For two years, 2 August 2026 was the date circled in every AI compliance plan: the day most obligations for high-risk AI systems would apply. That date has now moved. Under the Digital Omnibus — a simplification package on which EU institutions reached political agreement on 7 May 2026 — the obligations for stand-alone high-risk systems listed in Annex III are set to apply from 2 December 2027, with high-risk AI embedded in regulated products pushed further still.

What has not changed

The relief is narrower than it looks. Several parts of the AI Act are already in force and are not affected:

  • Prohibited practices have applied since February 2025. Banned uses are still banned.
  • General-purpose AI (GPAI) model obligations have applied since August 2025. If you build on or provide a foundation model, your duties are live now.
  • The GDPR and KVKK never paused. Any AI that processes personal data must still satisfy data-protection law in full, today.

Why a later deadline is not a reason to wait

Building a high-risk system to be compliant — risk management, clean data governance, technical documentation, human oversight, logging — takes far longer than the calendar suggests, because it has to be designed in, not bolted on. Teams that treat December 2027 as permission to pause will face the same crunch later, with less leverage. Enterprise customers and investors are also not waiting for the deadline; due-diligence questionnaires already ask for AI Act readiness regardless of the formal application date.

The practical takeaway

Treat the extension as breathing room to do the work properly, not as a stop order. Confirm you are clear of prohibited uses, get your GPAI and data-protection obligations in order now, and keep building the documentation trail for any high-risk system on the original timeline. One caution: the Omnibus changes take legal effect only on formal adoption and publication, so the safe planning assumption is to be ready early rather than to rely on a date that is still being finalised.