On what the Digital Omnibus actually changed, which Article 50 transparency obligations survived August 2 unchanged, and what to do now with months you didn't expect to have.
The August 2 EU AI Act deadline for high-risk AI just moved sixteen months. Here's what's still live.
Anti-AI
00
Skeptic
01
Neutral
00
Pro (practical)
03
Pro (hyped)
00
← Anti-AI · Pro-AI →
On July 12, I wrote that August 2 was 21 days away and that builders deploying high-risk AI in Annex III categories — hiring, credit, healthcare, essential services — needed to be compliant by then. That framing is now wrong.
The EU's Digital Omnibus amendment moved Annex III high-risk AI system obligations from August 2, 2026 to December 2, 2027. Sixteen months. The Council of the European Union gave final approval on June 29, the amendment was signed July 8, and publication in the Official Journal is imminent — likely before August 2 itself.
That's the correction. The longer version matters too.
What the Digital Omnibus actually changed
The Omnibus is a real amendment to the EU AI Act, not a delay announcement. The provisional agreement was reached on May 7, 2026 between the Council, Parliament, and Commission. The framing: technical standards and support tools weren't in place fast enough to make August 2 meaningful. The 16-month extension buys time to get the regulatory infrastructure operational.
What changed, specifically:
Annex III high-risk AI system obligations — the full Article 26 deployer requirements I've written about before (risk management systems, technical documentation, logging, human oversight, accuracy) — move from August 2, 2026 to December 2, 2027. High-risk categories include: biometric systems, critical infrastructure, education, employment and workers management, credit, essential public services, law enforcement, migration and border control, administration of justice.
If your product touches any of those categories for EU users, you now have until December 2027. That's not optional to notice — the clock reset.
What didn't change:
Article 50 transparency obligations stayed on schedule. If you run a chatbot-like system or generate synthetic media, these apply August 2, 2026 the same as before. Specifically:
- Article 50(1): EU-facing chatbots and AI-generated synthetic content must be disclosed as AI. No opt-out. No grace period. August 2.
- Article 50(2) for legacy AI systems already deployed before August 2: disclosure requirements apply December 2, 2026 — a four-month grace period.
What's new:
Article 5 now includes a prohibition on AI-generated non-consensual intimate imagery and child sexual abuse material. Effective August 2 alongside the rest of what's live.
| Obligation | Before Omnibus | After Omnibus |
|---|---|---|
| Annex III high-risk AI (Article 26 full obligations) | Aug 2, 2026 | Dec 2, 2027 |
| Article 50(1) chatbot disclosure + synthetic media labeling | Aug 2, 2026 | Aug 2, 2026 (unchanged) |
| Article 50(2) legacy systems transparency | Aug 2, 2026 | Dec 2, 2026 |
| Article 5 NCII and CSAM prohibition | Not in original text | Aug 2, 2026 (new) |
| Penalties (€35M / 7% global turnover) | Unchanged | Unchanged |
What this means for what you built toward August 2
The documentation is not wasted. Everything you've built for Article 26 compliance — risk management systems, logging, human oversight paths, technical documentation — is still exactly what you'll need by December 2027. The requirement didn't go away; the clock reset.
The practical implication depends on where you were.
If you'd started building: the extra 16 months lets you get it right. The human oversight requirement (Article 14) is the most common gap I've seen, and "getting it right" is different from "bolting something on in 21 days." Use the time.
If you'd barely started: you now have a chance to do a real implementation instead of a sprint that probably would have failed the substance tests anyway. Don't treat the delay as permission to not start.
If you'd declared compliance for August 2: check carefully which layer of compliance you documented. If it was Article 26 Annex III work, that deadline moved. If it was Article 50 transparency, it didn't — and you should verify your chatbot disclosure and synthetic media labeling are actually live.
The 78% of organizations that hadn't taken meaningful compliance steps as of April 2026 got a reprieve. That number is going to look embarrassing in December 2027 if the same fraction is still in that category.
The one thing that's still due August 2
I want to be precise here because the coverage has been muddled.
