
The AI Act omnibus that came into force on 27 July 2026 moved a deadline, not the work. Obligations covering AI used in recruitment, performance management and credit decisions now apply from December 2027, the transparency rules still apply from 2 August 2026, and in Norway the regulation is not yet in force at all.
That combination is why “delay” is the wrong word for what happened this week.
What actually changed on 27 July
Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal of the European Union on 24 July 2026 and came into force three days later. The compressed timetable was deliberate, because the date it amends was only days away.
Two things moved. High-risk obligations for the standalone systems listed in Annex III now apply from 2 December 2027. High-risk obligations for AI embedded in regulated products under Annex I now apply from 2 August 2028.
Two things did not move. The transparency duties, the ones requiring people to be told when they are dealing with a machine and requiring AI-generated content to be marked, still apply from 2 August 2026. And the prohibitions that have applied since February 2025 remain untouched, carrying the highest penalty tier in the Act.
Almost every summary I read reported the first half and skipped the second.
Why Annex III is the part that matters to most companies
Annex III is not an exotic list. It covers AI used in recruitment and candidate selection, in performance management and task allocation, in credit scoring and insurance pricing, in education and examinations, and in biometrics.
The ordinary company is a deployer, not a provider
Most companies do not build AI systems. They buy them and use them, which makes them deployers rather than providers, and the obligations are lighter. Lighter is not the same as absent. A deployer still has to use the system as instructed, keep competent human oversight, and tell employees before an AI system that affects them is put to work.
There is one line worth knowing about. A company that white-labels a system, substantially modifies it, or repurposes it for something it was not built for can become a provider, with the full obligation stack attached. Organisations fine-tuning models cross that line without noticing.
December 2027 is not a distant date. It is a budget line.
This is the part I have not seen written down anywhere.
Most companies set their 2027 budgets between September and November of this year. Whatever this work costs has to be argued for in a document being drafted within weeks, by people who have just been told the deadline moved sixteen months.
Anyone who has sat in a budget meeting knows what happens to a line item whose deadline just receded. It gets deferred to the following cycle, and the following cycle is the one where the deadline is real.
The Norwegian position, which is widely misread
Norway is not a member of the European Union. The AI Act is not law in Norway today. It is EEA-relevant and awaits incorporation into the EEA Agreement, and the Norwegian implementing law, the KI-loven, has slipped, partly because the EEA adaptations are still being negotiated and partly because the omnibus changed the text under negotiation. Nkom is to be the coordinating supervisory authority.
Some leaders will hear that and relax. Three reasons not to.
Norwegian companies selling into the European Union are reached anyway. Nordic groups with Swedish, Danish or Finnish subsidiaries are reached directly in those jurisdictions. And using AI to screen candidates or score employees is already governed in Norway today, through the Personal Data Act and through the long-standing rules on control measures in the workplace. None of that was waiting for Brussels.
The question underneath all of it
Every date above is a legal question, and legal questions have owners. The question that decides whether any of this is manageable is not legal at all.
Can you say, without asking anyone, which AI systems are running in your company, which of them touch a decision about a person, and who owns each one by name?
Most leaders I put that to cannot. Not through carelessness. Because nobody was ever given the job. An inventory is unglamorous work that no one volunteers for, and it is the foundation everything else in the Act sits on. It is also the cheapest it will ever be to build, because doing it under a deadline costs several times what doing it calmly costs.
I have written before that the delay is not the reprieve your board thinks it is, and that it functions more like a stopwatch than a break. This week’s regulation makes both of those more true, not less.
Two related things sit close to this one. The inventory problem is inseparable from the AI your employees are already using without telling you, because a register that omits shadow usage is not a register. And if you would rather not be asked about any of this without warning, it is worth knowing which board questions can actually hurt you. If you suspect you are behind, arriving late is only a disadvantage if you stay still.
Where this leaves you
Not a crisis. Not a reprieve either. A gap that is currently cheap to close and will not stay that way, sitting in a company where nobody has been asked to close it.
Frequently asked questions
Was the EU AI Act delayed?
Partly. Regulation (EU) 2026/1744 moved the high-risk obligations for Annex III systems to 2 December 2027 and for Annex I embedded systems to 2 August 2028. The transparency obligations still apply from 2 August 2026, and the prohibitions in force since February 2025 were not changed and carry the highest penalty tier in the Act.
Does the EU AI Act apply in Norway?
Not yet. Norway is in the EEA rather than the European Union, so the regulation must first be incorporated into the EEA Agreement and implemented in Norwegian law through the KI-loven, which has been delayed. Norwegian companies selling into the European Union are still reached, Nordic groups with subsidiaries in EU member states are reached directly there, and AI used in recruitment or employee monitoring is already governed in Norway by the Personal Data Act and by existing rules on workplace control measures.
What applies from 2 August 2026?
The transparency obligations. People must be told when they are interacting with an AI system, synthetic and deepfake content must be labelled, AI-generated content must be machine-readably marked, and the use of emotion recognition or biometric categorisation must be disclosed. Systems already on the market have until 2 December 2026 for the marking requirement.
What should a board do before the 2027 budget is set?
Ask for an inventory. A single list of every AI system in use, which ones touch a decision about a person, and a named owner for each. It is the input every later decision depends on, it costs very little to produce now, and it is the one thing that cannot be bought quickly once a deadline is close.
Thomas Anglero is a Strategic AI Advisor, keynote speaker and author of Intro to Artificial Intelligence. He has delivered over 450 keynotes across 30 countries for organisations including IBM, the WHO, the World Government Summit and the European Commission. He founded the IBM Watson AI Lab for Cancer at the Oslo Cancer Cluster and closed over $500 million in enterprise transformation deals as CTO and Chief Innovation Officer at Cognizant. Read more about Thomas.
If your leadership team needs to get clear on where it actually stands with AI, that work starts here: The Reset.