Somewhere this week there is a CTO with a half-finished spreadsheet. It is an Annex III classification workbook, started in Q1 when the AI Act deadline looked immovable, sixty rows deep, maybe a third complete. Then the Omnibus landed, the “high-risk rules pushed to 2027” headlines followed, and the CEO forwarded one of them with a single line: can we take the compliance line out of the H2 budget? So let me answer that email directly. Yes, the AI Act's high-risk deadlines were delayed. No, your 2026-08-02 obligations were not.
The same week that headline arrived, something else did: a security review from the company's largest enterprise prospect. Question 47: “Describe your AI governance framework, including model provenance and AI subprocessors.” Both things are true at once. The regulator's deadline moved. The one attached to revenue did not. That is the whole argument of this piece: the Omnibus changed the regulator's calendar, and in doing so it quietly handed your deadline to a new owner, your biggest customer. Standing your programme down because of the headline means confusing those two calendars, and only one of them has ever sent you an invoice.
What was actually delayed, and what still applies on 2026-08-02
First the sort, because most of the coverage has not done it. Regulation (EU) 2026/1744, the Digital Omnibus on AI, was signed on 2026-07-08, published in the Official Journal on 2026-07-24, and has been in force since 2026-07-27. It amends the AI Act in three ways that matter here: it delays some things and adds a few new dates, but it leaves the biggest date alone. I am not your lawyer, and what follows is not the memo your lawyer will send you. It is the sort I run when a diligence question lands on my desk: which obligations moved, which are live as of 2026-08-02, and which arrive in December.
| Obligation | Was | Now | Where it says so |
|---|---|---|---|
| Annex III high-risk obligations (Article 6(2)) | 2026-08-02 | 2027-12-02 | Reg 2026/1744 Art. 1(40)(b); AI Act Art. 113, third para., point (c)(i) |
| Annex I embedded high-risk obligations (Article 6(1)) | 2027-08-02 | 2028-08-02 | Reg 2026/1744 Art. 1(40)(b); AI Act Art. 113, third para., point (c)(ii) |
| Article 50(2) machine-readable marking, generative systems on the market before 2026-08-02 | 2026-08-02 | 2026-12-02 | Reg 2026/1744 Art. 1(39)(b); AI Act Art. 111(4) |
| New prohibitions: non-consensual intimate imagery, CSAM generation | Not in the 2024 text | 2026-12-02 | Reg 2026/1744 Art. 1(40)(a); AI Act Art. 113, third para., point (a) |
| Article 50 transparency duties and Article 101 fining powers over GPAI-model providers | 2026-08-02 | 2026-08-02, unchanged | AI Act Art. 113, second and third para. |
Delayed: the high-risk machinery
Regulation 2026/1744 moves the Annex III high-risk obligations to 2027-12-02 and the Annex I embedded high-risk obligations to 2028-08-02. That is the delay in the headlines, and it is real. Here is the honest part the headlines skip: for most mid-sized companies building AI into a product, this bucket was never the main event. Annex III covers systems in areas like employment screening, credit scoring, and critical infrastructure. If your product genuinely sits there, the extra time is valuable and you should use it well. If it does not, and for most of the companies I work with it does not, then the delay you are celebrating applies to obligations you never had.
Live now: transparency duties and GPAI teeth
Nothing in Regulation 2026/1744 touches the AI Act's general application date, so on 2026-08-02 the Article 50 transparency duties start to apply, and with them the Commission's power under Article 101 to fine providers of general-purpose AI models up to the higher of EUR 15 million and 3% of worldwide annual turnover. The governance structures and the GPAI-model obligations themselves are not new; they have applied since August 2025. What arrives now is the transparency layer and the enforcement teeth. Let me be precise about Article 50, because this is where false alarm creeps in. It splits duties by role: providers of interactive AI systems must make sure people know they are dealing with AI, providers of generative systems must machine-mark their output, and deployers must disclose deepfakes, emotion recognition, and certain AI-generated public-interest text. It is disclosure and labeling, not a management system, and nobody should sell you one on the back of it. But disclosure duties still need someone to have checked which products they touch, and the enforcement machinery standing behind the GPAI rules is live from 2026-08-02, not from 2027.
Coming December: prohibitions and the marking grace period
Regulation 2026/1744 gives providers of generative systems already on the market before 2026-08-02 until 2026-12-02 to comply with the Article 50(2) machine-readable marking duty, while systems placed on the market from 2026-08-02 comply from day one. The same December date brings the new prohibitions on non-consensual intimate imagery and CSAM generation into application. And to keep the sort fair: the Omnibus also extends the simplified technical documentation regime to SMEs and small mid-caps, a genuine concession that lowers the paperwork load when the high-risk dates do arrive. The Omnibus is not a trick. It just is not the pause the forwarded headline made it sound like.
The regulator was never your enforcement mechanism
Here is the thing the legal coverage structurally cannot say, because it is not a legal point. For a company your size, the first AI Act deadline with real commercial teeth was never going to come from the AI Office. It was always going to be question 47 on your biggest customer's vendor questionnaire. Procurement does not read CELEX numbers. It reads your answers, and it reads hesitation.
