Aug 3, 2026
/
Regulation

The AI Act's high-risk delay buys 16 months, not a reprieve

The Digital Omnibus moved Annex III high-risk obligations to December 2027, but Article 50 transparency duties applied from 2 August 2026. What to build meanwhile.

For most of the past two years, 2 August 2026 was circled on every AI compliance calendar in Europe. It was the date the EU AI Act's high-risk regime for Annex III systems — employment, creditworthiness, education, access to essential services — was due to apply.

That date passed yesterday. For high-risk systems, very little happened.

The Digital Omnibus on AI, proposed by the Commission on 19 November 2025, reached political agreement on 7 May 2026 after a near-breakdown in April. Parliament adopted the final text on 16 June, the Council on 29 June, with entry into force in July. Its flagship provision defers the high-risk obligations by sixteen months.

The headline most organisations heard was "the EU delayed the AI Act". That is half true, and the imprecision is dangerous. Some obligations moved. Others did not move at all and applied yesterday exactly as originally scheduled.

What moved and what didn't

EU AI Act application dates following adoption of the Digital Omnibus on AI
Date Obligation
2 February 2025 Prohibited practices and AI literacy obligations — already in force
2 August 2025 General-purpose AI model obligations — already in force
2 August 2026 Article 50 transparency obligations apply, except Article 50(2) for systems already on the market
2 December 2026 Article 50(2) marking requirements for legacy systems; new prohibited practices apply
2 August 2027 Member States to establish at least one national AI regulatory sandbox
2 December 2027 High-risk obligations for stand-alone Annex III systems
2 August 2028 High-risk obligations for AI embedded in regulated Annex I products

The Omnibus also introduced a new prohibition in Article 5 covering AI systems used to generate non-consensual intimate imagery and child sexual abuse material, including so-called nudifiers, and significantly expanded the supervisory powers of the AI Office.

Article 50 is the provision most often misread, because it is not one rule. It is a cluster of distinct disclosure duties falling on different actors:

  • Chatbot notices. Providers of AI systems intended to interact directly with people must ensure those people are informed they are dealing with an AI system, unless it is obvious to a reasonably well-informed person.
  • Synthetic content marking. Providers of systems generating synthetic audio, image, video or text must mark outputs in a machine-readable format as artificially generated or manipulated. For systems already on the market at 2 August 2026, this obligation applies from 2 December 2026.
  • Emotion recognition and biometric categorisation. Deployers must inform the people exposed to such systems of their operation.
  • Deepfake disclosure. Deployers of systems generating or manipulating image, audio or video content constituting a deepfake must disclose that it is artificially generated or manipulated.
  • Public interest text. Deployers publishing AI-generated or manipulated text to inform the public on matters of public interest must disclose that fact, subject to exceptions including human editorial review and responsibility.

Conflating these produces both over-compliance and under-compliance. They apply to different parties, carry different exceptions, and — crucially — apply regardless of whether your system is high-risk. A customer service chatbot is not a high-risk AI system, and it was in scope yesterday.

Why "we'll start in 2027" fails

The delay was granted for a specific reason. Implementation was visibly off track: national competent authorities had not been designated in many Member States, and the harmonised standards and conformity assessment tools needed to make Chapter III workable were incomplete. CEN-CENELEC JTC 21's work on those standards is still in progress.

The delay was not granted because the underlying work is smaller than expected. The Council's own framing was explicit: additional time to achieve compliance, with the expectation that implementation efforts are already under way.

Three practical reasons not to wait.

You do not know what you have. Almost every organisation that starts an AI inventory discovers more than it expected — a screening tool inside the applicant tracking system, a scoring model in a procurement platform, a summarisation feature that a team enabled in a SaaS product last quarter. Building a defensible inventory across a mid-sized organisation takes months, and it is the prerequisite for every other decision. You cannot classify what you have not found, and you cannot classify at speed in the last quarter before a deadline.

Classification is genuinely hard. Whether a system falls within Annex III is a legal and technical judgement, and it interacts with your role — provider, deployer, importer, distributor — which can change when you fine-tune or rebrand a model. Getting this wrong in either direction is costly: unnecessary conformity assessment burden on one side, unmitigated exposure on the other.

The market is not waiting for the regulator. Enterprise procurement questionnaires already ask about AI governance. So do public sector tenders. Whatever December 2027 requires, your customers are asking this year.

Where ISO/IEC 42001 fits

ISO/IEC 42001:2023, published in December 2023, is the first international management system standard for artificial intelligence. It specifies requirements for establishing, implementing, maintaining and continually improving an AI management system, and it follows the same Harmonised Structure as ISO 9001 and ISO/IEC 27001 — ten clauses, same core text, designed to integrate with what you already run.

Its most useful features for AI Act preparation are structural rather than technical:

  • An AI system inventory and lifecycle scope. The standard forces you to enumerate systems and define where your responsibility begins and ends.
  • AI impact assessment. A required process for assessing consequences for individuals and groups, distinct from risk to the organisation. This is the conceptual bridge to the AI Act's fundamental rights orientation, and to GDPR Article 35 DPIAs.
  • Role clarity across the supply chain. Provider, deployer and third-party responsibilities have to be written down.
  • The management system machinery. Internal audit, management review, nonconformity handling, continual improvement. Unglamorous, and precisely what makes governance survive staff turnover.

