The headline was that the EU delayed the AI Act. That is roughly true of one obligation and misleading about everything else, and the gap between the headline and the text is where organisations lose time they thought they had.

The reform is real and it is law. Regulation (EU) 2026/1744 — formally, the regulation of 8 July 2026 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 as regards the simplification of the implementation of harmonised rules on artificial intelligence, known as the Digital Omnibus on AI — was published in the Official Journal on 24 July 2026 and entered into force on the third day following publication, 27 July 2026.

Here is what actually moved, what did not, and what was added.

The timeline as it now stands

ObligationApplies fromChange
Transparency obligations 2 August 2026 Unchanged. Already in effect.
Two new prohibited practices
Systems designed to generate or manipulate realistic intimate imagery, or child sexual abuse material
2 December 2026 New. Added by the Omnibus.
Stand-alone high-risk systems (Annex III) 2 December 2027 Deferred from 2 August 2026 — about sixteen months.
Product-embedded high-risk systems (Annex I) 2 August 2028 Deferred from 2 August 2027 — one year.

The three ways the headline misleads

1. Transparency obligations were not deferred

They applied from 2 August 2026. If your organisation read “the AI Act was delayed” in the spring and stood down its programme, this obligation arrived on schedule and is live now.

This is the most consequential misreading available, because it is the obligation most likely to touch an ordinary product team rather than a specialist compliance function.

2. Two new prohibitions were added

A reform framed as simplification and burden reduction also expanded the prohibited-practices list. The two new prohibitions target systems designed to generate or manipulate realistic intimate imagery or child sexual abuse material, and they apply from 2 December 2026.

Prohibitions are the sharpest end of the AI Act — they are bans, not compliance obligations you can document your way through. A summary that describes the Omnibus purely as a delay omits the one change that adds outright prohibitions to the statute.

3. Enforcement was consolidated, not loosened

The European AI Office gained exclusive supervisory responsibility for certain AI systems built on general-purpose AI models, and for AI systems integrated into very large online platforms and very large online search engines regulated under the Digital Services Act.

For organisations in those categories this is a structural change with practical consequences: it centralises the supervisory relationship at EU level rather than leaving it to national market surveillance authorities. That can simplify life — one regulator rather than twenty-seven — but it is not a reduction in oversight.

What the extra time is actually for

Sixteen months is a genuine reprieve for anyone with an Annex III system, and it is worth being clear-eyed about why it happened. The deferral was driven substantially by the harmonised standards not being ready: the technical specifications organisations were meant to build against were not available in time to build against them.

Two implications follow, and they point in opposite directions:

  • The work did not shrink. The obligations for Annex III systems are the same obligations; only the date moved. An organisation that stops now will face the same requirement with sixteen fewer months of runway.
  • The target is clearer than it was. The standards work that caused the delay is what will eventually tell you what compliance concretely looks like. Building against a moving target was genuinely hard; some of that difficulty resolves as the standards land.

The sensible posture is to keep going at a sustainable pace rather than either sprinting to an obsolete date or standing down. The classification work in particular — deciding which of your systems are high-risk at all — does not depend on the standards and can be finished now.

What to do, in order

  1. Confirm your transparency obligations are met. This one is live. Treat it as an immediate check, not a project.
  2. Check the new prohibitions against your product surface before 2 December 2026. Most organisations will be plainly outside them; those handling image generation or user-generated imagery should confirm rather than assume.
  3. Finish classification. Which of your systems fall in Annex III, which are Annex I safety components, which are neither? This is the foundation for everything else and needs no standards to complete.
  4. Establish your role for each system — provider, deployer, importer, distributor. Obligations differ sharply by role, and organisations frequently occupy more than one.
  5. Track the harmonised standards as they are published. They are what turn a legal obligation into a technical specification.
  6. Re-plan against December 2027 rather than treating the deferral as cancellation.

A note on reading anything published before August 2026

The Omnibus was provisionally agreed on 7 May 2026, adopted on 8 July, and published on 24 July. Guidance written between those dates may correctly describe a provisional agreement that had not yet been enacted — accurate when written, and now describing a superseded state of the world.

Anything published before May 2026 will show the original 2 August 2026 high-risk date, which is no longer correct. Anything that describes the Omnibus as "proposed" or "expected" is out of date: it is in force.

Check the date on any EU AI Act resource before relying on it, including this one. Nothing here is legal advice, and questions of classification or role should go to counsel qualified in EU law.