EU AI Act Delayed to December 2027: What Still Applies on 2 August

The EU AI Act high-risk deadline moved to December 2027. Transparency (Art. 50) and AI literacy (Art. 4) did not. What to arrange before 2 August 2026.

Gepubliceerd door NordX Consulting — AI bureau voor enterprise bedrijven in Nederland.

The EU AI Act's high-risk obligations were due to apply from 2 August 2026. That date has moved. But not everything moved, and the difference decides whether you are compliant as of 2 August 2026.

What actually changed

The European Parliament approved amendments to the AI Act on 16 June 2026 as part of the Digital Omnibus package. The essentials:

CategoryOld dateNew date
High-risk systems (Annex III, standalone)2 August 20262 December 2027
High-risk AI in regulated products (Annex I)2 August 20262 August 2028
Transparency obligations (Article 50)unchangedunchanged
AI literacy duty (Article 4)unchangedunchanged

Annex III covers standalone high-risk uses: AI in recruitment, credit scoring, medical diagnostics, education and justice. For that category you have sixteen extra months.

The two things that were not postponed

This is where most boardrooms get it wrong. The headline was "the AI Act has been delayed." That is partly true, and the part that is not true costs money.

Article 50: transparency. Do you run a chatbot that talks to customers? Do you generate text, images or audio with AI? Then the user must know they are dealing with an AI system. This obligation has not moved. For most Dutch businesses this, not the high-risk regime, is the provision that actually applies.

Article 4: AI literacy. Organisations must ensure that staff working with AI systems have sufficient understanding of them. Also unchanged. This is not a certification requirement, but it is not optional either: you need to be able to show you did something.

Why you should not bank the delay yet

The postponement has been politically agreed, but becomes legally binding only on publication in the EU Official Journal. That publication is expected before 2 August 2026. Expected, not guaranteed.

If you decide today to stop your high-risk preparation, you are betting on a publication date you do not control. That is a manageable risk if you take it deliberately and write it down. It is an unmanageable one if nobody recorded the decision.

What this means for Dutch businesses

Statistics Netherlands (CBS) reports that in 2025, 29.8 percent of Dutch SMEs (10 to 249 employees) used one or more AI technologies. Among large companies with 250 or more employees, it was 66.2 percent. Of the businesses using AI, 35 percent do so for marketing or sales and 32 percent for business administration.

Those are precisely the applications that fall under Article 50 rather than Annex III. In other words: most Dutch AI usage touches the rules that were not postponed.

What to do now

1. Build an AI register. One overview listing, per application: its purpose, the vendor, what data goes in, who is accountable, and the date of the last review. This is the foundation every other compliance conversation rests on, and it takes an afternoon.

2. Classify each application. Annex III, Article 50, or neither? Most marketing and administration uses fall under Article 50. Know which of your systems those are.

3. Handle transparency. Every chatbot, every AI-generated message to customers, every automated reply: make it clear AI is involved. This is usually a copy change, not a rebuild.

4. Record your AI literacy effort. A short internal session plus a noted attendee list is more than most organisations currently have.

5. Document the decision to defer. If you are pausing high-risk work because of the Omnibus agreement, write down why, on what basis, and when you will revisit it.

The penalties

Non-compliance with high-risk requirements can reach 15 million euro or 3 percent of global annual turnover, whichever is higher. That is the ceiling rather than the standard penalty, and enforcement will target the largest risks first. But it indicates the order of magnitude the legislator is working with.

In short

The high-risk deadline has moved to December 2027. Your transparency and literacy obligations have not. If you use AI for customer communication, content generation or internal administration, more probably applies to you on 2 August 2026 than the headlines suggest.

The good news: those obligations are considerably lighter than the high-risk regime. A register, a classification, and a few adjusted lines of copy gets most organisations most of the way there.

For the full step-by-step plan, see our AI Act compliance guide for Dutch businesses.

Sources

Frequently asked questions

Has the EU AI Act been postponed entirely?

No. Only high-risk obligations for Annex III systems moved to 2 December 2027, and Annex I to 2 August 2028. The transparency obligation (Article 50) and the AI literacy duty (Article 4) are unchanged.

Does the transparency obligation apply to a simple chatbot?

Yes. Article 50 requires users to know when they are interacting with an AI system or seeing AI-generated content. That includes basic customer service chatbots.

Is the delay legally final?

Not yet. It was politically agreed and approved by the European Parliament on 16 June 2026, but becomes binding only on publication in the EU Official Journal, expected before 2 August 2026.

How large are the AI Act penalties?

Non-compliance with high-risk requirements can reach 15 million euro or 3 percent of global annual turnover, whichever is higher.

Related articles

Meer weten? Bekijk onze andere artikelen op het NordX blog of neem contact op via nordx.ai.