
For two years, 2 August 2026 was circled in every European compliance calendar as the day the AI Act's high-risk obligations would start to bite. Then, at the end of July, the Digital Omnibus entered into force and moved the goalposts: the obligations for stand-alone high-risk systems listed in Annex III are deferred to 2 December 2027, and for AI embedded in regulated products under Annex I to 2 August 2028.
What did take effect on August 2
The deferral is not a pause on the whole Act. Since 2 August 2026, the transparency obligations of Article 50 are enforceable: people must be told when they are interacting with an AI system, synthetic content has to be labeled, and deepfakes must be identified as such. The same date activated the Commission's enforcement powers over general-purpose AI models and the full penalty regime, with fines of up to €35 million or 7% of global turnover for the most serious violations.
If your product has a chatbot in front of customers, generates images, audio or text that could be mistaken for human-made, or fine-tunes a general-purpose model, you are already inside the enforceable part of the regulation.
The deferral is a window, not a waiver
For systems in hiring, credit scoring, education, critical infrastructure and the other Annex III domains, the substance of the requirements has not changed: risk management, data governance, technical documentation, human oversight, logging and post-market monitoring are all still coming. Only the date moved. In our experience, a credible conformity setup takes 12-18 months to build, which makes December 2027 closer than it looks.
What we recommend doing now
- Inventory every AI system you build or deploy and classify it against Annex III; most companies find more in-scope systems than they expected.
- Ship Article 50 compliance immediately: AI-interaction disclosures, synthetic-media labeling and deepfake identification are live obligations, not future ones.
- Assign clear ownership for AI governance and start the technical documentation while systems are still small enough to document cheaply.
- Build evaluation, logging and human-oversight hooks into your systems now, because retrofitting them under deadline pressure is the expensive way.
We help teams turn this from a legal reading exercise into an engineering backlog: system inventories, gap analyses and the technical controls that make compliance a property of the architecture rather than a binder on a shelf.