If your board had 2 August 2026 circled in red, you can rub it out. The Digital Omnibus on AI was published in the Official Journal on 24 July 2026 and entered into force on 27 July. The high-risk deadline everyone was racing towards has moved.
That is genuinely good news. It is also where a number of organisations are about to make an expensive mistake, because three sets of obligations did not move at all — and one of them started this month.
What moved
- Standalone high-risk systems (Annex III) — the ones that make decisions about people: recruitment, credit, education, essential services, law enforcement. From 2 August 2026 to 2 December 2027.
- High-risk AI embedded in regulated products (Annex I) — machinery, medical devices, vehicles, lifts. From 2 August 2027 to 2 August 2028.
Deferred, not deleted. The obligations themselves are unchanged: risk management, data governance, technical documentation, logging, human oversight, accuracy and robustness. Only the date by which you have to be able to show them has moved.
What did not move
Prohibited practices. In force since 2 February 2025. Social scoring, exploitative manipulation, certain biometric categorisation and untargeted scraping for facial recognition databases are not future requirements. They are already unlawful.
AI literacy. Also in force since 2 February 2025, and the most widely overlooked line in the whole Act. Providers and deployers must take measures so that the people operating their AI systems actually understand them. Not a policy on a shelf — the people using the tool.
Transparency, Article 50. In force from 2 August 2026. This month. If a person is interacting with an AI system, they have to be told. If content is artificially generated or manipulated, it has to be marked in a machine-readable way.
That last one is the quiet story of this summer, because it is the obligation most likely to land on a company that does not think of itself as an AI company at all. It catches the support chatbot on the website, the AI-drafted copy in the newsletter, and the synthetic voice in the call centre.
The trap inside the good news
Most organisations start compliance work when a date forces them to. Move the date, and the work stops. Sixteen months feels like plenty, right up to the moment somebody asks for a system inventory and discovers nobody has ever made one.
The slow parts of this are not legal. They are organisational: finding every AI system already in use, including the ones bought on a departmental card; deciding who owns each one; agreeing who is competent to overrule it. That work does not compress. It is the same work in December 2027 as it is today, except that in December 2027 it will be done in a hurry.
What sixteen months is actually worth
- An inventory that is real. Every AI system in use, who owns it, what it decides, and whether a person can overrule it.
- A classification you could defend. High-risk, limited-risk or minimal-risk, with the reasoning written down and a named person behind it.
- Human oversight that exists in practice. Not a clause — a named role, with the authority and the information to intervene.
- Records that already exist when they are asked for. Logs, decisions, versions, and the reasons behind them.
- Supplier terms that carry the obligation. Buying an AI system from a vendor does not move your duty to the vendor.
The question to ask on Monday
Not “are we compliant?” — that question has no useful answer this far out. Ask instead: which of our systems would we have to classify, and who here would put their name to that classification?
If the room goes quiet, that is your finding. It is also the cheapest one you will ever get, because you now have until December 2027 to act on it rather than until next week.