EU AI

The EU AI Act Just Moved Its Own Goalposts — Here's What Actually Changes for Your Compliance Timeline

Corvus AI Regulatory Update — July 2026

Corvus AI Regulatory Update — July 2026

If you've been planning your AI compliance roadmap around an August 2, 2026 deadline, pause before you finalize anything. On July 27, 2026, a substantial amendment to the EU AI Act entered into force, and it changes the calendar for a large share of the obligations that businesses have spent the past year preparing for — while leaving others completely untouched.

This is not a rumor circulating on LinkedIn. It is Regulation (EU) 2026/1744, part of the so-called "Digital Omnibus" simplification package, published in the Official Journal on July 24, 2026 and now legally binding across all EU member states, including the Netherlands.

What Actually Happened

The European Commission proposed the Digital Omnibus in late 2025 with the stated goal of reducing administrative burden and improving alignment between the AI Act and other digital legislation (GDPR, the Data Act, and others). After months of negotiation, the European Parliament approved the simplification package on June 16, 2026, the Council of the EU gave its final sign-off on June 29, 2026, and the text was published and entered into force on July 24–27, 2026.

The result is a revised — and in some places, softened — implementation timeline.

The Revised Timeline

Already in force and unchanged:

Since February 2, 2025 — prohibited AI practices (manipulative AI, untargeted facial-recognition scraping, social scoring, certain emotion-recognition uses) and the AI literacy obligation under Article 4.

Since August 2, 2025 — governance rules, obligations for general-purpose AI (GPAI) model providers, and penalty provisions.

Confirmed for August 2, 2026 — no change:

Article 50 transparency obligations remain on schedule. Organizations deploying chatbots, generating synthetic content, or producing deepfakes must disclose AI involvement to users from this date, regardless of the Omnibus amendments.

Pushed back under the new regulation:

High-risk AI systems under Annex III (recruitment, credit scoring, law enforcement, education, access to essential services, and similar use cases) — postponed from August 2, 2026 to December 2, 2027.

High-risk AI systems embedded in regulated products under Annex I (medical devices, machinery, toys, and other CE-marked product categories) — postponed from August 2, 2027 to August 2, 2028.

Softened rather than delayed:

The Article 4 AI literacy obligation, while formally still in force since February 2025, has been rephrased from a hard obligation into an encouraged practice for many use cases — reducing the immediate documentation burden, though not eliminating the underlying expectation.

A proposal to scrap registration requirements for certain narrowly procedural AI systems was rejected; the registration duty stays in place.

Fundamental rights authorities can no longer request documentation directly from deployers of high-risk systems — such requests must now be routed through the national market surveillance authority.

Why This Doesn't Mean "Slow Down"

It's tempting to read a two-year delay on high-risk obligations as a green light to deprioritize compliance work. That would be a mistake, for three reasons.

First, transparency obligations are unaffected and land in one week. Any organization using generative AI in customer-facing products, chatbots, or content pipelines needs disclosure mechanisms operational by August 2, 2026 — not aspirational.

Second, the postponement changes when full compliance becomes enforceable, not whether your organization needs an AI inventory, a risk classification exercise, or documented governance. Regulators and courts will still ask, in 2027 and 2028, why a company that had two additional years of runway wasn't ready.

Third, national enforcement structures are catching up in parallel, and they will not wait for Brussels' next delay to start asking questions.

The Netherlands Angle

The Netherlands is finalizing its own implementation law, the Uitvoeringswet AI-verordening, which designates which national authorities supervise which parts of the AI Act. The bill was open for public consultation until June 1, 2026 and must still pass through the Council of State (Raad van State) and both chambers of parliament before it takes effect — a process that is very unlikely to conclude before the AI Act's own deadlines arrive.

That delay is not a loophole. The AI Act is an EU regulation, meaning it has direct effect in every member state whether or not national implementing legislation is in place. Dutch companies remain fully bound by the August 2, 2026 transparency deadline and the revised 2027/2028 high-risk deadlines regardless of where the domestic bill stands.

Under the current Dutch proposal, oversight will be split across ten sectoral market surveillance authorities, with the Data Protection Authority (Autoriteit Persoonsgegevens) and the Digital Infrastructure Inspectorate (RDI) playing a coordinating role, and the Netherlands Institute for Human Rights (College voor de Rechten van de Mens) designated as the fundamental rights authority for AI matters.

What This Means for You

If your organization operates in the EU — and especially if you have any footprint in the Netherlands — the practical priorities right now are:

Confirm which of your AI systems trigger Article 50 transparency duties and make sure disclosure is live before August 2, 2026.

Keep your AI system inventory and risk classification current — the extra runway on high-risk obligations should go toward better implementation, not toward pausing the work.

Track the Dutch Uitvoeringswet as it moves through the Council of State and parliament, since it will determine which regulator knocks on your door first.

Re-verify vendor contracts and GPAI documentation, since governance obligations from August 2025 are already enforceable today.

Regulatory timelines under the AI Act have proven that they can move — sometimes later, sometimes with tighter enforcement in the areas that stay on schedule. Corvus AI helps organizations cut through this shifting timeline: mapping AI systems against current obligations, building the documentation and governance structures regulators will expect, and keeping compliance roadmaps aligned as EU and Dutch rules continue to evolve. If you'd like a clear picture of where your organization stands against the revised timeline, get in touch with our team.

Sources: Official Journal of the European Union (Regulation (EU) 2026/1744); European Parliament press release, June 2026; Rijksoverheid.nl; Autoriteit Persoonsgegevens; College voor de Rechten van de Mens.

logo