The Next AI Act Deadline Is December 2: What Changes Then

Europaflaggen vor einem Gebäude der Europäischen Union in Brüssel
Photo by Guillaume Périgois on Unsplash

The amending regulation known as the “Digital Omnibus” took effect at the end of July, pushing the AI Act’s toughest obligations back by more than a year. Anyone concluding that nothing happens until 2027 is missing the next deadline. On December 2, 2026, a transition period expires that affects considerably more companies than the postponed high-risk rules.

Key takeaways

  • Amending Regulation (EU) 2026/1744 appeared in the Official Journal on July 24, 2026, and entered into force on July 27. It changes the AI Act in 43 places but removes no obligation.
  • Obligations for standalone high-risk systems under Annex III now apply from December 2, 2027, and for AI embedded in regulated products from August 2, 2028.
  • December 2, 2026 ends the transition period for labeling synthetic content: systems placed on the market before August 2, 2026 will need machine-readable markings.
  • The same date brings new prohibitions on non-consensual intimate imagery and on software that computationally undresses people in photos.
  • The prohibitions in Article 5, the AI literacy duty in Article 4, and the obligations for providers of general-purpose AI models all remain in force unchanged.

What was postponed, and what was not

The road to the amendment was long: political agreement in trilogue on May 7, 2026, approval by the European Parliament on June 16 with 423 votes to 57 and 174 abstentions, formal adoption by the Council on June 29, and publication on July 24. Without that conclusion before August 2, the original deadlines would have taken effect automatically.

What got postponed is the chapter that costs companies the most effort. Annex III of the AI Act lists standalone high-risk applications: biometric systems, AI in hiring, in education, in creditworthiness assessments of individuals, in critical infrastructure, and in law enforcement. For these, December 2, 2027 replaces August 2026. Where AI is embedded in a regulated product under Annex I, the deadline runs to August 2, 2028, and for certain systems designated by authorities it extends to 2030.

What matters is what the delay is not. The substantive requirements for high-risk systems — risk management, data quality, technical documentation, human oversight — were not watered down, only deferred. And three blocks still apply unchanged: the prohibitions in Article 5, in force since February 2025 and backed by fines since August 2025; the Article 4 duty to give employees a level of AI literacy appropriate to their use; and the requirements for providers of general-purpose AI models, whose enforcement began in August 2026.

The deadline that counts now

For most companies, December 2, 2026 is the practically relevant date. That is when the transition period for Article 50(2) ends, the labeling duty for machine-generated content. Systems that synthetically produce audio, images, video, or text and were placed on the market before August 2, 2026 must then mark their output in machine-readable form. The text requires markings that are technically effective, interoperable, robust, and reliable. Exempt are functions that merely assist with editing without substantially altering content, and investigative systems used by authorities.

This duty does not fall on large model providers alone. It reaches anyone offering a system with generative features, from an image generator inside a product configurator to a text assistant in a customer portal. How hard the industry finds durable marking has been demonstrated repeatedly this year: watermarks can be stripped, and a missing watermark proves nothing in return. The regulation demands them regardless.

Two new prohibitions take effect on the same date. Non-consensual intimate imagery and applications that computationally undress people in photos are banned outright. Both now sit in the same category as social scoring, practices prohibited regardless of purpose. The fine ceiling here is 35 million euros or seven percent of worldwide annual turnover; for breaches of high-risk obligations it is up to 15 million euros or three percent.

Relief measures and criticism

Small and medium-sized enterprises, along with a newly defined group of “small midcaps,” receive concessions: simplified technical documentation following a Commission template, more proportionate quality management requirements, priority access to regulatory sandboxes, and lower fine ceilings for certain breaches. A small midcap is defined as a company with fewer than 750 employees and no more than 150 million euros in annual turnover or 129 million euros in total assets.

Objections came from Europe’s data protection authorities. The European Data Protection Board and the European Data Protection Supervisor warned in a joint opinion in January 2026 that simplification must not come at the expense of fundamental rights protection, and criticized the postponement of the high-risk rules explicitly. They prevailed only in part: bias testing with sensitive data now carries a strict necessity criterion in the text, while their call for tougher literacy obligations found no majority.

What companies should do now

The delay calls for a different order of work rather than a pause. The sensible first step is an inventory: which AI systems are in the building, who procured them, and what do they produce? Only from that does it become clear whether a high-risk case exists at all. In practice, many applications do not qualify — fraud detection is explicitly excluded, and ordinary accounting AI for document recognition generally is too. Anyone offering generative features, by contrast, should now be settling how labeling will work technically by December.

The second point gets overlooked because it costs nothing but time. The AI literacy duty has applied since February 2025 to everyone operating AI systems, regardless of risk class. Handing employees a tool also means enabling them to use it. It is the lowest bar in the entire regulation, and the one missed most often.

That leaves supervision. In Germany, the Bundesnetzagentur, the federal network regulator, is set to take the central role, flanked by the new AI safety institute, and the national arrangements are not settled on every point. For consumers, the December date changes little, since the rules visible to them covering chatbots and labeled content have applied since August. For providers, December 2 is the day the last grace period runs out.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top