EU AI Act Amendment: New Deadlines Compliance Teams Cannot Miss
The EU AI Act Amendment hit the Official Journal on 24 July 2026 and became effective on 27 July 2026.
EU AI Act Amendment: New Deadlines Compliance Teams Cannot Miss
The EU AI Act Amendment hit the Official Journal on 24 July 2026 and became effective on 27 July 2026. Compliance leads who spent Q2 racing toward high-risk system conformity now have breathing room — 18 additional months, in some cases two years. The transparency deadline of 2 August 2026 stayed put.
That mixed signal is the whole story.
What actually shifted
High-risk AI systems under Annex III (biometric ID, critical infrastructure, employment screening, credit scoring) receive the 18-to-24-month extension. The reasoning is operational: harmonised standards from CEN-CENELEC JTC 21 are not finalised, and Member State notified bodies are understaffed. Rather than trigger a wave of non-conformity findings, Brussels moved the clock.
Transparency obligations under Article 50 mostly held. General-purpose AI providers must still label synthetic content by 2 August 2026, but synthetic content generators specifically get a four-month reprieve for watermarking implementation. The European Commission AI Office has signalled technical specifications for provenance signalling before December 2026.
Two substantive changes matter beyond dates. First, the Article 5 prohibited-use list now covers non-consensual intimate imagery, aligning the AI Act with Directive (EU) 2024/1385 on combating violence against women. Second, Article 4’s AI literacy obligation was softened: providers must ensure a “sufficient level” rather than an “adequate level of understanding” — a lexical shift that closes a live audit-finding vector on training curriculum depth.
compliance_calendar:
transparency_article_50: 2026-08-02
synthetic_watermarking: 2026-12-02 # +4 months
gpai_code_of_practice: 2026-08-02
high_risk_annex_iii: 2028-02-02 # +18 months
high_risk_annex_i: 2028-08-02 # +24 months
prohibited_ncii: effective_immediately
Supply-chain duties get sharper
The amendment rewrites Article 25 on provider chains. Original providers of general-purpose models must share, within 30 days of request, the technical documentation downstream deployers need for conformity assessments — including training-data summaries per Article 53(1)(d). Downstream providers who fine-tune or substantially modify a model inherit provider status and its full obligations. That reallocation ends a year of ambiguity for enterprises building on Mistral, Llama, or Anthropic APIs.
The CAI position
Extensions are not amnesty. Teams that treat the 18-month window as slack will hit the same crunch in Q1 2028 — with notified body capacity even tighter than today. Our reading, informed by ongoing work on risk classification under the AI Act, is that the value of this window sits in instrumenting systems for continuous conformity, not deferring paperwork. Document high-risk classification decisions now. Renegotiate supply-chain contracts to reflect the new Article 25 duties. Audit fine-tuning workflows against the topology-first approach to agentic AI safety, which reduces conformity surface area rather than expands documentation.
If you want a scoped review of where your systems land after the amendment, our Lexnomia practice runs half-day compliance sessions.