If you marked August 2026 on the calendar as the EU AI Act “high-risk cliff,” the Digital Omnibus (European Council endorsement, June 2026) changed the picture. Annex III high-risk duties move to 2 December 2027. Annex I embedded high-risk moves to 2 August 2028. Sandboxes extend to 2 August 2027.
That is real relief for credit, HR screening, and safety-critical embedded AI. It is not a holiday for a typical operating company deploying customer-facing agents and generative assistants.
This article is the operator’s calendar — precise dates per guardrail 2 — not vendor urgency. Deeper narrative: The Omnibus moved your deadline.
Calendar that still matters (2026–2028)
| Obligation | Date | Who should care |
|---|---|---|
| Article 50 transparency (AI-generated content, chatbots, synthetic media) | 2 Aug 2026 | Organisations deploying generative AI to customers or citizens |
| Watermarking / detection grace ends | 2 Dec 2026 | Teams relying on interim technical measures |
| Annex III high-risk duties | 2 Dec 2027 | Credit, employment, essential services, law enforcement, migration, justice, democratic processes |
| Annex I embedded high-risk | 2 Aug 2028 | Manufacturers / integrators of regulated product safety components |
Article 50 catches teams who think “we are not high-risk.” Your support bot, marketing assistant, or guest messaging agent can trigger transparency duties without Annex III classification.
What a normal operator should do in 2026
Proportionate middle path — not panic buying, not strategic pause:
1. Inventory what actually runs
Shadow spreadsheets of “who bought which copilot” are not governance. List:
- Agent or assistant name and owner
- Purpose and data categories touched
- Models and regions
- Who approves external actions
- Whether customers know they interact with AI (Article 50)
2. Separate Article 50 work from Annex III planning
| Track | 2026 focus | 2027+ focus |
|---|---|---|
| Article 50 / transparency | Notices, disclosure patterns, logging for customer-facing generation | Maintain as features evolve |
| Annex III high-risk | Only if you are genuinely in scope — roadmap to 2027 | Conformity, risk management, documentation |
| Internal ops agents | Access control, approval queues, retention | Same — do not over-build for deferred annexes you do not match |
3. Evidence security questionnaires already ask for
Enterprise buyers and public frameworks want:
- What models? What data can agents reach?
- Who approved deployment? Can you prove it?
- Human oversight on consequential actions?
Those questions arrive whether or not Annex III applies in 2026.
4. Ignore two failure modes
Panic buying: six-figure “AI Act platform” producing PDFs nobody enforces.
Strategic pause: “we will revisit in 2027” while shadow agents multiply and contracts renew on opaque SaaS copilots.
Agents specifically — practical controls
For governed agents (our day job):
- Minimum-privilege tools — MCP/APIs, not broad admin passwords
- Human approval before guest/customer-facing sends
- Per-call logs — model, tool, timestamp, approver
- Regional deployment agreed for personal data
- Pause control that stops the agent without ripping integrations
Maps to AI governance and agent automation deliverables — not theoretical policy.
What most operators can deprioritise for now
- Full Annex III conformity systems if you are not in listed high-risk use cases
- Embedded product safety (Annex I) if you are not a manufacturer integrator
- Rewriting entire IT for “AI Act readiness” without article-level scoping
Do not deprioritise: customer transparency where Article 50 applies, personal data under GDPR, or contract clauses customers already send.
Why accuracy wins citations
Most English content still sells the old August high-risk cliff. Being precise — Article 50 live August 2026, Annex III deferred to December 2027 — is a low-cost trust signal with legal, procurement, and answer engines.
We would rather lose a fear-based sale than mis-date an obligation.
Getting help without a fear budget
The ladder below is background from when this note was written. Current public work is a Web & eCommerce quote or US → EMEA.
| Step | Cost | Outcome |
|---|---|---|
| Efficiency Audit | Free | Honest scope check |
| Discovery Workshop | €1,950 | Written plan: which articles touch your agents, what evidence to build first |
| Pilot with governance | from €4,800 | Production workflow with logs and approval gates |
If your board still has one date on a slide, ask for a package quote or read The Omnibus moved your deadline. Current public work is Web & eCommerce and US → EMEA.
Frequently asked questions
Are we high-risk under the EU AI Act?
Most hospitality, mid-market services, and internal ops agents are not Annex III high-risk by default. Credit scoring, employment screening, essential services, and similar Annex III categories face deferred high-risk duties from 2 Dec 2027. Ask which annex and article apply — not 'AI Act yes/no'.
What still happens in August 2026?
Article 50 transparency duties for AI-generated content and certain customer-facing systems — including many support bots and generative assistants — with related watermarking grace ending 2 Dec 2026. That date did not move with Annex III.
What evidence should we keep?
Agent inventory (purpose, data, approvers), logs of model/tool calls, human approval on external actions, DPIA where personal data warrants, and transparency notices where Article 50 applies. Policies nobody uses do not count.
Should we buy a six-figure compliance platform now?
Only if it maps to obligations you actually owe in 2026–27. Many teams need proportionate controls and audit artefacts first — not shelfware. A Discovery Workshop can separate Article 50 work from deferred Annex III planning.
