LinkedInInstagramXTikTok

The EU AI Act’s new timeline: what your business needs to know

Why the new AI Act timeline affects more businesses than many think

On 29 June 2026, the Council of the EU gave its final approval to the simplification package for the AI Act (Regulation (EU) 2024/1689), known as the Digital Omnibus on AI, following the European Parliament’s endorsement on 16 June. The package postpones several of the most demanding obligations for high-risk AI systems by up to two years. Many companies conclude that the entire regulation is now on hold, but that is not the case.

Important obligations still take effect on 2 August 2026, and the package introduces an entirely new prohibition. This article explains what is postponed, what continues to apply and how your business should act now.

What is the Digital Omnibus on AI?

The omnibus is an amending regulation that simplifies and defers parts of the AI Act. The background is that several of the technical standards and guidance documents companies need in order to meet the high-risk requirements are not yet in place. The act will be published in the Official Journal of the EU shortly and enters into force on the third day after publication. Until then, the exact dates should be treated as provisional.

Which obligations are postponed?

Stand-alone high-risk systems (Annex III)

The obligations for stand-alone high-risk systems, such as AI used in recruitment, credit scoring, education, law enforcement and biometrics, were originally due to apply from 2 August 2026. That date now moves to 2 December 2027. For most providers and deployers of such systems, this means roughly sixteen months of additional preparation time.

AI embedded in regulated products (Annex I)

For AI systems embedded in products already covered by EU product legislation, such as medical devices and machinery, the application date moves to 2 August 2028. The Member States’ obligation to establish national regulatory sandboxes is also deferred, to 2 August 2027.

What still applies from 2 August 2026?

The transparency obligations in Article 50 are not affected by the postponement. From 2 August 2026, companies must inform users when they are interacting with an AI system, such as a chatbot, and AI-generated content such as text, images, audio and video must be labelled. Generative AI systems already on the market before that date do, however, get a transitional period until 2 December 2026 to meet the machine-readable marking requirement.

The regulation’s penalty provisions also become operative on the same date. Breaches of the transparency obligations can result in fines of up to 15 million euros or three percent of global annual turnover. In addition, the Commission’s AI Office gains its enforcement powers over providers of general-purpose AI models from that date.

A new prohibition: non-consensual intimate imagery

The omnibus also introduces a new prohibition on AI systems designed to generate non-consensual intimate imagery or child sexual abuse material. The ban covers both providers placing such systems on the EU market and deployers using them for those purposes, with a transitional period until 2 December 2026. Companies offering image-generating AI should already be analysing whether their services could be misused in this way and what safeguards are required.

Practical example: a recruitment tool

A Swedish SaaS company offers an AI tool that ranks candidates in recruitment processes. The tool is a stand-alone high-risk system under Annex III, so the full high-risk requirements (risk management, data governance, technical documentation and CE marking) apply only from 2 December 2027. But if the tool also includes a chatbot that communicates with candidates, the company must inform candidates that they are interacting with AI from 2 August 2026. The same company would be wise to use the extra time to build the high-risk requirements into its product development rather than deferring everything to the last minute.

Common mistakes companies make

Many companies read the postponement as a signal that the AI Act is no longer urgent and pause their compliance work entirely. That is risky, because the transparency obligations and the penalties apply from August 2026. Another common mistake is mixing up the different dates: the deferral to December 2027 applies to stand-alone high-risk systems, not to AI embedded in regulated products, which instead has until August 2028. Finally, many overlook that the regulation’s prohibitions, including the new ban on non-consensual intimate imagery, sit outside the postponement.

Recommended actions

Start by mapping which AI systems your business provides or uses and classify them under the regulation’s risk categories. Then identify which obligations apply from 2 August 2026 and which are deferred, and make sure chatbots and AI-generated content meet the transparency requirements in time. Carry out a gap analysis against the new prohibition on non-consensual intimate imagery before December 2026. Use the extended deadline for high-risk systems to integrate the requirements into product development, and document the work as you go. Finally, monitor the publication in the Official Journal to confirm the final dates.

Frequently asked questions

Is the entire AI Act postponed?

No. The postponement mainly concerns the high-risk requirements for stand-alone systems in Annex III and AI embedded in regulated products under Annex I. The prohibitions, the AI literacy rules, the Article 50 transparency obligations and the rules for general-purpose AI models follow the original timeline.

What happens if we do not label AI-generated content after 2 August 2026?

Breaches of the transparency obligations can lead to fines of up to 15 million euros or three percent of global annual turnover, whichever is higher. Generative systems already on the market do, however, have until 2 December 2026 to meet the machine-readable marking requirement.

Are the new dates final?

The act has been adopted by both Parliament and Council but not yet published in the Official Journal of the EU. The dates should therefore be treated as provisional until the official text is available, although no substantive changes are expected.

Conclusion

The Digital Omnibus gives companies with high-risk systems valuable extra time, but it is not a pause of the AI Act as a whole. The transparency obligations, the penalties and the Commission’s oversight of general-purpose AI models apply from 2 August 2026, and the new prohibition on non-consensual intimate imagery requires action before December 2026. Businesses that map their systems, separate deferred from applicable obligations and use the extra time wisely reduce both the legal risk and the cost of late adjustments. At Lawgent, we help companies navigate the AI Act, from risk classification and gap analyses to documentation and internal procedures. Get in touch if you want to know what the new dates mean for your business.

Leave a Reply

Your email address will not be published. Required fields are marked *


0Cart0,00 

No products in the cart.

Return to shop