The deadline that didn't move
For two years, "August 2, 2026" was the date that dominated every European AI compliance roadmap. It was supposed to be the moment the EU AI Act's most consequential provisions — the obligations governing "high-risk" systems used in hiring, credit scoring, education, policing and border control — finally bit. As of this week, that framing is dead. The date survives, but almost everything companies feared about it has been pushed years down the road.
Under the EU's Digital Omnibus, a simplification package the European Commission published on 19 November 2025 and that the Parliament and Council provisionally agreed on 7 May 2026, August 2 remains a live compliance deadline. What comes due on that day, however, is far narrower than originally written into law. The hard parts — the full weight of high-risk obligations — now land in December 2027 and August 2028.
What stays on August 2
Two things do not move. The transparency duties in Article 50 of the AI Act still apply from 2 August 2026 as originally scheduled. That means providers and deployers of systems like chatbots, deepfake generators and emotion-recognition tools must disclose, in most cases, that users are interacting with or looking at AI-generated content.
The enforcement architecture for general-purpose AI (GPAI) models — the foundation models from the likes of OpenAI, Google, Anthropic and Mistral — also holds its August timeline. GPAI transparency and documentation obligations took effect in August 2025, and the Commission's ability to enforce them against model providers matures on schedule. For the frontier-model layer of the AI economy, in other words, the Omnibus changes little.
What slips to 2027 and 2028
The deferral is aimed squarely at the high-risk regime. The provisional agreement sets a fixed, two-track timeline:
- 2 December 2027 for stand-alone high-risk systems — the Annex III category covering recruitment, credit and access to essential services, law enforcement, education, migration and the administration of justice. - 2 August 2028 for AI used as a safety component of a regulated product under Annex I, such as medical devices, machinery and vehicles.
The stated rationale is implementation, not ideology. The harmonised technical standards that high-risk providers are supposed to build their compliance on are running badly behind schedule, and many member states have yet to designate the national competent authorities meant to police the rules. The Commission's argument is blunt: you cannot enforce obligations against companies when the standards and support tools they need to comply do not yet exist.
The package carries other AI-specific changes too. It adds a new prohibition targeting AI that generates child sexual abuse material and non-consensual intimate "nudifier" imagery, with compliance due by 2 December 2026, and pushes watermarking obligations for AI-generated content to the same date. It also clarifies the definition of a "safety component," so systems that merely assist or optimise performance without creating health or safety risks won't automatically be swept into the high-risk tier.
The simplification fight
The Omnibus sits inside a much broader deregulatory push — the same legislative vehicle proposes amendments to the GDPR, the ePrivacy Directive, the Data Act and NIS2 — and that scope is exactly what has civil society alarmed.
Henna Virkkunen, the Commission's executive vice-president for tech sovereignty, security and democracy, has framed the effort as housekeeping rather than retreat. "We need to make doing business in Europe easier without compromising our high standards of online fairness and safety," she said, calling for "an innovation-friendly rulebook" and "immediate steps to get rid of regulatory clutter."
Digital-rights groups see something larger. In an open letter, more than 130 civil society organisations and unions urged the Commission to halt the package, warning it amounts to the biggest rollback of digital protections in EU history. The Austrian group noyb put it flatly: the Digital Omnibus "brings deregulation, not simplification." European Digital Rights (EDRi) and others have also attacked the process, arguing the Commission skipped a proper impact assessment and leaned on industry "reality checks" while sidelining public-interest voices.
The substantive worry is that "simplification" is being used to quietly reopen a law that took years to negotiate. Even supporters of a delay concede the optics: the EU spent 2024 branding itself the world's first jurisdiction to comprehensively regulate AI, and it is now spending 2026 postponing the enforcement of that regulation's core.
What to watch
The immediate question is formal adoption. The provisional deal still needs to be finalised by Parliament and Council and published in the Official Journal before it takes legal effect — and before 2 August, or the un-amended high-risk rules technically switch on. Watch, too, whether the standards bodies actually hit the new 2027 targets; if they slip again, the credibility of "temporary" deferral erodes. And keep an eye on the GPAI track: it is now the one part of the AI Act moving on its original clock, which makes foundation-model providers the first real test of whether Brussels can enforce the rules it fought so hard to write.
"We need to make doing business in Europe easier without compromising our high standards of online fairness and safety."— Henna Virkkunen, European Commission EVP for Tech Sovereignty