EU AI Act

EU AI Act Deadline Has NOT Changed. Here Is Why.

Petru Constantin
8 min read
#eu-ai-act#compliance#digital-omnibus#regulation#devidevs

The EU AI Act Deadline Has NOT Changed. Here Is What Actually Happened.

Update, June 16, 2026: The European Parliament voted (423-57-174) to extend the high-risk deadlines. Standalone Annex III high-risk obligations now move to December 2, 2027, and embedded Annex I systems to August 2, 2028. The Council formally adopted the extension on June 29, 2026, so both dates are final. The article below was written in March 2026 while this was still only a proposal; at that time August 2, 2026 was the binding high-risk date. That part has now changed. What did NOT change: the Article 50 transparency obligations stay August 2, 2026, the AI-generated content marking rule stays December 2, 2026, and prohibited practices (since Feb 2, 2025) and GPAI obligations (since Aug 2, 2025) remain in force. The near-term clock that still binds you is transparency, not high-risk.

The Headlines Are Wrong

If you opened LinkedIn this week, you probably saw some version of "EU delays AI Act by 16 months." The European Parliament's IMCO and LIBE committees adopted their negotiating mandate on March 18, 2026. The Council agreed its position on March 13. Headlines everywhere announced the delay.

Here is the part they left out: none of this is law yet.

The Digital Omnibus is a legislative proposal. Both institutions adopted negotiating positions, which means they can now start trilogue talks. (The Parliament has since voted to extend the high-risk deadlines, and the Council adopted them on June 29, 2026 - see the update at the top.) At the time of writing in March 2026, the talks had not started, the earliest realistic adoption date was late 2026, and August 2, 2026 remained the binding deadline for high-risk AI system obligations.

What never moved, in any version of the proposal: the Article 50 transparency obligations stay August 2, 2026.

What the Digital Omnibus Actually Proposes

The proposal is more nuanced than "delay everything by 16 months." Here is what it says:

Annex III high-risk systems (standalone AI in HR, finance, law enforcement, education): enforcement moves to the earlier of December 2, 2027 or six months after the Commission confirms that harmonized standards are available.

Annex I high-risk systems (AI embedded in regulated products like medical devices, vehicles): enforcement moves to the earlier of August 2, 2028 or twelve months after standards availability.

The word "conditional" matters here. The delay only kicks in after the Commission confirms that CEN/CENELEC harmonized standards or equivalent compliance support exists. Those standards missed their own August 2025 deadline and are not expected before Q4 2026 at the earliest.

So the delay is conditional on something that does not exist yet, proposed in a law that has not been adopted yet, and depends on trilogue negotiations that have not started yet.

That is three layers of "not yet."

What Is Already Enforceable Right Now

While companies debate whether the deadline moved, they are missing what already applies:

Since February 2, 2025: All prohibited AI practices are illegal. Social scoring, manipulative AI, predictive policing, untargeted facial recognition scraping, workplace emotion recognition. Fines: up to EUR 35 million or 7% of global turnover.

Since August 2, 2025: GPAI model obligations are in force. Transparency requirements, copyright due diligence, safety evaluations for systemic risk models. The EU AI Office already issued formal document retention orders to X (Grok) in January 2026 and opened an investigation into Meta.

August 2, 2026 (NOT delayed by Digital Omnibus): Article 50 transparency obligations for AI-generated content. If your marketing team uses generative AI, you need machine-readable labels and disclosure workflows by this date. The Omnibus does not touch Article 50.

So even in the best-case scenario where the Omnibus passes and high-risk deadlines shift, companies still need to comply with prohibited practices (already live), GPAI obligations (already live), and transparency requirements (August 2026, not delayed).

Why Pausing Compliance Is the Worst Move

I have talked to CTOs who saw the headlines and told their teams to "wait and see." That is a mistake for three specific reasons.

