The EU delayed the part with no standards
Three AI Act obligations take effect today and the widely reported headline says the opposite. What was deferred, what was not, and why the split falls exactly where it does.
TL;DR. Today, 2 August 2026, three EU AI Act mechanisms take effect: Article 50 transparency obligations, general-purpose AI penalty powers, and market surveillance authority. The headline most people read was that the EU delayed the AI Act. That is half accurate. The Digital Omnibus, given final European Parliament approval on 16 June 2026 by 423 votes to 57 with 174 abstentions, deferred Annex III high-risk obligations from today to 2 December 2027 and Annex I product-embedded systems to 2 August 2028. Article 50 was not deferred, except the watermarking provision in Article 50(2), which moves to 2 December 2026 and does not apply to systems already on the market today. And the split is not arbitrary. What was deferred is what required harmonised technical standards that do not exist; CEN-CENELEC pushed delivery toward the end of 2026, leaving an obligation with no route to demonstrating compliance.
---
Status: established, and the primary instrument is public. Sources are the AI Act itself, the Digital Omnibus as agreed, and law firm analyses of the final text. This corpus does not take positions on contested political questions, and whether this regulation is well designed is one. What follows describes what applies, to whom, and from when.
---
What takes effect today
Article 50 transparency obligations. These require, among other things, that people are informed when they are interacting with an AI system, and that certain generated or manipulated content is disclosed as such.
General-purpose AI penalty powers. The obligations themselves have applied since 2 August 2025: technical documentation, copyright compliance policies, training data summaries, downstream provider disclosures, and systemic risk assessment for models above 10^25 FLOPs. What arrives today is the ability to penalise non-compliance with them.
And market surveillance authority. Enforcement of Article 50 sits with national market surveillance authorities rather than centrally with the EU AI Office, and that layer activates today.
None of the three was postponed.
What was deferred, and by how much
The Digital Omnibus was proposed by the European Commission on 19 November 2025. A first trilogue collapsed on 28 April 2026, provisional political agreement was reached on 7 May, the European Parliament approved the amendments on 16 June by 423 to 57 with 174 abstentions, and the Council gave final approval on 29 June.
Annex III standalone high-risk systems move from today to 2 December 2027. These cover recruitment, credit scoring, law enforcement, education and border control tools, among others. A sixteen-month deferral.
Annex I systems, meaning AI embedded in regulated products such as medical devices, machinery and vehicles, move to 2 August 2028.
Article 50(2), the watermarking provision, moves to 2 December 2026, and does not apply to systems already on the market as of today.
Regulatory sandboxes, which member states were required to establish, move to August 2027, a year later than the Act provided.
The agreed text replaced a conditional trigger mechanism, which would have tied application to standards readiness, with fixed dates. That is a meaningful change: the obligations now arrive on a calendar rather than on a condition.
Why the split falls where it does
This is the part worth understanding, because the pattern is not random.
What was deferred is what required harmonised technical standards to be operable.
Harmonised standards are the technical specifications that let a provider demonstrate conformity without case-by-case regulatory interpretation. Without them, a high-risk obligation exists as a legal duty with no defined route to satisfying it.
Those standards were not ready. Throughout late 2025 and into 2026 the Commission, standards bodies and industry flagged that the specifications needed to operationalise Annex III compliance would not arrive in time, and CEN-CENELEC and other European standardisation organisations pushed their delivery timelines toward the end of 2026.
So providers faced a regulatory obligation with no finalised technical roadmap for meeting it.
What was not deferred is what needs no standard. Telling a person they are talking to a machine requires no conformity assessment. Publishing a training data summary requires no harmonised specification. Penalising a party that did neither requires only an authority.
The division is between obligations that need an apparatus and obligations that need a decision. The first slipped and the second did not.
Which is the corpus's own finding arriving as legislation
Territory 8 closed on the observation that the reliability of a figure tracked whether anyone was obliged to publish it. Securities filings, regulatory crash reporting and statutory environmental returns produced numbers that survive scrutiny; everywhere else the best figure came from an interested party.
The AI Act is the largest test of that finding to date, and today is when part of it begins.
The general-purpose AI obligations already in force are, in principle, exactly the kind of thing this corpus has repeatedly said was missing. Training data summaries address a question the model collapse article found unanswerable. Technical documentation and systemic risk assessment address the composition gap that Territory 8 identified as the most valuable missing disclosure in AI economics.
