Regulation
EU AI Act readiness for enterprises: what the December 2027 deferral did and did not change
Almost every EU AI Act page still ranking today was written against a deadline that no longer exists. Here is the timetable as it stands after Regulation (EU) 2026/1744, which obligations are live right now, and the 90 days of work the deferral did not remove.
What actually changed on 27 July 2026
Regulation (EU) 2026/1744, the Digital Omnibus on AI, amended the AI Act. It was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026, six days before the deadline it postponed. The sequence, for anyone who has to write this into a board paper:
| Event | Date | Source |
|---|---|---|
| Commission proposal published | 19 November 2025 | European Parliament legislative train |
| Trilogue agreement reached | 7 May 2026 | European Parliament legislative train |
| Council provisional agreement confirmed | 13 May 2026 | Gibson Dunn, 27 May 2026 |
| Parliament approval, 423 for, 57 against, 174 abstentions | 16 June 2026 | European Parliament legislative train |
| Council final approval | 29 June 2026 | Cloud Security Alliance research note, 1 August 2026 |
| Official Journal publication | 24 July 2026 | Cloud Security Alliance research note |
| Entry into force | 27 July 2026 | Cloud Security Alliance research note |
The Cloud Security Alliance titled its note on the change "deferred, not cancelled", and that is the whole reading in three words. The trilogue also added two new prohibited-practice categories covering non-consensual intimate imagery and AI-generated child sexual abuse material, with a grace period to 2 December 2026 for the technical safeguards.
The compliance calendar as it stands today
| Obligation | Applies from | Moved by the Omnibus? |
|---|---|---|
| Article 5 prohibited practices | 2 February 2025 | No. Two new categories added, safeguards due 2 December 2026 |
| General-purpose AI provider obligations, Articles 51 to 56 | 2 August 2025 | No |
| Article 50 transparency duties | 2 August 2026 | No |
| Content marking for systems placed on market before 2 August 2026 | 2 December 2026 | Own date, unchanged |
| Annex III standalone high-risk systems | 2 December 2027 | Yes, from 2 August 2026 |
| Annex I high-risk embedded in regulated products | 2 August 2028 | Yes, from 2 August 2027 |
Penalty bands did not change. Up to EUR 35 million or 7 percent of global annual turnover for prohibited practices, and up to EUR 15 million or 3 percent for the remaining obligations, whichever is higher in each case.
What binds you in September 2026
Three things, and none of them are the ones the trade press has been writing about.
Article 5, since February 2025
The prohibitions have been enforceable for over eighteen months. Social scoring by public authorities, exploitation of vulnerability, untargeted facial-image scraping to build recognition databases, emotion inference in workplaces and schools. Two categories joined the list this summer. If any of these describe a system you run, the deferral is irrelevant to you.
General-purpose AI obligations, since August 2025
If your organisation places a general-purpose model on the EU market, Articles 51 to 56 have applied for a year. Technical documentation, a copyright policy, a public summary of training content, and systemic-risk obligations above the compute threshold. Most enterprises are deployers rather than providers here, but a fine-tuned model distributed to customers can put you in scope, and that determination is worth writing down rather than assuming.
Article 50 transparency, since 2 August 2026
This is the one that reaches the widest set of ordinary systems, and it went live on schedule five weeks ago. Three duties. Disclose to a person that they are interacting with an AI system, unless it is obvious from context. Mark synthetic audio, image, video and text in a machine-readable format that downstream systems can detect. Label deepfakes and AI-generated text published to inform the public on matters of public interest.
The chat assistant somebody added to a marketing site last spring is in scope. So is the summarisation feature inside a customer portal. Systems placed on the market before 2 August 2026 have until 2 December 2026 to meet the content-marking part, which is the deadline most organisations should currently be working to.
Why the deferral is not eighteen free months
Two arguments, one regulatory and one commercial.
The regulatory one is about ordering. Classification is the prerequisite for every later obligation. You cannot write Article 9 risk-management documentation, or Article 11 technical documentation, or design a human-oversight mechanism, until you know which of your systems are Annex III and which are not. That exercise is slow, it needs legal and engineering in the same room, and most organisations have not started. An appliedAI analysis cited in the Cloud Security Alliance research note of 13 March 2026 found that 40 percent of 106 enterprise AI systems examined could not be clearly classified under the Act's risk tiers. The same note reported that more than half of organisations have not established systematic inventories of the AI systems they operate. You cannot classify what you have not inventoried.
