Enforcement Countdown · Originally 19 April · Updated 27 June 2026
What Still Applies on 2 August 2026, and What Moved to 2 December 2027
The Digital Omnibus (adopted by the European Parliament 16 June 2026, Council adoption 29 June 2026) moved Annex III high-risk obligations from 2 August 2026 to 2 December 2027. But a meaningful set of EU AI Act obligations still hits 2 August 2026, Article 50 transparency (chatbots, deepfake disclosure to users), Article 49 registration, GPAI enforcement, national market surveillance authority designations. This piece tells you what remains required this quarter, what becomes new on 2 December 2026, and how to prioritise the runway to 2 December 2027. The structure of the work is unchanged.
What still applies on 2 August 2026
The Omnibus is targeted. Most of the AI Act's August 2026 obligations are not touched. If your organisation operates in the EU and processes any AI system, plan against this list:
- Article 50 transparency obligations (most), chatbot disclosure, deepfake disclosure to users, emotional-recognition disclosure. These apply from 2 August 2026 as enacted. Only the synthetic-content watermarking obligation under Article 50(2) shifted.
- Article 49 EU database registration, providers must register high-risk AI systems in the EU database. This applies from 2 August 2026 because the database obligation runs on a separate track to the substantive high-risk requirements.
- National market surveillance authority enforcement powers, Member State competent authorities gain enforcement powers from 2 August 2026 for the obligations that apply on that date.
- Article 5 prohibitions, already in force since 2 February 2025. Continue to apply.
- GPAI obligations (Articles 51–56), already in force since 2 August 2025. Continue to apply.
- Article 4 AI literacy, applicable since 2 February 2025. The Omnibus final consolidated text may amend Article 4's structure; until then, treat it as live.
What is new on 2 December 2026
Two obligations land four months after the original August 2026 deadline. Both affect every generative AI provider regardless of Annex III status:
- Article 50(2) synthetic content watermarking, providers of generative AI systems must mark synthetic audio, image, video and text content as machine-readable. Original deadline 2 August 2026; shifted to 2 December 2026 under the Omnibus.
- New Article 5 prohibition, placing AI systems on the EU market that generate or manipulate non-consensual intimate imagery, or that generate child sexual abuse material, is now prohibited. Compliance deadline 2 December 2026. Affects safety-filter documentation for every generative AI provider.
What moved to 2 December 2027, the 18-month horizon
Annex III high-risk obligations (Articles 9, 10, 11, 12, 13, 14, 15, 17, 27, 43, 49, 72, 73 as they apply to standalone high-risk AI systems) move to 2 December 2027. AI embedded as safety components in Annex I regulated products moves to 2 August 2028. The work, the Article 9 risk management system, the Annex IV technical documentation, the Article 27 FRIA, the Article 17 quality management system, remains exactly the same. CEN/CENELEC harmonised standards drafting continues, expected end-2026 at earliest. The runway after standards publish is roughly 12 months. That is realistic time but not abundant time.
What market surveillance authorities examine first
If a market surveillance authority opens an enquiry, the first request they will issue is not for your technical documentation, your model cards, or your FRIA. It is for two things:
- The list of all AI systems you build or deploy, with each classified against Annex III
- Your risk management policy demonstrating that Article 9 is operational
These two deliverables decide whether the authority treats your organisation as "compliance programme in operation with some gaps" (leading to a remediation plan) or "no compliance programme" (leading to market restriction orders and penalties). Prioritise them accordingly. The inventory and the policy are foundational regardless of whether the deadline is August 2026 or December 2027.
The work plan, sequence by what gets examined first
Weeks 1–3 (19 April – 10 May): Inventory and classification
Build a complete inventory of every AI system touching your organisation. Not your "known" AI systems , every one, including shadow AI.
- Every AI system built internally, including models in pilot or PoC
- Every AI system purchased from vendors, including SaaS platforms with AI features (HR tech, CRM, finance, marketing automation)
- Every API call your software makes to foundation model providers (GPT, Claude, Gemini, Mistral)
- Every AI agent or Copilot your teams use (Claude Cowork, Microsoft Copilot, GitHub Copilot, Cursor, etc.)
For each system, capture: name, provider, version, intended purpose, business owner, data types processed, users affected, geographic scope, current compliance status. Industry experience suggests 50% of organisations discover AI systems in this exercise that IT and compliance did not previously know existed.
Then classify each system against Annex III. For systems in scope, apply the Article 6(3) exception test. Document every classification decision in writing, the rationale will be requested.
Weeks 4–6 (11 May – 31 May): Risk management system and policy foundation
Article 9 requires a continuous, iterative risk management system across the AI system lifecycle. This is not an assessment, it is a process that must demonstrably operate.
- Draft and approve the AI Risk Management Policy (board-level document)
- Designate the AI Risk Officer (or formally assign the function to an existing role)
- For each high-risk system: identify known and reasonably foreseeable risks across the lifecycle
- Estimate risk likelihood and severity for both intended use and foreseeable misuse
- Define and document mitigation measures per Article 9(5)
- Establish risk review cadence, minimum quarterly for high-risk systems
Parallel work: adopt the LLM & Generative AI Governance Policy (board approval) and publish internally. This covers Articles 13, 14, and 50 for your organisation's use of external AI tools.
