Seven weeks ago we flagged 2 August 2026 as the date the EU AI Act’s high-risk Annex III obligations became enforceable, with fines running up to 35 million euros or 7 percent of global turnover. That deadline has since moved. It has not disappeared, and the part of it that survived is easy to miss if you were only tracking the headline date.
What actually got delayed
The Digital Omnibus simplification package received final Council approval on 29 June 2026 and enters into force shortly after publication in the EU’s Official Journal. Its most consequential change pushes the compliance date for standalone high-risk AI systems under Annex III, covering employment, education, essential services, law enforcement and critical infrastructure, from 2 August 2026 to 2 December 2027. Sector-specific high-risk obligations, where AI is embedded in products already regulated under existing safety legislation, move further still, to August 2028.
For organisations mid-way through a high-risk AI compliance programme, this is genuine breathing room. Conformity assessments, EU database registration, and the heavier documentation and logging requirements we described in June no longer need to be finished by tomorrow.
What did not move
Article 50 is a separate transparency layer, and the Omnibus deliberately left it alone. From 2 August 2026, any AI system that interacts directly with people, generates synthetic audio, image, video or text content, performs emotion recognition or biometric categorisation, or produces deepfakes must disclose that fact to users. This applies regardless of whether the underlying system is classified as high-risk. A marketing team running an AI chatbot on their website, a media company using generative tools to produce article images, or an agency shipping AI-voiced video content are all in scope, whether or not their sector touches anything Annex III would have covered.
The same date is when the European Commission’s enforcement powers over general-purpose AI model providers become fully active, and when national market surveillance authorities gain the ability to investigate and sanction AI Act breaches more broadly. Organisations already on the market with a generative AI system before 2 August 2026 get a grace period until 2 December 2026 to implement machine-readable watermarking under Article 50(2). Anything launched on or after tomorrow needs that marking from day one, with no grace period at all.
Why the smaller deadline still matters
The practical effect is that the AI Act’s first wave of real enforcement lands on a much broader base of organisations than the high-risk tier ever covered. Annex III applied to a defined list of sensitive domains. Article 50 applies to disclosure obligations that sit on top of ordinary marketing, content and customer service tooling that most European businesses already use. Many organisations that breathed a sigh of relief when the high-risk delay was announced have not yet checked whether their AI-facing customer touchpoints carry the required disclosures, because the delay news travelled faster and further than the detail of what stayed in place.
Regulators are not starting from zero here either. The AI Act’s enforcement bodies are building directly on a decade of GDPR investigative practice, and the assumption that early movers will be overlooked has already proven wrong once in this market.
If your organisation needs a quick audit of where Article 50 disclosure obligations apply across your AI-facing products, help implementing chatbot and synthetic content labelling before tomorrow’s deadline, or a broader read on what the Digital Omnibus changes mean for a compliance programme already underway, contact Excello Digital. We help European organisations separate what actually changed from what the headlines say changed.
