
The headline that the EU has delayed parts of the AI Act is true, but only partly. If your business has offices, customers or operations in Europe, it should not be treated as a reason to pause compliance work.
In June 2026, the European Parliament approved targeted AI Act simplification measures, and the Council gave its final green light on 29 June 2026. The biggest change is that the most difficult high-risk AI rules have been pushed back. Stand-alone high-risk systems now move to 2 December 2027, while high-risk AI embedded in regulated products moves to 2 August 2028.
That buys time. It does not remove the work. Transparency rules under Article 50 still apply from 2 August 2026, and obligations around marking AI-generated content have only received a short grace period in specific cases. A new ban on certain AI systems used to create non-consensual intimate content or child sexual abuse material is also due to apply from December 2026.
You can read the EU’s own summary of the agreement for the detail.
What moved, and what did not
The trap is assuming everything slipped. It did not. The core architecture of the AI Act remains in place: banned practices, general-purpose AI obligations, transparency duties and high-risk system rules all still matter.
| Obligation | Applies from | Moved by the Omnibus? |
|---|---|---|
| Banned AI practices under Article 5 | 2 February 2025 | No |
| General-purpose AI model rules | 2 August 2025 | No |
| Transparency duties under Article 50 | 2 August 2026 | No |
| Marking AI-generated content for systems already on the market before 2 August 2026 | 2 December 2026 | Yes, short grace period |
| Ban on AI systems used for non-consensual intimate content or CSAM | December 2026 | Newly added |
| Stand-alone high-risk systems, including many Annex III uses | 2 December 2027 | Yes |
| High-risk AI embedded in regulated products | 2 August 2028 | Yes |
The transparency duties are the part many businesses need to handle first. They can include telling people when they are interacting with an AI system, disclosing deepfakes or AI-generated public-interest text, and informing people where emotion recognition or biometric categorisation systems are used. This is exactly where why IT compliance matters stops being abstract.
Why UK firms can still be caught
The Act does not stop at the EU border. If your office in Paris, Amsterdam or Madrid deploys an AI system, or if the output of a system you run is used in the EU, you may be in scope even if your head office is in London.
Picture a recruitment tool your Madrid team uses to filter CVs. Employment and worker management are high-risk areas under the AI Act, so the obligations may attach to that European use case. It does not matter that the software was bought by a UK team or sits inside a wider global platform.
The penalties are also serious. The top tier for prohibited practices reaches €35 million or 7% of worldwide annual turnover, whichever is higher. Other breaches, including certain transparency obligations, carry lower but still significant caps.
What to do before the next deadline
The sensible response is unglamorous. Build an inventory of every AI system your business and European offices actually use, including the tools staff adopted without asking. The Office for National Statistics reported in April 2026 that 26% of UK businesses were using at least 1 type of AI technology, so the real number inside larger organisations is often higher than management expects.
Classify each system against the AI Act risk tiers, then deal with the transparency work first. Write a short staff policy covering what can and cannot be entered into public AI tools. A structured assessment is a good template for the level of detail. The same discipline you use to validate the controls you already have also applies to data flowing into AI systems.
If you would rather not run this alone, it is the sort of ongoing work a managed IT provider is built to carry. It also pairs naturally with the supplier risk lessons from the 2025 retail attacks, because your AI vendors are part of your supply chain too.
If you are not sure where you stand, our IT consultancy can help you map your AI systems against the new dates and decide what needs to happen before August. For teams handling client or employee data across borders, regular penetration testing after a major system change is a sensible way to check that new tools have not widened your attack surface.
If your European offices are not centrally supported yet, that gap is worth closing first, which is where our outsourced IT support comes in. Where third-party tools quietly process meeting data, it is also worth knowing what those tools do with that data.
FAQs
Has the EU AI Act been delayed?
Partly. High-risk obligations have moved to 2 December 2027 and 2 August 2028, but transparency duties still apply from 2 August 2026.
Does the EU AI Act apply to UK companies?
It can. UK businesses may be in scope if they deploy AI in the EU, place AI systems on the EU market, or have AI outputs used in the EU.
What are the penalties under the EU AI Act?
For prohibited practices, the maximum is €35 million or 7% of worldwide annual turnover, whichever is higher.
What should we do before August 2026?
Build an AI inventory, classify tools by risk, address transparency duties and set a clear staff policy on approved AI use.
Get ahead of the dates that did not move
The delay buys time on the hardest rules, not on all of them. If you want help mapping your AI systems against the new EU deadlines and tidying up the obligations already coming into force, talk to Northern Star and we will work out what actually applies to your offices.