Weeks 7–10 (1 June – 28 June): Technical documentation and data governance
This is the longest and most effort-intensive phase. For each high-risk system, build the Annex IV technical documentation pack. This is 21 specific documentation elements grouped into 5 parts:
- General description, intended purpose, architecture, version, interactions
- System components, design, development, model type, training methodology, training / validation / testing data
- Performance, controls, risk management, change log, monitoring, KPIs, Art. 9 risk management records, Art. 10 data governance
- Standards, conformity, declaration, harmonised standards applied, EU Declaration of Conformity, CE marking, Annex VIII registration reference
- Post-market and change management, PMM plan, incident procedure, change management procedure, retention policy
Parallel work for deployers: complete the Article 27 FRIA for each high-risk system in covered contexts. The FRIA must be submitted to the market surveillance authority before first deployment.
Weeks 11–13 (29 June – 19 July): Human oversight, vendor diligence, cybersecurity
Operationalise the requirements that depend on people, not documents:
- Article 14 human oversight, designate oversight personnel for each high-risk system. Document their competence. Document their authority to override, halt, or reverse AI outputs. Train them. Record training completion.
- Article 25 vendor diligence, issue the AI Readiness Questionnaire to every AI vendor. Track responses. Flag vendors who cannot demonstrate readiness by 15 July.
- Article 15 cybersecurity, confirm that security controls (authentication, access management, incident response, vulnerability management) are operating for each high-risk system. Test them.
- Quality management system (Article 17), document your QMS. For ISO 9001 or ISO 27001-certified organisations, extend existing documentation. For others, build baseline QMS documentation referencing the relevant Art. 17 capabilities.
Weeks 14–15 (20 July – 2 August): Registration, conformity, declaration
Final sequence before the deadline:
- Complete conformity assessment (Annex VI internal control for most Annex III; Annex VII notified body required for biometrics and Annex I embedded products)
- Draft, sign, and retain EU Declaration of Conformity (Article 47)
- Affix CE marking to the high-risk AI system (Article 48)
- Submit Annex VIII information to the EU AI database (Article 49)
- Publish complaint mechanism for affected persons; confirm escalation path to the AI Risk Officer
- Present compliance status to the board with the Board Executive Briefing before the deadline
- Verify authorised representative appointment (Article 22) for non-EU providers
Board-level priorities across all 15 weeks
Compliance programmes fail when the board is not engaged. Three board-level actions are as important as the technical work:
- Authority and budget, the AI Risk Officer needs formal authority to stop AI deployments that are not compliant, and budget adequate to the remediation work. Without board-level mandate, compliance recommendations get overruled by product deadlines.
- Visibility, the board should receive monthly written updates for the final 15 weeks. One-page status against the work plan, red/amber/green per system, decisions needed.
- Risk appetite, the board should formally document its risk appetite for non-compliance. This is not about planning to violate, but about deciding what residual risk is acceptable where full compliance is infeasible in 15 weeks.
What to do if you are starting from zero
If your organisation has not begun EU AI Act compliance work as of 19 April 2026, the realistic path is:
- Weeks 1–2: inventory and rough classification only. Be fast, not perfect.
- Week 3: identify the 1–3 highest-risk systems in your inventory. Focus remaining 12 weeks on those only.
- Weeks 4–12: build Article 9–15 compliance for those 1–3 systems.
- Weeks 13–15: document your programme for everything else as "in progress with remediation plan and named owner."
- After 2 August: proceed with the full inventory remediation plan on a schedule the board has approved.
This is not ideal, but it is defensible. Market surveillance authorities distinguish between "compliance programme operating with identified gaps on a remediation plan" and "no compliance programme." The first leads to remediation orders. The second leads to enforcement.
Watch for: Digital Omnibus outcome on 28 April
The 28 April trilogue may produce a political agreement extending the standalone high-risk deadline to 2 December 2027. Do not wait for the outcome. If the extension is adopted, you have 16 months of extra buffer on the work you have already done, that is a win. If the extension is not adopted, you are on schedule with work that was necessary either way.
The asymmetry is clear: the cost of preparing for the original deadline and getting an extension is low. The cost of waiting for an extension that does not arrive is high. Proceed.
Build the Compliance Programme in 90 Days
The Full Readiness Bundle delivers every document referenced in this work plan: 58-point checklist, Annex III classification matrix, AI system inventory template, FRIA starter, board briefing, Annex IV checklist, vendor questionnaire, governance policy, monitoring calendar, GPAI checklist, and ISO 42001 mapping matrix. Eleven documents. One week of drafting work compressed into one download.
Instant download · Word (.docx) + PDF · 12-month updates included · Unlimited internal use
Related Coverage
Digital Omnibus
28 April Trilogue Analysis
What the proposed 2 December 2027 extension will and won't change, and why August 2 should remain the operational deadline.
Practitioner Tool
Annex III Classifier
Run each AI system through the interactive classifier to determine high-risk status in 90 seconds.
Article 27
FRIA Template
Complete the Article 27 Fundamental Rights Impact Assessment before first deployment, full template walkthrough.