The EU AI Act Changed While It Was Arriving

The AI Act became applicable six days after an Omnibus changed part of its timetable. Some obligations arrived as planned, while others moved years into the future. I think that split exposes a tension built into the Act itself.

The EU AI Act Changed While It Was Arriving

A client asked me whether an AI system that introduces itself as a virtual assistant is clear enough under the new rules. A fair question with a short answer, I assumed. Twenty minutes later we had six dates on the table and were disagreeing about which two of them still applied.

The Act had entered into force two years earlier. Most of its provisions had become applicable three days before we spoke. Six days before that, the AI Omnibus had changed parts of the timetable. Some obligations were now in effect. Others had moved into 2027 and 2028.

I could not answer his question without first sorting out the dates, and the dates turned out to be the more interesting problem.

Several clocks

European legislation rarely arrives through one decisive moment. A regulation is proposed, negotiated, adopted and published. It then enters into force. Individual provisions may become applicable later, sometimes across several dates. Standards, guidance and supervisory arrangements develop alongside all of that.

The AI Act has been arriving through each of these stages for two years.

DATE WHAT HAPPENED
1 August 2024 The EU AI Act entered into force
2 February 2025 Prohibited practices and AI literacy provisions began to apply
2 August 2025 Governance rules and obligations for general-purpose AI models began to apply
27 July 2026 The Digital Omnibus on AI, commonly called the AI Omnibus, entered into force and amended parts of the AI Act
2 August 2026 Most remaining provisions became applicable, including the Article 50 transparency rules
2 December 2026 New prohibitions added by the Omnibus begin to apply, and the transition for Article 50(2) marking ends
2 December 2027 Revised date for high-risk systems in areas listed in Annex III
2 August 2028 Revised date for high-risk AI embedded in regulated products
🗒️
The Article 50(2) transition is narrow and easy to misread. AI systems already on the market before 2 August 2026 have until 2 December 2026 to meet the marking and detection requirements for AI-generated content. Systems placed on the market from 2 August onwards comply immediately, with no transition at all. Two products can be technically identical and sit on different sides of that line. The rest of Article 50 keeps its original timetable.

The Act became European law in 2024 and its obligations have been landing in stages ever since. The Omnibus changed some of those stages while the rest continued on schedule. This is why reports of the AI Act being delayed can be accurate in their detail and misleading overall.

One procedural fact makes the point better than any commentary. A European regulation normally enters into force twenty days after publication. This one took three, and the legislator justified the compression as a matter of urgency, because the deadline it was amending was six days away. A delay that arrives after the thing it is delaying is not a delay. The timetable was tight enough that the correction had to overtake it.

The change

When I wrote about the wider Digital Omnibus package in November 2025, it was entering the European legislative process. The package contained two separate proposals. One covered data, cybersecurity and privacy rules. The other contained targeted amendments to the AI Act. That second proposal is now law as Regulation (EU) 2026/1744.

The visible change concerns high-risk systems. Requirements for uses in employment, education, essential services and migration now apply from December 2027, rather than August 2026. Rules for high-risk AI embedded in regulated products, including machinery, toys and lifts, follow in August 2028, a year later than originally planned. Those shifts produced the headlines about delay.

The rest is smaller. The Omnibus extended simplified requirements to small mid-cap companies, widened access to regulatory sandboxes, adjusted the AI literacy obligation, clarified the interaction between the AI Act and other European rules, expanded parts of the AI Office's oversight, and added prohibitions on systems generating non-consensual intimate imagery and child sexual abuse material.

An organisation using a high-risk recruitment system now has more time to prepare. A provider covered by the transparency obligations in Article 50 does not. Both operate under the same Act, and the same week contained obligations that moved and obligations that arrived.

Why it moved

The official reason is readiness. High-risk requirements depend on harmonised standards, conformity procedures and competent authorities, and several of those were not going to exist in time.

