← Insights · August 13, 2026
EU AI Act delay: what UK firms should do with 16 months
On 27 July, with six days to spare before its own deadline, the EU rewrote the AI compliance calendar. Regulation (EU) 2026/1744 — the “Digital Omnibus on AI”, published in the Official Journal on 24 July — moves the AI Act’s high-risk obligations from 2 August 2026 to 2 December 2027. Across Europe, a thousand compliance programmes were quietly shelved by Friday.
That’s the wrong lesson, and it’s an expensive one. Two things are true at once: the hard rules moved, and the transparency rules didn’t — those went live on 2 August 2026, carrying fines of up to €15 million or 3% of worldwide turnover. And if your plan is “we’re a UK company, not our problem”, Article 2 of the Act would like a word.
Here’s what changed, what’s already in force, and what a sensible UK organisation does with a 16-month reprieve. Every date in this piece was verified on 3 August 2026. (Yes, dates in AI regulation now need a verification stamp. That’s the world we’ve built.)
What the Digital Omnibus actually changed
The legislative sprint, in one breath: the Commission proposed the Omnibus on 19 November 2025, the institutions shook hands in early May 2026, Parliament adopted it on 16 June by 423 votes to 57, the Council signed off on 29 June, and it was published on 24 July and in force on 27 July. Eight months, proposal to law. For the EU, that’s a land-speed record — which tells you how badly the original timetable had come off the rails.
The calendar you should now have pinned to the wall:
- 2 February 2025 — prohibited AI practices and the AI literacy duty. In force; unchanged.
- 2 August 2025 — general-purpose AI model obligations. In force; unchanged.
- 2 August 2026 — Article 50 transparency obligations. Unchanged. Live now. One narrow carve-out: systems already on the market before that date get until 2 December 2026 for the machine-readable marking of AI-generated content. Everything else, no grace.
- 2 December 2027 — high-risk obligations for stand-alone Annex III systems: recruitment and employment tools, credit scoring, education access, biometrics. Was 2 August 2026. That’s your 16 months.
- 2 August 2028 — high-risk AI embedded in regulated products under Annex I (medical devices, machinery). Was 2 August 2027.
The Omnibus also banned AI systems that generate non-consensual intimate imagery or child sexual abuse material outright, softened the AI-literacy duty, and wrote SME proportionality into the fine regime — Gibson Dunn’s alert has the full list.
Note what it didn’t do: shrink a single obligation. Risk management, data governance, technical documentation, human oversight — same list as before, later date. The deadline moved. The homework didn’t.
The rules that started on Sunday
While the headlines were busy with the delay, Article 50 quietly became enforceable — and a lot of it lands on systems nobody in the building has ever thought of as “high-risk AI”. Concretely:
- A system people talk to directly — chatbot, AI agent, avatar — must tell them it’s AI, from the first interaction, unless that’s obvious. (The regulation defines “obvious” restrictively. Your widget with a human name and a headshot doesn’t qualify.)
- Generated synthetic audio, images, video or text must carry machine-readable marking identifying it as AI-made.
- Emotion recognition or biometric categorisation — the people exposed to it must be told.
- Deepfakes need visible labels, and AI-generated text published to inform the public on matters of public interest must be labelled unless a human exercised real editorial control. Spell-checking doesn’t count as editorial control. The Commission wrote that down, presumably because someone tried it.
The stick: fines up to €15 million or 3% of total worldwide annual turnover, whichever is higher, enforced by national market surveillance authorities, with proportionality for SMEs. There’s also a voluntary Code of Practice on transparency of AI-generated content that signatories can lean on to prove compliance with the marking duties — worth a look before you invent your own approach.
“But we’re a UK company” — Article 2 doesn’t care
The Act’s scope is written around where a system’s output lands, not where the company is registered. Article 2 catches providers placing AI systems on the EU market wherever they sit — and providers and deployers in third countries where the output produced by the system is used in the EU. The Commission’s own guidance spells it out: outside the EU, still covered, if your system’s output is used in the Union.
For a UK firm the questions are unglamorous. Does the chatbot serve visitors in Dublin? Does the product generate content EU users see? Do you screen candidates or score applications for people in Amsterdam? Any yes, and Sunday’s transparency obligations are your obligations, and December 2027 is your deadline. This is GDPR’s territorial logic again, and “it doesn’t apply to us, we’re not in Europe” aged exactly as well the first time.
Meanwhile, at home: the UK’s quieter version of the same question
The UK still has no AI Act and no AI bill before Parliament. Read that as “no rules” at your peril. UK AI regulation runs through the UK GDPR — as amended by the Data (Use and Access) Act 2025 — and through regulators applying powers they already hold. Right now the one to watch is the ICO.
In March the ICO opened a consultation on updated automated decision-making guidance; it closed on 29 May, with the final version slated for winter 2026. Alongside it came a report on automated decision-making in recruitment — now a named regulatory focus. Two findings deserve a moment of quiet. First: the ICO engaged with over 30 employers, most confident they weren’t doing automated decision-making — and concluded several of them were. Not through malice; through drift. A tool arrives to “assist”, a threshold quietly becomes the decision, and eighteen months later nobody can explain why candidate X never reached a human. Second: the same report notes over 70% of organisations expect to increase AI and automation in recruitment over the next five years. More AI, more scrutiny, same direction of travel on both sides of the Channel.
Having worked inside regulated and public-sector environments, I can tell you the regulator’s questions are boringly consistent wherever they’re asked: who decided, on what evidence, with what human oversight — and show me the record. The EU has now codified those questions. The ICO is already asking them.
What to actually do with 16 months
We run AI in production ourselves. We built and operate a recruitment platform where every AI score ships with its evidence and every decision lands in an immutable audit trail — because a human makes every call and has to be able to defend it. Building that taught us the one lesson worth the price of admission: governance you design in is a feature; governance you retrofit is an excavation. Sixteen months is enough time for the first one. Here’s where I’d spend it:
- Inventory and classify now. List every AI system in use — including the ones buried inside your SaaS stack — and work out which fall under Annex III. The ICO found employers doing automated decision-making without knowing it. Assume you might be one of them until you’ve checked. This takes days, not months, and it turns “are we exposed?” from a board-meeting wince into a written answer.
- Deal with Article 50 this quarter, not next year. It’s in force. Chatbots, generated content, synthetic media touching the EU — disclosure and marking are current obligations, and the marking grace period for pre-existing systems runs out on 2 December 2026.
- Build the boring infrastructure on the calm schedule. Risk management, data governance, human oversight, logging. These take quarters, and they’re dramatically cheaper to build before a system goes live than to dig into one that’s been running for a year.
- Don’t dismantle what you built for August 2026. Pausing a governance programme means paying to remobilise it later, minus half the institutional memory of why decisions were made. Keep it running at a saner pace.
The reprieve is real. It’s enough time to design AI governance in properly rather than staple it on afterwards. It is not enough time to do it twice.
If you want the honest version for your own organisation — what’s in scope, what isn’t, and what to build first — that’s exactly what our fixed-scope AI Adoption & Governance Assessment does. And for one useful, sourced read like this each week, subscribe to the AI Applied Insights newsletter.
Insights
Occasional, useful notes on applied AI.
What's actually working, what to ignore, and what the new regulation means for UK businesses. No spam.