Back to blog
6 min read

Brussels Delayed the AI Act's Big Deadline. Yours Probably Didn't Move.

The EU delayed the AI Act's high-risk rules to December 2027 — but transparency and AI-literacy duties still apply. What small businesses need to know.

Brussels Delayed the AI Act's Big Deadline. Yours Probably Didn't Move.

On 29 June, the Council of the EU gave its final sign-off to the Digital Omnibus package, and the headlines wrote themselves: Brussels delays the AI Act. Somewhere between the summary and the share button, a lot of European business owners quietly filed the whole subject under "2027 problem". That is one part right and two parts wrong. The biggest compliance deadline did move — but the rules most likely to touch a small business either kept their original date or are already in force.

What was actually decided

The Digital Omnibus is a package that amends several EU digital laws in one go, and its AI chapter has one headline change: the obligations for so-called high-risk AI systems, originally due on 2 August 2026, will now apply from 2 December 2027. The process moved unusually fast by Brussels standards. Council and Parliament negotiators struck a provisional deal on 7 May 2026, the European Parliament adopted the text on 16 June by 423 votes to 57 with 174 abstentions, and the Council's approval on 29 June was the final political step. Publication in the EU's Official Journal follows within weeks, and the new dates take legal effect shortly after.

Two deadlines shifted. Stand-alone high-risk systems listed in Annex III of the AI Act — hiring and screening tools, credit scoring, biometric identification, systems that decide access to education — get sixteen extra months, until 2 December 2027. AI embedded in regulated products such as medical devices, machinery and toys, covered by Annex I, moves twelve months, from August 2027 to 2 August 2028.

Why Brussels blinked

The official reason is infrastructure, not mercy. The August 2026 deadline assumed that harmonised technical standards would exist, that conformity-assessment bodies would be accredited, and that national market-surveillance authorities would be staffed and ready. By late 2025 none of that was true: the CEN-CENELEC standards were behind schedule, key Commission guidance was still in draft, and several member states had not designated their surveillance authorities at all.

Compliance analysts are unusually aligned on what this means. Secure Privacy's analysis frames the new dates as the rulebook catching up with reality, and the Dutch AI Act Blog sums the delay up as runway, not reprieve. A system that qualifies as high-risk today will almost certainly still qualify in December 2027 — the list changed far less than the calendar did.

What still lands on 2 August 2026

Article 50, the transparency chapter, was deliberately left untouched — and it is the part of the AI Act most small businesses will actually meet. If customers interact with your AI — a chatbot on your webshop, a voice agent answering your phone — it must be clear to them that they are dealing with a machine. AI-generated or manipulated content, deepfakes included, must be disclosed as such. And providers of generative AI systems must mark their output in a machine-readable way, so other software can recognise it as synthetic.

There is one narrow concession: systems already on the market before 2 August 2026 get until 2 December 2026 to implement that machine-readable marking. The Omnibus also adds a new prohibition to the Act, banning AI systems built to generate non-consensual intimate images or child sexual abuse material.

The rules that already apply

Article 4, the AI-literacy duty, has applied since 2 February 2025 and the Omnibus does not touch it. If your team uses AI at work — and in most businesses someone does — you must take reasonable measures to make sure they understand what the tools can and cannot do. A short internal training session and a one-page usage policy go a long way; what matters is being able to show you did something deliberate.

The bans on prohibited practices — social scoring, manipulative systems, emotion recognition in the workplace — have applied since that same date, and the obligations for general-purpose AI models since August 2025. The penalty framework did not soften either: up to €35 million or 7 per cent of worldwide turnover for prohibited practices, and up to €15 million or 3 per cent for most other violations, transparency failures included.

Using the sixteen months well

The Omnibus is genuinely friendlier to small firms than the original Act was. It writes an SME definition into the AI Act itself and attaches concrete relief to it: simplified technical documentation, quality-management requirements proportionate to company size, and priority access to regulatory sandboxes. That makes the extra time worth something — if you use it.

This summer. List every AI system your business builds, sells or uses. For anything customer-facing, check it against Article 50: does the chatbot say it is a chatbot, is generated content labelled?

By autumn. Classify what you found against Annex III, using the Commission's Article 6 classification guidelines published on 19 May 2026. Most tools will fall outside it; knowing that in writing is itself useful evidence.

From there. If anything might be high-risk, start the documentation gradually — risk log, data description, human-oversight plan — instead of rediscovering the deadline panic in mid-2027.

When the delay genuinely matters — and when it never did

Honest answer: most European small businesses were never facing the August deadline in the first place. The heavy high-risk obligations fall mainly on providers — companies that build or sell such systems — while businesses that merely use AI tools carry much lighter deployer duties. If you develop or white-label AI for recruitment, credit decisions or school admissions, this delay is a real reprieve, and the classification homework above is urgent. If you use a general-purpose assistant to draft emails and summarise documents, your rules were never delayed: Article 4 applies now, and Article 50 arrives on schedule this August.

The AI Act, in other words, is not cancelled — it is arriving in the order that touches small businesses first. If the news cycle has left you unsure which of your tools fall where, Cresly's AI Readiness Scan maps how your business actually uses AI, which obligations apply when, and where AI could be doing more for you in the meantime — a clearer picture than any headline will give you.

EU AI ActDigital OmnibuscomplianceregulationSMEtransparency
C
The Cresly Team
AI Studio for European Businesses