Published: 2026-08-01
Categories: AI Governance & Regulation
Key Takeaways
- Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal on July 24, 2026, and entered into force on July 27, 2026 — six days before the EU AI Act’s original August 2, 2026 high-risk deadline. The question of whether the deferral would happen in time is now resolved: it is enacted law, not a pending proposal.
- The deferral pushes compliance for standalone high-risk AI systems (Annex III) from August 2, 2026, to December 2, 2027, and for AI embedded in products already covered by EU product-safety law (Annex I) to August 2, 2028.
- Several obligations remained on the original August 2, 2026, schedule: Article 50 transparency and AI-content-labeling duties, the General-Purpose AI (GPAI) provider obligations that have applied since August 2025, and the Article 5 prohibited-practices regime in force since February 2025.
- The final enacted text differs from the provisional political agreement CSA tracked in May and June 2026 in several concrete ways: it narrows high-risk scope for machinery-embedded AI, softens the AI literacy mandate, expands EU AI Office supervisory reach, and simplifies registration for self-assessed systems.
- Organizations that treated the deferral as settled the moment the provisional agreement or Parliament vote occurred should now reconcile internal compliance trackers against the actual regulatory text rather than earlier summaries of the negotiating position.
Background
The EU AI Act (Regulation (EU) 2024/1689) entered into force on August 1, 2024, and phased its obligations in over several years: prohibited practices and AI literacy duties became enforceable on February 2, 2025; GPAI provider obligations followed on August 2, 2025; and the compliance deadline for high-risk AI systems under Annex III was set for August 2, 2026, with embedded high-risk systems under Annex I following in August 2027 [1]. As that Annex III deadline approached, the Commission cited concerns that neither industry nor the harmonized standards bodies — CEN and CENELEC — would be ready in time, and that the conformity-assessment infrastructure the Act assumes would exist had not yet matured [2].
The European Commission responded on November 19, 2025, with the Digital Omnibus on AI, a package of targeted amendments intended to defer the highest-friction deadlines without reopening the Act’s substantive risk framework [2][3]. Negotiators reached a provisional political agreement on May 7, 2026 [4]. CSA’s AI Safety Initiative published an initial analysis of that agreement the following month, cautioning that it remained provisional and subject to formal adoption [10]. The European Parliament cast its plenary vote on June 16, 2026, approving the agreed text 423 votes to 57, with 174 abstentions [5], and the Council of the EU gave its final sign-off on June 29, 2026 [12]. CSA published a follow-up note at that point analyzing the Council-approved deadlines, again noting that the changes would take legal effect only once published in the Official Journal [11].
That formal step has now occurred. Regulation (EU) 2026/1744 of the European Parliament and of the Council, dated July 8, 2026, was published in the Official Journal on July 24, 2026, and — because of its proximity to the original deadline — was written to enter into force “as a matter of urgency” on the third day after publication, July 27, 2026, rather than the standard 20-day window [1][6]. For any organization still tracking this issue by reference to the provisional agreement or the Parliament vote, the operative fact as of this writing is simpler: the deferral is law, it has been law for five days, and the August 2, 2026, high-risk deadline that dominated compliance planning for the past year will not arrive as originally written.
Security Analysis
The practical effect of Regulation (EU) 2026/1744 is a two-tier deferral. Standalone high-risk AI systems under Annex III — covering biometric identification, critical infrastructure, education, employment, essential services such as credit scoring and insurance, law enforcement, migration, and administration of justice — now have until December 2, 2027, to complete conformity assessments, technical documentation, and registration in the EU database [1][6]. AI systems embedded in products already regulated under EU safety legislation, such as medical devices, machinery, and toys, move from an August 2027 deadline to August 2, 2028 [6][7]. Both figures match what CSA’s prior analyses projected from the provisional agreement and the Council-approved text, so no last-minute change occurred on the headline dates themselves.
