|

Postponement of the European AI law: new dates to 2027 and less red tape for companies

EU AI Act delay: compliance calendar for 2027 and 2028

On 7 May 2026 the European Union reached the agreement that half the industry had been waiting for: the AI Act obligations for high-risk systems are postponed to 2 December 2027 and 2 August 2028. The package, known as the AI Omnibus, simplifies procedures, reduces the administrative burden for SMEs and mid-caps, and expressly bans “nudification” apps.

What no headline is telling, and it is what I see in every conversation with management these days, is that there is a key obligation still in force for 2 August 2026. Skipping it can cost up to 15 million euros, and many people are assuming the postponement covers it. It does not.

In this article I explain what has been postponed, what still runs the same, what really changes for your company and how to plan compliance without it becoming a problem in 2027.

What the postponement of the European AI law is

The postponement of the European AI law is a provisional agreement between the Council of the EU and the European Parliament, reached in the early hours of 7 May 2026 after six months of negotiation. It is part of the Digital Omnibus package proposed by the European Commission on 19 November 2025.

The aim is twofold:

  • To postpone the obligations of high-risk AI systems because neither the harmonised standards nor the technical tools will be ready by the original date (2 August 2026).
  • To cut red tape by 25% for all companies and 35% for SMEs and mid-caps, as the Draghi report on European competitiveness demands.

It is important to understand the following: the AI Act remains in force. The structure, the penalties and the risk pyramid do not change. The only thing that moves are the deadlines and some procedures.

The new AI Act dates after the postponement

Consequently, this is the updated timeline that every Spanish company should have pinned to the wall:

ObligationOriginal dateNew dateSystems affected
High risk Annex III2 August 20262 December 2027HR, credit scoring, education, biometrics, critical infrastructure
High risk Annex I2 August 20272 August 2028Medical devices, machinery, toys, vehicles, lifts
Synthetic content marking (Art. 50)2 August 20262 December 2026Watermarking of generative AI already on the market
National sandboxes2 August 20262 August 2028Regulatory testing environments
AI literacy (Art. 4)2 August 2026UNCHANGEDAny organisation that uses AI
Prohibitions (Art. 5)February 2025IN FORCESubliminal manipulation, social scoring, mass biometrics

The delays are significant: 16 months for stand-alone high-risk systems and 12 additional months for AI embedded in regulated products.

Why the EU is postponing the AI law: three real reasons

On the other hand, behind the official headline there are three reasons I have been seeing for months in compliance projects, and which explain the postponement better than the Council’s press release:

1. The technical standards are not ready. The Commission was due to publish the official high-risk classification guidance in February 2026. To date it still has not appeared. Without that guidance, companies have no clear criteria to self-assess.

2. The national authorities are not operational. Only 8 of the 27 member states have designated their contact points. Supervision lacks a real operational structure. AESIA in Spain is the exception: it has already published 16 technical guides and launched the first call for its sandbox, but it is a European rarity.

3. Competitive pressure from the Draghi report. The United States and China are moving at a different pace. The EU needs a political signal to industry to prevent innovation from moving outside the European market.

Which AI Act obligations have NOT been postponed

So here is the trap that almost every executive I talk to is overlooking. Three blocks of obligations remain exactly where they were, and they are precisely the ones most had planned for 2026:

Article 4: AI literacy (2 August 2026)

First, every organisation that develops, deploys or uses AI systems must ensure that its staff have a sufficient level of AI literacy. The penalties reach 15 million euros or 3% of global turnover.

It does not distinguish by sector. Nor by size. And, moreover, the type of AI does not matter. If someone in your company uses ChatGPT, Copilot or a scoring system, you are an operator and it applies to you. I developed it in detail in my article on artificial intelligence literacy, where I explain how to land it in a real company without turning it into a formality.

Article 5: prohibited practices (in force since February 2025)

Subliminal manipulation, social scoring, mass biometric surveillance in public spaces, indiscriminate scraping of facial images: prohibited today. The fines reach 35 million euros or 7% of turnover.

Article 50: generative AI transparency (2 August 2026)

If you place a generative AI system on the market from August, it must allow the generated content to be identifiable as artificial by means of machine-readable marks. The technical watermarking capability must be operational.

The new development: ban on nudification and CSAM

In addition, the agreement of 7 May added a prohibition that was not in the original text. AI systems designed to generate non-consensual sexual or intimate content, or child sexual abuse material (CSAM), are banned.

The ban reaches:

  • Those who market these systems, even without that declared purpose, if they do not implement reasonable safeguards.
  • Those who deploy them to create that content.

It is one of the few restrictive additions in a package that, otherwise, eases obligations.

What changes with the administrative simplification

The bureaucratic component of the Omnibus includes six concrete measures affecting AI Act compliance:

  • Reduced registration in the European database for systems the provider considers exempt from high risk.
  • Conformity assessment procedures that are clearer, especially at the border with sectoral regulation (healthcare, automotive).
  • Expanded options for real-world testing.
  • Extension to mid-caps (up to 750 employees and €150M turnover) of the simplifications reserved for SMEs.
  • Postponement of the national sandboxes to 2 August 2028, giving authorities room to design them properly.
  • Expanded use of sensitive personal data for bias detection and correction, subject to safeguards. This is the most controversial provision of the package.

The criticism: simplification or disguised deregulation?

Not everyone is applauding. Digital rights coalitions —EDRi, Amnesty International, La Quadrature du Net— have called the Digital Omnibus a setback disguised as simplification.

