Le 16 juin 2026, le Parlement européen a approuvé le paquet Digital Omnibus, qui décale les obligations de conformité des systèmes d’IA à haut risque de l’annexe III du 2 août 2026 au 2 décembre 2027. Le Conseil a suivi le 29 juin. Le report sera juridiquement acquis à sa publication au Journal officiel de l’Union européenne. Ce report est réel, mais partiel : plusieurs obligations conservent leur calendrier, et le 2 août 2026 reste une date structurante.
Le calendrier actualisé
| Obligation | Échéance | Statut |
|---|---|---|
| Pratiques interdites (notation sociale, manipulation, reconnaissance émotionnelle au travail, biométrie temps réel) | 2 février 2025 | En vigueur |
| Article 4 : maîtrise de l’IA | 2 février 2025 | En vigueur, non reporté |
| Obligations des fournisseurs de modèles à usage général | 2 août 2025 | En vigueur |
| Contrôles de l’article 4 par les autorités nationales | 2 août 2026 | Maintenu |
| Transparence (article 50) | 2 août 2026 | Maintenu * |
| Conformité des systèmes à haut risque (annexe III) | 2 décembre 2027 | Reporté |
| Conformité de l’IA intégrée aux produits réglementés | 2 août 2028 | Reporté |
One point deserves special attention: Article 4. In its currently applicable version, it requires organizations using AI to take measures to ensure that their staff have a sufficient level of proficiency with these systems. This proficiency is not limited to formal training; it may combine training, awareness-raising, information, and guidance tailored to specific uses. The adopted Digital Omnibus amends this wording: after its publication and entry into force, providers and deployers will be required to take appropriate measures to support the development of AI proficiency, without guaranteeing a specific level for each individual. Until the text is published in the Official Journal, the current wording applies. The AI Act adds to an already extensive regulatory framework, alongside the GDPR, NIS2, and DORA, which we cover on our regulatory compliance page.
August 2026: Article 4 oversight takes effect
Effective August 2, 2026, national supervisory authorities will be able to oversee and enforce Article 4 throughout the Union. The regulation provides for penalties: these are caps, the application of which depends on the nature and severity of the violation. The primary issue is not financial; rather, it is about demonstrating that the matter is being addressed.
What the Calendar Doesn't Say
A regulatory calendar lists dates. It does not specify what those dates mean for a given organization.
A system’s risk level does not depend solely on the technology; it depends primarily on the system’s purpose, the context in which it is used, and, in some cases, the product into which the system is integrated. Two companies using the same software may therefore find themselves in different regulatory situations.
There is also the challenge of scope. The systems in question are not always limited to officially listed tools: some AI features are introduced through updates to existing applications or through practices adopted directly by teams. We address this topic in our article on Shadow AI and AI governance.
The implication is simple: an organization cannot derive its priorities from a general timeline. It must first determine what that timeline means in its specific context.
What does the new schedule really mean for your organization?
The consequences of the postponement vary depending on the existing AI applications, their purpose, and the role played by the organization.
Elit-Technologies’ AI-readiness audit helps small and medium-sized businesses and mid-market companies clarify their scope, identify areas requiring priority attention, assess their level of readiness, and develop a roadmap tailored to their environment.
Our approach brings together technical realities, business practices, security challenges, and governance, without limiting ourselves to a purely theoretical interpretation of the regulations. It is this integration that determines an organization’s true priorities.
Decisions That Should Not Be Postponed
Three issues remain relevant regardless of the postponement to December 2027.
- First and foremost, teams must master AI: Article 4 has been in effect since February 2025 and will be subject to oversight starting in August 2026. It applies to all employees who use AI systems, including service providers.
- Next, clarifying responsibilities. AI compliance spans IT, security, legal, human resources, and business units: it is recommended to clarify who is responsible for what before the issue becomes urgent.
- Finally, defining the scope. This is the most time-consuming task, and the one on which all the others depend: it is not possible to document or prioritize uses whose existence has not been established.
Is the postponement of the AI Act final?
Not yet. It will not become legally binding until the Digital Omnibus is published in the Official Journal of the European Union. Until that publication takes place, the initial timeline remains the legal reference, and the current version of Article 4 continues to apply.
Does the postponement mean that my company can wait until 2027?
No, for two reasons. Several requirements remain in effect, particularly staff training in AI, which will be subject to oversight starting in August 2026. And the implications of the timeline vary by organization: determining what the postponement means in a given environment requires first establishing the scope of its applications.
How can you tell if a use is subject to high-risk requirements?
The level of risk depends primarily on the purpose, the context of use, and, in some cases, the product into which the system is integrated. This includes, in particular, uses related to recruitment, personnel evaluation, credit scoring, access to essential services, and medical diagnosis. The assessment is conducted on a use-by-use basis.