The AI Act Was Delayed, But Probably Not the Part That Affects You
"The EU has delayed the AI Act" has been one of the most repeated compliance headlines of the year. It's true, as far as it goes. The problem is that a lot of teams read it as "nothing to do until 2027".
The Digital Omnibus deferred one tier of obligations and left three others alone. Including the tier most likely to apply to an ordinary company website, which has been enforceable since 2 August 2026.
The timeline, as it stands
| Obligation | Applies from | Changed? |
|---|---|---|
| Prohibited practices (Article 5) | 2 February 2025 | No, and the list was widened |
| General-purpose AI models (Articles 51–56) | 2 August 2025 | No |
| Transparency obligations (Article 50) | 2 August 2026 | No |
| Marking grace period for pre-existing systems | 2 December 2026 | No |
| High-risk, stand-alone systems (Annex III) | 2 December 2027 | Yes, from 2 August 2026 |
| High-risk in regulated products (Annex I) | 2 August 2028 | Yes, from 2 August 2027 |
Two rows moved out of six.
What was deferred
The high-risk regime. These are the heavyweight obligations: conformity assessments, risk management systems, technical documentation, human oversight requirements, post-market monitoring. They attach to AI used in consequential decisions like employment and recruitment, credit scoring, education, essential public and private services, biometric identification and critical infrastructure.
Stand-alone high-risk systems under Annex III moved from 2 August 2026 to 2 December 2027. High-risk AI embedded in already-regulated products under Annex I moved from 2 August 2027 to 2 August 2028.
The reason was practical, not political. The harmonised technical standards those obligations depend on weren't finished, and national authorities weren't resourced to enforce them. You can't ask companies to demonstrate conformity against standards that don't exist yet.
One detail in there helps with planning. The Commission originally proposed a conditional delay, where obligations would kick in once the supporting standards were ready. The agreed text replaced that with fixed dates, so you can plan against a calendar instead of a moving trigger.
What didn't move
Prohibited practices have applied since February 2025, and the omnibus expanded the list, adding nudification tools and CSAM-related applications. This tier went the opposite way to "delayed".
General-purpose AI model obligations have applied since August 2025.
Article 50 transparency obligations applied from 2 August 2026, exactly as originally scheduled. They cover disclosing that people are interacting with an AI, marking AI-generated output in machine-readable form, labelling deepfakes, and notifying people exposed to emotion recognition.
Then there's the one date sitting in the near future. Generative systems already on the market before 2 August 2026 have until 2 December 2026 to meet the machine-readable marking requirement. If you shipped an AI feature before August, that's your deadline, and it's closer than the headlines suggest.
Why the confusion took hold
The delayed tier generated the most coverage because its obligations are the most onerous and the most expensive, so that's where reporting concentrated. "The AI Act" also gets discussed as one object when it's really four regimes on four schedules. A headline saying it was delayed is true of one regime and false of the others, and headlines don't carry that nuance.
The deferred tier also doesn't apply to most companies. Ordinary businesses were never in scope for high-risk obligations. They are in scope for transparency ones. So the delay that dominated the news was the delay least relevant to them, and the rules that do apply passed with barely a mention.
What this means for a typical website
If you're not doing hiring decisions, credit scoring, biometrics or critical infrastructure, December 2027 is probably irrelevant to you. What's relevant right now:
- A chatbot or AI assistant on your site needs a disclosure that users are interacting with an AI.
- AI-generated images, audio or video that could pass for real need visible labelling when you publish them.
- Generative features you build need machine-readable marking of their output. If the feature predates August, your deadline is 2 December 2026.
- Emotion recognition or biometric categorisation, if you use it, means notifying the people exposed to it.
None of that involves a conformity assessment. Most of it comes down to a line of text and a conversation with your vendors.
So what should you do
The delay was real. It applied to the tier of obligations least likely to touch you. The tier most likely to touch you arrived on schedule and is enforceable today, with a follow-up deadline in December.
If you read the headline and filed the AI Act under "2027 problem", the fix is a fifteen-minute audit of where AI shows up on your site. Our Article 50 checklist walks through it, and the chatbot decision guide covers the most common case.
This article is general information, not legal advice. Whether a particular system falls into the high-risk category is a fact-specific question, so if you think you might be near that line, get advice rather than relying on a summary.
Sources: Gibson Dunn: EU AI Act Omnibus agreement and postponed high-risk deadlines · European Commission: Transparency obligations under Article 50 · Article 50, EU AI Act (full text)