The European Union has pushed back the start of its strictest artificial intelligence rules by 16 months, giving companies until 2 December 2027 to comply. But the bloc kept one deadline in place. From 2 August 2026, regulators can fine the makers of powerful general-purpose AI models up to 15 million euros or 3% of global annual revenue, whichever is higher.
The change comes from the "Digital Omnibus on AI", a package of amendments to the 2024 AI Act. The European Commission first proposed it on 19 November 2025. The European Parliament backed it on 16 June 2026 by 423 votes to 57, with 174 abstentions, and the Council gave final approval on 29 June. It was published as Regulation (EU) 2026/1744 on 24 July and took effect on 27 July, days before the original 2 August deadline it rewrote.
What moved are the "high-risk" systems listed in Annex III of the law. These cover AI used in hiring, credit scoring, biometric identification, education and border control. They were due to meet the full set of obligations by August 2026. That date is now December 2027. High-risk AI built into regulated products, listed in Annex I, slips a year to 2 August 2028. The reason is practical: the technical standards firms need to prove they comply are not ready, which left companies unsure how to pass conformity checks.
What did not move is the rulebook for general-purpose AI. Obligations on foundation-model makers such as OpenAI, Google, Anthropic, Meta and Mistral have applied since August 2025, but without any way to enforce them. From 2 August 2026 the Commission's AI Office gains teeth. It can demand documentation, evaluate models, order products off the EU market and issue penalties under Article 101. Separate transparency rules also start, requiring providers to disclose when people are dealing with AI-made content or chatbots. Providers of systems already on the market get until 2 December 2026 to add watermarks.
The package also writes a new ban into Article 5, targeting AI "nudifiers" that generate non-consensual intimate images and child sexual abuse material.
Beyond the calendar, the delay has drawn sharp criticism. Civil society groups including European Digital Rights, ECNL, Access Now and Amnesty International call it deregulation dressed up as simplification. They argue it strips protection from people exposed to high-risk AI before the safeguards ever applied.
Laura Caroli, who led the Parliament's technical talks on the AI Act as senior adviser to MEP Brando Benifei and now works as an independent AI-policy expert, warned that the delay risks "undermining the standardization ecosystem, which should be a strategic asset for Europe." She said she could not see anything positive coming from it, either for AI governance or for European democracy.
For any business using AI in the EU, the message splits in two. Firms deploying high-risk tools get breathing room. But anyone building or supplying large AI models faces real enforcement now. Two things are worth watching. Whether member states set up the market-surveillance bodies meant to police the rules, and whether the missing technical standards arrive before the new 2027 deadline. If they slip again, the reprieve could turn into a longer pattern of retreat.