Reason 1: The Article 50 transparency deadline did not move. The high-risk extension to December 2, 2027 (voted June 16, 2026) does not touch Article 50. If you run a chatbot, generate marketing content with AI, or use emotion recognition, the disclosure obligations still bind from August 2, 2026, with no transition. Taylor Wessing's analysis noted earlier the risk of a period where obligations apply while lawmakers debate postponement; for transparency, that ambiguity never existed.

Reason 2: The compliance work is the same regardless of deadline. Whether you face August 2026 or December 2027, you need the same things: an AI system inventory, risk classification per Annex III categories, technical documentation, a quality management system, and conformity assessment processes. The Commission was supposed to publish Article 6 classification guidelines by February 2, 2026. They missed that deadline. Harmonized standards are delayed. None of this reduces the compliance workload. It just means you are doing it without official guidance, which takes longer, not less time.

Reason 3: Companies that start early spend less. A 2-week structured assessment done calmly now costs a fraction of what a last-minute scramble costs under deadline pressure. Notified body queues will fill up. Every compliance consultancy will be booked. If you are starting your compliance work when the Omnibus is adopted, you are already competing for limited assessment capacity.

What You Should Actually Do

Stop reading headlines. Start with these three steps:

Step 1: Build your AI inventory. List every AI system your company develops, deploys, or uses. Include third-party models (yes, ChatGPT API calls count). This takes 1-2 days depending on your organization's size.

Step 2: Classify risk. For each system, determine whether it falls under Annex III high-risk categories. The Commission's guidelines are late, but the regulation text and Annex III categories are clear enough for practical classification. A half-day per AI system gives you a defensible determination.

Step 3: Check what already applies. Prohibited practices audit (half a day). GPAI compliance review if you deploy or fine-tune third-party models. Article 50 transparency assessment for AI-generated content.

You do not need to wait for Brussels. The regulation text, the recitals, and the existing ISO 42001 framework give you enough to start building a compliance posture that works regardless of which deadline lands.

Update: Trilogues Have Started (March 26, 2026)

Since this article was published, trilogue negotiations between the European Parliament, Council, and Commission officially began on March 26, 2026. A political agreement on a consolidated text is expected at the next trilogue session on April 28, 2026.

If the timeline holds, endorsement by Parliament and Council could follow in May and June, with publication in the Official Journal potentially in July 2026 - just before the August 2 deadline.

Since then, the Parliament voted on June 16, 2026 to extend the high-risk deadlines (Annex III to December 2, 2027, Annex I to August 2, 2028), and the Council adopted them on June 29, 2026. The core practical advice still holds: the Article 50 transparency obligations remain at August 2, 2026 with no transition, so companies running chatbots or generative-AI surfaces should keep preparing for that date. The heavier high-risk conformity work now has runway to 2027, but the compliance workload is the same either way.

Also relevant: On March 12, 2026, Romania designated ANCOM as the national market surveillance authority for the EU AI Act. ANCOM is now the lead enforcer for general AI systems in Romania. Companies operating in Romania should factor this into their compliance planning.

The Real Risk Is Not the Fine

The maximum fine for high-risk non-compliance is up to 3% of global turnover. That gets the headlines. But the real risk for most companies is simpler: you cannot sell into the EU market without compliance.

Companies that have their AI systems classified, documented, and assessed will be operating freely while their competitors are scrambling through notified body queues. The CE mark cliff is real. Products without conformity assessment cannot enter the market. First movers do not just avoid fines. They capture market share.

The Omnibus gives you more time on paper. But paper is not law yet. And even if it becomes law, the work starts now.


About DeviDevs: We build ML platforms, secure AI systems, and help companies comply with the EU AI Act. devidevs.com


Not sure where your AI system falls under the EU AI Act? Take our free risk assessment - find out in 2 minutes →

Want AI agents and automations your business can actually run on?

We build them with Claude Code, then we secure them. Book a free 30-minute call. No commitment.

Book a Call

Weekly AI Agents, Automation & Security Digest

How we build AI agents and automations with Claude Code, plus practical AI security, integrations, and platform notes, delivered weekly.

No spam. Unsubscribe anytime.