On 24 July 2026 Regulation (EU) 2026/1744, the Digital Omnibus, was published, and it entered into force on the 27th. Among other things it did something most boards have not yet processed: it pushed back the EU AI Act's high-risk obligations.

If your legal team told you in January that August 2026 was the deadline, they were right at the time. They are not any more.

What moved and what did not

This is the table that matters, and it is worth getting exactly right, because half the internet is still publishing the old calendar.

ObligationDate
Article 5 prohibitionsIn force since 2 February 2025
General-purpose AI models (GPAI)In force since 2 August 2025
Transparency, Article 502 August 2026
Marking synthetic content, Art. 50(2)2 December 2026 (grace period)
Standalone high-risk, Annex III2 December 2027 (was August 2026)
Embedded high-risk, Annex I2 August 2028 (was August 2027)
Regulatory sandboxes2 August 2027

Two readings of the same table.

The comfortable one: we have fifteen more months.

The correct one: transparency binds you in August 2026, and that catches far more companies than high-risk ever did.

Article 50 does land in August, and it hits almost everyone

Annex III high-risk is a specific list: recruitment, credit scoring, biometrics, education, critical infrastructure, law enforcement. If you are not on it, it was never your problem.

Article 50 transparency is a different animal. It requires telling people they are interacting with an AI system, and marking synthetic content. If you run a customer service chatbot, if you generate creative with AI, if an agent answers email in your name, this is yours. Most companies that thought they were outside the AI Act are inside it through this door, and this is the one that did not move.

Why a postponement is the worst moment to drop the subject

Three reasons, and all three show up in the field.

One: the work did not get smaller, only the date moved. Inventorying the AI systems already running inside your company, classifying them by risk, documenting what data trained them, deciding who supervises what, and standing up logs of automated decisions is quarters of work, not weeks. December 2027 sounds far away until you divide it by everything that has to be ready before it.

Two: you do not know what you have. Almost no mid-sized company can say today how many AI systems are running inside it, who signed for them, or on what data. Shadow AI does not wait for legislative calendars. The inventory is the first deliverable of any governance framework and the only one you can start today without depending on what Brussels approves next.

Three: you get governed before you get legislated. The enterprise client asking you for a no-training clause is not waiting for Annex III. Neither is the fund running due diligence. Neither is your insurer. Commercial obligation always arrives ahead of legal obligation, and that one is already here.

And in Mexico

Mexico closed the first half of 2026 without a general artificial intelligence law. The initiative is still in Senate commissions, tangled in an Article 73 constitutional reform, with a year-end target and odds analysts rate medium to low.

That does not mean there are no rules. Regulation is advancing sector by sector, dozens of initiatives are live, and the privacy notice already has to declare when data is used for automated decisions and profiling. Anyone operating in both Mexico and Europe does not have one calendar. They have two, and the two do not line up.

This is why in the AI Leadership Program the regulatory module is rebuilt for every cohort and written for each participant's market. A Mexican CEO exporting to the EU, one operating in the Gulf, and one selling only in Mexico do not have the same problem, and handing all three the same PDF would be useless to all three. The structure does not change: the international reference frame (EU AI Act, NIST AI RMF, ISO/IEC 42001) plus a regulatory report specific to your market and your cross-border compliance matrix.

What I would do this quarter

Without waiting for anyone, in this order:

  1. Inventory. Which AI systems run in the company today, contracted and uncontracted. Include what your team uses without permission.
  2. Classification. Which fall under Annex III, which only under transparency, which under neither. Most land in the second group and do not know it.
  3. Transparency, before August. Where you have to disclose that AI is involved, and where you have to mark generated content.
  4. Human oversight and logs. Who reviews what, and where the trace lives. High-risk systems will require retaining logs; building that afterwards costs far more.
  5. Vendors. No-training and data residency clauses in the contracts you are signing now, not the ones you renew in 2027.

None of those five depends on a date Brussels can move again.


Sources. Regulation (EU) 2026/1744 (Digital Omnibus), published 24 July 2026, in force 27 July 2026. Prior political agreement between Council and Parliament, 7 May 2026. Mexican legislative status: Ley Nacional para Regular el Uso de la Inteligencia Artificial, introduced 11 February 2026, in commission. Verified 25 September 2026. Note: several public AI Act trackers were still publishing the pre-Omnibus timeline on that date, so check against the Regulation itself.