Back to Blog
Data & Governance

The EU AI Act Deadline Moved. Here Is What Changed and What Did Not

A
Arun Godwin Patel
July 31, 20266 min read

The Digital Omnibus pushed the high-risk deadline to December 2027. Plenty of other duties did not move at all. A plain-English summary of what actually changed for UK businesses.

A timeline showing the high-risk deadline moving from August 2027 to December 2027, while the literacy and transparency duties stay where they were.

If you have spent any of this year being told that August 2026 was a hard deadline for the EU AI Act, you will have noticed the story change a few weeks ago. The Digital Omnibus on AI was published in the Official Journal on 24 July and entered into force on 27 July, and it moved one of the headline dates by sixteen months.

What it did not do is cancel the rest, which is the part being lost in the coverage. Several duties landed on schedule at the start of this month and are now live.

This article is part of our guide to the EU AI Act for UK businesses.

What moved

High-risk AI systems under Annex III were due to face full compliance obligations from 2 August 2026. That is now 2 December 2027.

Annex III is the standalone high-risk list: systems used in recruitment and worker management, education access, credit scoring, essential services, law enforcement, and similar. If you use AI to sift job applicants or assess creditworthiness, this is the category you were worried about.

High-risk AI embedded in regulated products under Annex I moved further still, to 2 August 2028. This covers AI inside machinery, medical devices, lifts and other products already governed by EU product safety law.

The heavy compliance work attached to both categories, conformity assessments, registration, risk management systems and technical documentation, is what has been deferred.

What did not move

This is the shorter list and the more immediately relevant one.

Article 50 transparency duties applied from 2 August 2026 as originally planned. You must disclose when a person is interacting with an AI system, and label AI-generated or manipulated content. This one catches far more businesses than the high-risk rules ever would, because it applies to anyone running a chatbot or publishing generated content. We cover it in Article 50: when you have to tell people they are talking to AI.

Article 4 AI literacy has applied since 2 February 2025, and supervision of it began on 2 August 2026. Organisations must ensure a sufficient level of AI literacy among staff and others operating AI on their behalf. Around 22 per cent of UK businesses have given AI governance training to the people deploying it, which suggests most are not currently in a position to demonstrate compliance. See Article 4: your staff are already required to understand AI.

Prohibited practices under Article 5 have been in force since 2 February 2025. Social scoring, certain emotion recognition in workplaces and education, untargeted facial image scraping. These carry the heaviest penalties in the Act.

General-purpose AI provider obligations have applied since 2 August 2025. Relevant if you build models, not if you use them.

Why this matters for a UK business

The UK has not adopted the AI Act, and it can still reach you. Scope follows the market, not the office. If you place an AI system on the EU market, or the output of your AI system is used in the EU, you can be in scope regardless of where you are based.

For most UK SMEs the practical exposure is Article 50 and Article 4 rather than the high-risk regime, which is precisely the part that did not move. If you concluded from the headlines that you have until December 2027, that conclusion is probably wrong for the duties that actually apply to you.

The five-question test in does the EU AI Act apply to my UK business will settle your position in about ten minutes.

What we would actually do about it

Not very much, and quickly.

This month: work out whether you are in scope at all. Most UK SMEs are not, and it is worth knowing definitively rather than assuming in either direction.

If you are in scope: check your chatbot discloses that it is a chatbot, and check whether AI-generated content you publish is labelled. Both are small changes.

Either way: do something about staff AI literacy, because it is the cheapest item on the list and the only one that pays for itself whether or not a regulator ever asks.

What we would not do: buy an AI governance platform, commission a compliance audit, or appoint anyone to a new role. For a business under a few hundred people, this is a morning's work and a one-page register, not a programme.

This is a plain-English summary, not legal advice. If you are genuinely in the high-risk category, take proper counsel.

Key Takeaways

  • The Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force on 27 July 2026 and deferred the high-risk deadlines.
  • Annex III standalone high-risk moved to 2 December 2027. Annex I embedded high-risk moved to 2 August 2028.
  • Article 50 transparency and Article 4 AI literacy did not move and are live now. These catch far more ordinary businesses than the high-risk rules.
  • Scope follows the market, not the office. A UK business can be in scope through EU customers or EU-used outputs.
  • For most SMEs the response is a morning's work, not a compliance programme. Be suspicious of anyone selling the latter.

Frequently Asked Questions

Does the delay mean the high-risk rules might be dropped altogether?

There is no indication of that. The deferral was about readiness, particularly the availability of harmonised standards, rather than a change of policy direction. Treating December 2027 as a reprieve rather than a cancellation is the sensible reading.

We only use ChatGPT and a few tools. Are we affected?

Almost certainly not by the high-risk regime. Possibly by Article 50 if you publish AI-generated content into the EU or run a customer-facing bot, and potentially by Article 4 if you are in scope at all. The literacy duty is worth acting on regardless, because untrained staff using AI tools is a real risk with or without a regulator.

What are the penalties?

For most breaches, up to EUR 7.5 million or 1.5 per cent of global annual turnover, whichever is higher. Prohibited practices under Article 5 attract considerably more. Enforcement is by member state authorities, so a UK business would face this through its EU market activity.


Unsure whether the EU AI Act reaches your business? Talk to Halo Technology Lab. We will give you a straight answer about scope, including the common answer, which is that it does not apply to you.

Share this article

Enjoyed this? Get the next one by email

Practical AI playbooks, build logs and tool teardowns. One email a week, free, unsubscribe in one click.

See what’s in it first

Have a project in mind?

Let's discuss how we can help bring your ideas to life.

Get in Touch