In full
When the Digital Omnibus on AI was published in the Official Journal on 24 July 2026 and entered into force three days later, a good deal of the commentary read as though the AI Act had been postponed. It had not. One set of obligations moved. Another set arrived on schedule on 2 August, and it is the set that touches the larger number of businesses.
Three questions settle it. Is the system on the Annex III high-risk list, which covers credit scoring, insurance underwriting, employment, education and access to essential services? Then your date is 2 December 2027. Does it generate content, or hold a conversation as though it were a person? Then the Article 50 disclosure and labelling duties applied on 2 August 2026, and you are already late. Does it do anything on the Article 5 prohibited list? Then it has been unlawful since February 2025. If the answer to all three is no, one obligation is still worth meeting: be able to show you asked the question and recorded the answer. "We checked and we are out of scope" is a far better position than "nobody looked".
What moved
Regulation (EU) 2026/1744 deferred the compliance date for standalone high-risk AI systems, the Annex III category, from 2 August 2026 to 2 December 2027. AI embedded in products already governed by EU product-safety law, the Annex I category, moved further still, to 2 August 2028.
High-risk is a defined list rather than a judgement call. It covers uses such as biometric identification, critical infrastructure, education, employment, and access to essential services including credit scoring and insurance. If you are a lender using a model in an affordability or scoring decision, or an insurer using one in underwriting, that is the category you sit in, and you now have until December 2027 rather than this month.
A deferral is not a reprieve. It is a longer run-up to the same bar, and the bar did not move.
What did not move
Three things stayed where they were. The prohibited-practices regime under Article 5 has been in force since February 2025. The obligations on providers of general-purpose AI models have applied since August 2025. And the Article 50 transparency duties, which include labelling AI-generated content and disclosing when a person is interacting with an AI system, applied from 2 August 2026.
Article 50 is the one worth reading twice, because it does not depend on your system being high-risk. A chatbot on a customer-facing page, a generated image in a campaign, a synthetic voice in an IVR: these are ordinary commercial uses that sit well outside Annex III and are still in scope for disclosure and labelling.
Why the reach is wider than most teams assume
The regime follows the output rather than the entity. A business with no EU establishment can still be in scope where its AI system's output is used in the EU through sales, access, or downstream integration into someone else's product. For a South African or UK firm selling into Europe, or supplying a platform that a European customer embeds, the question is not whether you have an office in the bloc.
That is a familiar shape for anyone who worked through GDPR. It is also the part that tends to be discovered late, because the trigger sits in a commercial relationship rather than in the engineering.
What to do with the extra time
- Inventory first. You cannot classify what you have not listed. Most organisations underestimate how many models are already in production, because several arrived inside a vendor's product rather than through a project.
- Classify against Annex III, not against instinct. The list is specific. Systems people assume are high-risk often are not, and systems nobody worried about sometimes are.
- Treat Article 50 as live now. Disclosure and labelling are in force. This is the shortest path from where most teams are to being wrong today rather than in December 2027.
- Write the evidence down as you go. The obligations that arrive in 2027 are documentation-heavy. Reconstructing a year of decisions afterwards is the expensive way to do it.
The engineering view
Almost everything the 2027 deadline will ask for is easier to build in than to bolt on: records of what data trained or tuned a model, logs of what it decided and on what input, a human review path that leaves a trace, and a way to show the thing behaved as documented. Teams that already built for POPIA or FCA obligations will recognise the shape, because it is the same discipline pointed at a different regulation.
The deferral bought sixteen months. Spent on inventory and evidence, that is comfortable. Spent waiting, it is the same scramble one year later.
The high-risk obligations moved to December 2027, and the Article 50 transparency and labelling duties took effect on 2 August 2026. The second set is narrower in what it asks and much wider in who it asks, and it applies now. Start with an inventory of what you already run, classify it against the actual Annex III list, and treat disclosure as a present obligation rather than a future one.
