If your compliance team spent the summer bracing for August 2, 2026 as a hard cutover to full high-risk AI obligations, you weren't wrong to prepare — you were working from the timeline that stood until just weeks before the date. The EU's Digital Omnibus on AI, signed July 8, 2026, moved the goalposts for a large chunk of the Act's highest-stakes requirements. Understanding what actually shifted, and what didn't, matters more than the headline deadline itself.

Aug 2, 2026
binding date for Article 50 transparency obligations
Dec 2027
new deadline for stand-alone Annex III high-risk systems
€15M
or 3% of global turnover — maximum penalty for non-compliance

What's live as of August 2, 2026

Article 50's transparency obligations are enforceable now, regardless of the Digital Omnibus changes: chatbot disclosure requirements, synthetic content marking, and deepfake labeling all apply. If your product or any agent-facing customer interaction generates AI content or holds a conversation without disclosing that it's AI, that's the part of the Act you're exposed on today — not the high-risk provisions everyone was watching for.

What got pushed back, and why it matters that it did

The Digital Omnibus split the high-risk timeline in two. Stand-alone Annex III systems — the category covering most task-specific enterprise agents making consequential decisions about people, like hiring or credit — now have until December 2, 2027. AI embedded in already-regulated products under Annex I (medical devices, machinery, and similar categories) has until August 2, 2028. Provider obligations under Articles 9 through 17 and deployer obligations under Article 26 follow that same extended clock for the systems it applies to.

That's real breathing room — but treating it as permission to deprioritize AI governance work would be a mistake. The extension exists because regulators recognized that conformity assessment infrastructure (the auditors, the standards bodies, the assessment tooling) wasn't ready industry-wide, not because the underlying risk concerns went away.

A delayed enforcement date isn't a delayed risk. It's a longer runway to get the governance right before the deadline that actually matters for your systems arrives.

Why "we have until 2027" is the wrong takeaway

Two reasons. First, penalties for the parts of the Act that are already enforceable are steep enough — up to €15 million or 3% of global annual turnover, whichever is higher — that even non-high-risk missteps carry real exposure. Second, building audit trails, human-oversight checkpoints, and documented risk assessments into an AI agent after it's already in production is dramatically more expensive than building them in from the start. Every enterprise agent deployment happening right now, high-risk classification or not, benefits from being built as if the deadline were tomorrow.

What this means for agent deployments specifically

If your AI agents make or materially influence decisions about employment, credit, benefits eligibility, or similar high-stakes categories, assume Annex III classification applies to you eventually and build accordingly now: human-in-the-loop checkpoints for consequential actions, a documented decision trail for every action an agent takes, and a way to demonstrate what data the agent had access to when it acted. This is exactly the governance layer Acclivity's AI Ethics & Governance and Legal agents are built to maintain continuously, rather than as a one-time audit exercise.