The deferral is no longer a proposal. Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026, six days before the high-risk deadline the industry had spent a year preparing for. The binding dates have moved. The question this page answered in June, whether to plan to an enacted date or a proposed one, has been replaced by a sharper one: what happens to all the plans, procedures, and guidance written to the old date?
What changed
The AI Act has applied in phases since it entered into force in August 2024. Prohibited practices came first, in February 2025, and the rules for general-purpose AI followed in August 2025. Under the enacted regulation, the largest tranche, the obligations on Annex III high-risk systems, was to apply from 2 August 2026.
The Digital Omnibus changed that timetable, and it is now law. Annex III high-risk systems, the use-based systems such as biometrics, employment, and credit scoring, apply from 2 December 2027. Annex I high-risk systems, the AI embedded in products already regulated under EU safety law such as medical devices, apply from 2 August 2028. What did arrive on 2 August 2026 is narrower but real: the Article 50 transparency duties, including telling people when they are interacting with an AI system, and the start of the Act’s enforcement machinery, with the AI Office and national authorities responsible for implementing and supervising it. A ninth prohibited practice follows in December 2026.
When this page was first published, in June 2026, the deferral was a provisional political agreement and the honest advice was to plan to the enacted date. That advice expired on 27 July 2026, and this page was corrected on 20 August 2026 to say so.
Who it applies to
For a pharmaceutical manufacturer the first question is whether the AI Act treats your system as high-risk at all, and the answer is more often no than the discussion suggests. AI used inside a GMP manufacturing process is not, on its own, an Annex III system. The high-risk classification reaches life sciences mainly where the AI is, or is a safety component of, a medical device already regulated under the MDR or the IVDR. Those are Annex I systems, and their date is now 2 August 2028.
So a typical pharma AI workflow sits in a particular place. It is usually not high-risk under the AI Act. It has been subject to the Act’s transparency provisions since 2 August 2026. And it is squarely inside the sectoral GMP regime, where the draft Annex 22 sets AI-specific expectations that are closer and more directly binding than the horizontal Act for most manufacturing uses. The AI Act and Annex 22 are converging on the same questions from two directions, and for manufacturing AI the GMP direction is the nearer one.
Why it matters for AI workflows
In June the trap was planning to a proposal. The trap has now inverted. Every internal plan, SOP, readiness assessment, and training deck that names 2 August 2026 as the high-risk deadline is asserting superseded law, and a team that spent 2026 preparing for that date is holding evidence checked against rules that moved. Stale guidance, not the deadline, is now the leading compliance risk. The dates moved once with a six-day runway; nothing prevents them moving again.
The expectations themselves did not soften. When the high-risk articles apply, on the dates that now bind, they ask a regulated AI system to show a risk-management process, governed and documented training data, technical documentation, logged records, human oversight, and demonstrated accuracy and robustness. Read that list next to the draft GMP Annex 22 and it is, in substance, the same list a GMP inspector will ask for.
That overlap is still the point. The two regimes are not asking for two evidence packages. They are asking, in different words, for one.
The preflight implication
A preflight produces that one package before the workflow runs: the intended use stated in scope terms, the provenance of the data the model learned from, the validation evidence tied to that intended use, the point at which a human must review rather than the system deciding alone, and the monitoring that would catch drift. Those five things are the common core of the AI Act’s high-risk requirements and of Annex 22.
The deferral is the argument for that record, not against it. A calendar that moved once with six days’ notice is a calendar you cannot build a compliance posture on; a record that is produced with the work and pinned to the rules it was checked against survives the calendar. Whether the binding date is 2 December 2027, 2 August 2028, or the GMP adoption of Annex 22 somewhere in between, the evidence is the same and it already exists. Waiting for the date that finally applies and assembling the record under it remains the expensive path.
What you can do now
Update everything that names the old date. An internal document asserting 2 August 2026 as the high-risk deadline is now itself the compliance risk this page is about, and the correction costs a line, not a program. Then triage: identify which of your AI workflows could be in scope as device-related Annex I high-risk (now 2 August 2028), and separate them from the larger set that the Act touches only through the transparency duties in force since August 2026 and that GMP Annex 22 governs more directly. For both, stand up the five-part evidence record now and keep it current, with the date it was checked and the text it was checked against pinned in the record. One file, produced before the work runs, that answers whichever regime asks first, on whichever date the calendar finally settles.
Sources
- Regulation (EU) 2026/1744 (the Digital Omnibus on AI), amending Regulation (EU) 2024/1689: published in the Official Journal 24 July 2026, entered into force 27 July 2026. eur-lex.europa.eu
- European Commission, Regulatory framework on Artificial Intelligence: application timeline as amended (standalone high-risk from 2 December 2027; product-embedded from 2 August 2028; transparency and enforcement from 2 August 2026; prohibitions since February 2025 with a ninth arriving December 2026; GPAI since August 2025). Retrieved 20 August 2026. digital-strategy.ec.europa.eu
- Regulation (EU) 2024/1689 (the EU AI Act), Article 113 (application), as amended. eur-lex.europa.eu
Status note: the Digital Omnibus on AI is adopted and in force as of 27 July 2026; the application dates above are current law. This page’s June 2026 version correctly described the deferral as provisional at that time; it was rewritten on 20 August 2026 when that stopped being true, and it will be updated again as the instrument moves. This item is reference-only and reproduces no regulatory text.