EU AI Act: the high-risk deadline has moved
The AI Omnibus pushes the biggest compliance date from August 2026 to December 2027 — but plenty is already binding.
Updated 31 Jul 2026 fast-moving — check a current source
Dates verified against the European Commission's AI Act pages, late July 2026. Orientation for non-lawyers — not legal advice, and national implementation varies.
If you planned around 2 August 2026 as the date the EU AI Act’s high-risk rules bite, that plan needs revisiting. The AI Omnibus simplification package, signed on 8 July 2026, defers the heaviest obligations by more than a year. This is orientation for non-lawyers, not legal advice.
The revised timeline
- Already in force since February 2025 — the ban on prohibited AI practices, and AI literacy obligations for organisations deploying AI.
- Already in force since August 2025 — governance rules, and obligations on providers of general-purpose AI models.
- 2 August 2026 — the Act becomes fully applicable, with the exceptions below.
- 2 December 2027 — deferred. High-risk rules for biometrics, critical infrastructure, education, employment, migration, asylum and border control.
- 2 August 2028 — deferred. High-risk rules for AI embedded in physical products such as lifts and toys.
What the deferral does and doesn’t change
It does not repeal anything. The prohibited-practice ban and the AI literacy duty have been binding for well over a year, and the general-purpose model obligations for nearly a year. If your organisation deploys AI in hiring, lending, or any other listed high-risk area, the requirements are unchanged — you simply have until December 2027 to meet them rather than next week.
The honest reading is that the extra time reflects how few organisations were going to be ready. A readiness gap is not the same as a reprieve, and conformity assessment, technical documentation and registration are not quick jobs.
Treat the deferral as breathing room, not a cancellation. The work that was hard to finish by August 2026 is the same work, still required, on a later date.
If you’re outside the EU
The pattern from earlier EU digital rules holds: organisations serving European users tend to apply one standard everywhere rather than maintain two. The disclosure and acceptable-use habits covered elsewhere here line up with the direction of travel regardless of where you operate.
For the earlier snapshot of how the Act is structured, see June’s status check. For anything compliance-critical, check the current text against official sources and take proper advice.
Sources
Everything above was checked against these on 31 Jul 2026. Providers change things without notice — if a detail matters to a decision, follow the link.