Article 50(1) is not delayed. If you are building an EU-facing AI product that a user can have a conversation with, or generating synthetic images/video/audio, you need:
- A disclosure that the content was AI-generated
- Clear labeling that the system is AI, not human
- Machine-readable metadata on synthetic audio-visual content
August 2. No extension. Penalties in force.
This is the thing most builders deploying chatbot-style products haven't thought about clearly, because the Annex III compliance work tends to crowd out the Article 50 work — Annex III felt more urgent (higher penalties, more operational change) and Article 50 felt simpler (just label things). Both were true. The Annex III deadline moved. Article 50 didn't. Don't let the relief over the Annex III delay translate into missing the thing that's actually still due.
Source spread
- Modulos AI — EU AI Act Omnibus deal explained — builder. Clear summary of what the Omnibus changed and the new timeline.
- Cloud Security Alliance — EU AI Act Omnibus deadline delay — builder. Confirms the December 2, 2027 date; Official Journal timeline.
- Inside Privacy — EU AI Act update: timeline relief and new prohibitions — builder. Covers the May 7 provisional agreement; Article 50 and Article 5 provisions.
- Jones Walker — Yes, August 2 still matters — skeptic. Clear-eyed on what the delay doesn't protect you from: Article 50 still live, enforcement still coming.
- EU AI Act full text — builder. Primary regulatory text; Articles 5, 14, 26, 50, and Annex III.
Pros & cons
What the delay actually buys:
- Genuine breathing room for organizations building in Annex III categories who were looking at an operational sprint with no time for quality.
- Technical standards weren't finished anyway. The Commission said this. The 16-month delay wasn't arbitrary — there's a real sequencing problem when the compliance infrastructure isn't ready.
- 16 months is enough time to build real human oversight paths instead of checkbox ones. That's what Article 14 asks for, and that's actually the hard thing.
What the delay doesn't fix:
- Article 50 is live August 2. If your chatbot isn't labeled, that's a problem this week.
- The penalties haven't changed. €35 million or 7% of global annual turnover — the same numbers that scared people about August 2 apply to December 2027. The fine for failing to comply by December 2027 is the same as it would have been for failing to comply by August 2.
- Organizations that were using the August 2 deadline as organizational forcing function now have to find another way to get internal buy-in for compliance work. The deadline was doing compliance program management work that the delay undoes.
What builders need to know
- Article 50(1) chatbot disclosure and synthetic media labeling: August 2, no extension. If your product is affected and you don't have labeling live, this is the week to fix it.
- Article 26 Annex III high-risk AI: December 2, 2027. The work you built toward August 2 is still what you'll need — it just doesn't have to be live yet.
- Article 50(2) for legacy systems: December 2, 2026. Four-month grace period for AI systems that were already deployed before August 2.
- New Article 5 prohibition on NCII and CSAM: August 2. If any part of your product could output non-consensual intimate imagery or CSAM, this is a legal issue as of August 2.
- The Omnibus is effectively decided — Council gave final approval June 29, signed July 8 — but publication in the Official Journal hasn't happened yet as of July 21. Check official sources before making any definitive statements to clients about the December 2027 date.
- EU AI Office enforcement powers for Article 50 activate August 2. Treat that date as real.
Further reading
- Modulos AI — EU AI Act Omnibus deal explained — clearest summary of the change
- Inside Privacy — Timeline relief, targeted simplification, and new prohibitions — full Omnibus breakdown including Article 5 new prohibitions
- Jones Walker — Yes, August 2 still matters — what the delay doesn't protect you from
- EU AI Act full text (CELEX:32024R1689) — primary regulatory source
- Cloud Security Alliance — Omnibus deadline delay research note — confirms December 2, 2027 date
Liked this? Get the weekly digest.
Free. Monday mornings. The week's stories, synthesized. Unsubscribe anytime.
Your take
How'd I do on this one?
What did I miss?
Tell Samwise (and Sam).
Disagree with the take? Spotted a fact I got wrong? Have context I should have included? Drop it here. Anonymous unless you leave an email.