The commercial argument is simpler and it moves faster than the regulation. Enterprise procurement already asks about model provenance, data residency and human oversight, this year, in the first pass rather than at contract stage. A vendor who cannot answer loses the deal regardless of what any deadline says. Independent analyses summarised in the Cloud Security Alliance note put initial compliance cost at USD 8 to 15 million for large enterprises and USD 2 to 5 million for mid-size ones, which is a reason to start the inventory now rather than an argument for waiting.
There is also a supply constraint nobody talks about. Notified bodies for conformity assessment are thin on the ground, and the harmonised standards are still landing. Fifteen months out looks comfortable. Fifteen months out with a queue in front of the assessor does not.
Who is doing this work in Europe
Three different categories get conflated on almost every page that ranks for this query, and conflating them is how buyers end up hiring the wrong one. A certification body audits you and cannot also build your system. A Big Four practice can run the programme and will subcontract the engineering. A delivery firm builds the thing but may have no assurance standing at all. Work out which you are buying before the first call.
| Firm | HQ | Category | Focus | Source |
|---|---|---|---|---|
| Addepto | Warsaw | AI consultancy | Regulation-aware AI consulting. Names NIST AI RMF, ISO/IEC 42001, GDPR, the EU AI Act, DORA, NIS2 and MDR, and ships ContextCheck as open source | addepto.com, article dated 2026-06-06 |
| Alice Labs | Stockholm | AI consultancy | Boutique implementation for regulated Nordic mid-market and enterprise, with documented EU AI Act alignment | alicelabs.ai, fetched 2026-09-01 |
| AIDOLS | Amsterdam, Keizersgracht 520 | AI consultancy | EU AI Act-ready positioning, self-published city guides | aidolsgroup.com, 2026-04-02, updated 2026-05-21 |
| 2021.AI | Copenhagen | Governance platform plus services | GRACE, an AI governance platform aimed at regulated enterprises | alicelabs.ai Nordics ranking 2026-07-28, 2021.ai live |
| Deloitte, KPMG, PwC, EY | Multi-country | Big Four | Risk, assurance and conformity-assessment readiness. Listed because they hold the enterprise relationship, not because they build the system | multiple SERPs, 2026-09-01 |
| BSI, TUV SUD, DNV | UK, DE, NO | Certification bodies | ISO/IEC 42001 AI management system certification. BSI is the first body UKAS-accredited for ISO/IEC 42001, with RvA accreditation in the Netherlands and ANAB in the US | live SERP, 2026-09-01 |
| Digiton Dynamics | Lisbon, with Digiton Dynamics OU in Tallinn | AI consulting firm, build and operate | Production agents and RAG built to Article 50 and GDPR from the first commit, operated after launch. Both entities EU-domiciled | first party |
Disclosure, because it belongs next to the table rather than in a footnote: Digiton Dynamics wrote this page and appears in it. Every other entry is a competitor or a body we would send a client to, and for a formal ISO/IEC 42001 certification the certification bodies above are the right call and we are not.
Where ISO/IEC 42001 fits
Buyers keep asking whether certification satisfies the Act. It does not, and it is not meant to. ISO/IEC 42001 is an AI management system standard: it certifies that you run a governance process, with the policies, roles, risk assessments and internal audits that implies. The AI Act asks about specific systems and specific obligations. The overlap is real and useful, because the documentation an AI management system produces is most of what an Article 11 technical file needs, and procurement teams increasingly ask for the certificate as a shortcut. Treat it as scaffolding for compliance rather than as compliance.
A 90-day plan for the window
Fifteen months sounds like room. Split into the work that has to happen sequentially, it is not.
- Weeks 1 to 3, inventory. Every AI system in the organisation, including the ones bought on a departmental card and the features that arrived inside a SaaS product you already licensed. Owner, purpose, data in, decision influenced, users affected. This is the step most organisations skip and the one everything else depends on.
- Weeks 3 to 6, Annex III classification. Legal and engineering together, per system, written down with reasoning. Expect a meaningful fraction to sit in the ambiguous band. Record the ambiguity rather than resolving it optimistically.
- Weeks 4 to 8, Article 50 audit. This one is live now, so run it in parallel. Every system a person can talk to, every piece of synthetic media you publish. Disclosure present, marking machine-readable, deepfake labelling where relevant. Fix before 2 December 2026 for anything placed on the market before 2 August 2026.
- Weeks 6 to 11, documentation. Article 9 risk management and Article 11 technical documentation drafted for anything classified high-risk. Drafted, not perfected. A draft you can improve beats a blank file with a 2027 date on it.
- Weeks 8 to 12, the procurement answer sheet. One document answering model provenance, hosting region, training-data exposure, log access and retention. Your customers are asking. Your sales team is currently improvising.
- Weeks 10 to 12, the December 2026 safeguards. Technical measures for the two new Article 5 categories, if any system you run could produce that output.