Whether the documents produced under those obligations are useful is an open empirical question, and it is now answerable rather than hypothetical. They exist, they will accumulate, and they can be read.
The honest expectation, based on what this corpus has found elsewhere, is mixed. Mandated disclosure produces comparable numbers where definitions are fixed and produces compliance artefacts where they are not. A training data summary with no specified format is a document whose usefulness depends entirely on who wrote it, which is the position water and energy figures occupied before the EU's data centre reporting regime fixed the indicators.
The grandfathering clause and what it rewards
Systems placed on the market before the applicable dates avoid high-risk requirements unless substantially modified afterwards.
That rewards shipping before a deadline, which is an ordinary feature of transitional provisions and has an ordinary consequence: a rush to place systems on the market before December 2027, followed by conservatism about modifying them.
The reset condition is substantial modification, and what counts as substantial will be decided by national authorities case by case until guidance or case law settles it. A provider improving a deployed system therefore faces a compliance question that a provider leaving it alone does not.
No position is taken here on whether that is a good design. The observation is narrower: the clause creates an incentive to freeze systems, and freezing systems is not usually what a safety regime is trying to achieve.
What "the EU delayed the AI Act" cost
The reporting problem here is precise and it is the corpus's own subject.
The deferral is real, large and correctly reported. Sixteen months on Annex III is a substantial change, it was contested, and the vote was decisive.
What did not travel is the exception. Article 50, GPAI penalties and market surveillance all land today, and one legal analysis puts it plainly: 2 August 2026 remains a live compliance date.
That is selective transmission in its most consequential documented form in this corpus, because the material left behind is operational. A reader who took away "delayed" and stopped has a compliance calendar that is wrong today, and the qualifying information was published in the same client alerts, in the same week, by the same firms.
The direction is the usual one. "The EU delayed the AI Act" is surprising, quotable, and supports a stronger claim. "Some obligations moved sixteen months and three others start on schedule" is accurate and fits nowhere.
The full timetable, as it now stands
Setting the dates out together is more useful than any narrative summary, because the confusion is entirely about which row applies.
| Date | What applies | Status |
|---|---|---|
| 2 Feb 2025 | Prohibited practices, AI literacy | In force |
| 2 Aug 2025 | General-purpose AI obligations | In force |
| 2 Aug 2026 | Article 50 transparency, GPAI penalties, market surveillance | Today |
| 2 Dec 2026 | Article 50(2) watermarking | Deferred to |
| Aug 2027 | Member state regulatory sandboxes | Deferred to |
| 2 Dec 2027 | Annex III high-risk systems | Deferred to |
| 2 Aug 2028 | Annex I product-embedded systems | Deferred to |
Two things are visible in the table that are hard to see in prose.
The regime has been arriving continuously since February 2025 and will continue until 2028. There is no single switch-on moment, which is why any headline describing one is wrong in both directions: nothing started today that had not started, and nothing stopped either.
And the deferrals are staggered rather than uniform. Watermarking moved four months, sandboxes a year, Annex III sixteen months, Annex I twenty-four. Each moved by roughly the amount its dependent infrastructure was behind, which supports the standards reading and is the strongest available evidence for it.
What a deployer outside the EU should know
Article 50 applies on the basis of where the output lands rather than where the provider sits.
A system whose output reaches people in the EU falls within scope regardless of where it was built or hosted, which is the same extraterritorial structure as the GDPR and produced the same initial confusion.
Three practical consequences, none of which requires legal advice to understand.
A chatbot serving EU users needs to disclose that it is a chatbot. The Act does not specify a form of words, which means the obligation is satisfiable and its adequacy is untested.
Generated or manipulated content in certain categories needs to be marked as such, with the machine-readable watermarking requirement arriving in December rather than today, and exempting anything already on the market.
And enforcement is national. A provider dealing with EU users is dealing with the market surveillance authority of each relevant member state rather than with one central body, which is where divergence in interpretation will appear first and where the practical burden differs from the legal text.
This corpus is not a legal adviser and this is not advice. It is a description of the structure, offered because the structure is public and most coverage of it has been about the deferral.
