For weeks the headline has been that the big EU AI Act deadline slipped. That is true, but only for half of it. Read it as "nothing happens on 2 August 2026" and you have misread it. One set of obligations lands on exactly that date, and it is the set that touches every business running a customer-facing AI system.
The confusion traces back to the Digital Omnibus, an amendment package to the AI Act. The European Parliament voted for it on 16 June 2026, the Council approved it on 29 June 2026, and it entered into force in July. Based on our reading of the published law-firm analyses, it reshuffles the deadlines rather than scrapping them.
What got pushed back
The delay applies to high-risk systems. These are the applications listed in Annex III of the AI Act: candidate screening and other HR tools, credit scoring, biometric identification, AI in critical infrastructure, certain systems in education and justice. For these standalone high-risk systems, the deadline moves from August 2026 to 2 December 2027. That is roughly 16 extra months.
High-risk AI embedded in regulated products, meaning Annex I, moves even further out, to 2 August 2028.
The reason is unglamorous. The harmonised standards and conformity tools that a business needs in order to prove high-risk compliance were not ready. Designation of the national supervisory authorities also lagged. So the delay is less a change of political heart than an admission that the machinery to comply was missing.
What stays on 2 August
The Article 50 transparency obligations stay exactly where they were. They apply on 2 August 2026. These rules do not depend on whether your system counts as high-risk, and they reach far more businesses than the Annex III list. Three cases matter:
- An AI system that interacts directly with people, such as a customer-service chatbot, must make clear to the person that they are talking to a machine, unless that is already obvious.
- AI-generated or manipulated content, meaning synthetic image, audio, video or public-facing text, must be marked as artificially produced. Deepfakes fall squarely under this.
- Emotion recognition and biometric categorisation systems must inform the people exposed to them.
One detail that is easy to miss: the provider duty to mark synthetic output in a machine-readable way (Article 50(2)) does not, per the analyses we have seen, hit systems already on the market on 2 August 2026 straight away. Those legacy systems get a grace period to 2 December 2026. A new system you launch today cannot lean on that.
Why the delay is not a free pass
The extra 16 months are a gift to preparation, not to inaction. A candidate-screening tool or an internal credit engine stays high-risk whether or not the formal deadline arrives later. The documentation, logging, human oversight and risk assessment that the AI Act demands for such systems do not get built in four weeks. Companies that book the extra time as breathing room will face the same mountain in December 2027 with less air.
There is also this: the General Data Protection Regulation applies throughout. If you push personal data through an AI system, you have duties independent of the AI Act. The Omnibus delay does not touch the GDPR.
What this means for local AI
Here is the practical lever. Running an AI system on-premise does not exempt you from the transparency duty. The chatbot still has to identify itself as AI even when it sits on your own server. But the obligations that bite in 2027 and 2028 land precisely where a local build shows its strength: traceable logging, control over training and input data, complete documentation of data flows, no murky handoff to third parties.
With a cloud API, the logs, model versions and data processing sit with the provider. A business that later has to prove high-risk conformity is collecting evidence secondhand. A stack you run yourself turns those proofs into a question of your own configuration. That is the core of data sovereignty, and it is why we do not treat compliance questions and local AI as separate problems.
A concrete example
Take a small trade business with a support chatbot on its website and an AI tool that produces images for social-media posts. Under Annex III neither counts as high-risk, so the December 2027 deadline does not touch it. Article 50 does: the chatbot needs a note that an AI is answering, and the generated images need a marker that they were artificially produced. Two small changes, due on 2 August. That same firm, if it rolls out AI-assisted candidate screening a year later, lands in the high-risk category and should spend the extra time on documentation and oversight rather than let it slide by.
Concrete steps before August
For most SMEs, 2 August comes down to a short list. Check whether any of your systems chats with customers or staff, generates content that goes public, or runs emotion or biometric recognition. If one of those applies, put clear labelling in place. A visible notice on the chat window and a marker on AI-generated content cover most of it.
For anything that sounds like Annex III, start with the inventory, not with the deadline in mind. December 2027 is nearer than the number suggests.
This is our reading of the current legal position and does not replace a review of your specific case. If you want to know which of your systems are affected and what an audit-ready local build looks like alongside them, talk to us about a pilot project.