On 27 July 2026 the Digital Omnibus on AI entered into force and pushed the high-risk obligations back by sixteen months. Most guidance published before that date still says 2 August 2026 — including pages currently ranking for this question. Here is the corrected timeline, and what genuinely still binds this weekend.
Last updated: 11 June 2026
Most systems people assume are Annex III are not — and the cost difference is enormous. Answer 4 questions and our EU AI Act risk checker classifies yours, with the obligations and the deadline that now applies to it.
Annex III high-risk obligations now apply from 2 December 2027, not 2 August 2026. Regulation (EU) 2026/1744 — the Digital Omnibus on AI — was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. AI embedded in regulated products under Annex I moves to 2 August 2028. The Article 50 transparency duties still start on 2 August 2026, Marking of AI-generated content is deferred to 2 December 2026 only for systems already on the market — anything placed after 2 August 2026 must comply immediately. Prohibited practices and the Article 4 AI-literacy duty have applied since February 2025 and did not move.
The Omnibus is the first set of amendments to the AI Act since it was adopted in 2024. It was voted through Parliament on 16 June 2026, cleared Council on 29 June, was signed on 8 July, published on 24 July and took effect on 27 July. Only the high-risk timing changed — the risk categories themselves did not.
| Obligation | Old date | Current date |
|---|---|---|
| Prohibited practices (Art. 5) | 2 Feb 2025 | unchanged — already applies |
| AI literacy (Art. 4) | 2 Feb 2025 | unchanged — already applies |
| GPAI model obligations | 2 Aug 2025 | unchanged — already applies |
| Transparency (Art. 50) | 2 Aug 2026 | unchanged — applies 2 Aug 2026 |
| Marking AI-generated content (Art. 50(2)) | 2 Aug 2026 | 2 Dec 2026 only if already on market; immediate for new systems |
| High-risk, Annex III stand-alone | 2 Aug 2026 | 2 Dec 2027 |
| High-risk, Annex I embedded in products | 2 Aug 2027 | 2 Aug 2028 |
Two things are worth being blunt about. First, the deferral applies to high-risk duties only — if you deploy a chatbot or generate content, Article 50 transparency lands on 2 August 2026 regardless. Second, the reason for the delay was that harmonised standards and national supervisory capacity were not ready, not that the requirements got easier. Conformity assessment, an Article 9 risk-management system, Article 12 logging, technical documentation, CE marking and EU database registration all still arrive — with sixteen more months to prepare rather than sixteen fewer.
The practical read for a Dutch or Belgian company: if you were about to spend heavily to hit 2 August, you have room to do it properly instead. If you were planning to ignore it, the deadline that moved was never the one that would have caught you first.
Annex III covers stand-alone systems used for biometrics, critical infrastructure, education, employment and worker management, access to essential services including credit scoring and insurance pricing, law enforcement, migration and border control, and the administration of justice. In SME practice the two that come up most often are recruitment screening and credit or insurance decisioning.
Annex I is different: AI acting as a safety component of a product already regulated under EU product law — machinery, medical devices, vehicles, lifts. That route runs through your existing product conformity process, which is why it was given until 2028.
Most business automation is neither. Invoice processing, demand forecasting, internal search and customer-service assistants normally sit in the limited or minimal tiers, where transparency and human oversight apply but conformity assessment does not.
The AI Act is a regulation, so the text binds identically in the Netherlands and Belgium — only enforcement is national. In the Netherlands the Autoriteit Persoonsgegevens coordinates algorithmic supervision alongside the RDI, and a regulatory sandbox is being stood up. Dutch employers also face a domestic constraint the AI Act does not mention: under article 27 of the Works Councils Act, introducing a system that assesses or monitors staff generally needs works council consent. In Belgium, CAO nr. 39 requires informing and consulting the works council before new technology with collective impact is introduced.
That local layer usually determines your real timeline. A recruitment screening tool can be AI Act compliant and still be unusable because the ondernemingsraad was not consulted.
The first task is not documentation, it is classification — a surprising number of systems people assume are high-risk are not, and the cost difference is enormous. Start with the free risk checker, then confirm whether you are a provider (you build or rebrand the system) or a deployer (you use someone else's), because the obligation sets differ sharply.
If you land in Annex III, the work is a genuine engineering programme: a risk-management system under Article 9, data governance, technical documentation, logging under Article 12, human oversight design, and a conformity assessment before market placement. Crux Digits scopes that the same way as any build — a €2,500 audit to establish where you stand, then a fixed-scope programme. Our €950 AI Act Check remains the cheaper entry point if you only need to know your obligations.
For high-risk systems, yes. The Digital Omnibus moved Annex III stand-alone high-risk obligations to 2 December 2027 and Annex I embedded systems to 2 August 2028. Transparency duties under Article 50 were not moved and still start on 2 August 2026.
The Article 50 transparency obligations. You must tell people when they are interacting with an AI system, and deep-fake and synthetic content must be disclosed. Marking of AI-generated content under Article 50(2) has a grace period until 2 December 2026 for systems already on the market.
Eight categories of stand-alone system, listed in Annex III. They cover biometrics, critical infrastructure, education, employment and worker management, access to essential services, law enforcement, migration and justice. For most SMEs only two are realistic candidates: recruitment screening, and credit or insurance decisioning.
No — the requirements did not change, only the date. Conformity assessment, Article 9 risk management, Article 12 logging, technical documentation, CE marking and EU database registration all still arrive. The deferral exists because harmonised standards and supervisory capacity were not ready, not because the bar was lowered.
You are a provider if you build it or brand it. You are a deployer if you use someone else's system under your own authority. Providers carry the heavy obligations: conformity assessment, technical documentation, CE marking, registration. Deployers carry lighter ones around oversight, monitoring and input data.
Classify your system free in four questions, or book a consultation and we will tell you honestly whether the December 2027 date is even your problem.
Book a free consultation →