Insights · EU AI Act

The AI Act after the omnibus: what was postponed, and what applies next week?

On 27 July 2026 the AI Omnibus entered into force. The date everyone was preparing for — 2 August 2026 — has moved to December 2027 for high-risk systems. But postponement is not exemption, and part of the regime starts next week.

Published 28 July 2026 · Reading time ± 6 minutes · General information, not legal advice

Anyone who built an AI programme over the past two years aimed at one date: 2 August 2026, when the bulk of the EU AI Act was to apply, including the heavy rules for high-risk systems. That plan no longer holds. On 27 July 2026 the AI Omnibus — the package with which the European legislator simplifies the regulation and staggers its introduction — entered into force.

What actually moved

The main change concerns high-risk systems. Stand-alone high-risk AI — the Annex III categories, which include recruitment and selection, employee evaluation, creditworthiness and access to essential services — now falls under rules that apply from 2 December 2027. High-risk AI embedded in regulated products such as medical devices and machinery follows on 2 August 2028. In addition, the obligation to register exempted AI systems in the central EU database has been removed, and the mandatory harmonised post-market monitoring plan has been dropped.

The change to AI literacy is notable. Since February 2025 this counted as a hard obligation for organisations: make sure staff working with AI are sufficiently competent. That requirement has now been replaced by non-binding encouragement, with the Commission and Member States taking a stronger role in promoting it. Expect months of confusion — many guides still list AI literacy as mandatory.

What does start on 2 August 2026

The transparency obligations in Article 50 remain and apply from next week. In practice: people must know they are interacting with an AI system rather than a colleague. Anyone deploying emotion recognition or biometric categorisation must inform the people concerned. Artificially generated or manipulated image, audio and video content that resembles reality — deepfakes — must be clearly and distinguishably labelled as such. A short transition period until 2 December 2026 applies to machine-readable marking of synthetic content.

That touches more organisations than it appears. A chatbot on your customer portal, an AI voice in your telephony, generated imagery in your marketing: none of these are exotic, and the duty to disclose sits with whoever deploys the system.

You are usually a deployer, not a provider

Most organisations do not build AI — they buy it, often without noticing, as a feature inside software they already had. In the regulation's terminology that makes you a deployer, not a provider. That distinction determines which obligations apply to you, and it is exactly the distinction missing from most AI policy documents.

The core deployer duties: use the system in accordance with the provider's instructions for use; assign human oversight to people with the necessary competence, training and authority; ensure input data is relevant and sufficiently representative where you control that data; monitor operation, inform the provider and the market surveillance authority when a risk is identified and suspend use where needed. Automatically generated logs must be kept for at least six months, workers' representatives and affected staff must be informed before workplace deployment, and you use the provider's information to meet your GDPR data protection impact assessment obligation.

That six-month log retention is the most underestimated point in practice. It is the evidence a supervisor asks for, and you can only deliver it if your contract obliges the vendor to make those logs available.

Penalties depend on the breach

Prohibited AI practices carry the heaviest regime: up to 35 million euro or 7% of total worldwide annual turnover, whichever is higher. Breaching most other obligations — including deployer duties and the transparency obligations starting next week — carries up to 15 million euro or 3%. Supplying incorrect or misleading information to an authority costs up to 7.5 million euro or 1%. For SMEs and start-ups the lower of the amount or the percentage applies.

Supervision in the Netherlands

The Netherlands is working on its AI Act implementation act. The cabinet took a step in April 2026 and the public consultation ran until 1 June 2026. Under the intended arrangement the Dutch data protection authority gains a dedicated AI division and the Radiocommunications Agency takes a coordinating role, alongside existing sectoral supervisors. Expect further movement here.

What this means for your planning

It is tempting to shelve the AI file for a year. That is unwise for three reasons. The transparency duties start next week. The work you must do before December 2027 — knowing which AI you use, from whom, for what and with which data — is the same work you already need for vendor risk, and it takes months. And your own customers and regulators will ask regardless of the European calendar.

The practical order is unchanged: discover what is running, classify each system, record in contracts what you need in documentation and logging, and only then write policy. Reverse that order and you are writing policy about systems you do not know. That is how we set it up too: our AI governance approach starts with the inventory, not the document.

Note: the consolidated text of the amended regulation was not yet available at the time of publication, so we cite the Commission and Council announcements. Have your specific situation assessed by your legal adviser.

Want to know which AI systems fall under the regulation in your case?

We inventory your AI usage, classify each system and record the evidence a supervisor will ask for. Your AI inventory is ready within four weeks.