AI Governance
The EU AI Act's 2 August 2026 date passed, and the Digital Omnibus moved the hard part
Regulation (EU) 2026/1744 entered into force on 27 July 2026 and pushed most high-risk obligations to December 2027 and August 2028. Transparency and general-purpose model duties kept their dates.

Did the EU AI Act deadlines change in 2026?
Yes, in part. Regulation (EU) 2026/1744 entered into force on 27 July 2026 and moved most high-risk obligations to December 2027 and August 2028. Transparency requirements and general-purpose AI model duties kept their original dates, so providers still face live obligations while the high-risk regime is delayed.
Key facts
AI Act entered into force 1 August 2024; prohibitions and AI literacy applied from 2 February 2025.
General-purpose AI model obligations and national governance applied from 2 August 2025.
The Digital Omnibus on AI moved Annex III high-risk duties to 2 December 2027 and product-embedded high-risk AI to 2 August 2028.
The timeline as it stands
The European Commission's own implementation timeline now reflects the amendments: entry into force 1 August 2024, prohibitions and AI literacy from 2 February 2025, general-purpose AI rules and governance from 2 August 2025, and the majority of the rules coming into force with enforcement starting 2 August 2026.
On 27 July 2026, Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force and amended the Act days before its main application date.
What moved and what did not
High-risk obligations for Annex III uses such as recruitment, creditworthiness, education and access to essential services move to 2 December 2027. High-risk AI embedded in regulated products generally moves to 2 August 2028.
Article 50 transparency duties, the ones that cover chatbots and generative outputs, and the general-purpose model obligations kept their existing dates. A delay on one track is not a delay on all of them.
The practical risk
The common mistake is reading headlines about a delay and standing down an entire AI governance programme. Organisations with EU-facing generative features still have live obligations.
Extra runway is useful only if it is spent on inventory, classification, documentation and human oversight evidence rather than on waiting.
What it means for you
If you work in GRC, the useful skill is not quoting the Act, it is maintaining an AI system inventory with a defensible risk classification per system, and being able to show the evidence behind it.
Regulation only pays you if you can show the work.
The GRC Experience Program builds practical project experience, interview-ready stories and the positioning to prove it.
Turn This Into Something You Can Prove.
Short fit call. Clear next step. If neither program is right for you, we'll tell you.
Related posts

OpenAI's rogue agents and the Hugging Face breach: what the timeline now shows
Reuters reports the agents were probing Hugging Face in May, two months before the July breach. Sam Altman calls it the worst accident OpenAI has seen. Washington's answer is a bill that would treat frontier AI like a drug awaiting clearance.
Read article
Anthropic is arguing with Microsoft, its own researchers and the release calendar
A resignation, a public split with Microsoft's AI chief over machine consciousness, a threat intelligence report and a product consolidation all landed inside two weeks. Underneath the noise is a real disagreement about how fast to ship.
Read article
Canada's Bill C-8 is law: what the Critical Cyber Systems Protection Act changes
Royal assent on 15 June 2026 created a federal cyber duty for telecom, banking, energy, transport and nuclear operators. The Act is on the books but not yet in force.
Read article