The AI Act delay everyone noticed... and the one they missed
The AI Act delay you heard about isn't the one that matters most
You know the date we all had circled: 2 August 2026, the day the EU AI Act's high-risk rules were finally going to bite. Six days before it landed, it moved. The Digital Omnibus on AI, Regulation (EU) 2026/1744, went into the Official Journal on 24 July 2026 and came into force on 27 July. Not a draft, not a rumour, actual law. Standalone high-risk systems under Annex III (hiring, credit scoring, education, biometrics) now have until 2 December 2027. The ones baked into regulated products under Annex I get until 2 August 2028. What you have to do hasn't changed, only when.
Here's the catch. If the delay headlines tempted you to quietly park your programme, it's worth a second look because the other half of that deadline didn't budge.
What Article 50 actually asks of you
This is the bit worth a second look. The transparency rules under Article 50 went live on 2 August 2026 and the Omnibus left them alone. They're enforceable now and they apply whether a system is high-risk or not, so they reach far more of your estate than the deferred rules ever would. In practical terms that catches most organisations because nearly everyone runs a chatbot, a generative tool or both.
It helps to keep the two halves clear because they're easily muddled. If a system talks to a person, your customer service chatbot say, it has to tell them they're dealing with a machine. That applied on 2 August, with no grace period. The only breathing space is the rule about marking AI-generated content so a machine can read it and even that only helps legacy tools: anything on the market before 2 August has until 2 December 2026. Anything launched after that applies from day one. The deployer duties, labelling deepfakes, flagging emotion recognition are live regardless. And the fines bite too: up to €15 million or 3% of worldwide annual turnover.
Why this lands on your GDPR programme
Here's the line worth pausing on. The delay gives you time under the AI Act. It gives you none under GDPR not under today's rules.
An AI system that handles personal data still needs a Data Protection Impact Assessment under Article 35, exactly as it did last month. It still has to appear in your Article 30 record of processing. If your RoPA doesn't mention the chatbot, the CV screener or the marketing image generator, that's a gap and it is the kind of gap regulators and auditors notice quickly. Article 17 is the trickier one. Erasure can mean pulling someone's data out of the model itself, its training data, its logs and everything it has generated, not just a database record and that's a genuine problem. The AI Act delay changes none of it. People can still ask today.
The DPIA is really where the two come closest together. Done properly, it captures the processing, the transparency steps and the risks in one place and most of that work carries straight across to whatever the AI Act asks for separately.
What to do with the time
So the time needs to be spent well. List every AI system in the organisation, put each one in the RoPA. Run or refresh a DPIA wherever personal data is involved and build transparency in before a system ships, rather than bolting a notice on afterwards. Transparency isn't waiting for you down the road, it's due now.
December 2027 is genuine breathing room, but a decent programme takes a while to build and the time only counts if you use it. If you'd like a hand turning that list into DPIAs and a RoPA that holds up under scrutiny, our Privacy Operations team does exactly this. It's a good place to start.