Security & Compliance

AI Act deadlines moved: what still lands August 2, 2026

By Technspire TeamJune 17, 202612 views

Yesterday, on 16 June 2026, the European Parliament gave its final approval to the Digital Omnibus on AI: 423 votes in favour, 57 against, 174 abstentions. The package rewrites the AI Act's most feared deadlines. Obligations for standalone high-risk AI systems under Annex III move from 2 August 2026 to 2 December 2027, and obligations for high-risk AI embedded in regulated products move from August 2027 to 2 August 2028. If your compliance programme was sprinting toward this August, you just got sixteen extra months on the hardest workstream.

Read the vote carefully before you stand the programme down, though. The omnibus delays the high-risk regime and nothing else that matters this summer. Article 50 transparency duties still apply from 2 August 2026. The Commission's enforcement powers over general-purpose AI providers, backed by fines of up to 15 million euros or 3% of worldwide annual turnover, also activate on 2 August 2026. The prohibitions on unacceptable-risk practices and the AI literacy requirement have been in force since 2025 and were never on the table. For a Swedish enterprise running chatbots and generative AI on Azure, the deadline that survived the vote is six and a half weeks away.

What the Parliament voted through on 16 June

The Digital Omnibus on AI has moved fast by EU standards. The Commission proposed the targeted amendments on 19 November 2025, the Council adopted its negotiating position on 13 March 2026, the co-legislators reached a trilogue agreement on 7 May 2026, and Parliament approved that agreed text yesterday. The final tally was notably weaker than the March negotiating-mandate vote, which reflects how contested the delay became, but the legislative outcome stands.

The substantive changes fall into four groups:

  • High-risk deadlines postponed. Standalone high-risk systems under Annex III (recruitment, credit scoring, education, critical infrastructure and similar use cases) now come into scope on 2 December 2027. High-risk AI that is a safety component of regulated products under Annex I (machinery, medical devices) follows on 2 August 2028.
  • Content marking gets a short grace period. The machine-readable marking of AI-generated content under Article 50 is postponed to 2 December 2026 for generative systems already on the market. The rest of Article 50 applies from 2 August 2026 as originally scheduled.
  • New prohibitions added. The omnibus bans AI systems designed to generate non-consensual intimate imagery and child sexual abuse material, with compliance required by 2 December 2026. This is a substantive tightening inside a package otherwise sold as simplification.
  • SME and small mid-cap relief. Simplified documentation for medium-sized companies, eased registration for non-high-risk systems, and more post-market monitoring flexibility for SMEs and small mid-caps.

Legal status today: Parliament's approval is not the finish line. The Council must formally adopt the text, both presidents must sign it, and it must be published in the Official Journal before the new dates become binding law. The institutions aim to complete this before 2 August 2026. Until publication, the 2024 AI Act text, with its original deadlines, remains the applicable law. Plan on the new dates, but do not certify anything to your board as final until the Official Journal publication lands.

What did not move

Article 50 transparency lands on 2 August 2026

Article 50 is the AI Act's transparency layer, and apart from the content-marking grace period it was left untouched. From 2 August 2026, three duties apply to most organisations deploying AI toward end users:

  • Chatbot disclosure. People interacting with an AI system must be informed they are talking to a machine, unless that is obvious from context. A customer-service bot on your website, an internal HR assistant exposed to employees, a voice agent on your support line: all in scope.
  • Machine-readable marking of AI-generated content. Providers of generative systems must ensure outputs are marked as artificially generated in a machine-readable format. New systems must comply from August; systems already on the market get until 2 December 2026 under the omnibus.
  • Deepfake and synthetic-content labeling. Deployers must disclose when content depicting real people, places or events has been artificially generated or manipulated.

Most Swedish enterprises we talk to sorted their high-risk gap analysis first and treated Article 50 as the easy part to do later. After yesterday's vote the priority inverts. The high-risk work can breathe; the transparency work cannot.

GPAI enforcement powers activate the same day

Obligations for providers of general-purpose AI models have applied since 2 August 2025: transparency about training, copyright policies, and additional security and reporting duties for models with systemic risk. What changes on 2 August 2026 is enforcement. From that date the Commission's AI Office can exercise its supervisory powers over GPAI providers, including information requests and fines of up to 15 million euros or 3% of total worldwide annual turnover. The omnibus did not touch this. A one-year gap between obligation and enforcement closes on schedule.

Most Azure customers are deployers of GPAI, not providers, and the direct exposure sits with Microsoft, OpenAI, Anthropic, Mistral and their peers. But the boundary is not always clean. If you fine-tune a foundation model substantially and place it on the market, or ship a product in which your modified model is the core capability, you should have a documented position on whether you have become a provider. That analysis is cheap now and expensive during an information request.

Prohibitions and AI literacy already apply

Nothing in the omnibus revisits what is already in force. The Article 5 prohibitions (social scoring, certain biometric practices, manipulation techniques) carry fines up to 35 million euros or 7% of worldwide turnover and have applied since February 2025. The Article 4 AI literacy duty, requiring appropriate AI competence among staff who operate AI systems, has applied just as long. If your organisation deferred literacy training while waiting for the deadline landscape to settle, that reasoning has now expired.

