The Signal FilesAI GovernancePlain-Language Brief

The deadline that moved

Europe moved the high-risk cliff. It did not move the rules that touch your chatbot today. Here is the map, in plain language.

~1,700 WordsFour Cited SourcesStop Trying To Be Invisible

For two years, one date sat circled in red in every European AI plan: August 2, 2026, the day the AI Act's high-risk regime was due to bite. Hiring tools, credit scoring, access to essential services: full obligations, conformity assessments, documentation, the works. Then, six days before that date arrived, the ground under it changed. On July 27, 2026, the Digital Omnibus entered into force as Regulation (EU) 2026/1744, and the cliff moved. Not the whole cliff, though: the part that stayed is the part most small businesses are standing on right now.

Who is writing, and what this is. This brief is written by our founder in a personal capacity (a lawyer by training, not your lawyer). It is orientation, not legal advice: enough to know which questions to ask, not a substitute for counsel who knows your systems.

This piece does one job: separate what moved from what did not, in language a founder can act on. Every date below comes from the legislative record, not from a headline.

Section OneWhat actually happened

The Digital Omnibus is not a rumor, a draft, or a lobbying position. It is settled, in-force law, and it got there through the full machinery. The European Commission proposed the package on November 19, 2025. The Council and the Parliament reached a provisional political agreement on May 7, 2026.

Council of the EU, "Artificial intelligence: Council and Parliament agree to simplify and streamline rules," May 7, 2026.

Parliament approved the text in plenary on June 16, 2026, by 423 votes to 57, with 174 abstentions. The Council gave its final green light on June 29, 2026. The act was signed on July 8, published in the Official Journal on July 24 as Regulation (EU) 2026/1744, and entered into force three days later, on July 27.

Council of the EU, "Artificial intelligence: Council gives final green light to simplify and streamline rules," June 29, 2026; Official Journal of the EU, Regulation (EU) 2026/1744, July 24, 2026.

Why this matters for how you read everything else: through spring 2026 the coverage was full of "proposed," "provisional," "expected." That tense is over. The dates below are not predictions. They are the law as it stands.

Section TwoWhat moved: two dates, not one

The deferral is the headline, and almost everyone quotes it wrong, because there is not one new deadline. There are two.

Standalone high-risk systems (the Annex III list: AI used in hiring and worker management, in credit scoring, in access to essential private and public services) were due to face the full high-risk regime on August 2, 2026. That obligation now applies from December 2, 2027. A sixteen-month deferral.

Embedded high-risk systems are AI built into products that already carry EU safety law: medical devices, machinery, toys, lifts. That is the Annex I route, and it was on a later clock, August 2027. That clock moved to August 2, 2028. Twelve months, not sixteen.

European Commission, "AI Omnibus enters into force," July 2026; Regulation (EU) 2026/1744.

Why two datesIf a summary you read gives one flat number ("the AI Act was delayed by a year"), it is compressing two different deferrals into a slogan. A recruiting-software startup and a machinery manufacturer are now on clocks nineteen months apart. Knowing which Annex you are on is the first question, and it changes every date after it.

Section ThreeWhat did not move

Here is the part the relief coverage buried. The Article 50 transparency obligations were not deferred. They applied from August 2, 2026. As you read this, that date is already behind us.

In plain terms: if a customer talks to your chatbot, they must be able to tell they are talking to a machine. If you publish AI-generated text, images, or audio, it must be marked as such. Deepfakes must be labeled. These are not high-risk rules for banks and hospitals; they touch every business whose website has an AI assistant or whose content pipeline runs through a model. In 2026, that is most of them.

If a customer talks to your chatbot today, the disclosure duty is not on its way. It is in force.

There is one grace window, and it is narrow: for systems already on the market before August 2, 2026, the duty to mark AI-generated content runs from December 2, 2026. That is a few months to retrofit labels, not a reprieve.

Regulation (EU) 2026/1744, transitional provisions; European Commission, "AI Omnibus enters into force," July 2026.

And two whole layers of the Act never entered the negotiation at all: the obligations for general-purpose AI models have applied since August 2025, and the outright bans (social scoring, manipulative systems and the rest of the prohibited-practices list) have applied since February 2025. Nothing in the Omnibus touched either.

