SDAV Explains

The EU AI Act timeline has changed — what companies should actually prepare.

On 29 June 2026 the Council of the EU gave final approval to the Digital Omnibus on AI, moving the high-risk compliance dates to 2 December 2027 and 2 August 2028. The transparency duties that apply from 2 August 2026 were left in place.

Insights bi îngilîzî tên weşandin.

The European Parliament approved the Digital Omnibus on AI on 16 June 2026, by 423 votes to 57 with 174 abstentions. The Council of the EU gave the file its final approval on 29 June, as part of the simplification package known as Omnibus VII. The amending act enters into force on the third day following its publication in the Official Journal.

Two dates move. Obligations for stand-alone high-risk systems listed in Annex III — recruitment and worker management, credit scoring, education, biometrics, critical infrastructure — move from 2 August 2026 to 2 December 2027. Obligations for high-risk AI embedded in regulated products under Annex I, such as medical devices and lifts, move from 2 August 2027 to 2 August 2028.

The rest of the corporate calendar holds. That is the part worth reading closely, because the obligation most companies will meet first was never in the high-risk chapter.

The deferral covers one chapter of the Act, and 2 August still arrives

The AI Act, Regulation (EU) 2024/1689, was built to apply in stages. The prohibited practices in Article 5 have applied since 2 February 2025. The obligations on providers of general-purpose AI models, the governance chapter and the penalty regime have applied since 2 August 2025. On 2 August 2026 the Act becomes generally applicable.

The omnibus leaves it intact, including the transparency duties in Article 50. It makes one narrow concession: providers of systems placed on the market before 2 August 2026 have until 2 December 2026 to bring the machine-readable marking of synthetic content into line with Article 50(2). The extension covers only systems already on the market.

The package also added a prohibition rather than removing one: the Act now bans AI systems that generate child sexual abuse material or non-consensual intimate imagery, and companies have until 2 December 2026 to bring their systems into line. Member States, meanwhile, now have until 2 August 2027, rather than 2 August 2026, to put at least one AI regulatory sandbox into operation.

The reason for the delay is administrative, and the architecture behind it is unchanged

The European Parliamentary Research Service records why the schedule slipped: application had been held up by, among other things, “the designation of national competent authorities and the publication of harmonised standards”. Without designated authorities, notified bodies and standards, a company cannot demonstrate conformity even if it wants to.

The Commission proposed the file on 19 November 2025; the Council agreed its mandate on 13 March 2026 and Parliament its position on 26 March; negotiators reached a provisional agreement on 7 May.

The risk-based structure survives intact. One softening reaches every company that uses AI, in Article 4: providers and deployers must take measures to support the development of AI literacy among staff, rather than guarantee a level of it. On 19 May 2026 the Commission published draft guidelines on the classification of high-risk systems under Article 6(5) — three non-binding documents covering general principles, Annex I products and Annex III use cases — and the AI Act Service Desk, live since 8 October 2025, offers a compliance checker and an article-by-article explorer. The Council also records that products covered by the machinery regulation are exempted from the Act’s direct application.

The obligation arriving first is the one most companies actually hold

Article 50 is short and reaches wide. Providers must design systems that interact directly with people so that those people are informed they are dealing with an AI system, unless that is obvious. Providers of systems generating synthetic audio, image, video or text must mark the output as artificially generated in a machine-readable format. Deployers of emotion recognition or biometric categorisation must inform the people exposed to it, deployers publishing deep fakes must disclose them, and AI-generated text published to inform the public on matters of public interest must be labelled unless a person has taken editorial responsibility for it.

The proportions explain why this matters more than the high-risk debate for most firms. Eurostat’s 2025 survey, published on 11 December 2025, found that 20.0% of EU enterprises with ten or more employees used AI technologies, up from 13.5% a year earlier. Across the same population, 9.5% used AI to generate images, video or audio and 8.8% to generate written or spoken language. Those are the systems Article 50 addresses; the Annex III categories describe a far smaller population.

The enforcement scale is set in Article 99: for undertakings, the higher of €35 million or 7% of worldwide annual turnover for breaching the prohibitions, of €15 million or 3% for breaching operator obligations, and of €7.5 million or 1% for supplying incorrect or misleading information. For SMEs and start-ups the lower of the two applies.

For a Swiss company the test is where the output lands, not where the company sits

Article 2(1)(c) extends the Act to providers and deployers established in a third country where the output produced by the AI system is used in the Union. That is a functional test, and it produces three distinct positions. A Swiss manufacturer placing a product with an embedded AI safety component on the EU market is a provider, with Annex I duties arriving in 2028. A Swiss group whose EU subsidiary runs an AI tool has a deployer established in the Union, in scope from 2 August 2026. A Swiss firm using AI for internal work whose output never reaches the Union is outside the Act — and should be able to say so on the basis of a documented assessment rather than an assumption.

The exposure is structural rather than exotic: 51% of Swiss exports go to the EU, according to the Federal Department of Foreign Affairs. Article 25 deserves particular attention. A deployer becomes a provider, with the full set of provider obligations, if it puts its own name or trademark on a high-risk system, makes a substantial modification to one, or changes the intended purpose of a system — including a general-purpose one — so that it becomes high-risk. Rebranding a supplier’s tool is a legal act, not a marketing decision.

Switzerland’s own framework is still being written. The Federal Office of Justice states that there is at present no AI-specific legislation in Switzerland, and that on 12 February 2025 the Federal Council instructed the justice department to prepare a consultation draft by the end of 2026 covering transparency, data protection, non-discrimination and supervision, alongside non-legislative measures on the same horizon. The package is designed to allow ratification of the Council of Europe’s AI convention.

What a management team can settle without waiting for 2027

  • Write the inventory. Every AI system in use, its purpose, its supplier, and whether its output is used in the Union. Without that list, no other question can be answered.
  • Classify, then document the conclusion. Where an Annex III system is judged not to be high-risk under Article 6(3), the derogation carries a duty to document the assessment and register the system — and it never applies where the system profiles individuals.
  • Turn the disclosures on. Customer-facing chat, generated images and copy, synthetic voice: establish for each whether the company is provider or deployer, because Article 50 assigns different duties to each. Both fall due on 2 August 2026.
  • Fix roles in contracts. Ask suppliers in writing for machine-readable marking, and for the technical documentation a high-risk classification would require in 2027. Check Article 25 before rebranding or repurposing a tool.
  • Treat AI literacy as a programme, not a certificate. The amended Article 4 asks for measures taken: training records, written usage rules, named responsibilities.

The dates that will carry information

Five markers belong in the corporate calendar: 2 August 2026, when the Act becomes generally applicable; 2 December 2026, when the marking grace period ends and the new prohibitions begin; 2 August 2027, when Member States must have a sandbox operational; 2 December 2027 and 2 August 2028 for the two high-risk populations. A sixth is domestic: the Swiss consultation draft due by the end of 2026.

The deferral bought time for regulators and standards bodies as much as for companies. It did not reduce the number of questions a management team has to answer, and the first of them — which of our AI uses sits in which category, and who counts as the provider — costs nothing but attention.

Bulten

Ji çalakiyên me agahdar bimînin.

Çalakî, weşan û nûçeyên komeleyê — çend caran di salê de, bi zimanê ku hûn hilbijêrin.