TL;DR: EU AI Act: What Actually Changed
Changes like this are easy to miss, and missing them is the kind of thing that surfaces in front of a partner or a customer at the worst possible moment. So here is the short version.
On 29 June 2026, the Council of the EU gave final approval to the Digital Omnibus on AI. The headline is that high-risk AI compliance deadlines moved back significantly. The detail that matters more is that the 2 August 2026 general application date did not move at all.
Past vs. now
| Topic | Old version | Amended version |
| High-risk AI rules — standalone systems (Annex III) | 2 Aug 2026 | 2 Dec 2027 |
| High-risk AI rules — AI embedded in products (Annex I) | 2 Aug 2027 | 2 Aug 2028 |
| National regulatory sandboxes operational | 2 Aug 2026 | 2 Aug 2027 |
| AI-content marking for systems already on the market | 6 months (as proposed) | Shortened — deadline 2 Dec 2026 |
| Article 50 transparency obligations | 2 Aug 2026 | 2 Aug 2026 — unchanged |
| AI literacy obligation (Article 4) | in force | in force, softened |
| NCII and CSAM generation prohibitions | — | new, from 2 Dec 2026 |
The regulation is Regulation (EU) 2026/1744. It was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026.
In February 2025, the first parts of the AI Act became applicable. In August 2025, the general-purpose AI and governance chapters followed. For the past year, most enterprise AI governance planning across Europe has been organized around a single date: 2 August 2026, when the high-risk regime was due to arrive.
That date is now three separate dates. The Council's final green light on 29 June, published in the Official Journal on 24 July and in force since 27 July, splits the high-risk timeline in two and leaves the rest of the 2 August 2026 package exactly where it was.
This post covers three things: what actually moved and what did not, why the new dates are more reliable than the previous proposal suggested, and what the additional runway is realistically useful for.
The Headline Says Delayed. The Calendar Says Otherwise
The deferral is narrower than the coverage implies. What moved is Chapter III, Sections 1, 2 and 3 - classification, technical requirements, and operator obligations, including Article 26 deployer duties and Article 27 fundamental rights impact assessments. Those now apply from 2 December 2027 for standalone high-risk systems and 2 August 2028 for high-risk AI embedded in regulated products.
Everything else on 2 August 2026 arrives on schedule.
Article 50 transparency was not deferred.
Chatbot disclosure, machine-readable marking of synthetic content, deepfake disclosure, and disclosure for AI-generated text published on matters of public interest all become applicable on 2 August 2026. The obligation text was not amended. Only the implementing-act power in Article 50(7) was touched.
This is the single most likely thing to be missed this year, because it is the obligation that sits closest to the tooling enterprises have already deployed. If Copilot output, an agent built in Copilot Studio, or a customer-facing bot generates content that reaches a person, the disclosure question is a deployer question. It does not transfer to the vendor.
Market surveillance and enforcement also start on 2 August 2026.
The amended Article 75 gives the AI Office exclusive competence over AI systems built on general-purpose models where the model and the system come from the same provider or from providers forming part of the same undertaking, and over systems that constitute or are integrated into a designated very large online platform or search engine.
New Articles 75a to 75d attach an antitrust-style procedural toolkit to that competence: on-site inspections, the power to seal business premises and records, binding commitments, and periodic penalty payments of up to 5% of average daily income or worldwide annual turnover, per day.
The limits matter as much as the powers. National authorities stay competent for AI in Annex I products, for critical infrastructure, for law enforcement, border management and financial institutions, and for the administration of justice. And AI Office competence reaches a deployer only where that deployer is also the provider or part of the same undertaking as the provider. For most organizations building on a third-party model, the national authority remains the interlocutor. The point is worth checking against your own architecture rather than assuming.
Two new prohibitions arrive on 2 December 2026.
Article 5 is extended to cover AI systems that generate non-consensual intimate imagery and child sexual abuse material. For deployers, the prohibition is narrow — it catches actual use for that purpose — but it belongs in an acceptable-use policy for any organization with generative tooling in the environment. It sits in the top penalty tier.
The New Timeline
| Date | What applies |
| 2 Feb 2025 | Prohibited practices; AI literacy; scope and definitions |
| 2 Aug 2025 | GPAI obligations; governance; penalties; notified bodies |
| 27 Jul 2026 | Omnibus in force. Amended Article 4, new Article 4a, revised "safety component" definition in Article 3(14) |
| 2 Aug 2026 | Article 50 transparency; harmonized standards provisions; market surveillance; AI Office enforcement; GPAI fines |
| 2 Dec 2026 | Marking obligation for generative systems already on the market; NCII and CSAM prohibitions |
| 1 Aug 2027 | Commission guidelines on the interplay with sectoral legislation due |
| 2 Aug 2027 | National sandboxes operational; legacy GPAI model compliance |
| 2 Sep 2027 | Commission post-market monitoring guidance and template |
| 2 Dec 2027 | High-risk regime for standalone systems (Article 6(2), Annex III) |
| 2 Aug 2028 | High-risk regime for AI embedded in products (Article 6(1), Annex I) |
| 2 Aug 2030 | Legacy high-risk systems used by public authorities |
The Dates Are Fixed. That Is the Real News.
