Postponement of the AI Act: Requirements That Will Remain in Effect in 2026

24 July 2026

Le 16 juin 2026, le Parlement européen a approuvé le paquet Digital Omnibus, qui décale les obligations de conformité des systèmes d’IA à haut risque de l’annexe III du 2 août 2026 au 2 décembre 2027. Le Conseil a suivi le 29 juin. Le report sera juridiquement acquis à sa publication au Journal officiel de l’Union européenne. Ce report est réel, mais partiel : plusieurs obligations conservent leur calendrier, et le 2 août 2026 reste une date structurante.

Le calendrier actualisé

ObligationÉchéanceStatut
Pratiques interdites (notation sociale, manipulation, reconnaissance émotionnelle au travail, biométrie temps réel)2 février 2025En vigueur
Article 4 : maîtrise de l’IA2 février 2025En vigueur, non reporté
Obligations des fournisseurs de modèles à usage général2 août 2025En vigueur
Contrôles de l’article 4 par les autorités nationales2 août 2026Maintenu
Transparence (article 50)2 août 2026Maintenu *
Conformité des systèmes à haut risque (annexe III)2 décembre 2027Reporté
Conformité de l’IA intégrée aux produits réglementés2 août 2028Reporté
Frise chronologique des échéances de l'IA Act de février 2025 à août 2028, distinguant les obligations déjà applicables, l'échéance d'août 2026 et les obligations reportées

One point deserves special attention: Article 4. In its currently applicable version, it requires organizations using AI to take measures to ensure that their staff have a sufficient level of proficiency with these systems. This proficiency is not limited to formal training; it may combine training, awareness-raising, information, and guidance tailored to specific uses. The adopted Digital Omnibus amends this wording: after its publication and entry into force, providers and deployers will be required to take appropriate measures to support the development of AI proficiency, without guaranteeing a specific level for each individual. Until the text is published in the Official Journal, the current wording applies. The AI Act adds to an already extensive regulatory framework, alongside the GDPR, NIS2, and DORA, which we cover on our regulatory compliance page.

August 2026: Article 4 oversight takes effect

Effective August 2, 2026, national supervisory authorities will be able to oversee and enforce Article 4 throughout the Union. The regulation provides for penalties: these are caps, the application of which depends on the nature and severity of the violation. The primary issue is not financial; rather, it is about demonstrating that the matter is being addressed.

What the Calendar Doesn't Say

A regulatory calendar lists dates. It does not specify what those dates mean for a given organization.

A system’s risk level does not depend solely on the technology; it depends primarily on the system’s purpose, the context in which it is used, and, in some cases, the product into which the system is integrated. Two companies using the same software may therefore find themselves in different regulatory situations.

There is also the challenge of scope. The systems in question are not always limited to officially listed tools: some AI features are introduced through updates to existing applications or through practices adopted directly by teams. We address this topic in our article on Shadow AI and AI governance.

The implication is simple: an organization cannot derive its priorities from a general timeline. It must first determine what that timeline means in its specific context.

What does the new schedule really mean for your organization?

The consequences of the postponement vary depending on the existing AI applications, their purpose, and the role played by the organization.

Elit-Technologies’ AI-readiness audit helps small and medium-sized businesses and mid-market companies clarify their scope, identify areas requiring priority attention, assess their level of readiness, and develop a roadmap tailored to their environment.

Our approach brings together technical realities, business practices, security challenges, and governance, without limiting ourselves to a purely theoretical interpretation of the regulations. It is this integration that determines an organization’s true priorities.

Assess Your AI Exposure

Decisions That Should Not Be Postponed

Three issues remain relevant regardless of the postponement to December 2027.

  • First and foremost, teams must master AI: Article 4 has been in effect since February 2025 and will be subject to oversight starting in August 2026. It applies to all employees who use AI systems, including service providers.
  • Next, clarifying responsibilities. AI compliance spans IT, security, legal, human resources, and business units: it is recommended to clarify who is responsible for what before the issue becomes urgent.
  • Finally, defining the scope. This is the most time-consuming task, and the one on which all the others depend: it is not possible to document or prioritize uses whose existence has not been established.
FAQ

Is the postponement of the AI Act final?

Not yet. It will not become legally binding until the Digital Omnibus is published in the Official Journal of the European Union. Until that publication takes place, the initial timeline remains the legal reference, and the current version of Article 4 continues to apply.

Does the postponement mean that my company can wait until 2027?

No, for two reasons. Several requirements remain in effect, particularly staff training in AI, which will be subject to oversight starting in August 2026. And the implications of the timeline vary by organization: determining what the postponement means in a given environment requires first establishing the scope of its applications.

How can you tell if a use is subject to high-risk requirements?

The level of risk depends primarily on the purpose, the context of use, and, in some cases, the product into which the system is integrated. This includes, in particular, uses related to recruitment, personnel evaluation, credit scoring, access to essential services, and medical diagnosis. The assessment is conducted on a use-by-use basis.

More articles
Shadow IT and AI Act 2026: Mastering Shadow AI with Elit-Technologies
IT outsourcing for SMEs: how to keep control of your information system
SOC & ISO 27001: what you’re really buying and what’s just a logo
Scroll to Top
Download form
Download form