A Dangerous Misreading Has Taken Hold
On 29 June 2026, the EU Council gave its final green light to the "Digital Omnibus" package. The news spread quickly through IT leadership teams, usually boiled down to a convenient headline: the AI Act deadlines have been pushed back. That shortcut — now reflexively repeated in boardrooms and IT committees across Europe — could prove extremely costly.
Because not everything has been delayed. The 2 August 2026 deadline remains very real for two distinct obligations, entirely independent of the risk classification of the systems you operate.
What the Digital Omnibus Actually Postponed
For AI systems classified as high-risk under Annex III of the regulation — algorithmic recruitment, credit scoring, critical infrastructure management, or medical decision support — the delay is genuine. The original 2 August 2026 deadline has been pushed to 2 December 2027, a sixteen-month extension. AI systems embedded in regulated physical products under Annex I benefit from a further extension to August 2028.
This relief responds to a concrete regulatory bottleneck: the notified bodies responsible for certification simply did not have the capacity to process the expected volume of submissions. The revision also expands the "small mid-cap" definition — now covering companies with up to 750 employees and €150 million in revenue — providing a simplified compliance path for mid-sized organisations.
What Is Still Due on 2 August
Two major obligations fall outside the scope of any delay. This is exactly where many IT teams' assessments fall short.
Article 50 and its transparency requirements enter into application on 2 August 2026, with no carve-out for company size or risk classification. Any organisation that exposes a chatbot to users, publishes AI-generated content, or distributes synthetic media is in scope. The core obligation is straightforward: clearly inform users when they are interacting with an artificial intelligence. This covers conversational assistants, image generators, and synthetic audio or video content. Penalties for non-compliance can reach €15 million or 3% of annual global turnover — whichever is higher.
Enforcement powers over general-purpose AI (GPAI) model providers also become operational on 2 August. The underlying obligations themselves — technical documentation, copyright compliance policies, and training data summaries — have been in force since August 2025. What activates now is the enforcement arm of the AI Office: the authority to inspect, conduct technical evaluations, restrict market access, and impose fines of up to 3% of global turnover.
The Practical Risk for Organisations
The arithmetic here is unforgiving. The vast majority of businesses do not operate a high-risk AI system under Annex III. But almost all of them have integrated conversational AI into customer support, HR operations, or internal tooling. These deployments — perceived as low-stakes, often rolled out by business units without structured IT oversight — are precisely what falls under Article 50 as of 2 August.
The compliance audit required is bounded but non-trivial: map every AI touchpoint exposed to European users, verify that explicit transparency disclosures are in place, and document the chain of accountability between model provider and deployer.
Read the Legislation, Not the Headlines
The Digital Omnibus delivered welcome breathing room on high-risk AI systems. It did not suspend the AI Act. CIOs and IT leaders who interpreted the delay as a general stand-down are carrying a documentable — and sanctionable — risk. In regulatory compliance, reading precision is often worth more than the monitoring effort that preceded it.

