For two years, the EU AI Act had one headline date: August 2, 2026. Then, six days before it arrived, Regulation (EU) 2026/1744 — the Digital Omnibus on AI, signed July 8, published in the Official Journal July 24, in force on the third day following publication, July 27, 20261 — moved the high-risk compliance deadline. Headlines condensed this to "EU delays AI Act". The consultancy ecosystem condensed it further: AI Act on pause, nothing to do until 2027.
Both compressions are wrong, and the second one is dangerous. What the Omnibus actually froze is one slice of one chapter of one regulation: the Chapter III, Sections 1–3 obligations for high-risk systems — deferred to December 2, 2027 for Annex III use cases and August 2, 2028 for Annex I embedded systems.2 Everything else — the transparency regime of Article 50, the GPAI model obligations, the prohibited practices under Article 5, and the December 2, 2026 marking deadline for pre-existing generative systems — applies on its original schedule. Meanwhile the enforcement machinery went live on August 2, 2026, and in September 2026 the AI Office and national market surveillance authorities opened their first compliance inspections — with automated résumé screening and hiring tools on the docket from day one.3
This article is the correction: what actually moved, cited to the amending articles of the regulation itself; what did not; who is being inspected in wave one; and what a self-hosting German SME still owes today. It builds on the site's AI Act self-hosting guide and the Article 50 marking analysis — read those for the role split and the marking state of the art.
1. The deferral table, built from the amending regulation
Every cell below is anchored in the amendment text of Regulation (EU) 2026/1744 as published on EUR-Lex, not in press coverage of it.1 The dates of application are unconditional: the Commission's original proposal contemplated a standards-readiness trigger that could have re-extended the dates; the co-legislators dropped it, and the enacted text contains no confirmation decision and no mechanism by which the obligations could bind earlier or later.2
| Obligation block | Was | Now | Amending article | Applies to |
|---|---|---|---|---|
| Chapter III, Sections 1–3 (Arts. 8–27: risk management, technical documentation, logging, human oversight, conformity assessment, registration) for Annex III high-risk systems (hiring, credit, education, essential services, biometrics, law enforcement) | 2 Aug 2026 | 2 Dec 2027 | Art. 1(40)(b) of (EU) 2026/1744, replacing Art. 113(3)(c) AI Act | Providers and deployers of standalone Annex III systems |
| Same block for Annex I high-risk systems (safety components of regulated products: machinery, medical devices, toys, aviation; Machinery Regulation added to Annex I Section B) | 2 Aug 2027 | 2 Aug 2028 | Art. 1(40)(b), same replacement; Art. 1(41) for the Annex I change | Manufacturers of regulated products with embedded AI |
| Art. 6(5) — high-risk classification filters | — | not deferred | Expressly excepted in the replacement text | Everyone |
| Art. 50(1)–(6) transparency — AI-interaction disclosure, machine-readable marking, deepfake disclosure | 2 Aug 2026 | unchanged | Untouched; applies from the general application date in Art. 113(2) AI Act (Chapter XI is not excepted in Art. 113(3)) | Providers and deployers now |
| Art. 50(7) | Commission implementing-act empowerments | Replaced: the Commission now encourages and facilitates Union-level codes of practice on detection, marking and labelling of synthetic content (a fallback implementing act remains if a code is deemed inadequate) | Art. 1(20) | Commission |
| New Art. 111(4) marking grace — generative systems placed on the market before 2 Aug 2026 comply with Art. 50(2) | (new) | by 2 Dec 2026 | Art. 1(39)(b), inserting Art. 111(4) | Providers of pre-existing generative systems |
| Art. 5 prohibited practices | 2 Feb 2025 | unchanged; two new prohibitions (NCII "nudifier" tools; CSAM generation) apply from 2 Dec 2026 | Art. 1(40)(a) replacement of Art. 113(3)(a) | Everyone |
| GPAI model obligations (Arts. 51–55) | 2 Aug 2025 | unchanged | Untouched by Art. 1 | GPAI model providers — since 2025 |
| Arts. 102 to 110 of the AI Act itself (its amendments to aviation and other Union harmonisation law) | — | from 27 July 2026 | Art. 1(40)(c), inserting point (d) of the AI Act’s Art. 113(3) | Aviation and other regulated-product sectors |
Three readings of this table matter.
