If you built a 2026 compliance plan around the original AI Act calendar, some of it is now out of date. In late June 2026 the Council gave its final green light to a package the EU has been calling the Digital Omnibus, and one of the things it does is push back the hardest deadlines in the AI Act. Worth knowing exactly what shifted before you rewrite anything.

What moved

The two deadlines that moved are the ones for high-risk systems, which were always going to be the heaviest lift.

  • The rules for standalone high-risk systems listed in Annex III (think biometrics, critical infrastructure, hiring, credit scoring, access to essential services) were due to apply from 2 August 2026. They now apply from 2 December 2027.
  • The rules for high-risk AI embedded in regulated products under Annex I (medical devices, machinery and the like) moved from 2 August 2027 to 2 August 2028.

The main reason is prosaic. The harmonised technical standards that companies need in order to actually prove conformity were running late at CEN and CENELEC, the European standards bodies. You cannot ask firms to meet a bar that has not been drawn yet. So the co-legislators drew the bar's deadline forward in time instead. The European Parliament's own write-up of the March committee vote lays out the logic.

What did not move

This is the part people miss. Plenty of the AI Act is already in force and none of it was delayed.

The ban on prohibited practices has applied since 2 February 2025. The AI literacy duty in Article 4, which says staff who use AI systems need a baseline understanding of them, has applied since the same date. The obligations on general-purpose AI models kicked in on 2 August 2025, along with the governance and penalty framework. And the transparency duties in Article 50, the ones that say you have to tell people when they are talking to a machine and label AI-generated content, still apply from 2 August 2026. They were not touched.

So if your reaction to the delay is "good, we have more time," check which bucket your use actually falls into. An internal assistant that drafts and summarises is usually not a high-risk Annex III system at all. Which means the deadlines that moved were never your deadlines. The literacy duty and the transparency rules, which did not move, probably are.

The penalties are unchanged, and they are large

None of this softened the enforcement side. Article 99 still sets fines of up to 35 million euro or 7 percent of global annual turnover for prohibited practices, up to 15 million euro or 3 percent for most other breaches, and up to 7.5 million euro or 1 percent for supplying wrong information to authorities. You can read the exact tiers on the AI Act Explorer. For a mid-sized firm, the percentage figures are the ones that bite.

What a deployer should actually do

Strip away the calendar noise and the to-do list is short. Work out where AI is already being used across the organisation, including the tools nobody officially bought. Sort each use into a bucket: banned, high-risk, limited-risk (which mostly means transparency duties), or minimal. Get the AI literacy training done, because it is already overdue and it is one of the cheapest boxes to tick. And for anything that even might be high-risk, name an owner now, because December 2027 arrives faster than it sounds when standards, documentation and human-oversight processes all have to be in place first.

One quieter point. A lot of the deployer burden is about evidence: keeping logs, pinning the exact model version you assessed, being able to say what the system does with an input. All of that is easier when the model runs on infrastructure you control rather than behind a vendor's API that can change under you. Sovereignty and compliance are not the same thing, but they rhyme.

This is general information, not legal advice. The omnibus text was still being finalised in the Official Journal as this went out, so confirm the final regulation number and any national guidance with your counsel before you act on it.