After months of argument about whether the August timetable would hold, there is finally a text to read rather than a rumor to track. The Digital Omnibus on AI was published in the Official Journal on 24 July 2026 as Regulation (EU) 2026/1744, and it entered into force on 27 July. The short version, for teams who have spent a year watching the calendar: part of the timetable moved, and the part that touches most professional services work did not.
This matters because the two halves have been discussed as though they were one thing. Every countdown to 2 August treated the date as a single wall that either arrived or slid. It did neither. The deferral landed on one set of obligations while another set stayed exactly where it was, and which half you care about depends entirely on what your firm actually does with AI.
The high-risk regime is the part that shifted. Obligations for stand-alone systems listed in Annex III now apply from 2 December 2027, and for AI embedded in products already regulated under Annex I, from 2 August 2028. The stated reasoning is practical rather than political: the harmonized standards, conformity assessment tooling, and national competent authorities that the high-risk regime depends on were not going to be ready in time, and applying obligations that nobody can yet demonstrably meet helps no one.
If your team has been reading the Act primarily through the high-risk lens, worrying about classification, conformity assessment, and technical documentation, you have been given roughly sixteen additional months. That is genuine breathing room and it would be dishonest to pretend otherwise.
The transparency obligations in Article 50 apply from 2 August 2026, as originally scheduled. Nothing in the Omnibus changed that date for the human-facing duties: telling people when they are interacting with an AI system, and disclosing AI-assisted or manipulated content where the Article requires it. One narrow carve-out exists around the machine-readable marking requirement in Article 50(2), which gets a short grace period for systems already on the market before August, but the disclosure duties that most professional teams will feel started on schedule.
This is the half that is easy to miss, because it is the less dramatic one. High-risk classification generates conference panels and law firm briefings. Transparency sounds procedural by comparison, which is precisely why it has been under-discussed relative to how many organizations it touches. A consultancy producing client deliverables with AI assistance is far more likely to meet Article 50 in practice than to ever classify a system under Annex III.
The predictable response to any extension is to put the file down for a year, and it is worth naming why that reads better on the day than it does in eighteen months. A deferral changes when obligations bite. It does not change what clients ask for, what procurement templates absorb, or what an insurer wants to see in a questionnaire, and those pressures were never keyed to the legal date in the first place.
There is also a quieter point about capability. The teams that will find December 2027 straightforward are the ones who spent the interval building an actual review habit, not the ones who drafted a policy the week before. Governance capability compounds slowly and cannot be acquired in a sprint, which is the same reason the last-fortnight scramble before August was never going to produce much of value. An extension is only useful to organizations that treat it as time, rather than as permission to stop thinking about it.
Between now and Sunday there is one question worth answering honestly: when your firm sends out work that AI helped produce, is there any record of who checked it and what they checked against? Not a policy stating that review happens, but a record showing that it did. Most teams discover the answer is scattered across chat histories and inboxes, which is a workable position to be in as long as you know it.
Qonera is the AI governance platform for professional teams, built around a structured review and approval workflow: evidence is checked before analysis, output is stress tested across multiple models, unsupported claims are flagged, and a named reviewer signs off before anything is delivered, with every step captured in a tamper evident audit trail. How the platform maps to the Act’s articles is published in full on the EU AI Act page. The Omnibus changed two dates on a calendar, but the underlying expectation, that AI-assisted work should be reviewable after the fact by someone who was not in the room, has not moved at all.
This article is for general information only and does not provide legal advice. Regulatory timelines for the EU AI Act are subject to change, and the status described here reflects the position as understood at the time of writing. Organisations should consult qualified legal counsel about how the EU AI Act and its deadlines apply to their specific systems, workflows, and obligations.
Multi-model stress testing, Conflict Heatmap, tamper-evident audit trail, and structured sign-off, built for teams who need defensible AI output.