Prefer to listen? Click play for AI narration
Updated 7 September 2026. This article originally ran on 3 August 2026, when the AI Act's high-risk obligations were expected to bite from 2 August 2026. They did not. The AI Omnibus — given final Council approval on 29 June 2026 and in force since 27 July 2026 — moved that deadline to 2 December 2027. The piece has been rewritten around the timeline as it actually stands.

If your organisation builds, deploys, or relies on AI in hiring, credit scoring, critical infrastructure, or border and law enforcement contexts, you spent most of 2026 bracing for 2 August 2026. That deadline came and went without the high-risk obligations attaching. You now have until 2 December 2027 — a 16-month extension, granted largely because the harmonised technical standards meant to make compliance achievable arrived late.

That is real relief, and it is narrower than it sounds. The delay moved one set of obligations. It did not move GDPR, it did not move the AI Act's penalty structure, and it did not move two new prohibitions arriving this December with no transition period at all. The overlap between the two laws — where they collide, and where a single set of facts can be assessed twice under two different tests — is exactly where it was.

What Actually Moved, and What Didn't

The AI Omnibus reshaped the calendar rather than the substance. The dates that now govern:

2 Dec 2027
Annex III high-risk systems (was 2 Aug 2026)
2 Aug 2028
Annex I product-embedded AI (was 2 Aug 2027)
2 Dec 2026
Two new Article 5 prohibitions — no grace period
2 Aug 2030
Public authority systems, any category

What did not move. Article 50 transparency duties applied from 2 August 2026 as planned — if your chatbot talks to customers, they still have to be told, and no extension covers that. The existing Article 5 prohibitions have applied since February 2025. And two new Article 5 prohibitions take effect on 2 December 2026: AI systems that generate or manipulate child sexual abuse material, and systems that generate realistic intimate imagery of an identifiable person without their explicit consent. That second one reaches beyond purpose-built "nudifier" apps to providers of general-purpose generative models where such output is a reasonably foreseeable outcome and no reasonable safeguards are in place.

What the extra runway is for. High-risk AI systems under Annex III — recruitment and worker management, creditworthiness assessment, access to essential services, biometric categorisation, education scoring — will still need all of this by December 2027:

Providers will need conformity assessments completed, technical documentation finalised, CE marking affixed and EU database registration done by that date. The Omnibus also narrowed the "safety component" definition — a component only pulls a system into high-risk territory if its intended purpose is preventing or mitigating risks to health and safety, so AI used purely for optimisation, user assistance or convenience is now out — and softened Article 4 AI literacy from a duty to ensure staff competence to a duty to support its development.

If several of those obligations sound familiar, that's because they should. GDPR already required data protection impact assessments, documented risk analysis, transparency to data subjects, and safeguards around automated decision-making. The AI Act doesn't replace any of that — it sits on top of it, with its own separate legal basis, its own documentation requirements, and its own fines. None of that was deferred, because GDPR was never part of the delay.

Where the Two Laws Actually Overlap

This is the part the delay does nothing about. The overlap is structural, not calendar-dependent: GDPR applies to the personal data in your AI system today, and the AI Act's obligations will land on the same systems in December 2027. The clearest collision points:

Data governance. The AI Act's Article 10 requires governance over training and validation datasets — relevance, representativeness, bias detection. GDPR's data minimisation and accuracy principles (Article 5) already govern the personal data inside those same datasets. From December 2027 a flawed training set can be a violation under both frameworks simultaneously, assessed by two different tests — and under GDPR alone, it already can be today.

Impact assessments. GDPR requires a Data Protection Impact Assessment (DPIA) for high-risk processing. The AI Act requires a Fundamental Rights Impact Assessment (FRIA) for certain high-risk deployments, particularly by public bodies and in sensitive sectors. These aren't the same document, but they draw on much of the same underlying risk analysis — which is precisely why the extra runway is worth spending on the DPIA foundation the FRIA will have to be built on.

Transparency. GDPR Articles 12–14 require clear information to data subjects about processing. The AI Act separately requires providers to give deployers instructions for safe use and information about system accuracy and limitations, and requires that people be told when they're interacting with an AI system. Two transparency regimes, two audiences, two sets of disclosure obligations.

Human oversight and automated decision-making. GDPR Article 22 restricts solely automated decisions with legal or similarly significant effects. The AI Act's human oversight requirement is broader and applies regardless of whether a decision is "solely" automated — meaning a system that clears the GDPR Article 22 bar because a human technically reviews outputs can still fail the AI Act's higher bar for what effective oversight looks like.

The Penalty Math

The Omnibus moved deadlines. It did not touch Article 99, which still sets a three-tier structure — and note which tier is already live: the top one, covering the prohibited practices that have applied since February 2025 and the two new ones arriving in December 2026.

