CFOtech UK - Technology news for CFOs & financial decision-makers
United Kingdom
Everyone read 'EU Delays AI Act' wrong, here's the actual timeline

Everyone read 'EU Delays AI Act' wrong, here's the actual timeline

Wed, 26th Aug 2026 (Today)
Graham Melville
GRAHAM MELVILLE Head of Marketing Veraify

For most of 2025 and early 2026, August 2, 2026, was the date that organized enterprise AI compliance planning across Europe. It was when the AI Act's high-risk obligations were scheduled to bite, and it drove budget, roadmaps, and board attention accordingly. That date has since moved, but not in the way a lot of headlines suggested.

What actually happened

On June 16, 2026, the European Parliament gave final approval to the Digital Omnibus on AI, the first substantive amendment to the AI Act since it was adopted in 2024. The Council of the EU followed with final approval on June 29, 2026. The change defers the compliance deadline for standalone high-risk systems under Annex III (recruitment, credit scoring, education, law enforcement, and similar uses) from August 2, 2026 to December 2, 2027, a 16-month push. High-risk AI embedded in already-regulated products under Annex I, things like medical devices, lifts, and machinery, moves from August 2, 2027 to August 2, 2028.

The reason wasn't a change of heart on substance. The harmonized standards that were supposed to give high-risk systems a presumption of conformity, along with the notified-body and conformity-assessment infrastructure the Act assumes exists, simply weren't ready. The requirements themselves are unchanged. Only the date they take effect has moved.

What didn't move

This is the part that gets lost in "EU delays AI Act" headlines. The prohibitions on unacceptable-risk AI practices have applied since February 2, 2025, and are untouched. General-purpose AI model obligations have applied since August 2, 2025, and are also untouched. And Article 50's transparency rules, disclosure of AI interactions, labeling of synthetic content, and deepfake identification were not part of the deferral. They took effect on schedule, and they reach a much broader set of companies than the high-risk category alone, since transparency duties apply to any customer-facing chatbot, AI-generated image or video, or AI-authored content touching EU users, not just the narrower list of high-risk use cases.

Who this applies to

The Act reaches providers who place AI systems on the EU market, deployers who operate high-risk systems inside the EU, and third-country organizations whose AI outputs are used by people in the EU. That last category matters for U.S. companies: exposure exists even without an EU entity, though how aggressively it gets enforced against a business with no EU presence remains an open question, similar to how GDPR enforcement against non-EU companies has played out unevenly in practice.

The security requirements, read carefully

Article 15 requires high-risk systems to be resilient against attempts by unauthorized third parties to alter their use, outputs, or performance by exploiting vulnerabilities, alongside baseline accuracy and robustness requirements. It's tempting to read that as a mandate for a specific security architecture, for example, treating every API a system or agent calls as a regulated attack surface. That's a defensible interpretation of what good practice under Article 15 looks like, but it's not what the statute says word for word. Worth presenting as an implication, not a literal requirement.

Article 10 is a distinct provision, focused on data and data governance, primarily the quality, relevance, and management of training, validation, and testing datasets. It's easy to blur this with cybersecurity obligations, but its core purpose is data quality and governance, not access control.

Penalties

Fines for Article 50 transparency violations and GPAI-tier violations top out at €15 million or 3% of global annual turnover, whichever is higher. That's the ceiling most companies watching the August deadline should have in mind. It's not the top of the Act's penalty scale, though: violations of the prohibited-practices regime under Article 5 carry a higher maximum of €35 million or 7% of global turnover. A separate GDPR track, up to €20 million or 4% of worldwide turnover, runs independently for mishandling personal data, particularly biometric or emotion-recognition uses, regardless of where the AI Act's own deadlines land.

Other changes worth knowing

The amendments added a new prohibited practice targeting AI-generated non-consensual intimate imagery and CSAM, effective December 2, 2026. SME compliance simplifications were extended to mid-caps (up to 750 employees and €150 million in revenue), including lighter documentation and sandbox access. Rules around using sensitive personal data to detect and correct bias in AI models were eased. And products already governed by the EU's Machinery Regulation are being moved toward a sectoral approach rather than a blanket carve-out, with AI-related safety requirements to be folded into future updates to that regulation by August 2, 2028.

The bottom line

"Delayed" isn't "off the hook." The high-risk compliance clock moved; the underlying obligations didn't. Meanwhile, transparency duties, GPAI obligations, and the prohibited-practices regime are already live or arriving this year regardless of the high-risk deferral. Teams that read the delay as a license to stand down are conflating one tier of the Act with the whole thing. The extra runway on high-risk requirements is best used to close a gap, not to file the deadline away for 2027.