The exception inside the exception. The deferral of Chapter III expressly preserves Article 6(5) — the mechanism that lets a deployer argue a listed Annex III use is not high-risk because it does not materially influence the outcome of a decision. That provision applies on the original schedule. So even the deferred chapter has a live piece: your classification arguments under Art. 6(5) can be tested today.
The grace period runs the wrong way for complacency. The new Article 111(4) does not postpone anything for systems placed on the market from August 2, 2026 onward — those needed compliant marking from day one. It gives pre-existing systems a bridge to December 2, 2026, and that bridge ends. By bunching obligations at a fixed calendar date rather than scattering them over onboarding dates, it creates exactly the cliff a deferred-compliance mindset walks off.4
The general application date never moved. Article 113's second paragraph — the AI Act applies from August 2, 2026 — was not amended. What changed is which chapters carve out of that date. On August 2, 2026, national market surveillance and the AI Office's enforcement powers went live as planned; the Omnibus moved three sub-deadlines within the high-risk track and added one marking bridge. That is the entire freeze.5
2. The enforcement reality: inspections opened in September 2026
The machinery that went live on August 2, 2026 is not dormant. The Commission's published enforcement framework gives the AI Office requests for information (with fines for incorrect, misleading or missing replies), model evaluations and requests for access, interviews, and inspections of providers' premises for AI systems; national market surveillance authorities hold the equivalent powers for systems deployed in their territories.6 In Germany, the KI-MIG (in force July 29, 2026) designated the Bundesnetzagentur as Marktüberwachungsbehörde, single point of contact and complaints body for the AI Act — with explicit competence for AI systems in personnel management, critical infrastructure and education, where it also polices the transparency obligations and prohibited practices.7
Through September 2026, the AI Office and the national authorities opened their first coordinated wave of compliance checks. Reported coverage, consistent across multiple trackers of the rollout, puts automated résumé-screening and HR decision tools, algorithmic credit assessment in retail banking, and healthcare triage systems at the front of the queue — with French, German and Spanish authorities (CNIL, BfDI, AESIA) leading the first requests and more than 30 information requests issued to AI providers overall.3 No consolidated official announcement of the wave's docket list was located on Commission pages as of this writing; the AI Office's powers and their August 2 activation are primary and official, the docket composition is reported coverage. Treat the categories as reliable and the individual names as unconfirmed.
Here is the apparent paradox, and its resolution. How do hiring tools get inspected when their high-risk obligations were deferred to December 2027? Because the inspectors are not (yet) auditing Annex IV conformity dossiers — which providers do not owe until the deferred date. What is inspectable today, for the same systems:
- Article 5 prohibitions — in force since February 2025. Emotion inference in the workplace, manipulative systems, social scoring: banned now, fine-triggering now, and an obvious first probe in any HR-tool inspection.
- Article 50 transparency — in force since August 2, 2026, untouched by any deferral. Candidates and employees being told, at first interaction, that they are dealing with AI; generated content disclosures. The Commission's own guidance treats employment-facing disclosure as the first thing an authority asks for.
- Deployer and operator duties that sit outside Chapter III Sections 1–3 (AI literacy under Art. 4; the Art. 111(2) regime for pre-existing high-risk systems, which the Omnibus rewrote rather than deferred), plus the market-surveillance information powers under Chapter IX, live regardless of which substantive chapter applies.
For a German SME running open-weights models in HR-adjacent or credit-adjacent tooling, the inspection docket means three concrete things. First, an RFI can arrive now — under Chapter IX information powers, answering it (correctly and on time) is a legal duty, and a misleading answer is itself a finable act. Second, your live duties (Art. 4 literacy records, Art. 5 screening, Art. 50 disclosures) are exactly what a first wave reads. Third, if the tool is Annex III high-risk, the inspectors' file on you becomes the baseline for the December 2027 conformity conversation — a documented classification and mitigation trail built in 2026 reads very differently in 2027 than a blank page. For the role split — when self-hosting makes you a provider rather than a deployer — see the self-hosting guide.
