Prefer to listen? Click play for AI narration

High-risk AI rules under the EU AI Act now start on 2 December 2027, not August 2026. The AI Omnibus that made the change was published in the Official Journal on 24 July 2026 and entered into force on 27 July. Many businesses read the headlines as “the AI Act is postponed”. It is not. Several obligations already apply, and the GDPR applies to every AI system that touches personal data.

This article turns the new dates into a working calendar. For the detail of the transparency rules, see our guide to the Article 50 guidelines; for the penalty maths, see the high-risk deadline and the GDPR overlap.

What the AI Omnibus changed

ObligationNew dateWhat it covers
High-risk AI, stand-alone (Annex III)2 December 2027Hiring, credit scoring, education, essential services, biometrics
High-risk AI embedded in products (Annex I)2 August 2028Safety components in medical devices, machinery, aviation
Machine-readable marking of AI content2 December 2026Only for generative systems placed on the market before 2 August 2026

The Omnibus also softened the AI literacy duty. Companies must now take measures to support the development of staff AI literacy, rather than ensure that every employee has sufficient knowledge. Small businesses and small mid-caps gain simplified technical documentation, lighter quality management and lower penalties.

What already applies today

Since 2 August 2026 the Article 50 transparency rules apply on schedule:

Breaches of Article 50 can cost up to €15 million or 3% of worldwide annual turnover, with lower caps for SMEs. The prohibited practices, in force since February 2025, and the rules for general-purpose AI models also remain in force, and enforcement is live: the AI Office and national authorities can act, with a dedicated complaints mechanism and a whistleblower channel.

2 Aug 2026
Article 50 transparency rules apply
2 Dec 2026
Marking deadline for older generative systems
2 Dec 2027
Stand-alone high-risk obligations
2 Aug 2028
High-risk AI embedded in regulated products

A calendar you can actually use

WhenWhat to have done
NowAI inventory complete; chatbot and content disclosures live; prohibited-practice check done
By 2 December 2026Vendors confirm they mark AI output; if you provide generative AI, marking in place
Q1 to Q2 2027Combined DPIA/FRIA template ready; high-risk candidates identified and risk-rated
H2 2027Documentation, human oversight and logging tested on high-risk systems
2 December 2027Stand-alone high-risk obligations apply
2 August 2028Obligations for AI embedded in regulated products apply

Where the AI Act meets the GDPR

The AI Act does not replace the GDPR. If your AI system processes personal data, both apply at once.

💬
GDPRGard Product
Planning your AI disclosures? Start with the website chatbot

GDPRChat is an AI customer chat widget built with Article 7 consent gates and automatic data deletion — compliance built into the architecture, not bolted on after a regulator starts asking questions.

See GDPRChat →

Use the extra time well

The delay gives roughly 16 extra months for stand-alone high-risk systems. Spend them on four things:

  1. Inventory every AI tool in use, including the ones staff adopted without asking, and classify each as prohibited, high-risk, limited-risk or minimal.
  2. Put AI disclosure into every customer-facing chatbot, form and content workflow now. This is the one duty that is live today.
  3. Start a combined DPIA/FRIA template for anything that might be high-risk, such as AI used in recruitment or credit decisions.
  4. Run a short AI literacy session for staff and keep a record of attendance and content.

The bottom line

When the GDPR arrived in 2018, thousands of companies treated the date as a starting line and spent the last months in a panic. The AI Act offers a gentler schedule, but only to those who use it. Treat December 2027 as the date by which your documentation must be finished, not the date on which you begin, and the postponement becomes a real advantage.

Book a free consultation with GDPRGard → and we will help you classify your AI tools and plan your calendar.

Sources

Share this article

Also read:

⚠️ This article is for informational purposes only and does not constitute legal advice. For complex compliance situations, consult a qualified data protection professional. GDPR and EU AI Act requirements are subject to ongoing regulatory guidance — verify current obligations with your legal adviser.