Five days before the deadline the whole sector had marked, the rules changed. Most summaries published since report a general reprieve. There was no general reprieve, and the difference is the part that binds you today.
On 24 July 2026 the Digital Omnibus on AI, Regulation (EU) 2026/1744, was published in the Official Journal. It entered into force on 27 July, six days before the EU AI Act's original 2 August high-risk deadline.
It moved two things and deliberately left a third where it was. Almost every summary written since collapses all three into a single sentence about the AI Act being postponed, which is how a compliance team ends up relaxed about an obligation that is already enforceable against them.
Risk management, data governance, logging, human oversight and conformity assessment. Annex III standalone systems deferred by sixteen months. AI embedded in products already regulated under Annex I legislation, including medical devices under the MDR, deferred by a further year beyond that.
A system that communicates with a person must disclose that it is AI. Synthetic content must be marked in a machine-readable format so it is detectable downstream as artificially generated. Unchanged, unpostponed, and enforceable now.
The practical effect is an inversion. The obligation most organisations were preparing for has considerably more runway than they think. The one almost nobody was reviewing already applies.
If your system is a medical device under the MDR, or otherwise a safety component of a product already covered by EU product-safety legislation, it does not enter through Annex III at all. Its high-risk obligations fall under Article 6(1) and apply from 2 August 2028, not December 2027. Advisors quoting a single high-risk date for every client are wrong for a large share of them.
These are separate regimes with separate assessments. A notified body does not assess Article 50, and a CE mark does not evidence it. Organisations that have invested heavily in MDR compliance are among the most likely to assume this is covered. It is not.
A hospital or company that builds an AI system internally and makes it available to patients or customers becomes a provider under the Regulation, not merely a deployer. The obligation set is materially different. This is the distinction most often missed by institutions that research and operate at the same time.
The instrument below computes from the application dates set by each legal instrument at the moment this page loads. Nothing in it is typed by hand.
Transparency obligations have applied since 2 August 2026.
The Act binds on output, not on establishment. A provider located anywhere is subject to Article 50 if the output of its system is used in the European Union, whether or not it holds an entity there.
There is a second-order consequence that matters more commercially than the penalty does. European procurement has been tightening against non-EU suppliers, and it rarely arrives as a written rule. It arrives as preference for local vendors and as tender questions that are cheap to ask and expensive to answer: who governs this system, who is accountable when it is wrong, and who can confirm that other than the vendor.
A supplier answering with its own documentation is asserting. A supplier answering with an independent certification and a public register entry the buyer can query directly is evidencing. On a panel that needs a defensible reason to choose between two capable suppliers, that is the reason they write down.
Every claim on this page is checkable. We would rather you checked it than took our word.
Score your systems against the obligations that bind them today, with the articles cited. Five minutes, no account required.
Open the Risk Scorer