A major part of the AI Act calendar has changed
Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July. It moves the application of requirements for stand-alone high-risk AI systems covered by Annex III to 2 December 2027. High-risk systems embedded in products covered by EU safety legislation move to 2 August 2028.
Those are material changes. They give organizations more time while standards, guidance and assessment capacity mature. But they do not postpone the AI Act as a whole. Prohibited-practice rules, obligations for providers of general-purpose AI models and Article 50 transparency rules each follow their own timelines. The European Commission's Article 50 guidance still points to 2 August 2026 for the transparency obligations, subject to the specific scope and transitional provisions in the law.
The practical conclusion is simple: a changed high-risk deadline is not permission to stop implementation. It is an opportunity to replace rushed paperwork with working controls.
The deadline matters less than knowing where AI operates
Most organizations do not yet have one reliable view of where AI touches operational work. Usage is spread across licensed assistants, features inside existing software, custom workflows and employee experiments. Legal classification is difficult when the underlying process is not documented.
Start with the workflow, not a list of model names. For each use case, record the business purpose, process owner, affected people, input data, output or decision, connected systems, human review, supplier and model, logging, failure path and expected business outcome. That inventory creates the basis for classification, risk assessment, procurement and technical control.
A generic register that says “customer service chatbot” is too shallow. A useful record explains whether the system only drafts an answer or sends it, which customer data it can retrieve, what sources it may use, who reviews exceptions and how an incorrect action is detected and reversed.
Use the extra time to collect operational evidence
Compliance cannot be reconstructed from a policy document after deployment. Organizations need evidence from the system itself: which data was accessed, which model and prompt version ran, what the system produced, which checks were applied, whether a person approved the result and what happened downstream.
The most useful preparation therefore also improves the product. Run new workflows in shadow mode before granting execution rights. Measure accepted outputs, corrections, escalations, false positives, processing time and failures by use case. Test permission boundaries and exception paths. Keep versioned records of methods, evaluations and changes.
This evidence helps a legal or compliance specialist determine what the law requires, but it also answers the operational question a buyer should care about: does the system deliver a controlled and repeatable result?
Four actions that should not wait for 2027
- Assign an owner to every operational AI use case. No system should sit between IT, legal and the business without someone accountable for its outcome.
- Separate assistance from execution. Document what AI may prepare, what needs human approval and what it may do autonomously.
- Build traceability into the workflow. Capture inputs, sources, model versions, decisions, approvals and downstream actions in a form that can be reviewed.
- Reassess when the workflow changes. A harmless drafting assistant can become a materially different system when it gains access to personal data or permission to update an ERP, CRM or case-management system.
More time is valuable only when it produces control
The Omnibus reduces deadline pressure for important high-risk categories. Companies should use that room deliberately. Waiting for the final month will not make system inventories, data boundaries, evaluations, human oversight or audit trails easier to build.
The organizations that benefit from the delay will not be those that pause longest. They will be the ones that can show, workflow by workflow, what their AI does, what value it creates, where it can fail and which controls remain in force when it does.
This article provides operational guidance, not legal advice. Classification and applicability should be assessed against the official text and, where needed, with qualified legal counsel.
Official sources: Regulation (EU) 2026/1744; Council final approval; European Commission guidance on Article 50 transparency obligations.