3. The consultancy-error taxonomy
| Wrong claim | Sometimes heard as | What the regulation actually says | Disproving article |
|---|---|---|---|
| "The AI Act is delayed/paused entirely" | "AI Act on hold until 2027" | Only Chapter III, Sections 1–3 moved; the Act applies since 2 Aug 2026 | Art. 1(40) of (EU) 2026/1744; Art. 113(2) AI Act unamended |
| "Nothing applies before December 2027" | "Compliance can wait" | Art. 50 has applied since 2 Aug 2026; Art. 5 since 2 Feb 2025; GPAI since 2 Aug 2025 | Art. 113(2) AI Act (Art. 50); Art. 113(3)(a) AI Act (Art. 5); Art. 113(3)(b) AI Act (GPAI) |
| "The marking deadline moved too" | "Watermark work is postponed" | Art. 50(2) marking for pre-existing systems is due 2 Dec 2026 — inserted by the same regulation, not deferred by it | Art. 1(39)(b), inserting Art. 111(4) |
| "The new dates could slip further if standards are late" | "Wait for CEN-CENELEC" | The adopted text has no standards-readiness trigger; the conditional mechanism from the proposal was dropped | Art. 1(40)(b) — unconditional dates |
| "December 2, 2026 is the AI Act's real deadline" | Inversion of the same mistake | Dec 2, 2026 is the Art. 111(4) grace end for one obligation (marking) of one role (providers of pre-existing generative systems), plus two new Art. 5 bans | Art. 1(39)(b); Art. 1(40)(a) |
| "High-risk work can stop until 2027" | "The deferral is a pause button" | Art. 6(5) and classification duties apply now; pre-existing high-risk systems' transition was rewritten, not lifted; enforcement dockets opened in Sept 2026 | Art. 1(39)(a) (Art. 111(2) replacement); Ch. IX |
The pattern in the table: every wrong claim errors in the same direction — widening the freeze. The regulation's actual architecture is the opposite: it narrows the freeze to twice-bracketed, article-numbered carve-outs and adds live items (a new marking grace that expires on a date earlier than any deferred deadline; two new prohibitions that arrive December 2, 2026 — and the highest penalty tier, EUR 35,000,000 or 7% of worldwide turnover, attaches to Art. 5 breaches.8 A claim about the AI Act's timing that does not cite an amending article number is a press-release memory, not legal information.
4. What a self-hoster still needs now
The provider/deployer split survives the Omnibus unchanged, and it does the deferral work for you. Providers mark; deployers disclose. If you call a third-party generative API, the machine-readable marking under Art. 50(2) is your provider's problem — their deadline is Dec 2, 2026 via Art. 111(4); your problem is the disclosure side, due since August. If you self-host open weights under a qualifying licence, the Art. 53(2) exemption mechanics are in the self-hosting guide — and the moment you fine-tune and republish a model as your own system you cross into provider territory, marking included. The full technical bar (and why current watermarking under-delivers against it) is in the Article 50 piece.
Duties that survive deferral, for a self-hoster, concretely:
| ✓ | Item | Legal anchor | Deferred? |
|---|---|---|---|
| ☐ | First-interaction AI disclosure for any assistant that talks to natural persons, unless obvious | Art. 50(1) | No — live since 2 Aug 2026 |
| ☐ | Disclosure for published deepfakes and synthetic public-interest text, in the artifact | Art. 50(4) | No — live |
| ☐ | Marking compliance plan if you are a provider of a generative system placed on the market before 2 Aug 2026 | Art. 50(2) + Art. 111(4) | Grace ends 2 Dec 2026 |
| ☐ | Screen every use case against Art. 5 prohibitions (new NCII/CSAM bans arrive 2 Dec 2026) | Art. 5 | No |
| ☐ | AI-literacy measures for staff, documented | Art. 4 | No |
| ☐ | Classification assessment per use: Annex III map, incl. Art. 6(5) filter arguments | Art. 6 | Applies now |
| ☐ | If Annex III: Chapter III project runs toward 2 Dec 2027 — documentation, risk management, logging, oversight | Ch. III §§ 1–3 | Deferred, single extension, no further trigger |
| ☐ | DSGVO stack (legal basis, Art. 28 with hoster, retention) — untouched by the Omnibus entirely | GDPR | Never deferred |
Which use-cases are already inspectable for the authorities: anything you expose to candidates, employees, applicants or borrowers. Résumé screening, task allocation, worker monitoring (Annex III points 4(a)–(b)), creditworthiness (point 5(b)) — the categories in inspection wave one. A customer-facing chatbot, a synthetic-content pipeline, a hiring tool: all carry now-live disclosure and literacy duties, all sit squarely in what a first-wave RFI reads.
