European AI Act: full application and lessons from the first cycle
Updated: 2026-07-07
The European AI Act took effect on 1 August 2024 with a staggered calendar, and its Annex III high-risk rules no longer land in August 2026. The Digital Omnibus, closed by the Parliament and the Council, moves that deadline 17 months to 2 December 2027. Prohibitions since February 2025 and general-purpose AI duties since August 2025 still apply.
The European AI Act entered into force on 1 August 2024, with a staggered calendar: absolute prohibitions and basic transparency obligations started applying on 2 February 2025, and general-purpose AI obligations arrived on 2 August 2025. The original calendar planned for Annex III high-risk systems (hiring, credit scoring, education, border security) to reach full application on 2 August 2026. That is not going to happen on that date. In the past few weeks the European Parliament and the Council closed the so-called Digital Omnibus, which pushes that full application back 17 months, to 2 December 2027. This piece covers what still applies this year, what exactly changed, and what it means in practice for anyone who has to comply with the law.
Key takeaways
-
Most Annex III high-risk obligations (hiring, credit, education, border systems) are delayed 17 months: from August 2026 to December 2027.
-
AI embedded in regulated products under Annex I (medical devices, machinery, vehicles) moves from August 2027 to August 2028.
-
Transparency for AI-generated content (Article 50) still enters into force on 2 August 2026; systems already on the market before that date get until 2 December 2026 to add the technical watermark.
-
The European Parliament passed the package on 16 June 2026 with 423 votes in favour, 57 against, and 174 abstentions; the Council gave its final green light on 29 June.
-
Digital-rights organisations such as EDRi say the package hollows out a central part of the Act, chiefly by removing mandatory registration of high-risk systems in the EU’s public database.
What still applies this year
The headline is the delay, but not everything moved. Absolute prohibitions (generalized social scoring, biometric identification in public spaces without judicial authorization) have been in force since February 2025, and the Digital Omnibus does not touch them. General-purpose AI obligations (technical documentation, copyright compliance, systemic-risk assessment for the largest models) remain in force since August 2025.
Transparency for AI-generated content is not going away either: Article 50 enters into force on 2 August 2026 as planned. What relaxes is only the technical deadline for watermarking systems already on the market before that date, which now get until 2 December 2026. The package also adds a new prohibition: generating non-consensual intimate imagery (so-called "nudifiers"), with removal from the market required before 2 December 2026.
For the technical side of all this, we already covered in detail what the regulation means for teams shipping systems into production in our checklist for Spanish CTOs.
The twist: what the Digital Omnibus actually changes
Here is what was on the original calendar and no longer applies on its initial date:
-
Annex III (stand-alone high-risk systems): full application moves from 2 August 2026 to 2 December 2027. That is 17 extra months to classify systems and build risk management, human oversight, and incident logging.
-
Annex I (AI embedded in regulated products): moves from August 2027 to August 2028.
-
Mandatory registration in the EU’s public database: the agreement removes, for certain cases, the obligation to register a system if the provider itself concludes it is not high-risk. This is the point that has angered digital-rights organisations the most, because it shifts the classification decision to the provider itself without prior external verification.
The official reason for the delay is technical: the harmonised standards that translate the legal text into verifiable requirements are not ready, and without them no company can genuinely audit whether it complies. European Commission Executive Vice-President Henna Virkkunen summed it up during the negotiation: "Our businesses and citizens want two things from AI rules. They want to be able to innovate and feel safe."
What critics say
Not everyone reads this as a reasonable technical simplification. EDRi (European Digital Rights), the main European network of digital-rights organisations, has described the removal of mandatory registration for high-risk systems as a move that risks "hollowing out a core pillar of the AI Act and turning it into an optional, compliance-light framework." Its argument, shared in a letter signed by sixty organisations and independent bodies, is that the real savings for companies are marginal against the cost in oversight and rights protection.
My own reading, without taking either side: the technical argument for the delay (harmonised standards are not ready) is real and verifiable, not an invented excuse. But EDRi’s argument is also reasonable: letting a provider decide on its own whether its system is high-risk, without prior verifiable registration, changes who watches whom. Both things can be true at once, and I think they are.
What companies should do now
December 2027 sounds far away, but classifying systems, building effective human oversight, and standing up incident-logging infrastructure cannot be improvised in a quarter. Companies that were already working toward August 2026 should keep the same pace: the delay buys margin, it does not remove the future obligation, and the harmonised standards that are missing today will arrive well before December 2027, not in the last month.
For anyone who has not yet started mapping which of their own systems would fall under Annex III, classification is still the practical first step, delay or not. And for teams evaluating where to host and train these systems within the Union, it is worth reviewing the implications we covered in our analysis of sovereign AI in Europe.
My reading
The headline I was originally going to write about this cycle was a different one: a scorecard of sanctions and lessons from a year of full application that, simply, has not happened yet. The AI Act, eighteen months after entering into force, is still a work in progress whose most demanding deadline keeps moving forward.
For companies, the practical takeaway does not change much because of the delay: treating compliance as a continuous process integrated with risk management is still cheaper than treating it as a last-minute project. What does change is the deadline for paying the price of getting that wrong, and anyone tempted to relax for another seventeen months should remember that the last time the calendar moved was a few weeks ago, not years ago.