The AI Act deadline moved. Your timetable probably hasn’t.
If you run credit decisions, price insurance risk or have put a chatbot in front of customers, and your service or product has a relevant connection with the EU, these changes may affect you. That is true whether or not anyone in your firm has yet used the phrase “AI Act” in a meeting. The Act can also reach further into business operations than many people expect: the marketing team generating synthetic imagery for a campaign, the HR system screening applicants and the vendor tool nobody classified as AI when it was procured may each engage different obligations.
The headline news is that the EU has pushed its hardest deadline out to December 2027. The more useful news is which obligations are already live, and why UK firms may find their own regulator, the Financial Conduct Authority, moves first.
What changed
The Digital Omnibus on AI is now law. It was published on 24 July 2026 and took effect on 27 July.[1] It is the EU’s tidying-up exercise for the AI Act: a single instrument that amends the original 2024 rules to reduce some of the paperwork and shift several deadlines. Worth noting for anyone searching the term: a separate and broader Digital Omnibus covering GDPR, ePrivacy and the Data Act is a different file on a different timetable.
The main change is a new deadline. The rules for what the EU calls high-risk AI systems, which is the list that includes credit scoring for individuals, pricing and risk assessment in life and health insurance, and recruitment and staff management tools,[2] were meant to apply from 2 August 2026. They now apply from 2 December 2027. Where AI sits inside a physical product that already has its own EU safety rules, the date is 2 August 2028.[3]
This is not a reason to slow down, because a lot is already in force.
What did not change
The outright bans on prohibited AI came into effect in February 2025 and carry the heaviest penalties in the Act, up to 35 million euro or 7 percent of worldwide turnover.[4] In the finance and marketing context, the one to watch is social scoring under Article 5(1)(c). The prohibition bites where you evaluate or classify people on their social behaviour or personal characteristics and the resulting score leads to detrimental treatment in an unrelated context, or treatment that is unjustified or disproportionate.[5] Pricing an insurance premium on a customer’s unrelated social media conduct would be the live version. For completeness, two further bans were added by the Omnibus and start on 2 December 2026, covering AI used to produce sexual imagery of people without their consent and material involving children.[6]
The AI literacy duty has also applied since February 2025, and the Omnibus softened rather than removed it. The wording now asks providers and deployers to take measures to support the development of AI literacy among their staff, and says expressly that this does not mean guaranteeing any particular level for any individual.[7] In regulated and high value businesses this is readily achieved through AI literacy training specific to your firm.
The transparency rules started on 2 August 2026, so they are live now. In plain terms: if a customer is talking to a bot, tell them so. If you are producing synthetic images, audio or video, it has to be marked in a way machines can read.[8] Systems that were already on the market before 2 August 2026 get four extra months for that marking requirement, which takes them to 2 December 2026.[9] That is a short runway.
For a retail bank, insurer or platform that has put generative features into service journeys over the last year or two, that last point above is the immediate one. It is also the cheapest to fix, and the most embarrassing to be caught out on, because it is visible to any customer or journalist who goes looking.
If your firm is in the EU
The delay buys you time on documentation, testing and sign-off. It does not buy you time on the substance, because most of what the AI Act asks for in a credit or insurance context is already being asked of you somewhere else.
The duty to explain a declined application is not new, and the AI Act does not create it. Depending on how the decision is made and the applicable national regime, automated lending decisions about individuals may already engage data protection rules on solely automated decisions,[10] creditworthiness and automated-processing safeguards under the new consumer credit regime as transposed in the relevant member state,[11] and existing supervisory expectations on model governance. The AI Act adds requirements including record keeping, human oversight by design and post-market monitoring. The underlying controls may therefore be familiar, but the evidence needed to demonstrate compliance is more extensive.
The same applies to your suppliers. If a high-risk system depends on an outside model provider, DORA already requires you to have the contract terms, the exit plan and the entry in your register of information.[12] None of that waits for December 2027.