Now the honest limitation, which some vendors gloss over: ISO/IEC 42001 certification is not conformity with the EU AI Act. It is not a harmonised standard under Article 40, it confers no presumption of conformity, and it does not replace the conformity assessment procedures in Chapter III. An ISO 42001 certificate does not make a high-risk system compliant.

What it does is build the organisational substrate that AI Act compliance sits on. When the harmonised standards land and the December 2027 date approaches, an organisation with a functioning AIMS is doing a gap analysis. An organisation without one is starting from an inventory.

If you buy an AI certificate, check what's behind it

This is where the AI assurance market is currently weakest, and where we would rather be blunt than commercially convenient.

In 2025, ISO published ISO/IEC 42006:2025, which sets the requirements a certification body must meet to audit and certify AI management systems. It builds on ISO/IEC 17021-1 and adds AI-specific requirements on auditor competence, audit time calculation and impartiality. It applies to the certifier, never to you — but it determines whether the certificate you receive means anything.

Accreditation is granular. A body accredited for ISO/IEC 27001 is not thereby accredited for ISO/IEC 42001. Before you engage anyone:

  1. Ask for the accreditation certificate, not a marketing claim.
  2. Check the scope on the accreditation body's public register — ANAB, UKAS, RvA, DAkkS. If ISO/IEC 42001 is not listed in the scope, the certificate is not accredited for ISO/IEC 42001, whatever the website says.
  3. Ask how the body meets ISO/IEC 42006 on auditor competence. A good one will answer in detail.
  4. Check the certificate scope statement. An AIMS scope is usually narrower than the whole organisation, and buyers frequently miss this.

As at mid-2026, accredited bodies remain a short list. RvA accredited the first body in December 2024; UKAS granted its first ISO 42001 accreditation under ISO/IEC 42006 in January 2026; ANAB has accredited several. DAkkS and other EU accreditation bodies are at various stages of building out their ISO/IEC 42006 schemes, with more accreditations expected through 2026 and 2027.

Our own position, plainly stated: Proks Certification does not currently hold DAkkS accreditation for ISO/IEC 42001. We offer AI management system work as a special audit — gap assessment against ISO/IEC 42001 and readiness review against the AI Act obligations that apply to you — and we do not describe the output as an accredited certificate, because it isn't one. If an accredited ISO/IEC 42001 certificate is what your customers require today, we will tell you so and point you to a body that holds it in scope.

A sixteen-month plan

Q3–Q4 2026 — find out what applies to youBuild the AI system inventory. Determine your role for each system. Screen for Article 50 exposure, because that is live now: chatbots, generative features, synthetic media, emotion recognition, deepfakes, published AI-generated text. Fix the disclosure gaps first — they are cheap, visible, and already binding. Confirm your Article 4 AI literacy obligations are met; they have applied since February 2025.

Q1–Q2 2027 — build the systemStand up governance: an accountable owner, an AI policy, an approval gate for new systems. Run AI impact assessments on the systems most likely to be Annex III. Integrate with what exists — your ISO 27001 risk process and your GDPR DPIA process already do most of the analytical work. Do not build a parallel compliance function.

Q3 2027 onward — verifyInternal audit against ISO/IEC 42001. Track the CEN-CENELEC JTC 21 harmonised standards and the AI Office's guidance as they land. Decide whether accredited certification is warranted for your market, and if so, engage a body with the scope early — accredited capacity is thin and will not expand as fast as demand.

Why this is filed under Ethics

Because the substance of AI governance is not paperwork. Article 50's disclosure duties exist so that people know when they are talking to a machine, and when an image has been manufactured. ISO/IEC 42001's impact assessment exists to make an organisation ask who might be harmed, not only what might be lost.

An organisation can meet both requirements as a compliance exercise. It can also treat them as what they are: a commitment that the people affected by its systems are told the truth about them. Auditors can only measure the first. The second is what makes the first worth doing.

If you are working out what applies to your AI systems and where a management system would help, get in touch.

Sources

  • Regulation (EU) 2024/1689 (AI Act), Articles 4, 5, 40, 50, Annexes I and III
  • Digital Omnibus on AI — Commission proposal, 19 November 2025; political agreement 7 May 2026; European Parliament adoption 16 June 2026; Council adoption 29 June 2026
  • Gibson Dunn, "EU AI Act Omnibus Agreement — Postponed High-Risk Deadlines and Other Key Changes"
  • Freshfields, "EU AI Act unpacked #34: The final Digital Omnibus on AI"
  • DLA Piper, "The Digital AI Omnibus: proposed deferral of high-risk AI obligations under the AI Act"
  • Jones Walker, "Yes, August 2 Still Matters: The EU Approved a High-Risk AI Delay, but Most Transparency Obligations Remain"
  • ISO/IEC 42001:2023, Information technology — Artificial intelligence — Management system
  • ISO/IEC 42006:2025, Requirements for bodies providing audit and certification of artificial intelligence management systems
  • ANAB, UKAS, RvA and DAkkS public accreditation registers

Last reviewed: 3 August 2026. This article summarises the position following adoption of the Digital Omnibus on AI and is not legal advice. Classification of AI systems under the AI Act depends on facts specific to each system and role.

The Digital Omnibus moved Annex III high-risk obligations to December 2027, but Article 50 transparency duties applied from 2 August 2026. What to build meanwhile.

GET IN TOUCH

Start your application process
now

Stop struggling with paperwork. Experience a streamlined, digital audit process that moves as fast as you do.