance page are built from that list, not from the compliance deadline itself, which is why the deferral doesn’t change any of them.

If anything, the extra runway is useful for exactly one thing: building the register and the traceability discipline properly, on your own schedule, instead of assembling them under deadline pressure in late 2027 the way most of the industry will.

Sources

Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026, amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 (Digital Omnibus on AI), Official Journal of the European Union, L series, 24 July 2026. Read the primary text on EUR-Lex. Parent act: Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 (the AI Act). The pre-amendment text of Article 113 quoted above is as published on the European Commission’s AI Act Service Desk, which at the time of writing still carries the original wording.

Questions

FAQ#

Answers to the questions this piece raises.

01 Did the EU AI Act get delayed?

Part of it. Regulation (EU) 2026/1744 pushed the high-risk obligations in Chapter III, Sections 1 to 3, to 2 December 2027 for stand-alone high-risk systems and 2 August 2028 for systems embedded in other products. The Article 5 prohibitions, the transparency duties, and the general-purpose-AI obligations were not delayed.

Link to this answer: Did the EU AI Act get delayed?
02 Is my system still subject to the Article 5 prohibited-practices rules?

Yes, on the original schedule. Chapters I and II of the Act, which include Article 5, have applied since 2 February 2025 and that date did not move. Two new prohibitions were added on top, covering non-consensual intimate imagery and AI-generated child sexual abuse material, and those apply from 2 December 2026.

Link to this answer: Is my system still subject to the Article 5 prohibited-practices rules?
03 What happens to systems already on the market before the transparency deadline?

Regulation (EU) 2026/1744 added a grace period: providers of systems generating synthetic audio, image, video or text that were placed on the market before 2 August 2026 have until 2 December 2026 to bring labelling in line with Article 50(2). Systems placed on the market after 2 August 2026 don't get the grace period.

Link to this answer: What happens to systems already on the market before the transparency deadline?
04 Where can I read the actual text instead of a summary?

Regulation (EU) 2026/1744 is published in the Official Journal of the European Union, L series, 24 July 2026. The amendment to the high-risk timeline is in Article 113.

Link to this answer: Where can I read the actual text instead of a summary?
Related services
Readiness & Diligence
Related tools
AI Readiness Scorecard
The old deadline still pays off.

The register and the system card this deadline covers are worth building now, not in 2027. The scorecard shows what a diligence team could ask for tomorrow, before the new date arrives.

Written by

CustomLabs Engineering

Applied-AI engineering team

CustomLabs is a small, senior-only studio that embeds with client teams and ships eval-tested, model-agnostic AI systems into production in weeks, not quarters. Every insight reflects work and lessons from the studio's own engagements — the people who write the code write the words.

Source: https://customlabs.io/insights/ai-act-high-risk-deadline-moved/

navigate select esc close