The EU delayed the AI Act. That is true, and it is the smaller half of the story. The delay is now law. It entered into force on 27 July, before any of this month's dates arrived. It moved the high-risk regime out by a year or more, from 2 August 2026 and 2 August 2027 to 2 December 2027 and 2 August 2028. It did not move the obligations that applied on 2 August, apart from one narrow transitional for marking, set out below.
Here is the actual position, taken from the enacting terms.
What applied on 2 August
Regulation (EU) 2024/1689 applies from 2 August 2026. Two things in it matter this month. Article 113
- The Article 50 transparency duties. The Article splits them by actor, and the split decides what you owe. Providers of systems intended to interact directly with natural persons must design them so those people are informed they are dealing with an AI system, unless that is obvious to a reasonably well-informed, observant and circumspect person in the circumstances. Providers of generative systems must mark outputs in a machine-readable format and make them detectable as artificially generated or manipulated. Deployers carry different duties: telling people when emotion recognition or biometric categorisation is being used on them, disclosing deepfakes, and disclosing AI-generated text published to inform the public on matters of public interest. Article 50
- The Commission's power to fine general-purpose AI model providers. Article 101 lets it impose fines of up to 3% of annual total worldwide turnover in the preceding financial year or EUR 15 000 000, whichever is higher, where it finds the provider acted intentionally or negligently. The obligations on those providers have applied since 2 August 2025 under Chapter V. Article 101 was expressly held out of that earlier date, which is why the power to fine arrives now rather than a year ago. Article 101
Which side of Article 50 you are on is worth settling. If you develop an AI system, or have one developed for you, and then place it on the market or put it into service under your own name or trademark, you are its provider. Both limbs matter: the definition reaches the company that commissioned the build, not everyone who puts a badge on someone else's finished product. Article 3(3)
Rebranding alone is a different rule, and a narrower one. A distributor, importer, deployer or other third party who puts their name on a system already on the market becomes its provider only where the system is high-risk. That is Article 25, not Article 3(3), and the high-risk regime it belongs to now applies from 2 December 2027 for the standalone Annex III systems and from 2 August 2028 for high-risk AI embedded in Annex I products. A straight rebrander of a non-high-risk system is not caught by that limb on any date, not merely until 2027. That is not the same as having nothing to do: if you run the system, you are its deployer, and the deployer duties in Article 50 applied on 2 August. Article 25(1)
If you are a UK company asking whether this reaches you: the Regulation applies to providers and deployers established in a third country where the output of the system is used in the Union. That is one route in, not the only one: Article 2(1)(a) separately catches providers placing an AI system on the Union market or putting it into service there, wherever they are established. A UK company can be inside on either limb. Article 2(1)(c)
What the Omnibus actually moved
The Digital Omnibus on AI is Regulation (EU) 2026/1744. It is dated 8 July, was published in the Official Journal of 24 July, and entered into force on the third day following publication, which is 27 July. The delay is not pending. It is on the statute book. Regulation (EU) 2026/1744
The high-risk regime moved. Sections 1 to 3 of Chapter III, with the exception of Article 6(5), now apply from 2 December 2027 for the standalone Annex III systems, the hiring tools and credit scoring and biometrics, and from 2 August 2028 for high-risk AI embedded in products already covered by EU product-safety law under Annex I. The rest of Chapter III was not deferred. amending Article 113
It reached Article 50 in two places, and neither is a general reprieve. It replaced paragraph 7, which is machinery about codes of practice. Separately, by amending Article 111 rather than Article 50 itself, it inserted a transitional at Article 111(4): providers of generative systems already placed on the market before 2 August 2026 have until 2 December 2026 to comply with the marking duty in Article 50(2). That is the whole of the grace. It reaches the marking obligation and nothing else, so the duty to tell people they are dealing with an AI system was never in it, and systems put on the market since 2 August get no transitional at all. The duties themselves were not amended. new Article 111(4) · amending Article 50(7)
That transitional is a different thing from what follows. The Omnibus also inserts two new prohibitions, on AI systems that generate non-consensual intimate imagery of an identifiable person, and on those that generate child sexual abuse material. They apply from 2 December 2026 as well. Both are narrowed by the same amendment: under the new Article 5(1a), placing such a system on the market is prohibited only where that generation is its intended purpose, or where its design, training, architecture or capabilities make that a reasonably foreseeable and reproducible outcome without significant technical modification and it lacks adequate safeguards. Use is prohibited only where the deployer uses it for that purpose. Same date, different provision, different subject matter. new Article 5(1)(ba) and (bb)
What the Omnibus did not do is touch Article 101. The Commission's power to fine general-purpose AI model providers arrived on 2 August on the original timetable. The supervision machinery around it is a different matter: the Omnibus amends Articles 72(3), 75, 76(1) and 77, and inserts four new Articles, 75a to 75d. Article 75a gives the AI Office all the powers of a market surveillance authority when it exercises its supervision and enforcement tasks. If you are reading the Act to work out who can do what to you, read those. new Article 75a
Meanwhile, the UK machinery changed shape
Four things are worth knowing about UK AI oversight this summer, and none of them was a new AI statute.
