The EU AI Act's Deadline Just Moved — Here's What Actually Changed

If you'd been preparing for the EU AI Act's high-risk obligations to land on 2 August 2026, you can exhale — a little. On 27 July 2026, a new EU regulation entered into force that pushes that deadline back by well over a year. But "pushed back" is not the same as "gone," and a few things that many businesses assume changed actually didn't.

Here's what SMEs operating in Belgium and France need to know.

What just happened

The European Union adopted the Digital Omnibus on AI, a regulation amending the original AI Act to simplify its rollout after widespread concern that implementation tools — harmonized technical standards, conformity assessment infrastructure — weren't ready in time for the original schedule. The text was published in the EU's Official Journal on 24 July 2026 and took legal effect just three days later, arriving just ahead of the original deadline it was designed to postpone.

What's been deferred

The headline change is that obligations for standalone high-risk AI systems — the ones listed in Annex III of the AI Act, covering areas like recruitment, credit scoring, education, and law enforcement — now apply from 2 December 2027 instead of 2 August 2026. That's a deferral of roughly sixteen months. For AI embedded in products already regulated elsewhere — think medical devices, machinery, certain consumer goods — the deadline moves even further out, to 2 August 2028.

What hasn't changed

This is the part worth paying close attention to, because it's easy to read "deadline moved" as "problem solved."

  • Classification rules are untouched — Annex III itself wasn't amended, so if a system you're using or building qualified as high-risk before this regulation, it still does, and any risk classification work you've already done stands.
  • General-purpose AI obligations are unaffected — if you're building on or deploying general-purpose AI models, those obligations have applied since August 2025 and continue exactly as they were.
  • Prohibited practices remain banned — the AI Act's ban on unacceptable-risk practices, including social scoring and certain forms of biometric surveillance, has applied since February 2025 and isn't touched by this change.

Why "later" isn't "never"

The deferral exists because the EU's own implementation infrastructure — harmonized standards, conformity assessment bodies — was running behind schedule, not because the underlying obligations were considered unnecessary. That's a signal worth taking seriously rather than as an invitation to deprioritize AI Act work entirely. For SMEs, the practical risk hasn't gone away — it's just less immediate. Many of the same tools that would have triggered scrambling in the next few weeks — HR screening software, automated credit or risk scoring, customer-facing chatbots making consequential decisions — can quietly fall into high-risk categories without anyone flagging it internally. The extra runway is genuinely useful, but only if it's used to build a proper system inventory and classification process, rather than spent waiting for the next deadline to feel real.

Where to start

RECOSA's gap assessment tool walks through exactly this — identifying which of your systems fall under the AI Act's scope, what risk tier they sit in, and what obligations now apply to each one, updated as the regulatory timeline itself evolves, so you're never working from a deadline that's already moved.

RECOSA

AI-powered EU regulatory compliance for SMEs in Belgium, France, The Netherlands and across Europe.

Social media

LinkedIn

© RECOSA 2026 - Software Made in Europe for European SMEs