
On 24 July 2026 the Official Journal carried Regulation (EU) 2026/1744, the Digital Omnibus on AI. It came into force three days later, on 27 July. For most compliance teams the headline reads like relief: the heaviest high-risk obligations under the AI Act now land in December 2027 and August 2028 rather than 2026. Budget cycles get breathing room. Vendor selection gets a second look. The internal steering committee can slow down.
That reading is half right, and the other half is where teams get caught. A deferred compliance deadline changes when your governance documentation is audited. It does not change what your staff wrote in an email this morning, or what your model surfaced to a customer this afternoon. The obligations that touch day-to-day language, transparency and the new prohibitions, arrive on the earlier dates and stay. This post gives you the exact timeline and a way to brief your organization on it. It is general information, not legal advice.
The Omnibus is a sequencing change. It pushes back the two heaviest tranches of obligations while leaving the near-term, behavior-facing duties untouched. The distinction that matters for planning is between duties that govern your systems (documentation, risk management, conformity assessment) and duties that govern your outputs and conduct (transparency to users, banned practices).
| Date | What applies | What it means for you |
|---|---|---|
| 2 August 2026 | General provisions and Article 50 transparency duties | Users must be told when they are interacting with AI, and certain AI-generated or manipulated content must be disclosed. This is live in days, not years. |
| 2 December 2026 | New prohibitions: non-consensual intimate imagery, CSAM | These join the existing banned-practice list. No transition period softens them. |
| 2 December 2027 | Annex III high-risk obligations (deferred by the Omnibus) | Risk management, data governance, logging, human oversight, and conformity assessment for high-risk use cases such as employment and credit. |
| 2 August 2028 | Annex I high-risk obligations (deferred by the Omnibus) | High-risk systems tied to products already covered by EU safety legislation. |
Read the table top to bottom and the shape is clear. The two dates that involve heavy engineering and paperwork moved out. The two dates that involve what a person or a system says to another person did not. Transparency at 2 August 2026 and the new prohibitions at 2 December 2026 govern conduct, and conduct happens every day regardless of what the audit calendar says.
Here is the practical trap. When a deadline slips 18 months, attention slips with it. The governance workstream that was tracking toward a 2026 conformity milestone loosens, and the loosening quietly extends to controls that were never deferred at all. The organization tells itself it has time. Meanwhile the transparency duty is already binding, and the ordinary output of a well-meaning employee still carries the same exposure it always did. Regulators do not read your project plan before they read your messages, and neither does a claimant’s counsel. The two are on entirely separate clocks, and only one of them was reset in July.
That exposure has a track record that predates the AI Act entirely. Consider an aircraft manufacturer whose internal instant messages, written quickly and never meant to leave the room, included lines like “designed by clowns, who in turn are supervised by monkeys” and “I basically lied to the regulators.” Those messages became central to a USD 2.5 billion deferred prosecution agreement. No regulation deferral would have helped, because the risk was in the sentence, not in the compliance framework around it. A generated draft, a customer-facing chatbot reply, or an internal note that a colleague fires off today sits in exactly the same category: written in seconds, stored forever, discoverable later.
Use this decision table to keep the deferral from being misread across your organization. Each row is a duty; the column that matters is whether the Omnibus actually bought you time.
| Duty | Deferred by Omnibus? | Action posture now |
|---|---|---|
| Transparency to users (Article 50) | No, live 2 Aug 2026 | Confirm AI-interaction and AI-content disclosures are in place this quarter. |
| New prohibitions (intimate imagery, CSAM) | No, live 2 Dec 2026 | Verify policy and detection cover these before December. |
| Annex III high-risk (e.g. hiring, credit) | Yes, to 2 Dec 2027 | Keep the programme moving; do not stall on the new date. |
| Annex I high-risk (safety-regulated products) | Yes, to 2 Aug 2028 | Longest runway; sequence after Annex III. |
| Everyday message and output risk | Never governed by these dates | Front-line control at the point of writing, independent of the timeline. |
The bottom row is the one people forget. It was never on the AI Act clock, so no deferral touches it. It is the line an employee sends today. For a fuller working resource on the Act’s tiers, prohibitions, and transparency duties, our EU AI Act resource hub breaks each section down with checklists and self-assessment tools.
A pre-send check reads a draft at the moment before it is sent and flags the phrase that creates exposure, then offers a short, safer way to say the same thing. On the aircraft example above, a scan of that text flags the admission and the disparagement at phrase level:
Be clear about the boundary. This is a front-end shield for accidental human risk, the careless line a well-intentioned person does not notice before hitting send. It is not an adversarial security control: it will not stop a determined bad actor or a prompt-injected agent that is trying to do harm. It complements your archiving and supervision stack (Smarsh, Proofpoint) rather than replacing it. Those systems catch and store what already went out; a pre-send check reduces how much problematic content reaches their queues in the first place. Fewer issues to review, fewer to explain later.
That framing also maps cleanly onto the transparency duty going live on 2 August. Article 50 is, in practice, a set of rules about wording: telling a person they are talking to a system, and labelling AI-generated or manipulated content so it is not passed off as human or authentic. Those are disclosure decisions made in the copy itself, so the point of communication is the natural place to reinforce them. A draft that quietly presents a generated reply as a colleague’s own words is precisely the kind of accidental slip a pre-send check is built to surface.
Do two things this quarter. First, split your AI Act programme into the two tranches the Omnibus created, and protect the momentum on the near-term duties (transparency from 2 August 2026, prohibitions from 2 December 2026) so the deferred 2027 and 2028 dates do not drag them backward. Second, treat everyday message and output risk as a standing control that lives outside the timeline entirely, because it always did. The regulation moved. The sentence your team writes today did not. This is general information and not legal advice; confirm specifics with your own counsel.
VerbaPulse flags risky wording as you write in Outlook and Gmail, then offers a safer phrasing before you send. Run it against your own messages and your own rules in a 30-day pilot.
Up to 10 seats. EUR 120, credited to your plan if you continue.
See how VerbaPulse flags risk before an email is sent, right inside Gmail and Outlook.
See VerbaPulse in action →