High-risk obligations are deferred to December 2027 and August 2028. The headlines stopped there. The deadline that companies should actually have in their calendar is 2 December 2026 — and it is roughly four months away.
The European Commission published its Digital Omnibus on AI on 19 November 2025. Council and Parliament reached political agreement on 7 May 2026. Parliament formally endorsed the package on 16 June, the Council gave its final green light on 29 June, and the act was signed on 8 July 2026.
Coverage since has been almost entirely about one number: the high-risk deadline moving from August 2026 to December 2027. That is the biggest change, and for companies building high-risk systems it is a genuine eighteen-month reprieve. It is also not the part that most companies need to act on this year.
| Obligation | Applies from | Status |
|---|---|---|
| Prohibited practices, AI literacy | 2 February 2025 | In force |
| GPAI model provider obligations | 2 August 2025 | In force |
| Governance, national authorities, penalties framework | 2 August 2025 onward | In force |
| Transparency and labelling of AI-generated content | 2 December 2026 | Next up |
| High-risk — standalone systems (Annex III) | 2 December 2027 | Deferred |
| High-risk — AI in regulated products (Annex I) | 2 August 2028 | Deferred |
The obligation to make AI-generated or manipulated content identifiable moved from August to December 2026 — a modest extension, not a deferral. It applies far more broadly than the high-risk regime: any company whose product generates synthetic text, images, audio or video for EU users is in scope, regardless of risk classification. This is the deadline that lands first, and it is the one the delay headlines buried.
The package was framed as simplification, and in parts it is. But it also tightened the regime in specific places, which is worth reading carefully before concluding that the direction of travel is uniformly permissive.
The pattern is consistent: procedural burden reduced for companies acting in good faith, substantive prohibitions extended where the conduct is unambiguous. Anyone reading the package as a retreat from the AI Act has read only the timeline.
Nothing in the package alters the structural requirement that sits underneath the whole regime. A provider established outside the Union still needs a person established inside the Union who can be addressed by the authorities — an authorised representative appointed by written mandate under Article 22 for high-risk systems, and under Article 54 for general-purpose AI models.
The Article 54 obligation for GPAI model providers has applied since 2 August 2025 and was not deferred. For a company outside the EU providing a general-purpose model into the European market, the representation requirement is not on the new calendar at all. It is already behind schedule.
Member States were required to designate their national competent authorities by 2 August 2025, and most did not meet it — reporting through early 2026 put the count that had designated both market surveillance and notifying authorities at around nine of twenty-seven. Spain is on the other side of that line, with AESIA, created by Royal Decree 729/2023 and operational since 2024 as the first EU supervisory body dedicated specifically to AI, seated in A Coruna.
The Spanish implementing law — the Proyecto de Ley Organica on the good use and governance of AI, designating supervisory authorities and setting a national penalty regime with fines reported up to €35 million or 7% of worldwide turnover — was approved by the Council of Ministers on 26 May 2026 and remains in parliamentary process. It is not yet in force.
Establishing an EU entity takes weeks to incorporate and months to bank properly. Appointing an authorised representative requires a counterparty prepared to accept statutory exposure and conduct real diligence first. Both are now comfortably doable before the technical work becomes urgent — which is exactly the window that tends to be spent doing nothing.