Skip to content
← Back to blog
6 min read

The EU AI Act After August 2: The Road to December 2027 Is Now Locked In

Key takeaways

  • -The Digital Omnibus entered into force on July 27, 2026 (published July 24 as Regulation (EU) 2026/1744). The deferral of high-risk obligations is now binding law: Annex III standalone systems apply from December 2, 2027, and high-risk AI embedded in regulated products from August 2, 2028.
  • -August 2, 2026 is unchanged. Article 50 transparency obligations apply, and for most companies that's the whole to-do list. Once it's done, the August 2 deadline is behind them.
  • -For high-risk companies, August 2 is the starting line, not the finish. The 16-month extension to December 2027 is roughly what a full conformity programme takes to build, so treating it as a break is how you end up in a 2027 scramble.

For more than a year, the entire EU AI Act conversation has pointed at one date: August 2, 2026. As of last week, the picture around it finally stopped moving. The Digital Omnibus, the package that reshaped the Act's timeline, was published in the Official Journal on July 24, 2026 and entered into force on July 27 as Regulation (EU) 2026/1744.

That matters because until now, the deferral of the high-risk rules was an agreement everyone expected to become law. Now it is law. The dates are fixed, and you can plan against them without hedging.

The Omnibus is now law

Two things are locked in. The heavy obligations for stand-alone high-risk AI systems listed in Annex III now apply from December 2, 2027. High-risk AI embedded in regulated products under Annex I applies from August 2, 2028. Both moved back from the original August 2, 2026 date, and both are now binding rather than provisional.

One date did not move. The Article 50 transparency obligations still apply from August 2, 2026. The Omnibus reshaped almost everything around that deadline without touching the deadline itself.

What August 2 settles

For most companies, August 2 is the finish line, and it is a short race. If you run a chatbot, you disclose that people are talking to AI. If you generate images, audio, video, or text, you mark it as AI-generated. If you deploy emotion recognition or deepfakes, you disclose those too. That is Article 50, and for a limited-risk company it is close to the entire obligation. We wrote the bare-minimum version of this in the actual minimum you need for August 2.

Once that is done, August 2 is genuinely behind you. There is no second shoe for limited-risk companies. The panic that treats the whole high-risk regime as an August 2 problem is scoping work that was deferred by 16 months.

The road to December 2027

If any part of your product is high-risk (recruitment and HR screening, credit scoring, insurance pricing, education assessment, biometric identification, and the rest of Annex III), then August 2 is not your finish line. It is your starting gun for a different and much longer race that ends on December 2, 2027. That is where the real work lives:

  • A continuous risk management system (Article 9)
  • Data governance and bias documentation (Article 10)
  • The full Annex IV technical documentation (nine sections)
  • Automatic event logging (Article 12)
  • Instructions and transparency for deployers (Article 13)
  • Human oversight built into the product (Article 14)
  • Accuracy, robustness, and cybersecurity (Article 15)
  • A quality management system (Article 17)
  • Conformity assessment before market placement (Article 43)
  • Registration in the EU database (Article 49)
  • A post-market monitoring plan (Article 72)

You still owe the Article 50 transparency piece on August 2 as well. The two tracks run in parallel, the high-risk one just has a longer finish. If that split is new to you, we broke it down in two deadlines, two compliance tracks.

Why 16 months isn't a break

Here is the trap. December 2027 sounds far away, so the instinct is to file high-risk compliance under "later." But a full conformity programme, which means risk management, data governance, documentation, testing, human oversight, a quality system, and an assessment at the end, takes most companies many months to build from scratch. It takes longer if the system is already in production and has to be retrofitted.

Important

The extension is runway, not a reprieve. The Omnibus did not give high-risk companies a break. It gave them roughly the amount of time the work actually takes. Companies that read December 2027 as "not yet" will start in mid-2027 and land in exactly the scramble everyone was bracing for this August, just 16 months later.

What to do from August 2 forward

The sequencing is not complicated. First, close out August 2. Get your Article 50 transparency in place, because it is live and it is small. That is true whether you are limited-risk or high-risk.

Then, if any part of your product is high-risk, treat the day after August 2 as day one of the December 2027 build. Start with the two things that take longest and gate everything else: your risk management system and your technical documentation. Neither can be produced in a sprint at the end, because both are meant to reflect a process you actually ran.

And if you are not sure which track you are on, that is the first question to answer, not the last. The whole roadmap depends on whether you are limited-risk or high-risk, and most companies assume high-risk when they are not. Work out your tier, then follow the track it puts you on.

The deadlines aren't moving. Get updates that matter.

Get EU AI Act updates, enforcement news, and compliance guides delivered to your inbox. No spam — unsubscribe any time.

Check your AI system's risk level for free

Our classifier maps your AI system against the EU AI Act and gives you your risk tier and obligations. No signup required.

Classify Your AI System