I saw this before the law even applied. At an international professional services firm, the forcing event for the whole AI governance effort was not a regulator. It was a client questionnaire asking which AI tools touched their matters and which model providers saw their data. The honest first answer would have been “we don't know,” and everyone in the room understood that answer was not sendable. The governance work that followed existed for one operational reason: to close that gap, so the next questionnaire would meet a documented, credible answer instead of a crisis meeting.
That questionnaire was early. It no longer is: in my client work, the same model-provenance and AI-subprocessor questions now recur in the established vendor-assessment tools, CSA's AI-CAIQ and the AI risk domain in Shared Assessments' SIG among them, which means the question arrives whether or not your buyer's security team cares about the AI Act as law. And in the enterprise sales cycles I see, security review already adds weeks; an AI section you cannot answer cleanly adds more, at the exact point in the quarter where you can least afford it. The regulator's delay does nothing to that clock. If anything it sharpens the question of who actually owns AI governance in your company, because “we paused it after the Omnibus” is an answer that tells an enterprise buyer exactly how you make decisions. I have written before about supplier audits reaching companies NIS2 never regulated; this is the same mechanism wearing a different acronym. The obligation reaches you through your customers, on their schedule, regardless of what Brussels moved.
The provider line you may have already crossed
There is a second reason the pause is riskier than it looks, and it sits inside your own product. Running AI diligence across a PE platform's portfolio, I kept meeting the same self-description: “we're just using AI.” Product teams that had fine-tuned a foundation model on their own data, or wrapped one so thoroughly that the product ships under their name, still filed themselves under “user.” Nobody had run the deployer-versus-provider check, because nobody knew there was a check to run.
Does fine-tuning a model make you a provider?
Not automatically, and that is exactly why the check matters. The AI Act separates the system you ship from the model underneath it. Ship an AI system under your own name or trademark and you are likely its provider; for high-risk systems, Article 25 adds that rebranding, substantial modification, or a change of intended purpose can transfer provider status. Becoming the provider of the underlying general-purpose model through fine-tuning is rarer: Commission guidance treats it as the exception. The check itself is not exotic. Per product: what did we start from, what did we change, whose name is on the thing the customer sees. What has changed as of 2026-08-02 is what stands behind that line. The Commission's enforcement and fining powers over providers of general-purpose AI models apply from 2026-08-02, which means the cost of a wrong classification is no longer theoretical. This is exactly the check a diligence team runs in an acquisition, and it is much cheaper to run it on yourself first.
Why the law-firm memo blesses the wrong pause
The memos you have read about the Omnibus are mostly accurate. That is what makes them dangerous. They frame the AI Act as a matter between you and the regulator, so when the regulator's dates move, the frame says you can stand down. For this audience the frame is wrong. The relationship that prices your governance work is between you and your pipeline, and no article of Regulation 2026/1744 amended that one. The European Parliament's legislative train documents the statutory timetable, not procurement. That is the limit of the legal-memo frame: it can tell you when obligations apply, but not when a buyer will block a renewal.
I will concede the sunk cost honestly, because the CEO forwarding that headline is not being unreasonable. If you spent Q1 on Annex III classification, part of that work is now parked for sixteen months, and some of it will need redoing when the technical standards mature. That is a real loss and pretending otherwise would be spin. In the spring, before the Omnibus was law, I wrote about the AI Act deadline most companies had already missed; the transparency duties described there go live now, on the original date; the AI-literacy duty has applied since February 2025. There are two calendars in play, and the memo on your desk only reads one of them.
What to keep, what to genuinely park
So here is the sort I would run on that CTO's programme, and it is not “keep everything.” Park the Annex III conformity-assessment track. The delay is real, the standards it depends on are still moving, and grinding through conformity paperwork well ahead of the new deadline is not diligence, it is waste. If your product is genuinely high-risk under Annex III, put a restart date in the plan for early 2027 and move on.
Keep the work your customers grade you on, because none of it moved. The AI system inventory: which systems you run, bought, built, or embedded. The deployer-versus-provider sort per product, for the reasons above. The model provenance and AI subprocessor answers, which is what question 47 actually wants. And Article 50 disclosure where it applies to you: which of your interfaces need to tell people they are talking to an AI system, and who checked. That list is deliberately short. For most companies this size it is bounded work, weeks rather than quarters, not a transformation programme, and I have laid out the fuller version in the AI Act readiness guide for growing companies.
One paragraph for the Danish readers, because the local version of “no regulator until 2027” is doubly wrong. Digitaliseringsstyrelsenis Denmark's coordinating national supervisory authority for the AI Act and its central contact point, with sector authorities supervising the rules inside their own areas and parts of the final allocation still being settled. At EU level, the Commission's AI Office supervises general-purpose AI models. The machinery is being stood up now, and the obligations it covers from August are the ones that did not move. A Danish company treating the Omnibus as a general stand-down order has misread both the EU calendar and the Danish one.
The test for whether you have kept the right things is simple, and it is the standard I hold my own clients to: when the next AI questionnaire arrives, and it will, can you answer it from documents you already have, without convening anyone? If yes, your programme is sized correctly. If the honest answer is a crisis meeting, you parked the wrong work.
Two calendars
The Omnibus gave you a real gift, just not the one in the headline: sixteen extra months on the work that probably was not yours, in exchange for noticing which work still is. The CTO's spreadsheet does not need to be finished by Monday. The answer to question 47 does. There are two calendars on your desk now, the regulator's and your revenue's, and only one of them was ever going to decide whether you close your next enterprise deal.