The Commission's original proposal from November 2025 tied the delay to a condition. High-risk obligations would apply only after the Commission confirmed that standards, common specifications and guidance were actually available. In other words, a deadline that nobody could plan against, because nobody could date it.
That mechanism is not in the adopted text. The Council killed it in its negotiating mandate of 13 March 2026 and replaced it with two calendar dates. Parliament did the same. Those are the dates that became law.
Recital 40 states the dates flatly. It acknowledges that delayed standards and delayed national authorities created the problem, then sets 2 December 2027 and 2 August 2028 without qualification. Support instruments are described as "important" and the Commission "should ensure" they arrive in time. That is a political undertaking, not an operative trigger.
The practical consequence is straightforward. Because nothing but calendar dates remains in the operative text, moving them again would require a fresh Commission proposal and a full legislative procedure. Planning against 2 December 2027 is now planning against something stable. Planning against a conditional decision never was.
One caveat on sources. Briefings published before May 2026 still describe the conditional cut-off and a 2 February 2027 marking deadline. Both are artifacts of the proposal, and search engines still return them as current. The Council press release and the Official Journal text are the reference points.
Article 4 Was Softened, Not Removed
The AI literacy obligation was rewritten and is in force in its new form since 27 July 2026. Providers and deployers must now "take measures to support the development of" AI literacy among staff, with an express statement that the obligation does not require guaranteeing any specific level of literacy in any individual.
Worth flagging, because the Commission's own news page announcing the omnibus describes the AI literacy requirement as "replaced by non-binding encouragement." It was not. That sentence describes the November proposal, not the regulation that passed. The duty is still binding. It is simply outcome-free. Keep the training and awareness evidence. Drop any attempt to certify individual competence.
A second change deserves attention from anyone running a DPIA process. When the high-risk regime does bite, Article 27 will allow a fundamental rights impact assessment to cross-reference the relevant sections of a GDPR Article 35 data protection impact assessment where the obligation is already met, and the AI Office's questionnaire template must accommodate those cross-references. That is genuine burden reduction, and almost nobody is writing about it.
What the Runway Is Actually For
Sixteen additional months for Annex III systems, twelve for Annex I, on the Commission's own arithmetic. That is meaningful. It is also the second time this framework has slipped - the deadlines have now moved once, and the supporting guidance has been late throughout.
The obligations moved. The analysis did not get easier.
Annex III itself was not amended. Every classification decision made against it still stands. Article 6(3) self-assessments - the documented conclusion that a listed system is not in fact high-risk - will still have to exist before a system is placed on the market once the regime applies, and national authorities will be able to request them. The Commission's draft Article 6 guidelines were published in May 2026, and consultation has closed. Final guidance is still outstanding.
Meanwhile, the volume of content that needs to be classified keeps growing. Agents created in Copilot Studio, flows in Power Automate, apps in Power Platform, and Copilot extensions are being produced by business users at a rate that no manual review process absorbs. The compliance deadline moved by sixteen months. The inventory problem did not pause for sixteen months to wait for it.
An accurate, current, owner-attributed inventory of AI systems in the Microsoft 365 estate is the prerequisite for every obligation in this regulation, on every one of these dates. Building it in 2026 with a known deadline in 2027 is a manageable project. Building it in late 2027 under an active deadline is not.
What to Do Before 2 August 2026
-
Confirm Article 50 coverage
Identify every AI system in the environment that produces content reaching a person, and confirm disclosure and marking are in place. The Commission published guidelines on transparency obligations on 20 July 2026, alongside a Code of Practice on Transparency of AI-Generated Content from June. Use them. -
Work back from 2 December 2026
For any generative system placed on the market before 2 August 2026 that requires machine-readable marking. Interoperable marking is not a four-month project in most estates. -
Establish who supervises you
Read the amended Article 75 against your own architecture. A change of competent authority is a change of interlocutor, not just a change of address. -
Finish the inventory and the classification work
Not because it is due, but because it is the input to everything that is.
At Rencore, we built Rencore Governance to keep that inventory continuous rather than periodic: automated discovery of AI agents, Power Platform assets and Copilot usage across the Microsoft 365 estate, with ownership attribution and policy enforcement attached.
Not every organization needs a platform to get through 2 August 2026. Most will need one to get through 2 December 2027 with evidence.
If you would like to see what that looks like against your own environment, book a 30-minute call with the team or start with a governance gap assessment.