Kai Zenner, adviser to MEP Axel Voss and a key figure in the original negotiation of the AI Act, sums it up bluntly: “It is a disaster for democracy”. His main concerns:

  • Weakening of the fundamental-rights supervisory bodies.
  • Exemptions for large companies through structural changes.
  • Risky use of sensitive data without adequate safeguards.
  • Substantial modification of the law’s structure by excluding a broad sector from the high-risk rules.

Michael McNamara himself, the Parliament’s lead negotiator, warns that shifting AI governance towards sectoral regulations may end up being “more deregulatory than simplifying”.

My reading, after reading the 240 pages of the full Omnibus: there is legitimate simplification — the original timeline was unrealistic — but there are also relaxations that affect fundamental rights and deserve scrutiny. Both things are true at once. Anyone who ignores the criticism will get surprises in the national transposition, especially regarding the cognitive footprint that generative AI is starting to leave on consumers and employees.

What your company should do before August 2026

The postponement is not an excuse to stop. It is the window many projects needed to do things well and not against the clock. These are the five priorities I am now focusing clients in regulated sectors on, and which I share in my AI Forge lab:

1. Close Article 4 before August

Design an AI literacy programme proportionate to each profile’s role:

  • Legal and compliance teams.
  • Business that makes automated decisions.
  • Technical staff who develop or integrate systems.
  • Management and the board.

Therefore, it is wise to document the programme, keep evidence and record attendance.

2. Inventory and classify your AI systems

Without an inventory, no compliance is possible. You need to know:

  • What AI systems you have (including SaaS with hidden AI modules).
  • Who the provider is and what technical documentation they supply.
  • Which level of the risk pyramid each one falls into.
  • What decisions it automates and about which people.

3. Prepare watermarking

If you deploy generative AI that produces content for end users, the technical marking capabilities must be operational in August 2026 for new systems. Existing ones have until December.

4. Audit your contracts with AI providers

The new 2027 deadline gives you time to require certifications, technical sheets, conformity documentation and contractual guarantees. Not to forget about the matter.

5. Design a roadmap to December 2027

Set quarterly milestones: mapping, fundamental-rights impact analysis, contractual adjustment, appointment of an internal owner, training, conformity assessment and, if applicable, CE marking.

AI Act penalties: what is at stake

It is worth recalling the penalty regime to size the risk correctly:

  • Up to €35M or 7% of global turnover: prohibited practices (Article 5).
  • Up to €15M or 3% of global turnover: breach of high-risk obligations, literacy (Article 4) or misleading information to authorities.
  • Up to €7.5M or 1% of global turnover: transparency infringements or incorrect information to notifiers.

SMEs pay the lower of the two values. Everyone else, the higher.

And a critical detail: the AI Act provides for personal liability of executives in cases of serious breaches, especially with prohibited systems or repeated breach of high-risk obligations.

If your organisation is also within the perimeter of DORA or NIS2, the penalty regimes accumulate and the scale of the risk grows. If you need to quantify it for your specific case, this is exactly the kind of diagnosis I do in the first phase of a project: tell me about your case here.

Frequently asked questions about the AI Act postponement

Is the AI Act still in force?

Yes. Regulation (EU) 2024/1689 entered into force on 1 August 2024 and remains fully operational. The Omnibus only modifies specific deadlines and procedures.

When does the AI Act apply to high-risk systems?

After the postponement, the full obligations for Annex III high-risk systems apply on 2 December 2027. For systems embedded in regulated products (Annex I), on 2 August 2028.

Which AI Act obligations apply in August 2026?

Three blocks remain in force for that date: AI literacy (Article 4), generative AI transparency (Article 50) and the penalty regime. The Article 5 prohibitions have already been in force since February 2025.

Does the AI Act affect Spanish SMEs?

Yes, but with proportionate measures. SMEs and mid-caps (up to 750 employees and €150M turnover) get access to simplified procedures, sandboxes and adapted implementation deadlines. However, the substantive obligations are the same if they use high-risk AI.

What role does AESIA play in AI Act compliance?

AESIA (the Spanish Agency for the Supervision of Artificial Intelligence) is the competent body in Spain. It inspects, requests documentation, penalises and orders market withdrawals. It has published 16 technical guides and operates the Spanish AI sandbox.

How does the AI Act relate to the GDPR and NIS2?

They are complementary and overlapping regulations. An AI that processes personal data must comply with the AI Act and the GDPR; if it is part of an essential service under NIS2, also that directive’s cybersecurity obligations. In financial entities, DORA for banking is added on top. I work on it combined every day: an AI rarely fits into a single regulation.

Conclusion: the 16-month clock is already ticking

The postponement of the European AI law is not a step backwards. It is a pragmatic readjustment in the face of an unworkable timeline. Companies serious about compliance gain room to do things well —with standards available, AESIA operational and technical guides published— instead of improvising against an impossible date.

Those using the postponement as an excuse to do nothing will find themselves, in December 2027, exactly where they are today: with no AI governance, no inventory, no traceability and no compliance culture. With the difference that the fines will be real and the market much more demanding.

If you want the date-by-date detail with the postponement already incorporated, I keep the EU AI Act compliance timeline updated.

Do you need an AI Act compliance roadmap tailored to your organisation? It is exactly what I do: I help companies in regulated sectors turn the AI Act into an executable programme, with quarterly milestones, clear ownership and real traceability. If you want to work on it with me, write to me here and I will reply personally.

Are you taking AI from pilot to real work? Let us talk.

Book 20 minutes

Leave a Reply

Your email address will not be published. Required fields are marked *