It is worth being precise about whose readiness. The Act set a timetable that assumed harmonised standards would be available by 2026. The bodies responsible for writing them did not deliver. The deferral is the regulator granting itself an extension and then passing the benefit to the regulated as relief.

I do not think that is scandalous. I think it was close to inevitable, and what made it inevitable is the part worth looking at.

The Act was proposed in April 2021, before general-purpose models were a public fact. The chapter governing them was added during the negotiations in 2023, because the ground moved while the text was being written. The Omnibus is the second time the technology has outrun the law, and the first time happened before the law was finished. These are capable people working in good faith. Nobody in Brussels in 2021 knew what the last three years would contain, and nobody now knows what the next three will. A legislature writing a five-year timetable for a technology with an eighteen-month horizon is making a promise it has no instrument to keep.

The competitiveness argument sits on top of this and convinces me less than it convinces the Commission. What I have watched freeze European organisations is not stringency. It is indeterminacy. Nobody I work with stopped because the requirements were too strict. They stopped because there was a date and nothing concrete to build against, and an institution facing an unknown obligation with a known deadline does nothing at all.

Which is also the strongest case against the extension. If indeterminacy was the problem, moving the date prolongs it. The extension only pays for itself if the standards actually arrive, so December 2027 is not the clock to watch. The standardisation work is. If that slips again, the date moves again, and after the second time nobody will plan against a European deadline at all.

The machinery

Passing a regulation and making it operational are different kinds of work. The legal text could be completed in 2024. Applying it requires standards, guidance, authorities, assessment procedures and organisations capable of interpreting their own responsibilities.

The AI Act is an EU regulation, so its substantive rules apply directly across the Member States. Countries do not first have to convert them into separate national AI laws, as they would with a directive. The European Commission explains that distinction between the types of EU law. National institutions still organise much of the supervision, which leaves the law shared across the Union while parts of its operation remain national.

For most organisations this machinery will be more tangible than the regulation itself. They meet it through procurement requirements, supplier documentation, internal governance, product reviews and questions from customers, which is where European rules stop being abstract and start touching everyday decisions.

Two kinds of work

Look again at what held its date and what did not.

What arrived on 2 August is individual-facing. Tell people they are talking to a machine. Disclose deepfakes. These protections matter and I am glad they are in force.

What moved to 2027 and 2028 reaches further into organisations and markets: hiring, education, essential services, migration, safety components in regulated products. Those obligations depend more heavily on standards, procedures, authorities and organisations knowing what they are expected to build against.

That difference has made me look at the Act differently.

What I am beginning to see is that it is doing two kinds of work at once.

Part of it establishes rules organisations should be able to build against: transparency requirements, conformity procedures, standards and responsibilities. That kind of regulation needs a degree of stability.

Another part is trying to shape the European AI market itself. The AI Office, regulatory sandboxes, thresholds for general-purpose models, exemptions for smaller companies and the continuing simplification agenda all respond to an industry that is still changing quickly.

Those two tasks tolerate change differently. A conformity regime becomes difficult to use if its requirements keep moving. Policy aimed at shaping an emerging industry becomes less useful if it cannot move when the industry does.

Putting both inside the same regulation does not make the combination wrong. It does make the timetable unusually difficult to hold.

Seen that way, July was more than a correction to a schedule. It exposed a tension inside the Act itself.

That is a longer argument than this piece can hold, and I will come back to it.

The immediate question is smaller and more useful. My client still needs to know whether an AI system introducing itself as a virtual assistant is sufficiently clear under Article 50. That answer exists, it is more specific than most of what has been written about the Act, and it is where the next article begins.

Share this article
Rob Hoeijmakers

Thanks for reading.

I’m Rob Hoeijmakers, a digital and AI strategist based in the Netherlands. I write about AI, organisations and technological change, with a European perspective and a focus on what these developments mean in practice. I’m also the founder of Schmuki, a digital and AI agency.

Every Thursday, I gather the latest essay — or a few of them — into a short note. If that’s useful, you’re welcome to receive it.