"Wasn't the AI Act delayed? So we're fine, right?"

That sentence — or a version of it — has closed a hundred boardroom conversations since July 2026. It's half right, which makes it the dangerous kind of wrong. The Digital Omnibus did push back the high-risk system deadlines. But several obligations have been in force since February 2025, the transparency rules landed in August 2026, and the nearest live deadline is now about ten weeks away. If your compliance plan is "the EU delayed it", you're planning against a version of the timeline that expired in the summer.

This page is the calm version: what's already in force, what actually moved, and what a UK or Irish SME should do before 2 December 2026. For the framework behind it all, start with our full guide to the EU AI Act for UK and Irish businesses.

What's already in force (as of September 2026)

Three dates have passed. Their obligations are live today — not phased in, not "expected", live. Most competitors' timeline articles still show the pre-Omnibus calendar; this is the one that reflects where you actually stand.

Prohibited practices — in force since 2 February 2025

The Act's outright bans took effect first: social scoring, AI that manipulates people through subliminal techniques or exploits vulnerabilities, untargeted scraping of facial images to build recognition databases, emotion recognition in workplaces and schools. Most SMEs don't build these systems — the "so what" is in what you embed. If you resell, white-label or integrate a third-party tool that crosses one of these lines, "we didn't build it" doesn't end the conversation. Know what's in your stack, including the tools your stack depends on.

AI literacy — in force since 2 February 2025

Article 4 requires anyone deploying AI at work to ensure their staff are competent to use it — training proportionate to the risk, appropriate to their role. This is the most-ignored obligation in the SME mid-market: no invoice arrives, so nobody notices the gap. Regulators and customers do notice, and unlike most obligations it's genuinely cheap to close — a documented training baseline turns a Tier 2 exposure into a closed item. We cover what "sufficient" looks like in practice on the AI literacy training page.

GPAI and governance rules — in force since 2 August 2025

If your team uses ChatGPT-class tools — ChatGPT Enterprise, Copilot, Gemini and the hundreds of products built on the same models — the general-purpose AI regime applies to your business today. The heavy transparency and copyright duties sit with the model providers. But deployers inherit duties too: use the tools in line with the provider's instructions, don't tamper with logging, keep an eye on what data staff paste in. If your AI policy is a paragraph nobody wrote, this is where it shows.

Transparency obligations — in force since 2 August 2026

Article 50 is the nearest live deadline, and the one to act on now. People must be told when they're interacting with AI — chatbots that don't disclose they're bots, generated content that passes as human. Deepfakes and synthetic media must be labelled and marked. Generative AI systems placed on the market before 2 August 2026 got a grace period for machine-readable marking and watermarking — and that grace period ends on 2 December 2026. If your customer-facing content is AI-generated and unmarked, that's not a 2027 problem. That's a live gap with a ten-week fuse.

What the Digital Omnibus actually delayed

Regulation (EU) 2026/1744 — the "Digital Omnibus" — entered into force on 27 July 2026 and moved two categories of deadline. Here's exactly what shifted, and what didn't:

2 December 2026 · ⏳ Not delayed — it was extended into this date

Watermarking grace period ends + new prohibitions apply

The grace period for marking generative AI systems already on the market before 2 August 2026 runs out. On the same date, the Omnibus's new bans — including non-consensual intimate imagery generators — take effect. This is the nearest date on the calendar.

2 December 2027 · ⏳ Delayed from 2 August 2026

Annex III standalone high-risk systems

Recruitment and employment tools, biometric identification, credit scoring, essential-services eligibility systems. If you build or deploy AI in hiring, lending or access-to-services decisions, your runway is this date — not the one from the original calendar.

2 August 2028 · ⏳ Delayed from 2 August 2027

Annex I product-embedded high-risk systems

AI embedded in regulated products: machinery, medical devices, toys. The extra year reflects the sectoral certification cycle, not a softening of the requirements.

Three things worth knowing about the delay. The dates are fixed calendar dates — no further readiness conditions, no "unless the Commission decides otherwise". The obligations themselves didn't change — requirements for high-risk systems are the same as before the Omnibus. And the compliance work you do now carries across: your AI inventory, risk classification, documentation and literacy records all serve the 2027 and 2028 dates exactly as drafted. The clock moved; the work didn't become wasted.

The other side of that coin: work you haven't done is now silently compounding against a nearer date for transparency than most people realise, and for what missing any of these dates can cost, see our guide to EU AI Act penalties and fines.

Why UK and Irish businesses are on this clock anyway

The Act follows output, not registration. If your AI systems' output is used in the EU, you sell to EU customers, or EU-based people use your tools, the deadlines above apply to your business wherever it's incorporated. That's the short version — the three tests, with worked examples, are unpacked in does the EU AI Act apply to UK businesses?

The practical reading for an MD: you don't get to opt out by geography, and you don't get to opt out by delay. The only lever you control is whether you're ready before the date rather than after the letter arrives.

What to do before the next date hits

2 December 2026 is close enough to plan against and far enough to fix things calmly. Work the ladder:

  • Step 1 — Audit your AI tools against the nearest date. Inventory every AI tool your team uses — including the unapproved ones — then ask two questions of each: does it generate content, and does it interact with people? Those carry transparency duties that are live today, and the watermarking grace expires in weeks. Inventory, classify, close the two or three gaps that actually matter.
  • Step 2 — Take the AI Act quiz (2 minutes). Six questions, instant read on where your AI use actually lands against the timeline above.
  • Step 3 — Exposure Assessment. A structured pass over customers, users and AI output to confirm which of the Act's triggers you meet, and how hard.
  • Step 4 — AI Readiness Diagnostic. The full map — every tool, data flow and obligation, prioritised against the dates in this timeline. Our AI Act Readiness service works alongside your legal counsel: they interpret the regulation, we make your systems legible against it.

The SMEs on the wrong side of 2 December 2026 won't be the ones who ignored the AI Act. They'll be the ones who read "EU delays AI Act deadlines" and stopped reading. Don't be a headline statistic in someone else's 2027 retrospective — take the quiz and find out where you stand.