Most finance functions spent the first half of 2026 preparing for a date that no longer applies. A smaller number are now in breach of a rule nobody rescheduled. Both groups made the same mistake. They treated the European AI rules as one deadline rather than several.

Key Takeaways

  • The EU moved its high-risk AI compliance date from 2 August 2026 to 2 December 2027 through Regulation (EU) 2026/1744, which entered into force on 27 July, six days before the date it moved.
  • Article 50 transparency obligations were not moved. They took effect on 2 August 2026 and have been in force since.
  • Breach of either obligation sits in the same penalty tier, up to EUR 15 million or 3% of total worldwide annual turnover, whichever is higher.
  • Only the watermarking requirement under Article 50(2) received relief, four months to 2 December 2026, and only for systems already placed on the market.
  • Creditworthiness evaluation of natural persons and pricing in life and health insurance remain Annex III high-risk. The obligation moved. The classification did not.

The Date Moved. One Duty Did Not.

On 24 July 2026 the European Union published Regulation (EU) 2026/1744, the Digital Omnibus on AI, in the Official Journal. It entered into force on 27 July, six days before the compliance date it was written to move.

The deferral is real and it is substantial. Standalone high-risk systems under Annex III, the category that captures creditworthiness evaluation of natural persons and risk pricing in life and health insurance, now have until 2 December 2027. AI embedded in products already covered by European product-safety law has until 2 August 2028. For an institution that had budgeted a conformity assessment for the third quarter of this year, that is roughly sixteen months of recovered time.

Then there is the part that did not move.

Article 50 governs transparency. It requires that a person be told when they are interacting with an AI system. That obligation took effect on 2 August 2026 and the Omnibus left it there. The only relief granted was narrow. The watermarking requirement under Article 50(2) received four months, to 2 December 2026, and only for systems already placed on the market.

So the position on 24 August 2026 is not that the AI rules were delayed. It is this. The heavy engineering obligation moved out by sixteen months. The disclosure duty has been live for three weeks.

Regulation (EU) 2026/1744, in force 27 July 2026
What the Omnibus Moved, and What It Left in Place
Obligation Original date Date now Status at 24 Aug 2026
Standalone high-risk
Annex III, incl. credit scoring
2 August 2026 2 December 2027 Deferred
Embedded high-risk
Annex I, product-safety scope
2 August 2026 2 August 2028 Deferred
Article 50 transparency
Disclosure of AI interaction
2 August 2026 2 August 2026 In force
Article 50(2) watermarking
Systems already on market only
2 August 2026 2 December 2026 Grace period

Why "Delayed" Is the Wrong Word for a Board Minute

The gap matters because of how the two obligations differ in character.

High-risk compliance is a build. It requires a risk management system, data governance, bias testing, technical documentation, human oversight design and a conformity assessment before deployment. Institutions measure that work in engineering quarters. It is exactly the kind of programme a board defers when a regulator hands it sixteen months.

Article 50 is not a build. In most institutions it is a sentence in a chat window, a line in an interactive voice response script, a label on an automated email. The work is small. The exposure is not. Breach of either obligation sits in the same penalty tier, up to EUR 15 million or 3% of total worldwide annual turnover, whichever is higher.

That asymmetry is the trap. The obligation that was easiest to satisfy is the one still binding, and it is the one most likely to have been swept into a programme that stood down in July.

The Four Approvals a Board Actually Owns

Regulatory text does not tell a board what to sign. These four decisions do, and a board cannot delegate any of them to the model risk team and still own the outcome.

  1. The inventory, and who attests to itNot a list of models. A list of the points where a system touches a person: which customer conversations an AI system handles, which credit decisions it informs, which claims it prices. Most institutions already hold a model inventory. They built it to track what predicts, not what speaks. The board approves the scope of the inventory and names the executive who attests that it is complete.
  2. The classification callWhether a given system falls inside Annex III is a legal determination with a sixteen-month consequence attached. Read it too permissively and the December 2027 date was never yours to use. This decision needs a named owner, written reasoning and a review trigger, because the classification survives the deferral even though the obligation moved.
  3. The disclosure standardArticle 50 is live, so the board approves what "informed" means in practice: the wording, the placement, the point in the journey where it appears, and the treatment when a human takes over mid-conversation. Teams miss this item most often, because it looks like a customer experience question rather than a governance one.
  4. The evidence layerIn December 2027 a supervisor will not ask whether the institution had a policy. It will ask for the record. Which system, which version, which decision, which human reviewed it. Institutions that treat the deferral as sixteen months of quiet will arrive with a policy and no evidence. The board approves who owns that record, and when it starts. It starts now, because the systems running today are generating the record for 2027.

The American Parallel, and Where It Stops

United States institutions reading this from outside the European perimeter should not assume the question differs in kind.

SR 11-7, the Federal Reserve and OCC supervisory guidance on model risk management, has been in force since April 2011. It already requires validation, documentation and independent review for models used in business decisions. It is not new and nothing has superseded it.

What it was not written for is systems that act. SR 11-7 assumes a model produces an output that a person then uses. A system that resolves a customer query, adjusts a limit or completes a workflow does not fit that shape cleanly, a gap we set out in The Agentic Economy's Governance Gap. The validation questions still apply. The control questions, who authorised this action, against what mandate, with what audit trail, do not have a settled answer in the 2011 text.

The practical consequence is that a firm with a mature SR 11-7 programme stands further ahead than one without, and is not finished. An inventory built for model validation will not, on its own, answer the Article 50 question about which systems talk to customers.

What to Do Before December

Three things are worth completing in the next ninety days, and none of them require the deferred programme to restart.

Separate the register. Split the AI inventory into systems that inform decisions and systems that interact with people. The second list is the Article 50 population and it is smaller than most teams expect. It is also the list already in scope.

Close the disclosure gap. Where an AI system speaks to a customer, confirm the disclosure exists, and confirm it survives handover to a human. This takes days of work, not quarters.

Start the record. Whatever the December 2027 evidence standard turns out to require, it will be satisfied from logs that either exist or do not. Sixteen months of deferral is sixteen months of records nobody can recreate later.

The Question Behind the Deadline

The Omnibus did not reduce the governance question. It rescheduled part of it and left the visible part in place. Where that governance work accrues value is the subject of The AI Repricing.

For a board, the useful framing is not compliance date management. It is this. If a customer asks tomorrow whether they were talking to a person, and a supervisor asks in 2027 who authorised a decision, can the institution answer both from a record it already keeps? The first question is live now. The systems running today are answering the second one, correctly or not.

Sources

All primary documents accessed 24 August 2026. Regulatory positions stated are as of that date.

Establish Which Obligations Actually Bind You Today

The deferral changed the schedule, not the classification, and it left the disclosure duty in force. We provide independent review of AI inventories, Annex III classification reasoning and the evidence layer a 2027 supervisor will ask for. We are provider-agnostic and hold no platform relationships.

Request a Governance Review

Or start with the two-minute AI readiness assessment

For the CFO: Ask one question at the next risk committee. Which of our systems speak to a customer, and does each one say so? That is the Article 50 population, it is in force now, and it is answerable this week. The December 2027 programme can wait. The record that programme will be judged on cannot, because it is being written by the systems running today.

Disclaimer: This article is research and market commentary for informational purposes only and does not constitute legal, tax, or investment advice. Regulatory positions stated are as of 24 August 2026. Institutions should consult qualified counsel on the application of Regulation (EU) 2024/1689 and Regulation (EU) 2026/1744 to their specific circumstances.