If you bookmarked 2 August 2026 as the date your AI compliance obligations got serious, that date has now passed and, for most of what people were worried about, nothing happened. The deadline that dominated vendor webinars and LinkedIn posts through the first half of the year was moved before it arrived.
This matters for anyone who read guidance published earlier in 2026. Through the spring the deferral existed as a political agreement waiting on formal adoption, so responsible write-ups hedged it heavily and told readers that August 2026 remained the operative legal date. That hedge is no longer correct, and the qualification has quietly reversed.
The Digital Omnibus is now in force, and the high-risk compliance date for Annex III systems is 2 December 2027. This article sets out what moved, what did not, and which parts of the work you should keep doing anyway.
For the broader picture of how the Act classifies agents in the first place, see EU AI Act and AI agents.
What actually changed
The Digital Omnibus package was politically agreed on 7 May 2026 and published in the Official Journal in late July 2026, entering into force on publication. Its effect on the timeline is straightforward:
| Category | Original date | New date |
|---|---|---|
| Annex III stand-alone high-risk systems | 2 August 2026 | 2 December 2027 |
| Annex I AI embedded in regulated products | 2 August 2026 | 2 August 2028 |
| Article 50 transparency obligations | 2 August 2026 | Unchanged |
| Article 5 prohibited practices | 2 February 2025 | Unchanged |
| General-purpose AI provider obligations | 2 August 2025 | Unchanged |
The single most common error in current commentary is treating this as one blanket delay of the whole Act. Two categories that shared a date have been separated and pushed to different years, while three sets of obligations that were already live stayed exactly where they were.
Annex III covers the stand-alone high-risk uses that most SMBs encounter: employment and recruitment, education, creditworthiness evaluation, access to essential services, and law enforcement. If you are screening CVs with an agent, that is the category you sit in, and you now have until December 2027.
Annex I is a different animal. It covers AI built into products that already fall under EU product-safety legislation, so medical devices, machinery, lifts, and similar. Those obligations were pushed further, to August 2028, on the reasoning that they have to be sequenced with existing conformity assessment regimes.
What did not move, and why it matters more
Article 50 is the provision most Swiss SMBs actually touch, and it was deliberately left on the original schedule. It applied from 2 August 2026, which means it is a present obligation as you read this.
The core duty is disclosure. A person interacting with an AI system has to be told they are interacting with an AI, unless that is obvious from the context. For a company running a support chatbot, a booking assistant, or a voice agent that answers the phone, this is the compliance item with a live deadline behind it.
There is one carve-out worth knowing. Providers of systems placed on the market before 2 August 2026 that generate synthetic audio, image, video, or text have until 2 December 2026 to meet the Article 50(2) marking obligations for that content. That is a transitional window for existing deployments rather than a general extension.
The Omnibus also added two prohibited categories covering non-consensual intimate imagery and child sexual abuse material, which take effect on 2 December 2026.
Why the extra time is smaller than it looks
Sixteen months sounds generous until you look at what an Annex III conformity assessment actually requires. The obligations are not a document you write at the end. They are claims about how the system behaved over its operating life, and they have to be evidenced.
A provider of a high-risk system needs a risk management system maintained across the lifecycle, data governance covering the training and validation sets, technical documentation, automatic logging of events, human oversight measures designed into the system, and a demonstrated level of accuracy and robustness. A deployer carries a lighter but real set of duties around monitoring, human review, and record-keeping.
Every one of those rests on data your system has to have been capturing. Decision logs cannot be reconstructed after the fact. Training data provenance cannot be established retroactively for a dataset assembled without records. Human oversight has to be an actual step in the workflow rather than a claim in a document.
This is the practical argument for continuing the engineering work on the original schedule while relaxing the paperwork. A system architected with audit logging, override points, and lineage tracking from the beginning turns compliance into a documentation exercise in 2027. A system built without them turns it into a rebuild.
For most B2B automation, this is less alarming than it sounds. Support triage, invoice processing, and scheduling agents generally fall in the limited-risk or minimal-risk tiers, where the heavy Annex III documentation burden does not apply at all. The question worth answering early is which tier you are actually in, because the answer drives everything else.
What Swiss companies should take from this
The Act applies extraterritorially. It reaches you when your AI system is placed on the EU market or when its output is used in the EU, so establishment in Switzerland is not a shield if you serve EU clients.
Swiss obligations run in parallel rather than as a substitute. The revised Federal Act on Data Protection governs the personal data your agent processes irrespective of its AI Act risk tier, and sector regulators such as FINMA impose their own explainability expectations on regulated firms. A deferral in Brussels changes none of that.
The reasonable posture is to treat December 2027 as the documentation deadline and today as the architecture deadline. Confirm your risk tier, satisfy the Article 50 disclosure duty now because it is already binding, and keep building the logging and oversight hooks that any later assessment will depend on.
If you are weighing that assessment against a build decision, our AI development work starts from the governance constraints rather than bolting them on, and the AI agent governance playbook covers the operational side in more depth.
Sources
Frequently asked questions
Did the EU AI Act high-risk deadline actually move, or was that only a proposal?
It moved, and it is now settled law. The Digital Omnibus package was politically agreed on 7 May 2026 and published in the Official Journal in late July 2026, at which point it entered into force. Obligations for stand-alone Annex III high-risk systems now apply from 2 December 2027 instead of 2 August 2026. Anything you read before August 2026 describing this as provisional or pending formal adoption is out of date.
Which EU AI Act obligations are in force right now?
The prohibited-practices regime under Article 5 has applied since February 2025 and obligations on general-purpose AI providers since August 2025. Article 50 transparency duties applied from 2 August 2026 and were explicitly left out of the deferral. If you run a customer-facing chatbot or voice agent in the EU, the requirement to disclose that a user is dealing with an AI is a present obligation.
Does the delay apply to AI built into physical products?
Those follow a separate and later track. AI embedded in products already covered by EU product-safety law, the Annex I category covering things like medical devices and machinery, moved to 2 August 2028. The two categories were both scheduled for August 2026 under the original Act and have now been split, so a single "high-risk deadline" no longer exists.
Is my Swiss company affected if we do not sell into the EU?
The Act reaches you when your AI system is placed on the EU market or its output is used in the EU, so a Swiss company serving EU clients is in scope regardless of where it is established. Swiss law applies in parallel rather than instead. The revised Federal Act on Data Protection governs the personal data your agent handles whatever the AI Act says about risk tier.
Should we slow down our compliance work now that the deadline has moved?
Slowing the documentation work is reasonable. Slowing the engineering work is usually a mistake. Conformity assessment for an Annex III system rests on evidence that has to be generated while the system runs, including decision logs, human review records, and training data provenance. A system built without those hooks needs re-engineering rather than paperwork when the date arrives.