ApexClaw
HomeStandards › EU AI Act
Standards

The EU AI Act's high-risk obligations were deferred, but most transparency obligations took effect on 2 August 2026.

The Digital Omnibus moved Annex III high-risk compliance to 2 December 2027 and Annex I to 2 August 2028. It did not move the transparency obligations, including those on deployers. "The AI Act was delayed" is therefore a dangerous summary to run a programme on.

Get an Agent Trust Gap Brief

What moved, and what did not

Obligation setWasNow
Annex III high-risk (use-based)
Providers Art. 9–17, deployers Art. 26
2 August 20262 December 2027
Annex I high-risk (product-regulated)
Radio equipment, lifts, medical devices and similar
2 August 20272 August 2028
Transparency obligations, incl. deployer2 August 2026Unchanged — in force

Political agreement on the Digital Omnibus reached 7 May 2026. Stated cause of the deferral: late harmonised standards from CEN-CENELEC JTC21. Verified 2026-08-06. Not legal advice — scope, applicability and national implementation vary, and this page is a starting point for a conversation with counsel, not a substitute for one.

The articles an agent operator actually meets

Art. 9 — Risk management

A continuous, documented process across the lifecycle. For agents the hard part is foreseeable misuse: an agent composes its own plans, so the misuse surface is not enumerable in advance.

Art. 12 & 19 — Logging and retention

Automatic recording of events over the lifetime, retained. This is where an execution receipt does structurally what a log line only approximates — it records the authorization, not just the outcome.

Art. 14 — Human oversight

Oversight must be effective, including the ability to intervene or interrupt. 14(4)(e) is the stop button. An untested kill switch does not satisfy an obligation to be able to stop something.

Art. 15 — Accuracy, robustness, cybersecurity

Where the OWASP agentic risks land: goal hijack, tool misuse, memory poisoning and supply chain are all robustness and security questions under this article.

Art. 26 — Deployer obligations

Including assigning human oversight to named natural persons with the competence and authority to exercise it. Named, not nominal.

Art. 72–73 — Post-market monitoring, incidents

Monitoring in real use and reporting serious incidents. Reconstructing an agent incident without receipts is slow, and the reporting clock does not wait.

Direct answers

Was the EU AI Act delayed?

Partly. Under the Digital Omnibus, agreed politically on 7 May 2026, Annex III use-based high-risk obligations moved from 2 August 2026 to 2 December 2027, and Annex I product-regulated obligations moved from August 2027 to August 2028. Most transparency obligations were not deferred.

What still applies from 2 August 2026?

Most transparency obligations, including those falling on deployers, took effect as scheduled. The deferral covers the high-risk obligation sets, not the whole Act.

Why was it deferred?

The stated reason is the late arrival of harmonised standards from CEN-CENELEC JTC21. Without them, providers had no agreed technical means of demonstrating conformity.

Does the AI Act cover AI agents specifically?

Not as a named category. The Act was drafted around AI systems and general-purpose models, not around software that plans, holds memory and calls tools autonomously. Agentic behaviour is governed indirectly through risk management, human oversight, logging and post-market monitoring obligations.

What should we do during the deferral?

Build the evidence layer that every obligation set ultimately requires: logging that reconstructs an action, human oversight that can actually intervene, and documentation that matches what the system does. None of that becomes less necessary in December 2027.

The practical read

The deferral changed a date, not a direction. Every obligation set above ultimately requires the same three things: an action you can reconstruct, oversight that can actually stop it, and documentation that matches the running system. Teams that treat December 2027 as permission to wait will meet the same requirements with less time.

There is also a live confusion cost right now: because most transparency obligations did not move, "the AI Act was delayed" is a dangerous summary to operate on.

See where your evidence gaps are