One scope point catches people out. Recruitment and staff management tools are on the high-risk list, which means most EU financial institutions will be in scope for something even if they use no AI at all in their regulated business. These tools are almost always bought rather than built, and the duties that come with using them sit with you, not the vendor. If nobody in your firm has looked at what HR has licensed, that is a short and worthwhile conversation.
If your firm is in the UK
The AI Act does not apply in the UK, but a fair number of UK firms are in scope of it anyway. The Act reaches firms outside the EU in two ways: if you put a system onto the EU market, and if the output of your system is used in the EU.[13] A UK insurer pricing risk for policyholders in Europe, or a UK asset manager whose model feeds a decision taken in Dublin, is worth checking.
Group structures make this sharper. If a UK parent builds a model and an EU subsidiary uses it, the parent is usually treated as the provider and picks up the heavier set of duties, and the Act also sets out when someone else’s changes to a system make them the provider instead.[14] Several UK groups have concluded it is cheaper to run one standard across the whole business than to maintain two, and that is a commercial judgement as much as a legal one.
At home, the direction is settled for now. Of the 37 bills announced in the King’s Speech on 13 May 2026, none creates a general AI regime, and the Regulating for Growth Bill points the other way by creating cross-economy sandbox powers that let existing rules be temporarily relaxed for controlled testing.[15] The FCA has said plainly that it does not plan to introduce extra regulation for AI and will rely on existing frameworks instead.[16] In practice that means the Consumer Duty,[17] the senior managers regime,[18] the operational resilience rules, and, for banks and building societies with internal model approval, the PRA’s model risk expectations in SS1/23.[19]
The pressure is coming from Parliament and from the industry itself. The Treasury Committee said the FCA’s approach had been reactive and left firms to work out for themselves how the Handbook applies to their AI use, and asked for practical guidance by the end of this year covering both consumer protection and the level of assurance expected of senior managers for harm caused through AI.[20] The FCA chief executive has separately said the regulator is rethinking what it means to be an effective regulator in this area.[21] And the Financial Services AI Adoption Plan, written by the government’s independent AI Champions and accepted by HM Treasury in July, concluded that the problem is not an absence of regulatory support but its accessibility and consistency, and called for a single authoritative source of cross-regulator guidance.[22]
That is the sequencing point UK firms should notice. If the FCA delivers on time, its expectations will land roughly a year before the EU deadline. So the EU delay may not change your timetable at all.
Where I would put the effort now
Sort out the transparency piece this quarter. It applies today, it is usually a product and design fix rather than a governance programme, and the December 2026 date for systems already in the market is closer than it looks.
Then do the inventory, properly. What AI do you have, who built it, are you the provider or just the user, whose data does it touch, and where do the decisions land geographically. Every other decision depends on this and it always takes longer than the plan says. Firms that have done it tell me the surprises come from procurement and HR rather than from the model teams.
Name an owner. Under the senior managers regime someone is already accountable for this whether or not they have been told. Make it explicit, put it in the statement of responsibilities, and give them a standing slot at the risk committee.
Keep the governance work moving at a steady pace rather than parking it. Records, oversight, monitoring and challenge are things a supervisor may ask about under rules that already exist, long before December 2027, and whether that supervisor sits in Paris or in Stratford.
The deadline moved. The reason for it did not.
References
[1]: Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI), OJ L, 2026/1744, 24.7.2026, Article 4 and recital 46. ELI: http://data.europa.eu/eli/reg/2026/1744/oj
[2]: Regulation (EU) 2024/1689 (Artificial Intelligence Act), Annex III, point 4 (employment and worker management) and point 5(b) and (c) (creditworthiness evaluation and credit scoring of natural persons; risk assessment and pricing in life and health insurance). ELI: http://data.europa.eu/eli/reg/2024/1689/oj
[3]: Regulation (EU) 2024/1689, Article 113, third paragraph, as amended by Article 1, point (40) of Regulation (EU) 2026/1744: Chapter III, Sections 1 to 3 apply from 2 December 2027 to systems classified as high-risk under Article 6(2) and Annex III, and from 2 August 2028 to systems classified as high-risk under Article 6(1) and Annex I. See recital 40 of Regulation (EU) 2026/1744 for the reasoning.
