EU AI Act: why postponement is not a postponement of homework
The political agreement on the Digital Omnibus delays the EU AI Act's high-risk rules, but transparency and classification already require action now.
You must now inventory your AI systems, classify which ones are high-risk under the EU AI Act, and put in place logging and transparency controls. The political agreement on the Digital Omnibus delays some obligations, but the transparency rules and classification work start in 2026, not later.
The prompt is an analysis of 2 August 2026 of the EU AI Act's transparency and classification obligations, which argues that postponement of the high-risk rules does not postpone the foundational work organisations must do now. The analysis draws on the provisional political agreement on the Digital Omnibus, which defers the heaviest obligations for high-risk systems to December 2027 for stand-alone systems and August 2028 for embedded ones. In our assessment, this creates a practical paradox: whilst some deadlines have shifted, the classification work, transparency controls and logging architecture you need to build cannot wait, because Article 50 transparency obligations come into force on 2 August 2026 and have not been postponed.
Which AI systems in your organisation count as high-risk?
The European Commission's draft guidelines on Article 6 and Annexes I and III set out how to classify systems across four risk categories, with worked examples in recruitment, credit assessment, medical devices and systems with system access. The consultation closed on 23 July 2026. Without a clear inventory of which applications you operate, what they do, and which annex they might fall under, every subsequent compliance step is guesswork. Start by mapping your AI landscape: which models are in use, for what purpose, and under which legal basis are you processing the data they touch.
What transparency duties take effect now?
Article 50 of the EU AI Act came into force on 2 August 2026 and has not been deferred. The transparency obligations require you to mark AI-generated content in machine-readable form and to inform those affected where AI has been involved in a decision or output. The guidelines give specific attention to deepfakes and synthetic media. This is not a future obligation: it is a present duty that requires policy, labelling processes and record-keeping ready in time. You must be able to demonstrate where AI was deployed, what it was asked to do, and how you informed the people it affected.
What controls must you be able to demonstrate?
The high-risk rules ultimately turn on demonstrability. Even though the formal compliance deadlines have shifted, the architecture you need to build is the same. You must establish a control layer that shows, with traceable logs and documented configuration, which model each workflow uses, when it was deployed, what data it processes, and how human oversight was applied to sensitive decisions.
- Record the model and its purpose — document which model each workflow uses and the lawful basis for the data it touches.
- Log system configuration and changes — maintain version-controlled records of model parameters, training data provenance and any material modifications.
- Implement human oversight for sensitive workflows — establish and record the human review steps that apply before a model output is acted upon.
- Mark AI-generated content — apply machine-readable marking to any output generated by AI, and document how affected parties were informed.
- Maintain audit trails — keep records of who accessed the system, when, what they asked it to do and what it returned.
What failure modes should you guard against?
The classification and logging work you do now must account for the risks that high-risk rules are designed to catch:
- Scope creep — a system deployed for one purpose may drift into a high-risk use case after modification, triggering obligations retroactively.
- Data leakage and memorisation — personal data reproduced or inferred from model outputs, especially where the model was trained on sensitive information.
- Lack of traceability — inability to show which model version processed which data, when, and under what oversight.
- Inadequate human review — decisions made by AI in sensitive domains without documented human judgment applied beforehand.
- Unlawful basis for processing — using personal data to train or operate a model without a lawful ground, or without informing the data subject.
How should you use the deferred deadlines?
The postponement to December 2027 and August 2028 is not an exemption; it is time to get your house in order. Organisations that begin now with classification, transparency controls and logging will be in a stronger position when the formal high-risk obligations arrive. You do not need a major system migration. You do need policy, record-keeping and a verifiable control layer that shows how and why you deployed each AI system. The work is the same whether you have two years or two months; starting now simply means you do it carefully rather than in a rush.
Tools can help you implement logging, anonymisation and verification steps, but they cannot replace your own professional judgment about what your organisation does with AI and why. The law asks you to demonstrate control. The architecture you build now—the inventory, the transparency processes, the audit trails—is yours to own and maintain. No platform can do that for you. What tooling can do is make the recording and verification visible, so that you and your colleagues can see what is happening under the bonnet and act on it with confidence.
Sources: This article draws on reporting and guidance from European Commission.
Written by
Elena Kovač
Follows EU policy as it turns from consultation into enforceable requirement.