Three things this establishes
Standards readiness, not political will, set the timetable. The obligations that slipped are the ones requiring harmonised technical specifications that standards bodies did not deliver. The obligations that survived need no apparatus, which means the split is a statement about infrastructure rather than about appetite for regulation.
A deferral is not a dismantling and the two read identically in a headline. The risk-based architecture, the governance structure and the core obligations are intact. What changed is when parts of it bind, and a fixed date replaced a conditional trigger, which arguably strengthens the eventual obligation by removing a dependency on standards that could slip again.
And the disclosure thesis is now testable. This corpus has repeatedly found that obligation predicts evidence quality. The GPAI obligations have been in force for a year and gain teeth today, so the documents they produce can be examined rather than anticipated, and the finding can be checked against a regime nobody designed to test it.
What it does not establish
That compliance will follow. An obligation with enforcement powers is not the same as a compliant market, and the first year of enforcement will be informative rather than decisive.
That the deferral was avoidable. A duty with no route to demonstrating conformity is a genuine problem, and the standards timeline was not within the legislators' control.
That the documents will be useful. Mandated disclosure produces comparable data where definitions are fixed. Several of these obligations do not fix a format, and this corpus has found that outcome before.
And nothing about whether the Act is well designed. That is a contested political question and this corpus does not take positions on those.
The threshold that penalties now attach to
One provision deserves separate attention because today changes its character.
Systemic risk obligations apply to general-purpose models above 10^25 floating point operations of training compute. That threshold has been in the Act since adoption and has been in force since August 2025. What arrives today is the power to penalise a provider that ignored it.
The threshold writes a technical proxy into binding law, and the proxy is contested on grounds this corpus has documented elsewhere.
Training compute is a measure of what was spent, not of what resulted. Test-time compute and distillation both decouple capability from training FLOP: a model can be made more capable after training without additional training compute, and a smaller model can inherit capability from a larger one. A capable model below the threshold and an unremarkable one above it are both constructible, and the second is easier.
This is proxy decay written into legislation. Training compute was a workable indicator of frontier capability when capability came almost entirely from scale. The relationship has weakened since the threshold was set, and unlike a metric in a research paper, this one cannot be revised by whoever notices.
Two qualifications, both real. A bright-line numeric threshold is administrable in a way that a capability assessment is not, and the alternative, case-by-case evaluation of whether a model is systemically risky, is slower, more contestable and more expensive. A proxy that is auditable may beat a construct that is correct and unmeasurable.
And the Act provides for the threshold to be updated. Whether that happens at the pace capability changes is a different question, and legislative amendment cycles are not fast.
The narrow observation is that today converts an imprecise line into an enforceable one, and the imprecision does not improve by being enforced.
What is unresolved
How national market surveillance authorities interpret Article 50. Enforcement is distributed across member states, which is where divergence usually appears first.
What counts as substantial modification. The grandfathering reset condition is undefined in practice and determines how much of the installed base ever falls in scope.
Whether harmonised standards arrive by the new dates. They were pushed toward the end of 2026 once, and a fixed application date now applies whether or not they land.
And whether the training data summaries are legible. The single most valuable disclosure in this regime, judged against what this corpus has found missing, is also the one whose format is least specified.
Why this corpus is writing about a live legal instrument
A note on method, because articles about law age differently from articles about measurements.
Most of this corpus examines findings that stay put. A study published in 2021 says what it said. A filing from Q1 reports what it reported. An article checking those numbers is correct indefinitely, and its risk is being wrong now rather than becoming wrong later.
Legislation is the opposite. Every date in this article was different eight months ago, and two of them were different in April. A reader arriving in 2027 needs to know that this was written on the day the transparency obligations landed, before any enforcement had occurred, with the Omnibus adopted and the standards outstanding.
Which is why the dated timetable is the centre of the piece rather than the argument. The argument, that the split fell along standards readiness, may be revised by better information about the negotiation. The table is a record of what applied on 2 August 2026, and that stays true even if every subsequent date moves again.
The corpus has one habit that helps here and one that does not. It records changes with reasoning on a public page, so a revision is visible rather than silent. And it treats concept nodes as durable, which is correct for a mechanism and wrong for a statute: the EU AI Act node was accurate when written and operationally stale within a year, without anybody making an error.
That is a maintenance category rather than a mistake, and naming it is the useful part. A node describing a live instrument needs a review date. A node describing scope boundary does not.
