Skip to main content
AI systems

The EU AI Act Deadline You Think You Missed

Radek Venzhöfer ·

If you run a small or mid-sized company in the EU, you have probably absorbed two impressions about the AI Act this year. First, that a big deadline hit in August 2026. Second, that it got postponed and you can stop worrying.

Both are half true, and the half that is wrong is the expensive one. Here is the actual state of play as of September 2026, in the order it matters to a company that is using AI rather than building it.

What was deferred

The Digital Omnibus on AI entered into force on 27 July 2026, and it moved the high-risk regime back substantially.

Obligations for standalone high-risk systems, the Annex III category, shifted from 2 August 2026 to 2 December 2027. For AI embedded in products already covered by EU product-safety law, the Annex I category, the date moved to 2 August 2028.

That regime is the heavy one: conformity assessment, registration, risk management, data governance, logging, human oversight. If you were bracing for that this summer, the pressure genuinely came off. Deferred, though, is not cancelled, and the scope of what counts as high-risk did not shrink just because the clock did.

What did not move

Article 50, the transparency obligations, stayed exactly where it was. It has applied since 2 August 2026.

In plain terms, and stripped of the legal drafting, it covers two things that show up constantly in ordinary businesses. People have to be told when they are interacting with an AI system rather than a human. And AI-generated or AI-manipulated content has to be identifiable as such.

There is no phase-in left on that. It is the live obligation right now, and it is the one most likely to apply to a company that has never thought of itself as an AI company.

Two other things were already in force and remain so. The Article 5 prohibitions on certain practices have applied since February 2025. Obligations on providers of general-purpose AI models have applied since August 2025, which matters to you mainly as a buyer: it shapes what the model vendors must tell you.

Why this gets inverted

The reporting followed the drama. A postponement is news, so the postponement travelled. Article 50 did not move, so nothing was written about it, and a rule that generates no headlines reads like a rule that does not exist.

The result is a fairly common situation: a company that spent the spring worrying about a high-risk classification it probably never had, while running a customer-facing chatbot that does not say it is a chatbot.

The four questions worth answering this month

Where does AI touch someone outside the company? A support chat widget, an email autoresponder that drafts replies, a phone system that answers first, a lead qualifier on the website. Any of these puts a person in conversation with a system. That is the Article 50 trigger, and it is usually a wording change rather than a project.

What do we publish that a model generated? Blog copy, product descriptions, social posts, images, synthetic voice. The obligation is about identifiability of AI-generated content, and the practical question is whether a reader could tell.

Do we actually have a high-risk system? Most companies do not. The category is defined by use, not by how impressive the technology feels, and the areas that matter include things like employment decisions, access to essential services, and creditworthiness. If your AI writes drafts and sorts tickets, you are almost certainly not in Annex III. If it screens job applicants or scores customers, get that assessed properly, because December 2027 arrives faster than it sounds.

Who owns this internally? In a twenty-person company the answer is usually nobody, which is how a five-minute fix stays undone for a year. It does not need a compliance department. It needs one named person and one reviewed page.

The realistic reading for an SME

The deferral bought most companies eighteen months of breathing room on the expensive part. It bought exactly zero days on the cheap part, and the cheap part is the one that is visible from the outside. Anyone can open your website and see whether your chatbot introduces itself honestly.

So the sensible order is: handle disclosure now because it is a week of work at most, and schedule the high-risk assessment as a real project rather than a panic, since you know the date.

Our practical version of the first half is in The AI Transparency Checklist for a Twenty-Person Company. If you are still deciding what to automate at all, What Is an AI Agent? is the better starting point.

One caveat, stated plainly: this is an orientation piece written by people who build these systems, not lawyers. The dates and structure above are what a technical team needs in order to plan. Before you rely on a classification decision, especially an Annex III one, have it reviewed by counsel who does this for a living.

Chat with us on WhatsApp