AI Briefing: July 31, 2026 — The EU AI Act's August 2 Deadline Just Split in Two. The Half That Survived Has No Grace Period.

THE DEADLINE THAT GOT CUT IN HALF

The Digital Omnibus on AI moved fast once it moved. A provisional agreement between the three EU institutions landed May 7, roughly a month after Brussels itself acknowledged that the harmonized standards and conformity-assessment infrastructure the high-risk regime depends on — notified bodies, testing protocols, the technical standards the Act's Annex III rules point to but don't define — weren't going to be ready in time. The European Parliament formally endorsed the package on June 16. The Council of the EU gave it final green light on June 29. It entered into force on the third day after publication in the Official Journal. The result: obligations for standalone high-risk AI systems classified under Annex III — the kind used in hiring, credit scoring, and law enforcement — are deferred to December 2, 2027. Obligations for high-risk AI embedded in regulated products under Annex I are deferred further, to August 2, 2028. Both dates were, until May, this Sunday.

THE HALF WITH NO GRACE PERIOD

Article 50 is the part of the Act that almost every general-purpose AI product touches, and the omnibus left it alone. Any system meant to interact directly with people — chatbots, virtual assistants, automated phone systems — must be built so users are told they're talking to AI, and the disclosure has to be perceivable inside the interaction itself; a line buried in terms and conditions, or a metadata watermark nobody sees, doesn't satisfy the duty. Deepfake content — AI-generated or manipulated audio, image, or video that resembles a real person, place, or event closely enough to pass as authentic — has to be labeled under Article 50(4), and that duty applies even when there was no intent to deceive anyone. Neither rule got an extension. The one concession: systems already on the market before August 2 get until December 2, 2026 to implement the machine-readable marking and detection duty under Article 50(2) for synthetic content specifically. The deepfake-disclosure duty itself has no such runway. Enforcement sits with national market surveillance authorities in each of the 27 member states, and the fines — up to €15 million or 3% of global annual turnover, whichever is higher — apply from Sunday, full stop.

WHAT WE GOT WRONG IN APRIL

This site's April 28 briefing, "The EU AI Act Is Now Operational," told product teams in scope of the high-risk rules they had four months to get ready before those rules became enforceable in August. That was an accurate read of the Act as it stood in April. It stopped being accurate in May, when the Digital Omnibus negotiations that had been running quietly since earlier this year produced a deal nobody outside Brussels compliance circles was watching closely enough. Any team that built its 2026 roadmap around an August 2 conformity-assessment deadline for a hiring tool, a credit-scoring model, or a biometric system was working off a date that no longer applies to them this year. The correction isn't a small one — it's the difference between a compliance sprint due this weekend and one due at the end of 2027.

WHO GOT THE DELAY, AND WHO'S LIVID ABOUT IT

More than 60 civil society organizations, including European Digital Rights, pushed EU lawmakers to reject the omnibus package before it passed, arguing it weakened enforcement and legal certainty for what they called negligible benefit to the companies asking for it. A specific target of that opposition was a proposed deletion of Article 49(2), which would let providers skip registering a system in the EU's public AI database simply by asserting it isn't high-risk — a self-certification civil society groups say removes the one check that made the high-risk classification meaningful in the first place. Analysts at Corporate Europe Observatory and the Jacques Delors Centre both framed the broader package as industry-shaped deregulation landing before the rules it waters down had even taken effect, and political groups spanning the European Parliament's left-to-center bloc read the Commission's push as, in part, a concession to pressure from the Trump administration and Big Tech lobbying over the Act's compliance burden on U.S. firms operating in the EU. The counter-argument from industry and, implicitly, from the Commission itself: notified bodies and harmonized standards genuinely weren't ready, and enforcing a high-risk regime without the infrastructure to assess compliance against would have been theater, not protection.

WHAT THIS MEANS FOR TEAMS BUILDING ON AI

Don't let "the EU delayed the AI Act" headlines set your team's calendar — that framing is only half true, and the half that's false is the one with an enforcement date this weekend. If your product talks to EU users directly — a support chatbot, a voice agent, an AI feature with a conversational interface — check today whether your AI disclosure is visible in the interaction itself, not a line in your terms of service; that's the exact gap Article 50 was written to close, and there's no extension left to close it before the fines start applying. If you ship image, audio, or video generation or editing that could plausibly resemble a real person, the deepfake-labeling duty applies now, regardless of whether deceiving anyone was ever the intent — label the output or don't ship it into the EU market. If you were mid-build on a high-risk conformity assessment for a hiring, credit, or biometric system, you likely have real breathing room now — until December 2027 or August 2028, depending on which annex applies — but treat that as time to build the assessment properly, not a reason to shelve it; the standards infrastructure the delay is buying time for is still being built, and a political fight already broke out over whether this delay itself should have happened at all.