What was actually deferred, and what was not
Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026. It moved two dates. It did not roll back anything already in force, and it added two prohibitions.
Binding today
- Prohibited practices — since 2 February 2025 (Article 5)
- AI literacy — since 2 February 2025 (Article 4)
- General-purpose AI models — since 2 August 2025 (Article 53)
- Transparency — since 2 August 2026 (Article 50)
Deferred
- Annex III high-risk — 2 August 2026 moved to 2 December 2027
- Annex I products — 2 August 2027 moved to 2 August 2028
The stated reason was that the conformity-assessment infrastructure, harmonised standards and designated notified bodies, was not ready. That shortage is not resolved by waiting for it.
There is also a date between the two that is easy to miss. 2 December 2026 brings two new prohibitions, on AI that generates non-consensual intimate imagery and on AI that generates child sexual abuse material, and closes the transitional window for marking generative systems that were already on the market. Neither is grandfathered. What the Omnibus changed, clause by clause.
Check your position
What applies to you
Eight answers, about a minute. Nothing you enter leaves your browser or is stored; the result lives in the page address, so you can send it to a colleague.
Every obligation this guide covers, dated
8 obligations are live; 3are scheduled. Dates are read from the Act's application timetable as amended, last checked against the consolidated text on 11 August 2026.
| Applies from | Status | Obligation | Who it binds | Provision |
|---|---|---|---|---|
| 2 February 2025 | Live | Support AI literacy in anyone using AI on your behalfYou must take measures to support a sufficient level of AI literacy among staff and anyone else operating AI systems for you. It binds every provider and deployer, and it was not deferred. | Provider, Deployer, Product manufacturer | Article 4 |
| 2 February 2025 | Live | Confirm you are running none of the prohibited practicesEight practices are banned outright across the EU, and none of the deferrals touched them. Two more, covering non-consensual intimate imagery and child sexual abuse material, are added from 2 Dec 2026 with no grandfathering. | Provider, Deployer, Importer, Distributor, Product manufacturer | Article 5 |
| 2 February 2025 | Live | Watch for the point where you become the providerRole is fixed per system, not per company. A deployer takes on the provider's obligations by putting its own name or trade mark on a high-risk system, substantially modifying one, or changing its purpose so that it becomes high-risk. | Deployer | Article 25 |
| 2 August 2025 | Live | Meet the general-purpose AI model obligationsProviders of GPAI models owe technical documentation, information to downstream providers, a copyright policy and a training-content summary. Models meeting the systemic-risk threshold carry evaluation, incident-reporting and cybersecurity duties on top. | Provider | Article 53 |
| 2 August 2026 | Live | Tell people they are dealing with an AIAnyone interacting with your AI system must be able to tell that it is an AI, unless that is obvious from the context. For a chatbot the disclosure has to come before or at the very start of the conversation, not buried in a policy. | Provider, Deployer | Article 50(1) |
| 2 August 2026 | Live | Mark synthetic output in a machine-readable formatProviders of systems that generate synthetic audio, image, video or text must mark that output so it is detectable as artificially generated. Systems placed on the market before 2 Aug 2026 have until 2 Dec 2026 to comply. | Provider | Article 50(2) |
| 2 August 2026 | Live | Tell people when emotion recognition or biometric sorting is in useDeployers of emotion recognition or biometric categorisation systems must inform the people exposed to them. Note the prior question: in the workplace and in education, emotion inference is prohibited, so disclosure will not save it. | Deployer | Article 50(3) |
| 2 August 2026 | Live | Label deep fakes and AI-written public-interest textDeployers must disclose that image, audio or video content is artificially generated or manipulated, and that AI-generated text published to inform the public on matters of public interest is AI-generated. | Deployer | Article 50(4) |
| 2 December 2026 | Scheduled | Bring already-live generative systems into markingGenerative systems already on the market before 2 Aug 2026 were given a transitional window. It closes on the date shown against this duty. | Provider | Article 50(2) |
| 2 December 2027 | Scheduled | Build the high-risk regime for your Annex III useThe Annex III high-risk obligations were deferred. That is a schedule change, not a reprieve: risk management, data governance, technical documentation, logging, human oversight and conformity assessment all still have to exist by then, and the work takes longer than the time remaining suggests. | Provider, Deployer | Article 6, Annex III |
| 2 August 2028 | Scheduled | Fold AI conformity into your existing product routeWhere AI is a safety component of a product already covered by EU harmonisation law, the high-risk obligations apply from this date and are assessed through the sectoral conformity route you already use. | Provider, Product manufacturer | Annex I, Article 6(1) |
Provider or deployer? It is decided per system
This is the single most common error in AI Act compliance work: treating provider and deployer as labels for the company. They are not. They attach to each system, and one organisation is routinely both — the deployer of a support chatbot it bought, and the provider of the scoring model it built.
