This Sunday, 2 August 2026, was supposed to be the AI Act’s big bang: the date the bulk of the regulation became applicable, circled on compliance calendars since 2024. Then, five weeks before the deadline, the EU adopted the Digital Omnibus on AI and redrew the map. The obligations most companies spent two years preparing for have moved to 2027 and 2028, while the ones many overlooked arrive exactly on schedule. If your AI Act plan was written before July, it is already out of date. Here is what actually happens on Sunday, and what doesn’t.
What still applies on 2 August
The Article 50 transparency obligations were not deferred. From Sunday, providers and deployers must tell people when they are interacting with an AI system, label deep fakes and AI-generated text on matters of public interest, and disclose the use of emotion recognition or biometric categorisation. On 20 July the Commission published its Guidelines on Transparency of AI-Generated Content, alongside the voluntary Code of Practice. That is guidance arriving barely two weeks before the deadline. Read them now: signing the Code is the simplest route to demonstrating compliance, and non-signatories must prove equivalence by other means.
What moved
The heavyweight high-risk obligations are deferred: stand-alone Annex III systems (hiring, credit scoring, education) shift to 2 December 2027, and AI embedded in regulated products under Annex I to 2 August 2028. Machine-readable marking of AI-generated content under Article 50(2) gets a short grace period for systems already on the market, moving to 2 December 2026, the same date new prohibitions on CSAM-generating and “nudifier” systems kick in. National regulatory sandboxes slide to August 2027.
How the Digital Omnibus changed the AI Act
The Omnibus, now Regulation (EU) 2026/1744, is the first amendment to the AI Act since its adoption, and it didn’t come out of nowhere. The push began with the 2024 Draghi report, which warned that Europe’s layered digital rules were weighing on competitiveness and called for radical simplification. Then implementation reality caught up with ambition: the harmonised standards that were supposed to give companies a presumption of conformity fell badly behind schedule, the Commission missed its own February 2026 deadline for high-risk classification guidance, and several Member States had not even designated their supervisory authorities. Proposed in November 2025, the Omnibus spent months in contested trilogues, leaving companies unsure which deadline to plan for, before Parliament and Council adopted it in June. It entered into force on 27 July, six days before the date it amends.
Beyond the deferrals, the changes are substantive. A new prohibition, added at Parliament’s initiative, bans AI systems used to generate child sexual abuse material and non-consensual intimate imagery, the so-called nudifier apps, covering both placing such systems on the market and using them, from 2 December 2026. The AI literacy duty in Article 4 was softened from ensuring a sufficient level to taking measures to support it. The legal basis for processing special category data for bias detection was extended from high-risk systems to all AI systems and models, under strict safeguards. SME simplifications now extend to small mid-caps, and the AI Office gained significantly expanded supervisory powers. What the Omnibus does not touch: the existing prohibitions in force since February 2025, the GPAI rules, and the penalty ceilings of €35M or 7% of turnover.
Looking ahead
The deferrals buy time, not exemption. The transparency rules land this Sunday, and the extra runway on high-risk systems is only valuable if it is actually used: to educate teams, build transparency into how systems are designed, and make conscious choices about where AI belongs. As with the Italian AI law we wrote about last year, implementation will be the real test.