EU AI Act High-Risk Deadline Is Five Weeks Out as Enterprises Scramble

Five weeks before the European Union's most consequential AI compliance deadline was set to bite, the rule itself is in flux. August 2, 2026 has loomed for two years as the date high-risk artificial intelligence systems must meet the bloc's full slate of obligations. But a last-minute simplification deal struck in Brussels this spring would push that deadline more than a year down the road, and as of late June it is not yet law. The result is a rare kind of regulatory limbo: the deadline that thousands of enterprises spent eighteen months preparing for may evaporate, but no general counsel can yet bank on it.

The original timeline was unambiguous. The AI Act entered into force in August 2024 on a phased schedule. Bans on prohibited practices, such as social scoring and certain biometric surveillance, took effect February 2, 2025. Rules for general-purpose AI models followed on August 2, 2025. The marquee date, August 2, 2026, was always meant to switch on the heaviest tier of the law: obligations for high-risk systems used in employment screening, credit scoring, access to essential services, law enforcement, migration, education, and the administration of justice, plus AI embedded in regulated products like medical devices.

The Brussels reversal

That plan changed on May 7, 2026. Negotiators from the Council, the European Parliament, and the Commission reached a provisional agreement on the "Digital Omnibus on AI," part of the bloc's broader simplification push. The deal would defer high-risk obligations on a staggered timeline: standalone Annex III systems, the recruitment, credit-scoring, and law-enforcement tools at the center of enterprise anxiety, would move from August 2, 2026 to December 2, 2027. AI embedded in regulated products under Annex I, such as medical devices and machinery, would slide from August 2, 2027 to August 2, 2028.

The stated rationale is operational. European standards bodies, chiefly CEN-CENELEC, have not finished the harmonized technical standards that companies are supposed to build their conformity assessments against. Under the new approach, the high-risk clock starts only once the Commission confirms those standards and support tools actually exist.

"We are ready to work with our co-legislators in our common efforts to support our companies, facilitate innovation and build a more competitive Europe," said Marilena Raouna, Cyprus's Deputy Minister for European Affairs, in the Council's announcement of the agreement.

On June 16, the European Parliament formally endorsed the May compromise. But the law is not done. As of late June, formal adoption by the Council remained pending, and the changes take legal effect only once published in the Official Journal, expected before the original August 2 deadline. Until that ink dries, the statutory deadline on the books is still August 2, 2026.

Why enterprises cannot exhale

That gap is the whole problem. Compliance teams face a genuine decision under uncertainty: continue racing toward an August deadline that will probably be repealed, or bet on a delay that has not been ratified. Most large operators have kept their programs running. Conformity assessments, technical documentation, CE marking, and registration in the EU's high-risk database are not assembled in a weekend, and the penalties for getting it wrong are severe, up to 35 million euros or 7 percent of global annual turnover, whichever is higher.

The relief, even if confirmed, is partial. The new prohibitions and several transparency duties, including labeling of AI-generated content, are not being deferred on the same schedule, and one transparency grace period was actually shortened. Companies treating the omnibus as a blanket reprieve risk missing the obligations that survive it.

The coding-agent question

One ambiguity the omnibus does not resolve is where autonomous AI coding agents fall. The Act classifies systems by use, not by underlying capability, so a code-generation tool is not inherently high-risk. But the moment such an agent is deployed in a regulated context, writing or modifying software inside a medical device, a credit-decisioning pipeline, or critical infrastructure, the analysis shifts. If the agent's output materially shapes a high-risk system's behavior, it can be pulled into the high-risk perimeter, dragging documentation, human-oversight, and risk-management duties with it. With agents now committing production code at many enterprises, this is not a hypothetical, and the law offers no bright line. That classification gray zone is precisely the kind of question the deferral buys time to answer, but does not answer itself.

The American complication

Layered on top is a fragmenting US picture that does not move in step with Brussels. Colorado's pioneering AI Act, the first US law to import the EU's risk-based, consequential-decision framework, was set to take effect June 30, 2026. Governor Jared Polis signed SB 189 on May 14, 2026, delaying it to January 1, 2027 and gutting the risk-management and impact-assessment duties in favor of a narrower disclosure regime. Texas's TRAIGA took effect January 1, 2026 but focuses on intent-based prohibitions and state-agency use rather than affirmative private-sector compliance. The net effect for a multinational is divergence in both directions at once: Europe loosening its timeline while keeping its architecture, and US states retreating from European-style mandates toward lighter-touch disclosure.

What to watch

The near-term signal is procedural: formal Council adoption and Official Journal publication of the Digital Omnibus, expected before August 2. Only then does December 2, 2027 become the operative date for standalone high-risk systems. Watch, too, for the Commission's progress on the harmonized standards that now gate the entire high-risk regime, because under the new design, no standards means no clock. And keep an eye on how regulators and standards bodies treat autonomous coding agents in regulated workflows, the unresolved edge case most likely to surprise enterprises that assumed the extra time meant they were off the hook.

"We are ready to work with our co-legislators in our common efforts to support our companies, facilitate innovation and build a more competitive Europe."
— Marilena Raouna, Deputy Minister for European Affairs, Cyprus
Aug 2, 2026
Original high-risk deadline
Dec 2, 2027
Proposed new deadline
7% turnover
Max penalty under the Act