The 16-Month Deferral Most SMEs Never Saw Coming
Regulation (EU) 2026/1744, the Digital Omnibus on AI, moved the compliance deadline for Annex III standalone high-risk AI systems - the hiring tools, credit-scoring models and biometric identification systems that most small and mid-size businesses actually deploy - from 2 August 2026 to 2 December 2027, a 16-month extension that landed while nearly every business owner was reading a different headline.
The regulation cleared its final Council approval on 29 June 2026, was published in the Official Journal on 24 July 2026, and entered into force on 27 July 2026, just days before the original 2 August deadline it was quietly rewriting.
What Did Not Move: Article 50 Labelling Is Already Live
Article 50 of the AI Act, the transparency and labelling duties that require disclosure of AI-generated content and chatbot interactions, was left untouched by the Digital Omnibus and took effect exactly on schedule on 2 August 2026, together with the compliance obligations placed on general-purpose AI providers.
That timing split is the trap: an owner who heard 'the AI Act got delayed' and stopped there may now be running an undisclosed AI chatbot or unlabelled AI-generated marketing content in breach of a rule that has already been enforceable for three weeks.
Annex I Embedded Systems Get A Shorter, Different Clock
Annex I high-risk systems - AI embedded inside physical products such as medical devices, industrial machinery and AI-enabled toys - received a separate deferral of twelve months rather than sixteen, moving their deadline from August 2027 to August 2028.
| Requirement | Original deadline | New deadline | Change |
|---|---|---|---|
| Annex III standalone high-risk AI (hiring, credit scoring, biometric ID) | 2 August 2026 | 2 December 2027 | Deferred 16 months |
| Annex I embedded high-risk AI (medical devices, machinery, AI toys) | August 2027 | August 2028 | Deferred 12 months |
| Article 50 transparency, labelling and GPAI obligations | 2 August 2026 | 2 August 2026 | Unchanged, already in force |
The two deferrals run on different clocks and cover different products, so a manufacturer embedding AI in a machine cannot borrow the Annex III timeline, and a hiring-software vendor cannot borrow the Annex I one.
A New Red Line: Nudifiers And AI-Generated CSAM Banned Outright
The same regulation that delayed two compliance clocks introduced a new prohibition with no delay attached at all: Article 5 now bans AI systems built to generate non-consensual intimate imagery, so-called nudifiers, and AI-generated child sexual abuse material, effective from the regulation's entry into force on 27 July 2026.
There is no grace period and no phased rollout attached to that ban, which puts it in sharp contrast with the multi-year timelines given to the high-risk categories in the same text.
Which Bucket Is Your AI Tool In
The one question worth answering this week for any EU or UK business running AI software is which of these two buckets the tool actually sits in, because acting on the wrong assumption carries a real cost in either direction.
A business that assumes the whole AI Act moved risks running an undisclosed chatbot or unlabelled AI content past 2 August 2026 in plain breach of Article 50. A business that panics over Annex III risks spending on hiring-tool or credit-scoring audits sixteen months before the file is actually due. Check which annex covers the specific tool, not the regulation's name, before deciding which one applies.
Read next: Brussels Can Now Pull An AI Model From The EU Market | Google's Watermark Opt-Out Tests the EU AI Act