Across 8 countries, Digiton's average time from a signed scope to a production system is 45 days, which is roughly the length of one Annex III classification exercise. That comparison is the point: the classification work is not large. It is only slow to start.
Where the engineering actually bites
Compliance documents describe outcomes. Systems have to produce them, and two places break more builds than the rest combined.
The first is erasure. A GDPR deletion request has to reach every derived copy of a record: the vector store, the cached retrieval context, the agent's conversation memory, and any evaluation set assembled from production traffic. Most retrieval builds delete the source row and leave the embedding in place, which means the system can still recite the deleted record. The mechanism that fixes it, source-linked chunk identifiers and a re-index path, has to be designed in rather than added.
The second is citation adequacy. Article 50 and the transparency obligations sit alongside an expectation that an organisation can show where an answer came from. A retrieval system that returns a fluent paragraph with no traceable source is not auditable, whatever the model scored on a benchmark. Both are covered in detail on GDPR-compliant RAG.
The governance layer around an agent is a third: scoped identity, least privilege, human approval on irreversible actions, an immutable audit log and a kill switch. That is on AI agent governance.
What this page will get wrong, and when
This document is accurate as of 1 September 2026 and it has a shelf life. The Commission still has delegated acts to adopt, harmonised standards are landing through 2027, and the Omnibus process itself proved that a deadline in the Official Journal is not the same as a deadline that holds. Check the European Parliament legislative train and the Cloud Security Alliance research feed before quoting any date here in a board paper.
Frequently asked questions
Did the EU AI Act high-risk deadline move?
Yes. Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It moved Annex III standalone high-risk obligations from 2 August 2026 to 2 December 2027, and Annex I systems embedded in regulated products from 2 August 2027 to 2 August 2028. Nothing else in the timetable moved.
What did the Digital Omnibus on AI actually change?
It deferred two high-risk deadlines and added two prohibited-practice categories covering non-consensual intimate imagery and AI-generated child sexual abuse material, with a 2 December 2026 grace period for the technical safeguards. Article 5, the general-purpose AI obligations under Articles 51 to 56, and Article 50 transparency were left alone. Penalty bands were unchanged.
Which EU AI Act obligations bind my systems today?
Three. Article 5 prohibited practices, enforceable since 2 February 2025. General-purpose AI provider obligations under Articles 51 to 56, enforceable since 2 August 2025. Article 50 transparency duties, live since 2 August 2026, covering disclosure when a person is talking to an AI, machine-readable marking of synthetic media, and deepfake labelling. Systems placed on the market before 2 August 2026 have until 2 December 2026 for content marking.
Does the deferral to December 2027 give us eighteen months off?
No, for one structural reason. Classification is the prerequisite for every later obligation, and you cannot draft risk-management or technical documentation until you know which systems are Annex III. An appliedAI analysis cited by the Cloud Security Alliance in March 2026 found 40 percent of 106 enterprise AI systems could not be clearly classified, and the same note reported that over half of organisations have no systematic inventory of what they run.
What are the penalties under the EU AI Act?
Up to EUR 35 million or 7 percent of global annual turnover, whichever is higher, for the Article 5 prohibited practices. Up to EUR 15 million or 3 percent for the remaining obligations. The Omnibus did not change either band. Enforcement sits with national market surveillance authorities, and for general-purpose models with the AI Office.
Does ISO/IEC 42001 certification make us AI Act compliant?
It does not, and it is not designed to. ISO/IEC 42001 certifies that you operate an AI management system, meaning policies, roles, risk assessments and internal audits. The AI Act asks about specific systems against specific obligations. The documentation an AI management system produces covers much of what an Article 11 technical file needs, so treat certification as scaffolding rather than as an answer.
Who should we hire for EU AI Act readiness?
Work out which of three things you are buying first. A certification body such as BSI, TUV SUD or DNV audits you against ISO/IEC 42001 and cannot also build your systems. A Big Four practice runs the programme and subcontracts engineering. A delivery firm builds and operates the systems but may hold no assurance standing. Most organisations need the inventory and classification first, which is consulting work, and only then the other two.
What should a mid-size enterprise do in the next 90 days?
Inventory every AI system including the ones bought on a departmental card, classify each against Annex III with legal and engineering in the same room, audit Article 50 disclosure and content marking in parallel because that obligation is already live, draft Article 9 and Article 11 documentation for anything high-risk, and write one answer sheet covering model provenance, hosting region and data residency for the procurement questionnaires your customers are already sending.
Related
Ready to put AI to work?
Book a discovery audit and we will map the highest-ROI AI agents and automations for your business.
Book a discovery audit →