Europe Resets the Clock on the AI Act
Brussels has pushed its high-risk AI rules back to December 2027. For welfare offices, border agencies, police forces and schools, the extra sixteen months are a window to build governance, not a reprieve.

On 27 July 2026, the European Union quietly rewrote the most important date in its flagship technology law. The AI “omnibus” amendment, agreed politically on 6 May, approved by the European Parliament on 16 June, adopted by the Council on 29 June and signed on 8 July, entered into force that day, according to legal trackers following the file. It moves the obligations for stand-alone high-risk systems listed in Annex III of the AI Act from 2 August 2026 to 2 December 2027. Obligations for AI embedded in regulated products, under Annex I, now apply from 2 August 2028.
For the public sector, this is the date that matters. Annex III is where the state lives. It covers the systems governments use to decide who receives welfare, how migration and asylum claims are handled, how police assess risk, and how students are admitted and assessed. The delay gives public bodies that deploy such systems roughly sixteen more months. The temptation will be to treat that as breathing room. It is better understood as a construction schedule.
What changed, and what did not
The omnibus does more than move a deadline. Gibson Dunn’s analysis of the agreement notes that it adds a new prohibition on AI-generated non-consensual intimate imagery and child sexual abuse material, softens the Act’s AI-literacy duties and pushes back the deadline for national regulatory sandboxes to August 2027.
What it does not do is pause the whole regime. From 2 August 2026, the Commission’s AI Office can enforce the obligations on providers of general-purpose AI models, with fines available. It is the first time a regulator anywhere has had that power over frontier-model developers. Most of the transparency obligations in Article 50 also apply from that date, including the duty to disclose that a person is talking to a chatbot and to label deepfakes. Systems already on the market have a grace period on watermarking until 2 December 2026.
That matters directly for governments. A ministry running a citizen-facing chatbot in the EU already has disclosure duties. A public broadcaster or government communications unit publishing synthetic imagery already has labelling obligations. The practical standard for meeting them is the Commission’s Code of Practice on marking and labelling AI-generated content, published on 10 June 2026. Under that voluntary code, providers apply “at least two layers” of machine-readable marking, such as metadata plus a watermark, and deployers label deepfakes and AI-generated text on matters of public interest.
The new timetable
| Date | What applies | Who it affects |
|---|---|---|
| 10 June 2026 | Final Code of Practice on marking and labelling AI-generated content published (voluntary) | Model providers; deployers publishing synthetic content on matters of public interest |
| 27 July 2026 | AI omnibus enters into force, including the new ban on AI-generated non-consensual intimate imagery and CSAM | All providers and deployers |
| 2 August 2026 | AI Office enforcement of general-purpose AI model obligations begins; most Article 50 transparency duties apply | Frontier-model providers; any body running chatbots or publishing deepfakes, including governments |
| 2 December 2026 | Watermarking grace period ends for systems already on the market | Providers of existing generative systems |
| August 2027 | National AI regulatory sandboxes due | Member-state authorities; innovators testing systems |
| 2 December 2027 | Annex III stand-alone high-risk obligations apply | Public bodies using AI in welfare, migration, policing and education; their vendors |
| 2 August 2028 | Annex I obligations apply to AI embedded in regulated products | Manufacturers of regulated products and those who deploy them |
Why waiting is the wrong lesson
There are reasonable arguments for the delay. Standards were not ready, national authorities were unevenly staffed, and industry and several member states warned that the original timetable would produce rushed, box-ticking compliance. A later deadline that is actually met may protect citizens better than an earlier one honoured only on paper.
But the high-risk obligations are not a form to be completed in November 2027. They describe an operating model: risk management that runs for the life of a system, data governance, documentation, human oversight with real authority, logging and post-deployment monitoring. For a public body, those are not features a vendor can bolt on. They depend on procurement contracts that grant audit rights, on case workers trained to overrule a recommendation, and on records that survive staff turnover. Each takes longer than sixteen months to build properly inside a large administration.
A deadline that moves once can move again, but the duty to explain a welfare decision to the person who received it never had a deadline at all.
There is also a political lesson. Brussels has shown it will move dates when industry and member states push hard enough. Some ministries may read that as a signal that further slippage is possible. That is a gamble. Contracts signed today for systems that will still be running in 2028 will be judged against the rules then in force, and retrofitting oversight into a live benefits or border system is far more expensive than designing it in. Courts, ombudsmen and data-protection authorities, meanwhile, already apply existing law to automated decisions regardless of the AI Act’s calendar.
Europe is no longer alone
The delay also changes Europe’s position abroad. South Korea’s AI Basic Act took effect on 22 January 2026, covering high-impact and generative AI with transparency, risk-management and labelling duties and a requirement for foreign firms to appoint domestic representatives. Fines and investigations are generally deferred during 2026, so enforcement begins in early 2027, according to the US International Trade Administration. On that timetable, Seoul may be enforcing comprehensive AI obligations before Brussels enforces its high-risk rules.
India has taken a different route. Amended IT Rules, effective since 20 February 2026, require prominent labels and embedded provenance metadata on synthetic content and three-hour compliance with takedown orders, down from 36 hours. It is one of the most aggressive deepfake regimes in a large democracy, and speech-rights advocates are watching it closely. It shows that transparency on synthetic media, the part of the EU regime already live, is becoming a global baseline rather than a European peculiarity.
What to watch
- Whether the Official Journal text confirms the in-force date and the exact scope of the new prohibition.
- The first enforcement signals from the AI Office on general-purpose models.
- How member states use the sandbox deadline of August 2027 to test public-sector systems before the Annex III date.
- Whether public bodies publish inventories of Annex III systems now, rather than in late 2027.
Sources
- Gibson Dunn — EU AI Act omnibus agreement: postponed high-risk deadlines and other key changes
- Usercentrics — EU AI Act high-risk delay and Article 50 transparency
- Taylor Wessing — GPAI obligations under the EU AI Act
- Jones Walker — Yes, 2 August still matters
- Jones Day — Commission publishes final Code of Practice on marking and labelling AI-generated content
- US International Trade Administration — South Korea AI Basic Act
- Hogan Lovells — India introduces mandatory labelling for AI and three-hour takedown
Discussion
No comments yet. Start the conversation.


