Skip to content
Cardan-AI
Back to analyses
AI Governance27 July 2026

The EU AI Act's two-speed calendar: one deadline holds, the rest slipped — don't misprice the slip

On 2 August 2026 the EU AI Act's transparency and GPAI-enforcement obligations go live — with fines up to €15M or 3% of turnover — while the Digital Omnibus pushes the high-risk deadlines out to 2027-2028. Read as an economist, that postponement is a mispriced option, not relief — and regulated sectors already own the discipline to exploit it.

On 2 August 2026 — six days from now — the EU AI Act reaches its first hard enforcement milestone, and it is not the one most executives are watching. The high-risk deadlines everyone feared have just been pushed back by the Digital Omnibus agreement: standalone high-risk systems (Annex III) move from 2 August 2026 to 2 December 2027, and product-embedded high-risk systems (Annex I) from 2 August 2027 to 2 August 2028. The coverage has been almost uniformly one word: relief. Read as an economist, that reading is a mistake — and an expensive one for capital-intensive, regulated sectors.

Start with what does not move. From 2 August 2026, Article 50 transparency obligations apply: users must be told when they are interacting with an AI system, AI-generated images, audio and video must be machine-readable and labelled, and deepfakes depicting real people or events must be disclosed. On the same date, the Commission's enforcement machinery for general-purpose AI (GPAI) becomes fully operational — information requests, model access and recall powers — backed by fines of up to €15 million or 3% of global annual turnover, whichever is higher. The substantive GPAI obligations have applied since August 2025; what arrives now are the teeth.

So the first thing a board should notice is that the near-term obligations were never postponed. Any firm whose AI touches a customer interface, produces synthetic content, or is built on a general-purpose model — which now describes most deployments in aerospace, energy and oil & gas support functions — faces a live obligation in days, not years. The Omnibus relief applies to a different category of system than the one most enterprises are actually shipping first.

Now the postponement itself. Moving Annex III by sixteen months and Annex I by twelve is real, and it is not trivial. But a deferred deadline is not a reduced requirement. The conformity work — risk-management systems, data governance, technical documentation, human oversight, post-market monitoring — is unchanged. What changed is only when it must be finished. In finance terms, the Omnibus did not cut the liability; it extended the exercise date on an option the firm still has to fund.

And options get mispriced — systematically in one direction. The natural corporate response to 'the deadline moved' is to reallocate the budget elsewhere and revisit later. That treats postponement as a discount. It is not. It is time, and time has a value that depends entirely on what you do with it. Build the governance capability now, while there is no deadline pressure, and its marginal cost is low while its by-products — cleaner data pipelines, documented models, auditable decisions — start paying immediately. Build it in 2027 under a hard date, with scarce specialists and a compressed timeline, and you pay the classic deadline premium.

This matters more for aerospace & defence, energy and oil & gas than for almost anyone else, for a reason usually treated as a burden and in fact an advantage. These sectors already run exactly the discipline that high-risk AI conformity demands: safety cases, certification dossiers, traceability, version control, acceptance thresholds. High-risk AI governance is not a foreign process bolted on — it is the safety-engineering muscle these firms have had for decades, pointed at models. The firm that recognises this starts from a standing position, not a standing start, and can convert compliance into a procurement argument long before competitors treat it as a cost.

The practical sequence follows directly. First, map every AI use case against the actual calendar — what is exposed on 2 August 2026 (transparency, GPAI enforcement), what has genuinely slipped to 2027-2028 (high-risk), and what sits in the transitional windows (the CSAM/deepfake ban and the watermarking grace period, both closing 2 December 2026). Second, price the postponement as bought time, not saved money, and use it to build governance while the marginal cost is lowest. One caveat: the Digital Omnibus is a political agreement, with formal adoption expected before 2 August 2026, so the final text is worth tracking — but the near-term dates are set. The question for a regulated-sector executive this week is not 'how long can we wait' but 'what is it worth to be ready before we have to be.'

Timeline of EU AI Act deadlines: 2 Aug 2026 transparency + GPAI enforcement; 2 Dec 2026 CSAM ban and watermarking grace end; 2 Dec 2027 Annex III high-risk (postponed); 2 Aug 2028 Annex I high-risk (postponed)
The near-term obligations (2 Aug 2026) were not postponed; only the high-risk deadlines slipped to 2027-2028. Source: EU AI Act (Reg. 2024/1689) & Digital Omnibus agreement.
Bar chart of postponement granted by the Digital Omnibus: GPAI 0 months, Article 50 0 months, Annex I +12 months, Annex III +16 months
The Digital Omnibus moved deadlines, not requirements: the conformity work is unchanged, only the exercise date shifted. Source: Digital Omnibus agreement (Nov 2025).

Analysis by

Cardan-AI Intelligence

Our research and analysis unit, dedicated to applied AI for business, industry and regulatory compliance.

Let's talk about your next competitive edge

A 30-minute conversation to identify your most profitable AI use cases.