[4]: Regulation (EU) 2024/1689, Article 5 and Article 113, third paragraph, point (a); penalties at Article 99(3) (up to EUR 35,000,000 or 7 percent of total worldwide annual turnover for the preceding financial year, whichever is higher).
[5]: Regulation (EU) 2024/1689, Article 5(1), point (c).
[6]: Regulation (EU) 2024/1689, Article 5(1), points (ba) and (bb), and Article 5(1a) and (1b), as inserted by Article 1, point (7) of Regulation (EU) 2026/1744; application date set by Article 113 as amended. See also recitals 11 to 14 of Regulation (EU) 2026/1744 on scope and safeguards.
[7]: Regulation (EU) 2024/1689, Article 4, as replaced by Article 1, point (5) of Regulation (EU) 2026/1744; see recital 8 of that Regulation for the reasoning.
[8]: Regulation (EU) 2024/1689, Article 50 (in particular paragraphs 1, 2 and 4), applicable from the general date in Article 113, second paragraph.
[9]: Regulation (EU) 2026/1744, recital 38 (four-month transitional period for providers of generative AI systems already placed on the market before 2 August 2026, in relation to the Article 50(2) marking obligation).
[10]: Regulation (EU) 2016/679 (GDPR), Article 22. ELI: http://data.europa.eu/eli/reg/2016/679/oj
[11]: Directive (EU) 2023/2225 on credit agreements for consumers, Article 18 (creditworthiness assessment, including the safeguards that apply where the assessment involves automated processing of personal data).
[12]: Regulation (EU) 2022/2554 (DORA), Articles 28 and 30 (register of information at Article 28(3); key contractual provisions at Article 30).
[13]: Regulation (EU) 2024/1689, Article 2(1), points (a) and (c).
[14]: Regulation (EU) 2024/1689, Article 25, as amended by Article 1, point (12) of Regulation (EU) 2026/1744.
[15]: Prime Minister’s Office, The King’s Speech 2026: background briefing notes, 13 May 2026 (updated 28 May 2026), Regulating for Growth Bill. https://www.gov.uk/government/publications/kings-speech-2026-background-briefing-notes
[16]: Financial Conduct Authority, AI and the FCA: our approach. https://www.fca.org.uk/firms/innovation/ai-approach
[17]: FCA Handbook, PRIN 2A (the Consumer Duty).
[18]: FCA Handbook, SYSC 23 to 27 and SUP 10C (Senior Managers and Certification Regime).
[19]: Prudential Regulation Authority, Supervisory Statement SS1/23, Model risk management principles for banks, published 17 May 2023, effective 17 May 2024. The expectations apply to UK-incorporated banks, building societies and PRA-designated investment firms with internal model approval. https://www.bankofengland.co.uk/prudential-regulation/publication/2023/may/model-risk-management-principles-for-banks-ss
[20]: House of Commons Treasury Committee, Artificial intelligence in financial services, Fifteenth Report of Session 2024-26, HC 684, published 22 January 2026, recommendation 22. https://publications.parliament.uk/pa/cm5901/cmselect/cmtreasy/684/report.html The regulators’ responses were published on 16 April 2026: https://committees.parliament.uk/publications/52647/documents/292955/default/
[21]: Nikhil Rathi, Rethinking regulation for the age of AI, speech to techUK’s Agents of Change conference, delivered 24 June 2026. https://www.fca.org.uk/news/speeches/rethinking-regulation-age-ai
[22]: HM Treasury, AI Adoption Plan: Financial Services, published 14 July 2026, prepared by the government’s independent AI Champions for financial services. https://www.gov.uk/government/publications/ai-adoption-plan-financial-services


The inventory-before-the-new-deadline is the bit I recognise. I have watched firms treat a moved date as permission to park the value question, then find the surprise in procurement and HR rather than in the model team. Naming an owner is the first useful move; cheaper models are not. If the FCA lands a year before the EU date, which of those systems would you still fund if someone had to stand behind the output this quarter?