High-risk AI rules under the EU AI Act now start on 2 December 2027, not August 2026. The AI Omnibus that made the change was published in the Official Journal on 24 July 2026 and entered into force on 27 July. Many businesses read the headlines as “the AI Act is postponed”. It is not. Several obligations already apply, and the GDPR applies to every AI system that touches personal data.
This article turns the new dates into a working calendar. For the detail of the transparency rules, see our guide to the Article 50 guidelines; for the penalty maths, see the high-risk deadline and the GDPR overlap.
What the AI Omnibus changed
| Obligation | New date | What it covers |
|---|---|---|
| High-risk AI, stand-alone (Annex III) | 2 December 2027 | Hiring, credit scoring, education, essential services, biometrics |
| High-risk AI embedded in products (Annex I) | 2 August 2028 | Safety components in medical devices, machinery, aviation |
| Machine-readable marking of AI content | 2 December 2026 | Only for generative systems placed on the market before 2 August 2026 |
The Omnibus also softened the AI literacy duty. Companies must now take measures to support the development of staff AI literacy, rather than ensure that every employee has sufficient knowledge. Small businesses and small mid-caps gain simplified technical documentation, lighter quality management and lower penalties.
What already applies today
Since 2 August 2026 the Article 50 transparency rules apply on schedule:
- Chatbots and AI assistants must tell people they are talking to AI, unless that is obvious.
- Synthetic content must be marked in a machine-readable way by the provider.
- Deepfakes must be disclosed by the business that publishes them, with lighter treatment for clearly creative or satirical work.
- AI-written text on matters of public interest must be disclosed, unless a human reviewed it and took editorial responsibility.
- Emotion recognition and biometric categorisation require notice to the people exposed.
Breaches of Article 50 can cost up to €15 million or 3% of worldwide annual turnover, with lower caps for SMEs. The prohibited practices, in force since February 2025, and the rules for general-purpose AI models also remain in force, and enforcement is live: the AI Office and national authorities can act, with a dedicated complaints mechanism and a whistleblower channel.
A calendar you can actually use
| When | What to have done |
|---|---|
| Now | AI inventory complete; chatbot and content disclosures live; prohibited-practice check done |
| By 2 December 2026 | Vendors confirm they mark AI output; if you provide generative AI, marking in place |
| Q1 to Q2 2027 | Combined DPIA/FRIA template ready; high-risk candidates identified and risk-rated |
| H2 2027 | Documentation, human oversight and logging tested on high-risk systems |
| 2 December 2027 | Stand-alone high-risk obligations apply |
| 2 August 2028 | Obligations for AI embedded in regulated products apply |
Where the AI Act meets the GDPR
The AI Act does not replace the GDPR. If your AI system processes personal data, both apply at once.
- One assessment, not two. A high-risk system will often need a GDPR Data Protection Impact Assessment and, for some deployers, an AI Act Fundamental Rights Impact Assessment. Build one combined template rather than two files that drift apart. See why AI features need a DPIA.
- Transparency in two places. The Article 50 AI disclosure sits alongside your GDPR privacy notice. Update them together, so the chatbot banner and the privacy policy tell the same story.
- Human oversight. AI Act oversight duties and the GDPR's Article 22 limits on automated decisions point the same way: a real person with real authority must be able to change the outcome. The Dutch regulator's record fine on Uber in August shows how seriously this is taken.
GDPRChat is an AI customer chat widget built with Article 7 consent gates and automatic data deletion — compliance built into the architecture, not bolted on after a regulator starts asking questions.
Use the extra time well
The delay gives roughly 16 extra months for stand-alone high-risk systems. Spend them on four things:
- Inventory every AI tool in use, including the ones staff adopted without asking, and classify each as prohibited, high-risk, limited-risk or minimal.
- Put AI disclosure into every customer-facing chatbot, form and content workflow now. This is the one duty that is live today.
- Start a combined DPIA/FRIA template for anything that might be high-risk, such as AI used in recruitment or credit decisions.
- Run a short AI literacy session for staff and keep a record of attendance and content.
The bottom line
When the GDPR arrived in 2018, thousands of companies treated the date as a starting line and spent the last months in a panic. The AI Act offers a gentler schedule, but only to those who use it. Treat December 2027 as the date by which your documentation must be finished, not the date on which you begin, and the postponement becomes a real advantage.
Book a free consultation with GDPRGard → and we will help you classify your AI tools and plan your calendar.
Sources
- Gibson Dunn: EU AI Act Omnibus agreement, postponed high-risk deadlines and other key changes
- European Commission: Guidelines on transparency obligations for providers and deployers of certain AI systems
- EU Artificial Intelligence Act: Article 50, transparency obligations
- Ashurst: Data Bytes 68, EMEA Data Privacy Update, September 2026
Also read:
- The high-risk deadline moved to December 2027. The GDPR overlap didn't move at all.
- The AI Act delay doesn't cover your chatbot
- Your AI chatbot isn't anonymising anything