5. The critical view
The deferral is narrower than every headline written about it. Regulation (EU) 2026/1744 moved two application dates within one chapter, lifted not one substantive requirement, and inserted a transitional marking duty that expires sooner than either deferred date. A regulation criticized as "the AI Act delay" actually accelerates one obligation (Dec 2, 2026 marking for legacy systems) and adds two prohibitions on an unchanged, near-term date. If your reading of the Omnibus produces a compliance holiday, the error is in the reading, not in the regulation.
The honest-buyer heuristic, for procurement and for consulting advice alike: check the article number, not the press release. Every load-bearing claim about what moved has an amending-article address — Art. 1(39) for the marking grace, Art. 1(40) for the application-date replacements, Art. 1(20) for Art. 50(7). A vendor deck, a law-firm alert, or a LinkedIn post that cannot name its amending article is summarising a summary.
And the specific risk for Mittelstand: "delayed" becoming an excuse to skip December 2, 2026 marking prep — the exact inversion of the legal reality. The grace period was inserted precisely because marking is due; its clock ends ten weeks from this writing. A German SME that shelved its Art. 50 work in July, on the strength of a headline about the "AI Act delay", holds live obligations that enforcement wave one is actively reading, plus a December marking cliff its own provider may not have solved, plus Annex III conformity work whose deadline — 2 December 2027 — is closer than the migration projects it will require were ever scoped for. The bandwidth the Omnibus bought was sixteen months on a documentation stack — nothing more. It bought nothing off the calendar of anything a market surveillance authority can ask you about tomorrow.
This article reflects the legal situation as of September 24, 2026 and is general information, not legal advice. Binding classification of your specific system requires individual review.
Footnotes
-
Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026 (Digital Omnibus on AI), OJ L 2026/1744, 24.7.2026; enters into force on the third day following publication (Art. on entry into force) — https://eur-lex.europa.eu/eli/reg/2026/1744/oj (CELEX 32026R1744) ↩ ↩2
-
Regulation (EU) 2026/1744, Art. 1(40)(b), replacing Art. 113(3)(c) of the AI Act: Chapter III, Sections 1, 2 and 3, with the exception of Art. 6(5), apply from 2 December 2027 (Art. 6(2)/Annex III) and 2 August 2028 (Art. 6(1)/Annex I) — https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32026R1744 ↩ ↩2
-
Reported coverage of the September 2026 first inspection wave of the AI Office and national market surveillance authorities (automated résumé screening, credit assessment, healthcare triage; CNIL/BfDI/AESIA leading; 30+ RFIs), e.g. https://kurums.com/eu-ai-office-launches-first-compliance-inspections-of-ai-hiring-tools-september-2026-what-law-teams-must-do — docket composition is reported, not an official consolidated announcement; the underlying powers are primary (see 6). ↩ ↩2
-
Regulation (EU) 2026/1744, Art. 1(39)(b), inserting Art. 111(4): providers of AI systems generating synthetic audio, image, video or text content placed on the market before 2 August 2026 shall comply with Art. 50(2) by 2 December 2026; European Commission AI Act Service Desk — https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-111 ↩
-
European Commission, AI Act Service Desk, implementation timeline reflecting the Digital Omnibus amendments — https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-111 ↩
-
European Commission, "The enforcement framework of the AI Act" (AI Office investigatory and sanctioning powers; RFI, evaluations, inspections of providers' premises) — https://digital-strategy.ec.europa.eu/en/policies/enforcement-ai-act ↩ ↩2
-
Gesetz zur Marktüberwachung und Innovationsförderung von künstlicher Intelligenz (KI-MIG), BGBl. 2026 I Nr. 223, in force 29.7.2026, § 1 — https://www.gesetze-im-internet.de/ki-mig/BJNR0DF0B0026.html; Bundesnetzagentur press release of 29.7.2026 — https://www.bundesnetzagentur.de/SharedDocs/Pressemitteilungen/DE/2026/20260729_KI_VO.html ↩
-
Regulation (EU) 2024/1689 (AI Act), consolidated text including the Digital Omnibus amendments; Art. 113(2)–(3) application dates, Art. 99 penalty tiers — https://eur-lex.europa.eu/eli/reg/2024/1689/oj ↩