The AI Act Enforcement Timeline: What's Real and What's Delayed

A lot of AI compliance marketing is currently running on a timeline that's out of date. "AI Act deadline: August 2026" is still a common line in vendor pitches and LinkedIn posts, and for the specific obligations it's usually attached to, it's no longer accurate. The 2026 Digital Omnibus changed the schedule, and the gap between what vendors are saying and what's actually in force is wide enough that it's worth checking before it shapes a budget or urgency decision.
What's actually in force right now
Three obligations that matter for most enterprises are live today, and none were affected by the Digital Omnibus delay:
Article 4 — AI literacy. Applicable since February 2025, this requires providers and deployers of AI systems to ensure staff involved in operating them have a sufficient level of AI literacy, relative to their technical knowledge, experience, and the context of use. This is a current, active obligation — not a future deadline, and one many organizations haven't yet documented compliance with.
Chapter VII — GPAI and governance obligations. Applicable since 2 August 2025, these cover general-purpose AI models placed on the market from that date — technical documentation, training content summaries, and copyright compliance obligations for GPAI providers. Legacy models already on the market have an extended transition window until August 2027.
Article 50 — transparency. Applicable since 2 August 2026, this introduces specific transparency obligations: informing people when they're interacting with an AI system (unless obvious from context), machine-readable marking of AI-generated synthetic content, and disclosure requirements for deepfakes and AI-generated content on matters of public interest. The European Commission published detailed guidelines on these obligations in July 2026.
Both Article 4 and Article 50 apply independently of high-risk classification, but Article 50 applies only to the specific transparency scenarios it covers — including direct AI interaction, synthetic content, deepfakes, and certain deployer use cases — not to every enterprise AI use broadly.
What got delayed, and by how much
The obligation most vendor marketing references when it says "August 2026 deadline" is the set of requirements for high-risk AI systems under Annex III — conformity assessments, technical documentation, human oversight mechanisms, and related obligations for systems used in areas like employment, credit scoring, law enforcement, and critical infrastructure.
Following the Digital Omnibus, which entered into force in July 2026, that timeline changed:
- High-risk AI systems under Annex III — application extended to 2 December 2027.
- High-risk AI embedded in regulated physical products (machinery, toys, lifts, and similar categories under Annex I) — application extended to 2 August 2028.
The stated rationale was to allow more time for the technical standards and conformity assessment infrastructure the high-risk obligations depend on to actually be ready — those standards weren't fully finalized on the original schedule, and enforcing conformity assessment requirements against standards that don't exist yet isn't workable in practice.
Why the outdated messaging persists
A few structural reasons vendor marketing hasn't caught up, worth naming plainly rather than assuming bad faith:
Content built before the delay is still live. A lot of "AI Act deadline" content — landing pages, blog posts, sales decks — was written when August 2026 was genuinely the relevant date for Annex III obligations. Updating it requires someone to notice the change and revise published material, which doesn't happen automatically.
Urgency sells, and the old date is more urgent-sounding. "Deadline in months" creates more buying pressure than "deadline in over a year," and that incentive doesn't automatically correct itself even after the facts change.
The regulatory picture genuinely is complicated. Article 4, Chapter VII, and Article 50 are in force on different dates. Annex III and Annex I are delayed to different dates again. A vendor conflating "the AI Act" as a single deadline, rather than a set of obligations with different dates and different scopes, isn't necessarily being deliberately misleading — it's collapsing real complexity into a simpler, less accurate story.
What this means for a budget or vendor decision right now
None of this means AI Act compliance can wait. It means the specific obligations driving urgency should be named accurately, because the right infrastructure decision depends on which timeline actually applies to your organization.
If your organization deploys or is developing systems that will fall under Annex III high-risk classification — HR/recruitment tools, credit or insurance underwriting, biometric systems, among others — you have until December 2027 for those specific conformity and documentation obligations, which is meaningful planning time, not a today problem.
If your organization deploys AI tools across the workforce, Article 4 (AI literacy) already matters today. Article 50 may also apply, depending on how those systems are deployed and whether the organization's use falls within one of its specific transparency scenarios — it's worth checking against your actual use case rather than assuming it applies uniformly. Confusing the delayed and active obligations risks either panic-buying for a deadline that isn't imminent, or — the more common mistake — assuming "the AI Act deadline got delayed" means nothing is currently required, which isn't true either.
A short list of questions worth asking any vendor citing an "AI Act deadline"
- Which specific article or annex are you referring to? "The AI Act" isn't one deadline — a vendor citing a single date without specifying the obligation is either simplifying inaccurately or hasn't tracked the update.
- Is this obligation affected by the Digital Omnibus? Article 4, Chapter VII, and Article 50 weren't. Annex III and Annex I were, substantially.
- What happens if we wait? For Annex III-scope systems, waiting until closer to December 2027 may be entirely reasonable, depending on implementation complexity. For Article 4 and applicable parts of Article 50, the obligation is already active.
The bottom line
Regulatory timelines shift, and August 2026 shifted meaningfully for the highest-profile part of the AI Act — the high-risk system obligations most compliance marketing was built around. What didn't shift: AI literacy and GPAI governance obligations that are active today, for organizations of essentially every size and sector using AI tools. The practical move isn't waiting for clarity or reacting to the loudest deadline claim — it's checking which specific obligation applies to your actual use case, and building toward that, not toward a generic "AI Act deadline" that may no longer describe anything real.
Colchix provides the runtime visibility, protection, and audit evidence regulated enterprises need to govern AI use as European requirements evolve — without tying governance infrastructure to a single regulatory deadline.
See how it works →