- AI policy is leaving DSIT. The written ministerial statement of 21 July sets out a redistribution of the department's functions. The limb that matters here is that responsibility for AI strategy, public sector AI adoption and the AI Security Institute will move to the Cabinet Office. Separately, the Prime Minister has created an Office for the Prime Minister and the Cabinet, and that office will include a new AI Taskforce. If you have been tracking UK AI policy by watching one department, that will no longer tell you where it is. HLWS298 · gov.uk fact sheet · on the AI Taskforce
- The ICO is to become the Information Commission. Part 6 of the Data (Use and Access) Act 2025 establishes the Commission and abolishes the office of Information Commissioner. The Commission itself already exists: section 117 was commenced on 20 August 2025, apart from section 117(4)(a). What has not happened is the handover. Section 118, which abolishes the office of Information Commissioner, and section 119, which transfers its functions to the Commission, are both still marked prospective. Recruitment for the Commission's Chair closes at 11:55pm on 19 August. section 117, in force · section 118, prospective · section 119, prospective DUAA 2025, Part 6 · the Chair vacancy
- The FCA published the Mills Review on 6 July, in its own words "the first work of its kind initiated by a regulator globally". Underpinning its recommendations is its conclusion that the regulatory framework remains fit for purpose. Its first priority recommendation is that the FCA should consider conducting a review, within three to six months, into general-purpose LLMs sitting outside the perimeter, and only then decide whether to amend guidance, recommend perimeter changes to government, or maintain the current approach. FCA press release · the Review, pp. 94 and 96
One consultation is still open to you. The DRCF call for input on consumer interest and AI put two topics out at once. The second, on the tools available to manage AI risks, closes on 2 September. The first, on consumer attitudes, closed on 3 July. DRCF call for input
Three things to do now
- 01
List anything customer-facing that talks or generates, and ask two questions of each. Did you build it, or have it built for you? And do you place it on the market or put it into service under your own name or trademark? Both together make you its provider. If you run someone else's under their name, you are its deployer. Article 50 gives those two roles different duties, and that is the question you cannot skip.
- 02
Check what each one currently tells people. If a system interacts with people, says nothing, and the fact that it is an AI system is not obvious in context, that is the gap. The marking transitional runs to 2 December 2026 and covers only machine-readable marking on systems placed on the market before 2 August 2026, so it will not cover you here.
- 03
Diarise 19 August and 2 September. The DRCF call for input closes on 2 September on its second topic. The call as a whole invites views from industry, academia, civil society, consumers and others; the topic still open asks academics, civil society and others about the tools available to manage AI risks. The Information Commission Chair recruitment closes at 11:55pm on 19 August, which is an appointment rather than a consultation.
The Blackletter Brief tracks UK and EU AI governance from official sources only: legislation, regulators and the institutions themselves, every claim traced to the primary record, with the source linked in the section that develops it. No law firm marketing, no trade press. Provisions are summarised and carry exceptions this summary does not repeat, so follow the link before acting on one. Where the Commission's own article pages have not yet been updated for the Omnibus, and they say so on their face, the amended text here is taken from the amending Regulation. Built by Blackletter, a UK AI governance intelligence platform launching soon. Forward this to the person in your company who quietly worries about this stuff.