The counter-argument
Calling the split a standards problem may be too tidy. The deferral was politically contested, a first trilogue collapsed, and industry lobbying for delay was substantial and public. Attributing the outcome entirely to standards readiness credits the process with more coherence than a collapsed negotiation and a 423 to 57 vote with 174 abstentions suggests.
The transparency obligations are the easy part and their arrival proves little. Telling users they are talking to a machine is a low bar that most major providers already meet voluntarily, and treating today as consequential because the undemanding obligations survived understates how much of the Act's substance moved.
Fixed dates may be worse than the conditional trigger. Tying application to standards readiness would have guaranteed a route to compliance existed. A fixed date without standards recreates in December 2027 precisely the problem that caused the deferral, and the agreed text removed the mechanism that would have prevented it.
And the corpus's enthusiasm for disclosure deserves examining here. This article treats mandated disclosure as the promising development because that is what previous territories concluded. A regime that produces compliance artefacts nobody reads is a cost with no benefit, and the evidence that disclosure improves outcomes rather than merely producing documents remains thin in this corpus's own findings.
The short version
Three AI Act mechanisms take effect today, 2 August 2026: Article 50 transparency obligations, general-purpose AI penalty powers for obligations in force since August 2025, and national market surveillance authority.
The Digital Omnibus, approved by the European Parliament on 16 June 2026 by 423 to 57 with 174 abstentions, deferred Annex III high-risk obligations to 2 December 2027, covering recruitment, credit scoring, law enforcement, education and border control, and Annex I product-embedded systems to 2 August 2028. Article 50(2) watermarking moves to 2 December 2026 and exempts systems already on the market today.
The split is not arbitrary. What slipped required harmonised technical standards that let providers demonstrate conformity, and CEN-CENELEC pushed delivery toward the end of 2026, leaving a duty with no route to satisfying it. What survived needs no apparatus: telling someone they are talking to a machine requires no conformity assessment.
And "the EU delayed the AI Act" is the year's clearest case of a headline losing its exception. The deferral is real and correctly reported. The three obligations landing today were in the same client alerts, in the same week, and a reader who stopped at "delayed" has a compliance calendar that is wrong as of this morning.
Which makes today a test of something this corpus keeps concluding. Evidence quality tracks obligation. The general-purpose AI obligations have run for a year and gain enforcement today, so whether mandated training data summaries and technical documentation produce anything a reader can use is now an answerable question rather than a preference.
Common questions
What takes effect on 2 August 2026? Three things. Article 50 transparency obligations, which require among other duties that people are informed when interacting with an AI system and that certain generated or manipulated content is disclosed. General-purpose AI penalty powers, applying to obligations that have been in force since 2 August 2025 including technical documentation, copyright compliance policies, training data summaries, downstream provider disclosures and systemic risk assessment for models above 10^25 FLOPs. And national market surveillance authority, which is where enforcement of Article 50 sits rather than centrally with the EU AI Office.
Did the EU delay the AI Act or not? Both, and the imprecision matters. The Digital Omnibus, approved by the European Parliament on 16 June 2026 by 423 votes to 57 with 174 abstentions and given final Council approval on 29 June, deferred Annex III high-risk obligations from 2 August 2026 to 2 December 2027, and Annex I product-embedded systems to 2 August 2028. Article 50 transparency obligations, GPAI penalty powers and market surveillance were not deferred. The watermarking provision in Article 50(2) moved to 2 December 2026 and does not apply to systems already on the market as of 2 August 2026.
Why were some obligations deferred and not others? Because of what each requires to be operable. The deferred obligations depend on harmonised technical standards, the specifications that let a provider demonstrate conformity without case-by-case regulatory interpretation. Those standards were not ready: CEN-CENELEC and other European standardisation organisations pushed their delivery timelines toward the end of 2026, leaving providers with a legal duty and no finalised route to satisfying it. The obligations that survived need no apparatus. Informing a user they are interacting with a machine requires no conformity assessment.
What is the grandfathering clause? Systems placed on the market before the applicable dates avoid high-risk requirements unless substantially modified afterwards. That rewards shipping before a deadline and creates an incentive to leave deployed systems unchanged, since substantial modification resets the position. What counts as substantial will be determined by national authorities case by case until guidance or case law settles it.
