Modulos Named in the Inaugural Gartner® Magic Quadrant™ for AI Governance PlatformsRead the

Press Release
Back to Blog
EU AI ActJuly 24, 2026

EU AI Act Omnibus Published: New Deadlines Are Now Law

Regulation (EU) 2026/1744 is in the Official Journal: the final EU AI Act calendar, what the adopted text settles, and the countdown to 2 December 2027.

By Modulos10 min read
EU AI Act Omnibus Published: New Deadlines Are Now Law

Share this article

The AI Act Omnibus Is Now Law: The Final Deadlines and What the Text Settles

The Digital Omnibus on AI appeared in the Official Journal of the European Union on 24 July 2026 as Regulation (EU) 2026/1744, and it enters into force on 27 July, on the third day after publication, a compressed timeline the regulation itself justifies "as a matter of urgency" because the general application date it amends falls on 2 August. That closes a question this blog has been tracking since January through a failed trilogue, a political deal on 7 May, a Parliament vote on 16 June and the Council's adoption on 29 June: whether the EU AI Act's deadlines would move, and where they would land. The answer now sits in the operative text of Article 113, carries a regulation number you can cite in a board paper, and omits the mechanism that could have moved the dates again. What remains is a compliance calendar, and it is shorter than the headline deferral makes it look.

The EU AI Act calendar, now law

Everything an enterprise needs to plan against fits in six dates. The first tier has been in force for some time: the original Article 5 prohibitions have applied since 2 February 2025, and the general-purpose AI rules in Chapter V since 2 August 2025, and the omnibus changed the substance of neither.

Chart of the final EU AI Act calendar with dates, obligations, and who it affects for GPAI and high-risk AI systems

Before the omnibus, Annex III high-risk obligations applied from 2 August 2026 and Annex I embedded systems followed from 2 August 2027. Under Regulation (EU) 2026/1744 those dates are 2 December 2027 and 2 August 2028. The transitional rules cut the other way for systems already in service: high-risk systems already on the market before the new application dates stay outside the obligations only until they undergo significant design changes, and any such pre-existing high-risk system used by a public authority must comply by 2 August 2030 regardless.

What the final text settles

Our June post flagged the open items that only the adopted text could close. The Official Journal text answers all of them, and two of the answers correct claims still circulating in professional commentary.

Start with the dates: they are unconditional calendar dates. The Commission's November 2025 proposal had tied the high-risk deadlines to a Commission assessment that standards and support tools were ready, which would have made the calendar conditional and contestable. The final Article 113 contains no such trigger; the recitals keep only a soft instruction that the Commission "should ensure" support measures arrive in due time. Anyone still describing a standards-conditioned clock is describing the proposal, and the proposal did not survive.

The registration duty survived intact. The Commission had proposed scrapping the database entry for systems a provider self-assesses out of high-risk under Article 6(3); the final text calls that registration "crucial for effective market surveillance and public accountability" and trims exactly two data points from Annex VIII, Section B. The assessment itself must still be documented before the system ships, and a national authority can ask for it.

The new prohibition is broader and more carefully engineered than the headlines suggested. Article 5(1) gains two new points: a ban on AI systems that generate or manipulate realistic non-consensual intimate material, and a ban on systems that generate or manipulate child sexual abuse material, both applying from 2 December 2026. For providers, placing such a system on the market is prohibited where the system is intended for that material, or where producing it is a reasonably foreseeable and reproducible outcome and the provider has not put reasonable and adequate technical safeguards in place; the recitals name refusal training, prompt guardrails, content filtering and abuse detection among the measures that qualify. A deployer is caught only when it uses a system for that purpose. For anyone shipping generative capability, documented safeguards are what keep a system on the right side of that prohibition, and crossing it carries the prohibited-practices penalty tier of up to 35 million euros or 7 percent of worldwide annual turnover, whichever is higher.

Several obligations got lighter. The AI literacy duty in Article 4 now requires measures to "support the development of" staff AI literacy and states outright that no specific literacy level must be guaranteed. The simplified quality-management regime once reserved for microenterprises now covers SMEs generally, and a new small mid-cap category, defined by reference to Commission Recommendation (EU) 2025/1099, gains a cap on the mid-tier fines at the lower of the percentage or the fixed amount.

The law firms are currently getting one point wrong in both directions: the legal basis for processing special categories of personal data to detect and correct bias. The new Article 4a keeps the existing basis for providers of high-risk systems, and its second paragraph extends it, under the same strict-necessity conditions and safeguards, to providers and deployers of all other AI systems and models and to deployers of high-risk systems. Summaries limiting the extension to high-risk deployers understate it, and the paragraph creates the lawful room for bias detection without imposing any duty to run it.

And machinery leaves through the front door. The Machinery Regulation moves from Section A to Section B of Annex I, which means the AI Act's substantive high-risk requirements stop applying to machinery-embedded AI directly, while its classification, testing and market-surveillance provisions still reach it; the AI-specific safety requirements will instead be written into the machinery framework itself through delegated acts. Consumer groups have called the adjacent Article 2(13) a back door for future deregulation, and the provision is real but narrower than the alarm: it lets the Commission limit the application of Articles 9 to 15 and 17 to 25 for Article 6(1) systems covered by Annex I Section A legislation, by delegated act due by 2 August 2027, only where the sectoral law already provides equivalent or higher protection and only where overall protection is not reduced. It does not touch Annex III systems at all.