A triage framework for the next six weeks

The vote splits your AI inventory into three buckets with very different clocks. Run every system through these questions:

  • 1. Does the system interact with people or generate content? If yes, it is in the August bucket. Verify chatbot disclosure in the interface, marking of generated output, and labeling of synthetic media. This is UI, pipeline and documentation work you can complete in weeks.
  • 2. Is the system a GPAI model you provide, or one you have modified enough to arguably provide? If yes, it is also in the August bucket, on the enforcement side. Confirm your provider-versus-deployer analysis in writing and check what compliance documentation your model vendor publishes for you to reference.
  • 3. Is the use case in Annex III? Recruitment screening, creditworthiness, exam scoring, critical-infrastructure management and the other listed categories now have until 2 December 2027. Keep the workstream alive at lower intensity: conformity assessment, data governance and human-oversight design are multi-quarter efforts, and December 2027 arrives faster than a sixteen-month headline suggests.
  • 4. Does anything you run touch image generation of real people? The new prohibition on non-consensual intimate imagery tools takes effect 2 December 2026. Review acceptable-use enforcement on any image-generation capability you expose, internally or to customers.

Doing the August work on Azure

For teams running generative AI through Azure OpenAI or Azure AI Foundry, the Article 50 duties translate into concrete engineering tasks.

Chatbot disclosure is a front-end change, not a legal memo. The disclosure has to reach the person during the interaction. A line in your terms of service does not meet the bar. Put clear interface text at conversation start, and keep it in the transcript. For voice agents, script the disclosure into the greeting. Inventory every bot surface first: the marketing-site widget everyone remembers, plus the Teams bots, the Copilot Studio agents and the pilot someone shipped to a customer portal last autumn.

Content marking needs a pipeline audit. If you generate images, audio or documents that leave your organisation, trace the path from model output to final artifact. Marking that your generation step applies is only useful if downstream steps preserve it; a thumbnailing job or an office-format conversion can silently strip metadata. Where you rely on your model vendor's built-in marking, document that reliance and verify it survives your post-processing.

Build the evidence trail while you build the feature. The cheapest time to create compliance evidence is when the control ships. Log disclosure events and marking operations into your existing observability stack. If your AI traffic already flows through Azure API Management, you have a natural choke point: a policy that stamps and logs transparency metadata gives you a queryable record in Log Analytics when a regulator, customer or auditor asks how long the control has been active.

Watch your vendor's compliance surface. GPAI enforcement lands on your model providers in August. Expect updated documentation, model cards and copyright-policy statements from Microsoft and the model vendors over the summer, and wire a review of them into your procurement and vendor-management routine rather than discovering changes by accident.

The Swedish angle: procurement, supervision and budgets

Three practical consequences for Swedish organisations follow from yesterday's vote.

Contracts and upphandling documents need a date review. AI Act compliance clauses have been flowing into Swedish procurement templates and supplier contracts for two years, and many name 2 August 2026 explicitly as the high-risk compliance date. Those references are about to point at the wrong deadline. Buyers should decide whether contractual high-risk commitments track the statutory dates or hold suppliers to the original ones anyway; suppliers should re-read what they have already signed before assuming the delay flows through automatically. Transparency-related clauses, by contrast, remain correct and enforceable on the original timeline.

Supervision arrives in layers. GPAI enforcement is centralised at the Commission's AI Office, so that layer activates in August regardless of how far any member state has come in standing up national market surveillance. The high-risk delay gives Sweden and the other member states extra time to finish building the national supervisory structures that the Annex III regime depends on. Do not read the quieter national layer as absence of enforcement risk: the transparency duties are law from August, and documented non-compliance ages badly.

Reallocate the 2026 budget, do not release it. Compliance budgets planned around an August high-risk deadline will tempt finance teams as savings. The better move is reallocation: pull the transparency and literacy work forward into the freed capacity, and convert the high-risk sprint into a paced programme with a December 2027 milestone plan. Teams that disband now will rebuild in mid-2027 at a higher cost and with less institutional memory.

What to ship before 2 August 2026

  • Inventory every user-facing AI surface: chatbots, voice agents, Copilot Studio agents, embedded assistants, customer-portal pilots.
  • Ship chatbot disclosure as perceivable interface text on every surface, logged per conversation.
  • Audit generative pipelines for marking: confirm machine-readable marking is applied and survives post-processing; note that systems already on the market have until 2 December 2026 for this specific duty.
  • Label synthetic media that depicts real people, places or events, wherever your organisation publishes it.
  • Write down your GPAI position: provider or deployer, per model, with the fine-tuning rationale documented.
  • Close the AI literacy gap: the Article 4 duty already applies, and evidence of training is easy to produce now.
  • Re-date the high-risk programme to 2 December 2027 with quarterly milestones, and keep it staffed.
  • Track the Council's formal adoption and Official Journal publication before treating the new dates as final, and update contract templates once they are.

Sources