Explore Enzai’s full suite of AI governance products designed to help organizations manage, monitor, and scale AI with confidence. From structured intake and centralized AI inventories to automated assessments and real-time oversight, Enzai provides the building blocks to embed governance directly into everyday AI workflows - without slowing innovation.

Enzai

AI Regulations

EU AI Act Delay Is Now Law: New 2027 and 2028 Deadlines

AI Regulations

EU AI Act Delay Is Now Law: New 2027 and 2028 Deadlines

AI Regulations

EU AI Act Delay Is Now Law: New 2027 and 2028 Deadlines

Belfast

Belfast

8 min read time

Topics

What changed

The EU's Digital Omnibus on AI is no longer a proposal. Regulation (EU) 2026/1744, which amends the EU AI Act, was adopted by the European Parliament and the Council on 8 July 2026, published in the Official Journal on 24 July, and entered into force on 27 July 2026, three days before the AI Act's original 2 August 2026 general application date. The European Commission confirmed the entry into force the same week. Executive Vice-President Henna Virkkunen has described the package as giving businesses "simpler and innovation-friendly rules" while "not lowering the bar on safety."

For enterprise AI governance teams, this matters because it removes the uncertainty that has shaped planning since the Omnibus was first proposed in November 2025. Until last week, the sensible advice was to treat the delay as contingency and keep building towards the original August 2026 deadline. That advice has now changed, because the delay is confirmed law with fixed backstop dates.

New deadlines for high-risk AI systems

The core change is timing. High-risk AI systems fall into two groups under the AI Act, and each now has a different, later deadline:

  • Standalone high-risk systems under Annex III (covering areas such as recruitment and worker management, credit scoring and creditworthiness assessment, biometric identification and categorisation, education and vocational training, access to essential services, and law enforcement) now have until 2 December 2027 to meet the full set of high-risk requirements. That is a deferral of roughly 16 months from the original date.

  • AI systems embedded in regulated products under Annex I (for example, safety components in machinery, medical devices, or aviation systems) now have until 2 August 2028, a 12-month deferral.

Both dates are described as backstops: they apply regardless of whether the harmonised technical standards that AI providers were originally meant to rely on have been finalised. That decoupling from the standards timeline was one of the more technical but consequential fixes in the Omnibus, because it removes a dependency that many providers and deployers had flagged as unworkable.

A new prohibition on AI-generated intimate imagery

The Omnibus does not only push deadlines back. It adds two new prohibited practices to Article 5 of the AI Act: placing on the market or using AI systems designed to generate, or that make it reasonably foreseeable will generate, child sexual abuse material, and AI systems that generate non-consensual intimate imagery of identifiable people, including so-called "nudifier" tools. This prohibition applies from 2 December 2026.

The scope is broader than purpose-built nudifier apps. General-purpose generative AI providers can also fall within it if such outputs are reasonably foreseeable in the absence of effective safeguards. There is a safe harbour for providers who put in place reasonable, proportionate and effective preventive measures, so this is a live design and documentation question for any organisation running or procuring image or video generation tools, not just a legal one. Penalties for breaching this prohibition sit at the top tier: up to €35 million or 7% of worldwide annual turnover, whichever is higher.

Other simplifications worth noting

A handful of smaller changes round out the package. The Commission has removed the requirement for providers to use a mandatory template for post-market monitoring plans. The regulatory sandbox regime has been expanded, including new EU-level sandboxes and coverage for some Annex I high-risk systems. Simplifications that were previously limited to small and medium enterprises now extend to small mid-cap companies. And the AI Office's supervisory scope has been broadened to reach AI systems built on general-purpose AI models within the same corporate group as the model provider, and to AI systems that are embedded in, or constitute, Very Large Online Platforms or Search Engines under the Digital Services Act.

What did not change

The most common misreading of this news is that "the AI Act got delayed," full stop. It did not. Several obligations are untouched and still land on their original dates.

Article 50 transparency rules still apply from 2 August 2026

The transparency obligations under Article 50 of the AI Act were not part of the Omnibus's deferral and still take effect on 2 August 2026, three days after this regulation entered into force. That means, from this weekend:

  • Providers of chatbots and other systems intended to interact with people must design them so users are informed they are talking to an AI.

  • Deployers using AI to create deepfakes must disclose that content has been artificially generated or manipulated.

  • Deployers publishing AI-generated text on matters of public interest must disclose that it is AI-generated, unless the text has undergone human review with an accountable natural or legal person taking editorial responsibility.

The Commission adopted final guidelines on these obligations on 20 July 2026, less than two weeks before they bite. Penalties for non-compliance reach €15 million or 3% of worldwide turnover. Teams that have been treating "the deadline moved" as a reason to slow down on transparency work should not: this is the one part of the original timeline that stayed exactly where it was.