Two penalty regimes, one AI system Two penalty regimes, one AI system Maximum fine ceilings · bar length = % of global annual turnover AI Act — prohibited practices (Art. 5) €35M / 7% GDPR — most serious infringements (Art. 83(5)) €20M / 4% AI Act — high-risk system violations €15M / 3% AI Act — misleading info to regulators €7.5M / 1% EU AI Act (Art. 99) GDPR (Art. 83) Whichever is higher applies — the euro ceiling or the percentage. Turnover means global annual turnover for the preceding financial year.
The AI Act's top tier now sits above GDPR's own maximum, making it the more punitive of the two regimes at its ceiling. The tier that will matter most to ordinary businesses, though, is the middle one — high-risk system violations at €15M or 3%.

The top tier now exceeds GDPR's own maximum of €20 million or 4% of global turnover, making the AI Act the more punitive of the two regimes at its ceiling.

Crucially, Article 99(8) includes a "same conduct, one penalty" rule: if a single factual violation breaches both the AI Act and another EU law like GDPR, regulators impose only the higher of the two applicable fines. But that protection is narrower than it sounds. If an AI system violates the AI Act's data governance rules through a biased training set, and separately violates GDPR's accuracy or minimisation principles through how that same data was collected or retained, those are treated as distinct violations — and can be penalised separately.

Legally, this isn't "double jeopardy" in the way many compliance teams assume. It's a determination made violation-by-violation — and the more entangled your AI system's data practices are with GDPR-governed personal data, the more surface area you have for that separation to work against you.

What to Do With 16 Extra Months

A delayed deadline is not a delayed risk, and it is certainly not sixteen months of nothing. The instinct to treat the AI Act and GDPR as two checklists to run in sequence is still the most expensive mistake available. A few things worth doing instead:

  1. Put the December 2026 dates in the calendar before anything else. The two new Article 5 prohibitions and the Article 50(2) marking rules for synthetic media arrive with no runway at all. If you generate or manipulate images, video or audio in any customer-facing way, that is a this-quarter question — not a 2027 one.
  2. Classify your systems now and document the reasoning, even where the answer is "not high-risk". The narrowed safety-component definition means some systems that looked in scope in 2025 have dropped out — write down why. The classification itself is something you're expected to be able to show, and it does not become easier by leaving it until 2027.
  3. Map your DPIAs and FRIAs against each other rather than commissioning them separately. If a system needs both, the underlying risk analysis should be a shared foundation, not two disconnected exercises that quietly contradict each other. If you don't have a DPIA process at all yet, start there — the FRIA is much harder to build on nothing.
  4. Audit your existing GDPR transparency notices against the AI Act's disclosure requirements. They cover different information, but a notice built only for GDPR compliance is likely to be missing what the AI Act separately demands — and the Article 50 duties that apply to customer-facing AI were never delayed. This lands at the same time the EDPB has made Articles 12–14 transparency its 2026 coordinated enforcement priority. Both regulators are looking at the same notices this year, for different reasons.
  5. Treat human oversight as a design requirement, not a policy statement. Regulators under both regimes are going to ask for evidence that a human can meaningfully intervene, not just that a human is nominally in the loop. Our AI oversight checklist covers what that evidence looks like in practice.
  6. Get legal and technical documentation teams talking to each other now. The AI Act's technical documentation and logging requirements will increasingly be the evidence base regulators use to evaluate GDPR compliance too, since both hinge on being able to show — not just assert — how a system actually processes personal data.

Why the Delay Doesn't Buy You a Quiet Year

The extension applies to one set of AI Act obligations. It does not apply to the enforcement environment those obligations land in, and that environment has not gone quiet.

€7.1B
Cumulative GDPR fines to date
€600M+
Issued in H1 2026 alone
443
Breach notifications per day
+22%
Year-over-year increase

GDPR fines have already crossed €7.1 billion cumulatively, with more than €600 million issued in the first half of 2026 alone. Daily breach notifications have climbed 22% year over year to 443 per day — the first time that figure has topped 400 since GDPR took effect in 2018. And enforcement has moved decisively past Big Tech: more fines have been issued against small and mid-sized businesses since January 2023 than in the previous five years combined.

Layer a second, higher-ceiling penalty regime onto that trajectory — arriving in December 2027, with two prohibitions arriving a full year sooner — and the message for compliance teams is straightforward: the AI Act didn't just add a new law to track. It added a second regulator with its own theory of what your AI system owes the people whose data it touches — which will run at the same time, on the same systems, often over the same facts. The delay changed when that starts. It changed nothing about what it costs to be unprepared for it.

If you're not sure which side of the high-risk line your systems fall on, that's the question to answer first — the obligations above only bite once you're inside Annex III, but the classification itself is something you're expected to have documented. For the full picture of which parts of the reform are settled law and which are still stuck in negotiation, see GDPR and AI governance in 2026. Book a free consultation with GDPRGard →

Sources

Share this article

Also read:

⚠️ This article is for informational purposes only and does not constitute legal advice. For complex compliance situations, consult a qualified data protection professional. GDPR and EU AI Act requirements are subject to ongoing regulatory guidance — verify current obligations with your legal adviser.