watsonx.governance

watsonx.governance

Direct, manage and monitor your AI using a single toolkit to speed responsible, transparent, explainable AI

 View Only

The EU AI Act after the omnibus: what still applies on August 2

By Boris Dzhingarov posted 07/31/26 01:23 AM

  

On July 24, the amendment package known as the Digital Omnibus on AI was published in the Official Journal of the European Union. It took effect three days later. The short version in most coverage: the AI Act's high-risk rules are delayed. That version is true. It is also the reading most likely to get a compliance team in trouble, because the obligations taking effect on August 2 did not move at all.

What moved, and why

The delay is real. Obligations for high-risk systems under Annex III, the use-based category covering AI in hiring, credit scoring, insurance pricing, education, and access to essential services, were due to apply on August 2, 2026. They now apply from December 2, 2027. High-risk AI embedded in regulated products under Annex I moves further out, to August 2, 2028. The path there was anything but smooth. A round of trilogue talks collapsed at the end of April, negotiators reached a provisional deal on May 7, Parliament voted on June 16, the Council approved on June 29, and the final text reached the Official Journal with about a week to spare before the original deadline would have bitten.

The reason for the extension matters more than the extension itself. Member states were slow to designate the market surveillance authorities meant to enforce the rules, and the harmonized standards that high-risk conformity depends on were unfinished. Regulators were heading toward demanding compliance against benchmarks that did not exist. Brussels moved the date because the enforcement machinery was not built. Enterprise readiness had very little to do with it, which is worth remembering before anyone treats the new timeline as proof that the pressure is off.

What did not move

Article 50, the transparency chapter, applies from August 2, 2026 as originally written. If your company runs a customer-facing chatbot under its own brand, that system now has a legal duty to tell people they are interacting with AI. The obligation attaches to whoever puts their name on the system, so buying the underlying model from a supplier does not shift it. The same date brings disclosure duties for emotion recognition, biometric categorization, and deepfakes. There is one carve-out: systems that generate synthetic audio, image, video, or text and were already on the market before August 2 get until December 2, 2026 to meet the machine-readable marking requirement. Fines for Article 50 violations reach 15 million euros or 3 percent of worldwide annual turnover, whichever is higher.

The omnibus also expanded the list of banned practices, in force since February 2025, to cover systems built to generate non-consensual intimate imagery. So this was not purely a loosening. The only ground Brussels gave was on obligations its own regulators were not yet equipped to enforce.

Who is exposed right now

The companies most at risk this quarter started preparing, read the May political agreement as a finish line, and quietly stood their programs down. They then spent June and July inside an uncomfortable gap: the political deal promised new dates, but until publication, the law as written still said August 2 for everything. That gap closed with a week to spare. Demobilizing in May was a bet that the legislative calendar would cooperate. It did, this time. Companies that never started preparing at least know exactly where they stand.

There is also a quieter shift in who carries the work. Early AI Act commentary talked mostly about providers, the companies that build and sell the systems. Annex III lands hard on deployers too: the bank using a scoring model, the insurer running automated risk checks, the HR team that bought a screening tool. Deployer duties include using systems according to the provider's instructions, assigning trained human oversight, monitoring operation, and keeping logs. None of that can be outsourced to the vendor, although plenty of contracts are currently written as if it could.

What sixteen months is for

Sixteen months sounds like room until you list what has to fit inside it. Most large organizations still cannot produce a complete inventory of the AI running across their business, including the models buried inside vendor software. You cannot classify what you have not catalogued, and classification against Annex III is the step everything else hangs on. A hiring workflow with a resume screening model inside it is high risk. A service bot that decides who qualifies for a payment plan probably is too. Nobody can say for certain until someone looks, system by system.

After classification comes the slower work: risk management documentation, data governance evidence, logging, and human oversight that exists in operations rather than on a slide. Then the contract renegotiations that carry provider duties through the vendor chain. Sixteen months in a large company is one budget cycle and, usually, one reorg. A program that restarts in mid-2027 will find its timeline set by procurement and system rebuilds, and neither of those compresses well.

Two dates, two workstreams

The practical reading of the omnibus is simple. August 2 is an operations task: find every system that talks to customers or generates content, switch on disclosure and marking behavior, and log that it happened. December 2027 is a governance build: inventory, classification, documentation, and oversight that will hold up in front of a market surveillance authority. Treat the second date as if it were next summer. Organizations that read the delay as a pause will rediscover the panic of early 2026 sometime in the spring of 2027, and betting on a second rescue is not a compliance strategy.


#watsonx.governance
0 comments
6 views

Permalink