Prohibited practices, GPAI obligations and AI Office enforcement powers are unaffected

The original Article 5 list of prohibited practices, in force since February 2025, is unchanged. General-purpose AI model obligations around transparency, copyright and systemic risk documentation, in force since August 2025, are unchanged. And critically, the Commission's enforcement powers over GPAI providers, including requests for information, model evaluation, corrective measures and the ability to restrict or withdraw a model from the EU market, still activate on 2 August 2026. The high-risk delay is a delay for high-risk systems. It is not a delay for the GPAI models many enterprises build on top of, and it is not a delay for transparency.

The penalty structure has not softened

The Omnibus simplifies process and timing. It does not reduce fines. The two-tier penalty structure, up to €35 million or 7% of worldwide turnover for the most serious breaches and up to €15 million or 3% for others, still applies in full, and now covers the new CSAM/NCII prohibition as well.

Five things to do this week

1. Correct the compliance calendar and the board deck

If your last board briefing said "we are working towards 2 August 2026 for high-risk systems, pending a possible delay," that line is now wrong in two ways: the delay is confirmed, and the new dates are specific (2 December 2027 for Annex III, 2 August 2028 for Annex I). Update the calendar and reissue the briefing this week so nobody is planning against a deadline that no longer exists, or assuming relief that does not extend to transparency obligations.

2. Finish the Article 50 work regardless of the delay

Chatbot disclosure, deepfake labelling and AI-generated text labelling still apply from 2 August 2026. If any part of your organisation has quietly deprioritised this because "the AI Act got pushed back," reverse that now. A clean AI inventory is the fastest way to find every chatbot, image generator and content tool that needs a disclosure mechanism before the weekend.

3. Screen generative AI tools for CSAM/NCII exposure ahead of December

You have four months, not four weeks, before the new prohibition bites on 2 December 2026, but the safe harbour requires "reasonable, proportionate and effective" preventive safeguards to already be built in, not bolted on after a complaint. Start now with any image or video generation capability, whether built in-house or procured, and document the safeguards as you go. This overlaps with existing deepfake governance work many teams already have underway.

4. Do not stand down high-risk AI system work, redirect it

An extra 16 months is real relief, but it is relief on timing, not on scope. The classification, documentation, conformity assessment and human oversight work for Annex III systems still needs to happen, and now you have room to do it properly instead of racing a deadline. Use the runway to build (or finish building) a defensible EU AI Act classification and control framework rather than shelving the project.

5. Re-check GPAI vendor documentation before 2 August

The AI Office's enforcement powers over general-purpose AI providers activate on 2 August 2026, and its supervisory reach has been extended to systems built on GPAI models within the same corporate group and to GPAI-embedded systems on very large platforms. If your organisation relies on third-party foundation models, this is a good week to pull current model documentation and confirm your vendor risk file is current, not scrambling for it after the Commission starts asking questions.

Where Enzai helps

Deadline changes like this one are exactly why AI governance needs to live in one place rather than in a set of spreadsheets and calendar reminders. Enzai's compliance frameworks track obligations against the dates that actually apply, so when a regulation like this one moves a deadline, the change propagates through your control library instead of sitting in an email thread. The AI inventory product is the practical starting point for both the Article 50 work due in days and the Annex III work due in 2027, since you cannot classify or govern a system you have not catalogued. And for teams tracking obligations across jurisdictions, not just the EU, our EU AI Act hub sets out the full picture, including the new high-risk deadlines and the unchanged Article 50 dates.

Join our Newsletter

By signing up, you agree to the Enzai Privacy Policy

Join our Newsletter

By signing up, you agree to the Enzai Privacy Policy

Join our Newsletter

By signing up, you agree to the Enzai Privacy Policy

Join our Newsletter

By signing up, you agree to the Enzai Privacy Policy

Compliance by Design

Compliance by Design

ISO 27001

Enzai is ISO 27001 certified, and has been since 2023. We commit to annual audits which are performed by NQA, and work closely with our security consultant partners Instil to continually update and enhance our security posture.

GDPR

ISO 27001

Enzai is ISO 27001 certified, and has been since 2023. We commit to annual audits which are performed by NQA, and work closely with our security consultant partners Instil to continually update and enhance our security posture.

GDPR

AI Governance

AI Governance

Infrastructure

Infrastructure

engineered for Trust.

engineered for Trust.

Empower your organization to adopt, govern, and monitor AI with enterprise-grade confidence. Built for regulated organizations operating at scale.

Seamlessly connect your existing systems, policies, and AI workflows — all in one unified platform.

Seamlessly connect your existing systems, policies, and AI workflows — all in one unified platform.