| Provider | Deployer | |
|---|---|---|
| You are this if | You develop the system, or place it on the market under your own name or trade mark | You use the system as supplied, under your own authority |
| Typical example | You built the CV-ranking model, or you white-labelled someone else's | You subscribe to a recruitment tool and screen candidates with it |
| Transparency duty | Build the disclosure and the machine-readable marking into the system | Give notice to the people exposed to it, and label deep fakes |
| If high-risk | The full Chapter III regime, conformity assessment and registration | Use per instructions, keep logs, assign human oversight, and run the fundamental rights impact assessment |
The trap in Article 25
A deployer becomes the provider, with every obligation that carries, by putting its name or trade mark on a high-risk system, substantially modifying one, or modifying its purpose so that it becomes high-risk. Fine-tuning and white-labelling are the two routes organisations take without realising the role has changed underneath them. Read Article 25.
Common questions
- Was the EU AI Act delayed?
- Part of it. Regulation (EU) 2026/1744 deferred the Annex III high-risk obligations to 2 December 2027 and the Annex I product obligations to 2 August 2028. Nothing already in force was rolled back. The Article 5 prohibitions and the Article 4 AI literacy duty have applied since 2 February 2025, the general-purpose AI model rules since 2 August 2025, and the Article 50 transparency rules since 2 August 2026.
- Our AI is not high-risk. Does that mean we have nothing to do?
- No. Three sets of obligations apply regardless of risk tier. You must not run any prohibited practice. You owe an AI literacy duty for anyone operating AI on your behalf. And if your AI talks to people or generates content, Article 50 transparency applies to it now, whatever its risk classification.
- Are we a provider or a deployer?
- Both, usually. The roles attach to each system rather than to the company. You are the provider of a system you develop, or one you place on the market under your own name or trade mark. You are the deployer of a system you use as supplied. Under Article 25 a deployer becomes the provider by putting its name on a high-risk system, substantially modifying it, or changing its purpose so that it becomes high-risk.
- Do we have to do anything if we only use ChatGPT or Copilot?
- Yes, though not much. You are a deployer. The AI literacy duty applies to your staff, the prohibitions apply to how you use the tool, and if you expose an AI assistant to customers you owe the Article 50 disclosure. You do not inherit the model provider's obligations by using their API.
- What is the next EU AI Act deadline?
- 2 December 2026: two new prohibited practices take effect, covering AI that generates non-consensual intimate imagery and AI that generates child sexual abuse material, and generative systems placed on the market before 2 August 2026 must carry machine-readable marking. Neither is grandfathered.
Where to go next
- Classify a single systemThe full assessment: Annex I and Annex III routing, penalty exposure, and a PDF record you can file as evidence.
- Work the compliance checklistEvery step from building a system register to post-market monitoring, each cited to its provision.
- See the full timetableEvery application date, what switches on, and what the Omnibus moved.
- Meet the Article 4 literacy dutyThe obligation that has bound every organisation using AI since February 2025.
This page describes Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744. It is an independent information resource, not legal advice, and it classifies organisations rather than systems. Where a classification carries consequence, take it through a per-system assessment and record the reasoning.