Section FourThe relief nobody is reading

The Omnibus did not only move dates. It created a category most founders have not heard of yet: the "small mid-cap," a company with fewer than 750 employees and up to €150 million in turnover (or a balance sheet up to €129 million). Firms in that band, and the small and medium enterprises below it, get a materially lighter regime: simplified technical documentation, a quality-management system proportionate to their size, reduced penalty caps, and priority access to regulatory sandboxes.

Regulation (EU) 2026/1744; Council of the EU press release, June 29, 2026.

The sandbox picture moved too. Member states now have until August 2027, a year longer than before, to stand up national AI sandboxes, and the Act adds an EU-level sandbox run by the AI Office. For a small company, a sandbox is the one place where you can test a borderline system with the regulator watching instead of waiting.

Plain languageTranslated out of Brussels: if you are under 750 people, the paperwork burden was deliberately sized down for you, the maximum fines were lowered for you, and you were moved to the front of the queue for supervised testing. The regime that arrives in December 2027 is lighter than the one you braced for in August 2026.

Section FiveThe wrong lesson

The tempting reading of all this is: we got away with it: park the file until 2027. That is the one mistake the new timeline actually punishes.

A delay is not a cancellation. The high-risk regime was deferred, not dropped; the definitions did not change; the December 2027 date is now as fixed as the August 2026 date used to look. And sixteen months is shorter than it sounds once you subtract the time it takes to answer suppliers' questionnaires, chase documentation from the vendors whose models you build on, and untangle which of your tools even fall on the Annex III list.

The cliff moved. The clock did not stop. It was reset, and it is running.

The move that costs almost nothing now and a great deal later is an inventory. One page per system: what the AI does, in one sentence. Who owns it: a name, not a department. What data goes in and what comes out. And what it may never do, written down. That single register answers the transparency duties you owe today, tells you instantly whether December 2027 concerns you, and is the first document any lawyer, auditor, or enterprise customer will ask for. Mapping your systems while the deadline is far is cheap. Reconstructing the map in the last quarter of 2027 is not.

In ClosingCompliance is legibility

Everything we publish circles one claim: machines can only act on what they can clearly read, and that now cuts in two directions. Outside your company, AI assistants recommend the brands the web has made legible. Inside it, the new law asks for exactly the same discipline: know what your AI does, write it down, put a name on it. The register that satisfies a regulator and the clarity that gets you cited by a machine are the same habit. The businesses that treat the moved deadline as sixteen months of silence will do the work twice; the ones that write it down once will find that the document was never really for Brussels.

If you want to see how legible your own business already is to the machines that answer your customers' questions, you can measure it at /signal-index/ or write to us at /contact/.

Figure 01 · What Moved, What Didn't
Two clocks reset. One never stopped.
+16 / +12
Months of deferral. Annex III standalone high-risk moved 16 months, to December 2, 2027. Annex I embedded high-risk moved 12, to August 2, 2028. Never one flat number.
0
Days the transparency rules moved. Article 50 covers chatbot disclosure, AI-content marking and deepfake labels. It applies from August 2, 2026, unchanged by the Omnibus.
Source: Regulation (EU) 2026/1744, in force July 27, 2026; Council of the EU and European Commission releases, May–July 2026.
Stop trying to be invisible.

Sources

  1. Council of the EU, "Artificial intelligence: Council and Parliament agree to simplify and streamline rules," May 7, 2026. consilium.europa.eu
  2. Council of the EU, "Artificial intelligence: Council gives final green light to simplify and streamline rules," June 29, 2026. consilium.europa.eu
  3. European Commission, "AI Omnibus enters into force," July 2026. digital-strategy.ec.europa.eu
  4. Regulation (EU) 2026/1744 (Digital Omnibus, AI chapter), Official Journal of the EU, July 24, 2026; in force July 27, 2026. eur-lex.europa.eu/eli/reg/2026/1744/oj

The Signal Index

How clearly can the AI era see you?

A free, transparent score of how AI and search find, understand and recommend you. Instant, from your domain.

Get your Signal Index →

The Signal Files

Field notes on visibility, in your inbox.

The research behind how brands get seen now. The Signal Files, the moment they publish. No noise.

Double opt-in. Unsubscribe anytime.