Where the final text does depart from the version CSA previously analyzed is in several second-order provisions that only became clear once the regulation was formally drafted. The Omnibus narrows high-risk scope by excluding AI embedded in Machinery Regulation products from direct Annex I classification, though the Commission retains authority to impose AI-specific requirements on such products through delegated acts later [7][8]. It also softens the AI literacy obligation in Article 4 from a mandate to achieve a defined level of staff competence to a duty to take “measures supporting” AI literacy — a lower bar that nonetheless does not eliminate the underlying requirement [7][13]. Supervisory reach moves in the opposite direction: the EU AI Office’s jurisdiction now extends to AI systems built on GPAI models within the same corporate group (rather than only the GPAI provider itself), and to systems integrated into Very Large Online Platforms and Very Large Online Search Engines already regulated under the Digital Services Act, creating overlap between the two regimes [7]. A further simplification allows providers who self-assess a system as falling outside high-risk classification under Article 6(3) to use a shortened Annex VIII documentation set rather than the full technical file [6]. None of these adjustments were locked in when CSA’s June and July notes went to press, since they depended on final legislative drafting rather than the political agreement’s headline terms.
This note treats the obligations that were not deferred as deserving equal emphasis, because the Omnibus’s framing as a “high-risk delay” risks being misread as a blanket delay. Article 50’s transparency duties — requiring disclosure when a person is interacting with an AI system, labeling of AI-generated synthetic audio, image, video, or text, and disclosure of deepfakes — took effect on schedule on August 2, 2026, and apply based on system function rather than risk tier, meaning mainstream generative AI deployments are squarely in scope regardless of the Annex III deferral. CSA’s dedicated analysis of this obligation, published three days before this note, sets out the four transparency duties, their exemptions, and the security limitations of the watermarking technology many providers rely on to satisfy the labeling duty [9]. GPAI provider obligations under Articles 51–56 have applied since August 2, 2025, and continue unaffected, as do the Article 5 prohibited practices in force since February 2, 2025. The Omnibus adds two new prohibited categories to that Article 5 list — systems that generate non-consensual intimate imagery and child sexual abuse material — with a grace period for the associated technical safeguards running to December 2, 2026, the same date given to the watermarking sub-obligation for systems already on the market before August 2026 [6][7]. Violations of Article 5’s prohibited-practices regime, including these new categories, carry the Act’s steepest penalty tier of up to €35 million or 7 percent of global annual turnover, whichever is higher, compared with up to €15 million or 3 percent for most other high-risk and GPAI violations [1].
The net compliance picture for an enterprise checking its posture the day before the original deadline is therefore neither “nothing changed” nor “everything is delayed.” It is a regulation that removed the single largest near-term obligation — Annex III conformity assessment — while leaving transparency, GPAI, and prohibited-practices duties on their original timeline and adding new prohibited-practices exposure with its own near-term deadline five months out.
Recommendations
Immediate Actions
Compliance and legal teams should update internal trackers to cite Regulation (EU) 2026/1744 directly — published July 24, 2026, in force July 27, 2026 — rather than the provisional agreement or Council-approval language that may still appear in board materials or vendor questionnaires drafted before formal adoption. Teams should also confirm, separately from the high-risk deferral, that Article 50 transparency disclosures and machine-readable labeling are live in production systems, since that obligation took effect on schedule and is a function-based rather than risk-tier duty that reaches chatbots, content generators, and other mainstream deployments regardless of Annex III status.
Short-Term Mitigations
Within the next 60 to 90 days, organizations should re-run their AI system inventory against the narrowed Annex I scope, removing systems embedded in Machinery Regulation products from high-risk tracking while noting the Commission’s retained authority to impose AI-specific requirements later. Providers relying on Article 6(3) self-assessment should evaluate eligibility for the simplified Annex VIII documentation path, and any organization deploying generative AI capable of producing intimate imagery or exploitative content should begin technical-safeguard work now against the December 2, 2026, grace-period deadline for the new Article 5 prohibitions, rather than treating it as a distant date.
