For many organisations, 2 August 2026 had been in the calendar for two years. On that day, most of the AI Act was due to apply, including the heavy obligations for high-risk AI systems. A week before the deadline, the calendar changed after all. On 27 July 2026, Regulation (EU) 2026/1744 entered into force, better known as the Digital Omnibus on AI. It moves the high-risk deadlines to late 2027 and 2028. The rest of the law took effect on 2 August as planned.
#Where the Digital Omnibus came from
The European Commission presented the proposal on 19 November 2025, as part of a wider package to simplify digital regulation. The reason was practical: many of the technical standards and guidance documents that providers need to meet the high-risk requirements were not ready. Keeping the original date would have forced companies to comply with requirements whose details had not been settled.
The package split into two tracks. The AI track is now law: the European Parliament voted in favour on 16 June 2026, the Council followed on 29 June 2026, and the regulation has been in force since 27 July 2026. The second track, with proposals touching the GDPR and the cookie rules among other things, is still with Parliament and Council. More on that below.
#The timeline as it stands
The AI Act entered into force on 1 August 2024 and phases in step by step. This is the schedule after the omnibus:
#What moved
The biggest shift concerns high-risk AI. The obligations for Annex III systems, think of AI used for hiring and selection, employee assessment, or access to services, now apply from 2 December 2027 instead of 2 August 2026. The duties for deployers of those systems move with them: human oversight, informing workers in advance, logging, and the fundamental rights impact assessment (FRIA).
For high-risk AI embedded as a safety component in regulated products, such as machinery or medical devices (Annex I), the new date is 2 August 2028. The obligation for member states to have a national AI sandbox moves to 2 August 2027.
The omnibus also brings relief for smaller companies: simplified technical documentation, requirements that scale with the size of the organisation, and lower fine caps for SMEs.
#What did not move
This is where much of the reporting went wrong over the past months. Only the high-risk part was deferred. All of this applies as planned:
- The prohibited practices, such as social scoring, since 2 February 2025.
- The rules for GPAI models, since 2 August 2025.
- The Article 50 transparency obligations, since 2 August 2026. Chatbots must make clear you are talking to AI. AI-generated audio, images, video, and text must carry a machine-readable marking. Deepfakes must be recognisable as artificial. Anyone deploying emotion recognition or biometric categorisation must inform the people involved. There is one transition: generative systems already on the market have until 2 December 2026 for the machine-readable marking.
- The fines. The ceilings stand: up to 35 million euros or 7 percent of global annual turnover for prohibited practices, up to 15 million euros or 3 percent for breaches of the transparency duties, among others.
And the GDPR was always separate from this. Personal data in an AI tool needs the same lawful basis, purpose limitation, and data minimisation today as it did last year.
#AI literacy: softened, not scrapped
The omnibus also rewrites Article 4. It used to say: organisations must ensure a sufficient level of AI literacy among people working with AI systems on their behalf. It now says: organisations must take measures that support the development of AI literacy. Lawyers call that a shift from an obligation of result to an obligation of effort.
In practice, little changes about what is sensible. You still want to show that you are doing something: explaining what AI may and may not be used for, and which data does not belong in a prompt. Our guide on what you can and cannot share with AI is a usable part of that.
#Two new prohibitions from 2 December 2026
The omnibus also adds to the list of prohibited practices. From 2 December 2026, AI systems intended for creating or spreading intimate images without the consent of the person depicted are prohibited, as are systems intended for creating material depicting child sexual abuse.
#The GDPR omnibus is not here yet
The second track of the package, which would move the cookie rules into the GDPR, raise the threshold for reporting data breaches, and add a legal basis for training AI models, is still a proposal. Supervisory authorities are critical and parts of the text have already been dropped in negotiations. Do not count on it. Until Parliament and Council agree, the GDPR applies as you know it.
#What this means for your planning
Deferral is not cancellation. For most organisations, the list is the same as before the omnibus:
- AI register. Track which AI tools are in use and for what. The AI Tools module does that work continuously.
- Short AI policy. A few pages with the rules for staff is often enough.
- AI literacy. Even as an obligation of effort, you want to be able to show what you do.
- Data processing agreement and GDPR basics. These were always separate from the AI Act.
- Using high-risk AI? Then you have until December 2027 for human oversight, logging, and the FRIA. Use that time, because the requirements themselves barely change.
An AI register kept by hand goes stale the moment a tool shows up that nobody logged. BeeSensible's catalog covers that step: over 700 AI tools, each scored for risk, with new arrivals added and assessed as they appear.
#What to set up in the meantime
The timeline moved, the risk on the work floor did not. An employee pasting customer data into a prompt today is not waiting for December 2027. What the AI Act and the GDPR both ask for is the same thing: not just policy on paper, but measures that demonstrably work. BeeSensible connects three things that usually sit apart:
The highlight appears while you type in browser-based AI tools, so sensitive data can be removed, replaced, or masked before the prompt is sent. That supports data minimisation under the GDPR and makes AI literacy concrete at the moment it counts. The accountability view in the dashboard turns those same observations into substantiation per framework and per measure. BeeSensible runs on ISO 27001 certified EU infrastructure.
Further reading: what the AI Act means for your business alongside the GDPR and GDPR and workplace AI.