AI Act August 2026: What to expect - delayed standards, pending guidance, and the Digital Omnibus on AI

Legal News
Under the current AI Act timetable, Article 50 and Annex III high-risk obligations apply from August 2, 2026. However, even though August 2, 2026 is less than five months away, the compliance infrastructure the AI Act was designed to rely on has not arrived. The Commission missed its own statutory deadline for issuing high-risk classification guidance under Article 6 - that guidance was due by February 2, 2026 - and the Commission's "Digital Omnibus on AI" proposal, which would delay parts of the high-risk regime, has no adopted text in sight.

Key points at a glance

  • Harmonised standards are the AI Act's main route to demonstrating compliance for high-risk AI (Article 40), but the standards are delayed.
  • The Commission missed its Article 6 guidance deadline of February 2, 2026. Broader AI Act guidelines are expected in stages during 2026.
  • The Digital Omnibus on AI (COM(2025) 836) proposes a delay to the entry into force of the high-risk regime. It is still in the ordinary legislative procedure.
  • Transparency obligations under Article 50, including requirements to label AI-generated content, apply from August 2, 2026, and are largely unaffected by the Omnibus.
  • In Denmark, sectoral supervision for high-risk AI remains undesignated, and the March 24, 2026 general election increases the risk of further delay.

Reasons for delay

The AI Act was designed to be implemented through harmonised standards: once cited in the EU Official Journal, they are supposed to give providers a presumption of conformity with the AI Act requirements in question (Article 40).

However, the development of these standards is delayed. The Commission formally recorded "significant delays" in the coming standards in its implementing decision of 23 June 2025 (C(2025)3871). 

As the EDPB and EDPS confirm in Joint Opinion 1/2026, this delay in standards, alongside delays in guidance, designating national authorities and conformity assessment bodies, is the Commission's reason for the Omnibus' proposed delay of high-risk AI implementation deadlines.

The Omnibus and the leaked drafts

The formal Commission proposal (COM(2025) 836) suggests a delay in high-risk application deadlines and would replace fixed high-risk application dates with a trigger: obligations start 6 or 12 months after a Commission decision confirming that adequate compliance tools are available, with longstop dates of December 2, 2027 (Annex III) and August 2, 2028 (Annex I).

The key Omnibus texts in circulation are: the  formal proposal; Member State comments; and the Parliament draft report, the latter of which supports a delay in high-risk AI application deadlines, but proposes fixed dates rather than a Commission-decision trigger.

The Omnibus provides only a narrow transition regarding Article 50(2) of the AI Act (Transparency obligations): providers of generative AI systems already on the market before August 2, 2026, have until February 2, 2027, to comply with the technical marking and detection requirements. All other Article 50 obligations apply from August 2, 2026. 

What is expected to apply from August 2, 2026

We emphasise that until any amendment is formally adopted, the current AI Act timetable is the law. 

Under the normal timetable, the high-risk AI obligations would apply from August 2, 2026, but given that the Member State draft and EU parliament draft accept a delay in high-risk implementation deadlines—the EU Parliament only disagreeing on when the high-risk AI application will apply, we assess it as likely that the high-risk AI application deadlines will be delayed.

Article 50 of the AI Act introduces a set of transparency obligations that apply regardless of whether a system is high-risk. They are particularly relevant for organisations using or deploying generative AI — systems that produce text, images, audio, or video in response to user input. 

The Article 50 obligations also apply from August 2, 2026, under the normal timetable. The Omnibus does not affect this timetable apart from proposed transition rules of 6 months for providers of generative AI systems subject to the marking obligations laid down in Article 50(2) who have already placed their AI systems on the market before August 2, 2026. The Member State and Parliament Omnibus drafts do not affect this proposal. Therefore August 2, 2026, should be the expected deadline, apart from the proposed transition of 6 months for Article 50(2).

We note that the Commission published a second draft Code of Practice on marking and labelling of AI-generated content on March 5, 2026, which leaves room for an article in itself.

Prohibited practices and GPAI obligations already apply.

Denmark: enforcement structures remain incomplete

Denmark has designated supervisors for prohibited practices (Article 5), including the Danish Data Protection Agency, the Agency for Digital Government, and Danish Court Administration. For high-risk obligations and Article 50, sectoral supervision is not yet finalised. The Danish general election called for March 24, 2026, effectively pauses legislative work, increasing the likelihood that national designations are not in place before August 2026. 

What we recommend organisations do now

Don't wait for perfect clarity from standards or guidance. We recommend organisations get going and start building the foundation of their AI compliance framework, which could include the following building blocks:

1. Map your current AI use cases. Build an inventory of AI systems classified at least against Article 5 (prohibited practices), Article 6 (high-risk), and Article 50 (transparency obligations). To ensure streamlining of the many common requirements and interfaces of the digital regulatory landscape (e.g., AI Act, GDPR, NIS2/DORA), we recommend strong cross-referencing between AI mapping and overall asset management, including mapping of systems, vendors and processing activities under GDPR (records of processing activities). This mapping is the foundation for everything that follows. 

2. Develop an AI screening policy (AI playbook) that enables the ongoing screening of new AI use-cases within the organisation. The playbook could include the following questions among others: 

  • Relevance
    • Is AI relevant/necessary to achieve your purpose?
    • Is it appropriate to use AI and is it in line with your organisations AI principles/ethics policy?
  • Classify the AI use case and update the AI inventory (step 1 above).
  • Map the data flow as part of the full AI life cycle and in case of processing of personal data ensure the appropriate privacy measures (step 3 below). 

3. Implement privacy measures. Even though parts of the AI Act may be delayed, the GDPR already applies. Accordingly, if personal data is processed throughout the AI life cycle, privacy considerations must be taken into account from the outset. Using AI often trigger high risks for data subjects, resulting in an obligation to carry out a data protection impact assessment, in order for you to identify appropriate organisational and technical measures and ensure privacy by design. In particular, a legal basis for each identified purpose must be in place, both regarding the development and deployment phase of the AI system.

4. Prepare an AI use policy. For any framework to be effective, it is important to strengthen awareness and AI literacy and set out guidelines for employees on how to use AI. The employees must be considered as first line of defence. 

Key official sources