Strategic Considerations
The extended runway to December 2027 and August 2028 should be used to build durable, auditable AI governance infrastructure rather than to deprioritize the work, a point CSA’s earlier analyses of this deferral have made and that remains true now that the deferral is confirmed rather than provisional [10][11]. Given that the EU AI Office’s supervisory reach has expanded to cover GPAI-model-based systems within a corporate group and integrations with Very Large Online Platforms and Search Engines, organizations with both AI and DSA-regulated digital services should map where those two supervisory regimes now overlap. Finally, national regulatory sandboxes must be established by member states by August 2, 2027, under the Omnibus [7]; enterprises developing high-risk systems in regulated sectors may find earlier engagement with a sandbox program a lower-friction path to conformity guidance than waiting for harmonized standards to finalize.
CSA Resource Alignment
This note completes a three-part arc in CSA’s coverage of the Digital Omnibus on AI and should be read alongside its predecessors rather than in isolation. CSA’s “EU AI Act Digital Omnibus: Enterprise Risk Recalibration” analyzed the May 7, 2026, provisional political agreement and first identified which obligations would remain enforceable regardless of the deferral. CSA’s “EU AI Act High-Risk Deadline Pushed to December 2027” followed the Council’s June 29, 2026, approval and translated the agreed dates into an enterprise governance roadmap. This note closes that arc by confirming the text as formally enacted law — Regulation (EU) 2026/1744 — and surfacing the provisions that changed between the provisional agreement and the final text: machinery-scope narrowing, the softened AI literacy duty, expanded AI Office supervision, and simplified self-assessment documentation. Readers should also treat CSA’s “EU AI Act Article 50: Transparency Obligations Take Effect” as the operative companion to this note for the obligations that were not deferred, since it details the four transparency duties, their exemptions, and the documented fragility of machine-readable watermarking as a compliance control.
For control implementation, the AI Controls Matrix (AICM) v1.1 remains the appropriate mapping layer across all three notes: its risk-management, technical-documentation, human-oversight, and transparency domains correspond directly to the Annex III, Annex IV, and Article 50 requirements discussed here, and organizations building governance infrastructure during the extended runway should use AICM v1.1 as the auditable structure underlying that work rather than building a bespoke EU-specific control set.
References
[1] European Parliament and Council of the European Union. “Regulation (EU) 2026/1744 of 8 July 2026 amending Regulation (EU) 2024/1689 (Digital Omnibus on AI).” Official Journal of the European Union, July 24, 2026.
[2] European Commission. “Digital Omnibus on AI Regulation Proposal.” Shaping Europe’s Digital Future, November 19, 2025.
[3] Holland & Knight. “U.S. Companies Face EU AI Act’s Possible August 2026 Compliance Deadline.” Holland & Knight Insights, April 2026.
[4] DLA Piper. “The Digital AI Omnibus: Proposed Deferral of High-Risk AI Obligations Under the AI Act.” DLA Piper GENIE, 2026.
[5] European Parliament. “Digital Omnibus on AI – Legislative Train Schedule.” European Parliament, 2026.
[6] Lewis Silkin. “The Digital Omnibus on AI Enters Into Force Today.” Lewis Silkin Insights, July 27, 2026.
[7] Freshfields Bruckhaus Deringer. “EU AI Act Unpacked #34: The Final Digital Omnibus on AI — Key Amendments to the AI Act and Their Impact on Businesses Active in the EU.” Freshfields Technology Quotient, 2026.
[8] Hunton Andrews Kurth. “EU Digital Omnibus on AI Enters Into Force.” Hunton Privacy & Cybersecurity Law Blog, July 2026.
[9] Cloud Security Alliance AI Safety Initiative. “EU AI Act Article 50: Transparency Obligations Take Effect.” Cloud Security Alliance, July 29, 2026.
[10] Cloud Security Alliance AI Safety Initiative. “EU AI Act Digital Omnibus: Enterprise Risk Recalibration.” Cloud Security Alliance, June 9, 2026.
[11] Cloud Security Alliance AI Safety Initiative. “EU AI Act High-Risk Deadline Pushed to December 2027.” Cloud Security Alliance, July 8, 2026.
[12] Council of the European Union. “Artificial Intelligence: Council Gives Final Green Light to Simplify and Streamline Rules.” Council of the EU Press Release, June 29, 2026.
[13] Stibbe. “AI Act Reloaded? What the Latest AI Act Changes Mean in Practice.” Stibbe Insights, 2026.