Somewhere in Europe this week, a compliance calendar is wrong. Any company that spent the past year building toward a single high-risk AI deadline of 2 August 2026 now has a date that no longer exists, because the EU Digital Omnibus reforms changed it.
Read the headlines, and you would think Brussels simply “delayed the AI Act,” full stop. That is half true, and the missing half matters. Some deadlines were moved by 16 months. One new prohibition appeared, and the deadline most organisations were racing toward did not move a single day. That deadline has already passed.
The reforms took legal effect through Regulation (EU) 2026/1744, published in the Official Journal on 24 July and in force since 27 July 2026, the first amendments to the AI Act since it passed in 2024. Here is what each part actually did.

What Did the EU Digital Omnibus Actually Delay?
Under the original AI Act, obligations for stand-alone high-risk systems listed in Annex III were set to apply from 2 August 2026. These are the systems that make decisions about people, such as hiring tools, credit scoring, education, law enforcement, and border control. The Omnibus moves that date to 2 December 2027, a slip of 16 months for the tier of the law that touches the most companies.
A second, quieter deferral sits underneath it. The deadline for high-risk AI built into already-regulated products under Annex I, such as machinery and medical devices, has been moved from 2 August 2027 to 2 August 2028, as Gibson Dunn notes. Two high-risk tracks, two new dates. Anyone reporting a single “delay” has already lost the thread.
The Commission’s stated reason is that the tools to comply were not ready. National authorities were not fully designated, conformity assessment bodies were thin on the ground, and the harmonised standards that tell a company how to meet the law did not exist yet. The European Commission’s own page frames the package as buying time while keeping the safeguards.
What Did the EU Digital Omnibus Leave Untouched?
The transparency obligations did not move an inch. Under Article 50, providers must tell people when they are dealing with an AI system, and mark AI-generated audio, images, video, and text so machines can read the label. That start date stayed exactly where it was, 2 August 2026. It applied on schedule and is already in effect.
Systems already on the market before 2 August 2026 have until 2 December 2026 to get their content-marking in order, per Lewis Silkin’s reading of the text. Anything launched on or after 2 August must comply immediately. So the labelling duty is live right now. If your mental model is “the AI Act got pushed to 2027,” you have already missed a deadline that is binding today. This is the gap between what the headlines said and what the AI Act 2026 calendar actually holds.
What New Rules Did It Quietly Add?
The Omnibus writes a new prohibited practice into Article 5, the list of outright-banned uses. It catches AI systems that generate child sexual abuse material, or non-consensual sexual and intimate imagery of real people, the so-called “nudifiers.” The prohibition became law when the regulation took effect on 27 July, but it does not bite until 2 December 2026. Until then providers have a transitional window to fit the required safeguards, such as refusal training and output filtering, or drop the capability, as Freshfields sets out. A package sold as simplification quietly tightened the rules in one of the areas where the public most wanted them tightened.
It also loosened one. The old Article 10(5) allowed only providers of high-risk systems to process special-category data, race, health, and biometrics, to test their models for bias. A new Article 4a extends that permission to all AI systems and general-purpose models under a strict-necessity standard, with safeguards such as pseudonymisation and deletion, as Orrick explains. It is a small change with real logic: you cannot fix a bias you are legally barred from measuring.
MRKT3.0 has tracked how the €890 million Google DMA fine turned a headline number into a deadline that actually bit. The Omnibus is that story in reverse: the number that grabs attention, the delay, is not the part that changes what companies must do next.
Is This Simplification or Retreat?
Critics call it capitulation, a rulebook blinking under industry pressure. There is a stronger case on the other side, and it deserves a fair hearing.
The standards genuinely were not ready. The AI Act handed the hard work of “how do we actually comply” to European standards bodies, and CEN-CENELEC fell behind. Enforcing a high-risk regime on 2 August 2026 would have meant requiring companies to meet a standard that nobody had finished writing. On this reading, moving the high-risk date to 2027 is not a weakness but a refusal to enforce against an empty page, while keeping the transparency duties and new prohibitions on time. Industry group DIGITALEUROPE backed the direction for roughly that reason.
The counter is just as real. Amnesty International called the wider simplification drive a rollback of rights, pointing not to the CSAM ban but to the provisions that let companies grade the risk of their own systems. A delay meant to wait for standards can also become a delay that never quite ends. We covered how the EU spent 2026 making its one AI law lighter and slower, even as China moved to write its first unified one.
Which returns us to the sentence that started all this. The claim “The EU delayed the AI Act” is technically defensible yet misleading. MRKT3.0’s earlier guidance that 2 August 2026 was immovable was half right: the transparency piece was immovable, and it just applied. The high-risk piece moved. Knowing which half applies to you is the whole job now.
Author: Ayanfe Fakunle
See Also:
Google DMA Fine: Why the €890 Million Barely Matters
What Is Sovereign AI? Definition, the Money Behind It, and Europe’s Reality