Table screenshot listing EU AI Act Omnibus items with new deadlines and statuses for high-risk AI and GPAI rules

What did not change

What the omnibus left alone defines how much of your existing work carries over, and nearly all of it does. Annex III itself was not amended, so a system that was high-risk in July is high-risk today and the classification exercise you ran against it stands. The general-purpose AI regime is untouched in substance: the amendment sequence skips from Article 50 straight to Article 56, leaving Articles 51 to 55, the systemic-risk thresholds and the model-provider obligations exactly as they have applied since August 2025, with the AI Office gaining a consolidated set of supervisory and enforcement powers in a new Article 75a, and the headline penalty tiers are unchanged. Article 50 transparency continues on its original schedule, subject to the four-month transition for marking content from generative systems that were already on the market before 2 August 2026.

Why these dates will not move again

Every previous entry in this series had to hedge on process, and this one does not, for a reason that is structural before it is optimistic. By deleting the conditional mechanism that linked application to standards readiness, the co-legislators left nothing in the operative provisions but calendar dates. Changing them now requires a new Commission proposal and a full ordinary legislative procedure through a Parliament that spent eight months and considerable political capital adopting this one, against a backdrop where both industry associations and civil society came away dissatisfied for opposite reasons. A date that can only move by reopening that fight is, for planning purposes, a date that does not move. The risky position has inverted: through 2025 it was building against deadlines that might shift, and from now on it is deferring work against deadlines that will not.

The countdown for a governance team

The practical consequence is three dated work packages. By 2 December 2026, a marking pipeline must cover the synthetic audio, image, video and text generators you placed on the market before 2 August 2026, and if you ship generative capability, the safeguards against intimate-imagery and CSAM misuse need to exist and be documented, because from that date the new prohibition carries the top penalty tier. By 2 December 2027, every Annex III high-risk system needs its conformity work done: risk management, data governance, technical documentation, human oversight and its entry in the EU database, while every Annex III-listed system you assess out of high-risk under Article 6(3) needs that assessment documented to a standard a market-surveillance authority can read, together with the streamlined registration the adopted text kept. By 2 August 2028 the same discipline reaches embedded AI in Annex I products, with the Commission's delegated acts and interplay guidelines due a year earlier telling you how much of the sectoral overlap you can consolidate.

Sixteen months to the Annex III date sounds comfortable until it absorbs a notified-body queue, an evidence backlog and a budget cycle. The teams that used the 2025 uncertainty to build classification inventories and evidence maps enter this stretch ahead; the omnibus rewarded them with more runway and, outside the product-embedded edge cases, took none of their scope away. Meeting the dates takes an inventory that connects classification, deployment context and evidence, and Modulos structures exactly that work: each AI system classified by intended use, assessed in its deployment context, and the evidence mapped once across the EU AI Act, ISO 42001 and NIST AI RMF so the same artifact serves every framework. If you want to see your inventory against the final calendar, request a demo and we will walk through it date by date.

The omnibus story that began as a question about delay ends as a fixed schedule with a regulation number, and the work it schedules starts now.

Frequently asked questions

Is the EU AI Act delayed? The delay is partial and now final. Regulation (EU) 2026/1744, in force from 27 July 2026, moves full high-risk obligations for Annex III systems to 2 December 2027 and for Annex I embedded systems to 2 August 2028. The pre-existing Article 5 prohibitions, the general-purpose AI rules and the Article 50 transparency duties keep their original schedule.

What are the new EU AI Act deadlines after the Digital Omnibus? 2 August 2026 for general application and transparency, 2 December 2026 for the new intimate-imagery and CSAM prohibition and the content-marking transition, 2 December 2027 for Annex III high-risk systems, 2 August 2028 for Annex I embedded systems, and 2 August 2030 for pre-existing high-risk systems used by public authorities.

What is the difference between the Annex III and Annex I deadlines? Annex III covers standalone high-risk use cases such as employment screening and creditworthiness, and its obligations apply from 2 December 2027. Annex I covers AI that is, or serves as a safety component of, a product subject to third-party conformity assessment, and its obligations apply from 2 August 2028; for machinery, the substantive requirements will now live in the Machinery Regulation itself.

What still applies on 2 August 2026? The Act's general application date stands: Article 50 transparency for newly placed systems, the governance and penalty framework, and everything already in force, including the Article 5 prohibitions and the general-purpose AI rules. The principal deferral concerns the high-risk chapters; the other new dates are additions and transitions.

What changed in the final Digital Omnibus on AI? The high-risk deadlines became fixed calendar dates with the proposed standards-conditioned trigger deleted, a new Article 5 prohibition on non-consensual intimate material and CSAM was added, the AI literacy duty was softened, the bias-detection data basis was extended to providers and deployers of AI systems and models generally, machinery moved to sectoral regulation, small mid-caps joined the SME relief regime, and registration for self-assessed systems survived with reduced data fields.

Share this article

Ready to Transform Your AI Governance?

Discover how Modulos can help your organization build compliant and trustworthy AI systems.