AI Compliance —
EU AI Act Deadlines 2026-2027
The EU delayed key AI Act deadlines in June 2026. Here's exactly what moved, what's already in force, and what compliance teams should do now.
Dogan Akbulut
EU-AI-ACT
Share this article

If you searched for "EU AI Act deadline" expecting a straightforward answer, you've probably noticed the internet disagrees with itself. A large share of the content still online says high-risk AI system obligations took effect on August 2, 2026. That's no longer accurate, and it hasn't been since late June 2026. If you're making compliance decisions based on outdated deadline information, this is worth five minutes to get right.
The Short Version
On June 29, 2026, the EU Council formally approved a "Digital Omnibus" package that delayed the compliance deadline for high-risk AI system obligations from August 2, 2026 to December 2, 2027, a 16-month extension. This was a deliberate simplification measure, not a sign the regulation is being abandoned, but it materially changes what compliance teams need to prioritize right now versus what can wait.
At the same time, not everything moved. One major set of obligations stayed exactly on schedule and is already in force.
What's Already in Force (as of August 2, 2026)
Article 50 transparency requirements kept their original deadline and took effect on schedule. These cover:
Disclosing to users when they're interacting with an AI system rather than a human
Labeling AI-generated or AI-manipulated content (including deepfakes and synthetic media)
Informing users when emotion recognition or biometric categorization systems are in use
There's one partial exception within this category: AI-generated content on systems that were already deployed before August 2, 2026 got a four-month reprieve on the specific watermarking requirement, pushing that piece to December 2, 2026. But the core transparency and disclosure obligations are live now, not pending.
Also already in force, and unaffected by the Digital Omnibus:
Prohibited AI practices (Article 5), in force since February 2, 2025, covering things like social scoring systems and certain forms of manipulative AI
General-purpose AI (GPAI) model obligations, in force since August 2, 2025
What Got Delayed
Requirement | Original Deadline | New Deadline |
|---|---|---|
High-risk AI system obligations (standalone, Annex III systems) | August 2, 2026 | December 2, 2027 |
Annex I product-embedded high-risk systems | August 2, 2027 | August 2, 2028 |
The maximum penalty structure itself did not change: fines for the most serious violations (prohibited practices) can still reach up to €35 million or 7% of global annual turnover, whichever is higher. Less severe violations carry a lower ceiling, typically cited around 3% of global turnover. The delay affects when high-risk obligations kick in, not how much it costs to violate them once they do.
Why This Matters More Than It Might Seem
A 16-month delay sounds like a reason to relax. In practice, it changes the shape of the work more than it removes it:
Transparency compliance is no longer optional homework, it's a live requirement. If your product interacts with users conversationally or generates synthetic content and you haven't implemented Article 50 disclosures, that gap is enforceable today, not in 2027.
The extra runway on high-risk obligations is genuinely useful, if you use it deliberately. Teams that were racing toward an August 2026 deadline now have real time to build risk classification and conformity documentation properly instead of under deadline pressure, but only if that time gets allocated to the project rather than treated as "solved."
This regulation is still actively being renegotiated. A delay of this size, approved this recently, is a signal that further adjustments are plausible. Treat any specific date beyond the next few months as provisional, not fixed.
What Compliance Teams Should Actually Do Right Now
Audit whether you've implemented Article 50 transparency requirements. This is the piece with zero runway left, it's already enforceable.
Don't shelve your high-risk risk classification work, just re-sequence it. Use the extended runway to build your AI system inventory and risk-tier classification methodically rather than dropping it entirely until 2027.
Revisit your compliance roadmap's internal deadlines, not just the regulation's. If your project plan still says "August 2026" anywhere, that plan is now based on outdated information.
Watch for further Digital Omnibus developments. This process moved fast once (proposal to formal approval in a matter of months), and further procedural changes are plausible before December 2027 arrives.
Frequently Asked Questions
Is the EU AI Act delayed entirely? No. Only the high-risk AI system obligations were delayed, and only by 16 months. Prohibited practices, GPAI obligations, and Article 50 transparency requirements are unaffected and are already in force.
Do I still need to comply with anything right now? Yes. If you deploy AI systems in the EU, transparency and disclosure requirements (informing users they're interacting with AI, labeling AI-generated content) are enforceable today. Prohibited-practice restrictions have been in force since February 2025.
What is the Digital Omnibus? It's an EU legislative simplification package, formally approved by the Council on June 29, 2026, that adjusted several implementation timelines across EU digital regulation, including the EU AI Act's high-risk system deadline.
Will the December 2027 deadline change again? It's possible. The Digital Omnibus process demonstrated that timelines here are not fixed in stone, and further adjustments remain plausible. Treat any specific future date as the current best information, not a guarantee.
Does the delay reduce the maximum fines? No. The penalty structure, up to €35 million or 7% of global turnover for the most serious violations, is unchanged. Only the compliance deadlines moved, not the enforcement stakes once they apply.
Explore more AI Compliance articles
Stop losing deals to compliance.
Get compliant. Keep building.
Join 100s of startups who got audit-ready in days, not months.



