The high-risk deadline moved. Almost nothing else did. The obligations that apply to nearly every organisation using AI have been in force since August, and reading a “delayed” headline as general rather than scoped is the expensive mistake.
Key points
- The Digital Omnibus, Regulation (EU) 2026/1744, in force since 27 July 2026, moved the Annex III high-risk deadline from August 2026 to December 2027 and Annex I to August 2028.
- Article 50 transparency was not deferred and has applied since 2 August 2026. Article 4 AI literacy has applied since February 2025, though the Omnibus did rewrite its wording.
- The Omnibus also added a new Article 5 prohibition, effective 2 December 2026. A package described as a delay contains a new ban.
- A Swiss organisation with any genuine EU nexus is bound by the live obligations now, regardless of the high-risk deferral.
What actually got deferred
The Digital Omnibus on AI was approved by the European Parliament on 16 June 2026 and adopted by the Council on 29 June. It was signed on 8 July, published in the Official Journal on 24 July as Regulation (EU) 2026/1744, and entered into force on 27 July 2026, six days before the original high-risk deadline.1
1Cloud Security Alliance research note, August 2026
It postponed two things. Annex III stand-alone high-risk systems, covering recruitment tools, credit scoring, biometric identification, education platforms and similar, moved from 2 August 2026 to 2 December 2027, a sixteen-month extension. Annex I high-risk AI embedded in regulated products, such as medical devices and machinery, moved from 2 August 2027 to 2 August 2028.2
That deferral is real and substantial for the organisations it covers. If your system is not an Annex III or Annex I system, it changes nothing for you, and that is precisely the distinction most headline coverage collapses.
What did not move
Article 50 transparency. The requirement that people be told when they are interacting with an AI system, and that AI-generated or manipulated content be identifiable, has applied since 2 August 2026. The single concession was a four-month grace period, to 2 December 2026, for the Article 50(2) watermarking obligation on systems already on the market at 2 August 2026. Systems placed on the market after that date comply from the outset. The core disclosure duty was never deferred.3
3Winston Taylor, on the final Omnibus position
Article 4 AI literacy. The duty on providers and deployers to ensure that staff and others operating their AI systems have a sufficient level of AI literacy has applied since 2 February 2025, more than a year before the Omnibus existed. Its application date did not move. Its wording, however, did: the Omnibus amended Article 4 with effect from 27 July 2026, so an organisation that documented its literacy position against the original text should check it against the current one.4
4Praxikon, on what the Omnibus left in place
The prohibited practices regime. Article 5 has applied since February 2025, and general-purpose AI provider obligations since August 2025. Neither was touched.
All of these apply regardless of whether a given use case is high-risk. A customer-facing chatbot, an internal drafting assistant, an AI feature added to existing software: none needs to be an Annex III system to trigger Article 50 disclosure or Article 4 literacy duties.
The part nobody calls a delay
The Omnibus also added a new prohibition to Article 5, covering AI systems intended for producing non-consensual intimate imagery and child sexual abuse material, or placed on the market without reasonable safeguards against it. It takes effect on 2 December 2026.
Worth noting for its own sake, and worth noting for what it says about the framing. A regulation reported almost universally as a deferral introduced a new ban in the same instrument. An organisation reading only the headline would not know it exists.
Why this matters for a Swiss organisation
Switzerland has no horizontal AI statute. The Federal Council’s February 2025 decision confirmed a sectoral, technology-neutral approach rather than a Swiss equivalent to the AI Act. That leads some Swiss organisations to treat EU developments as someone else’s regulatory news.
That reasoning has a gap. The Federal Act on Data Protection governs a Swiss organisation’s own processing directly and remains the primary statute. But Regulation (EU) 2024/1689, and the deployer-facing obligations within it, reach an organisation wherever a genuine EU nexus exists: EU customers, EU staff, an EU parent or subsidiary, or systems processing EU residents’ data. That exposure follows the nexus, not the postcode, and not where the servers sit.
For an organisation in that position, “the AI Act got pushed back” is true only for the narrow slice of systems that are genuinely Annex III or Annex I. The disclosure and literacy duties were never on the deferred list, and for most organisations they are also the more immediately actionable ones: a live requirement to tell people they are talking to an AI, and a live requirement to make sure the people running it understand it. Both can be implemented in weeks rather than the years a full high-risk conformity programme takes.
The actual takeaway
Read a “delayed” headline as scoped, not general. The question worth asking is not whether the deadline moved, but which specific article moved and whether it governs what you are actually doing. For nearly everyone outside genuine Annex III or Annex I territory, Article 50 and Article 4 are the two lines that matter, and both have been live for months.