What changed about the trigger mechanism? The Commission's original proposal included a conditional trigger tying application to standards readiness. The agreed text replaced that with fixed dates. This cuts both ways: a fixed date removes a dependency that could slip again, and it also removes the guarantee that a route to compliance will exist when the obligation binds.
Why does this matter for evidence about AI? Because the general-purpose AI obligations require the kind of disclosure that has been missing. Training data summaries bear directly on a question nobody could answer about how much training data is now model-generated. Technical documentation and systemic risk assessment bear on the composition gap in AI energy and compute reporting. Those obligations have been in force for a year and gain enforcement powers today, so whether mandated disclosure produces usable evidence is now an empirical question with accumulating documents rather than a hypothesis.
Will the disclosures actually be useful? Unknown, and the honest expectation is mixed. Mandated disclosure produces comparable numbers where the format is fixed, which is why greenhouse gas figures compare across companies and water figures historically did not. Several of these obligations do not specify a format, and a training data summary with no defined structure is a document whose usefulness depends entirely on who wrote it. That is the position water and energy reporting occupied before the EU's data centre regime fixed its indicators.
Does this article take a view on whether the Act is good regulation? No. This corpus does not take positions on contested political questions, and the design of AI regulation is one. What is described here is what applies, to whom, and from when, along with the reason the deferral fell where it did. The strongest objection to the framing is stated in the article: attributing the split entirely to standards readiness may credit a contested process, including a collapsed trilogue and substantial public lobbying, with more coherence than it had.
Sources
Primary documents only. Where a claim rests on a single report, the entry says so.
- EU AI Act Omnibus Agreement: Postponed High-Risk Deadlines and Other Key Changes Gibson Dunn The integrated milestone table, the deferral of Annex III to 2 December 2027 and Annex I to 2 August 2028, the replacement of the conditional trigger with fixed dates, and the statement that 2 August 2026 remains a live compliance date.
- AI Act rules on high-risk AI delayed as AI Digital Omnibus agreed Winston Taylor The revised compliance timetable including Article 50(2) watermarking moving to 2 December 2026 with an exemption for systems already on the market, and sandboxes deferred to August 2027.
- The Digital AI Omnibus: Proposed deferral of high risk AI obligations under the AI Act DLA Piper The negotiation record: proposal on 19 November 2025, the trilogue collapse on 28 April 2026, and the Council's final approval on 29 June 2026.
- EU AI Act Omnibus VII: Deadline Delay Cloud Security Alliance Lab Space The standards account: European standardisation organisations pushing harmonised standard delivery toward the end of 2026, leaving providers with a regulatory obligation and no finalised technical roadmap.
Further reading
The primary literature behind the claims above, drawn from the concept entries this post links to, so a claim carries the same source here as it does there.
- International Energy Agency (2025), Energy and AI — a worked example in the report that undercuts the framing its projections are used for. :: https://www.iea.org/reports/energy-and-ai Selective Transmission
- Epoch AI (2025), LLM inference prices have fallen rapidly but unequally across tasks — a hundredfold range and a contamination caveat published alongside the rate that circulated. :: https://epoch.ai/data-insights/llm-inference-price-trends Selective Transmission
- Raji et al. (2021), AI and the Everything in the Whole Wide World Benchmark — operationalisation standing in for the construct it was meant to represent. :: https://arxiv.org/abs/2111.15366 Proxy Decay
- Liang et al. (2023), GPT detectors are biased against non-native English writers — a statistical signature that stopped separating the populations it was assumed to separate. :: https://arxiv.org/abs/2304.02819 Proxy Decay
Related articles
- 1 to 2% of the chips, about 30% of the tokensExport controls were designed to constrain compute and have. The measure that moved instead was usage, and the two have separated sharply.
- One bug revoked every photo those cameras signedProvenance is the serious answer to synthetic media, it is now an ISO standard shipping in consumer hardware, and the gap between signing and verifying is wider than the adoption figures suggest.
- 4.7% at one attempt, 63% at a hundredThe previous article showed reliability decaying across repeated attempts. Security decays the same way with the sign reversed, and the per-attempt figure is the one that gets quoted.
- The same PDF says 83% and nobody quotes itTerritory 10 opens on enterprise deployment. The most-quoted statistic in the field is real, measures something much narrower than its use, and is contradicted inside its own source document.