All posts
Published
September 22, 2026

EU AI Act: What Companies Need to Know for December 2026 and What’s Delayed

Speyside Group provides a practical explanation of what the EU AI Act will require from companies on December 2nd, 2026, following the postponement of the main high-risk obligations to 2027. While the delay gives businesses more time to prepare for the most demanding compliance requirements, it does not represent a broader pause to the AI Act. The December 2nd, 2026 milestone remains relevant, bringing the end of a specific transition period and two additional prohibited AI practices into scope.

Speyside Group provides a practical explanation of what the EU AI Act will require from companies on  December 2nd, 2026, following the postponement of the main high-risk obligations to 2027. While the delay gives businesses more time to prepare for the most demanding compliance requirements, it does not represent a broader pause to the AI Act. The December 2nd, 2026 milestone remains relevant, bringing the end of a specific transition period and two additional prohibited AI practices into scope.

For companies planning their compliance for this year, it is important to know which rules already apply, what changed in August 2026, what changes again in December, and what can wait until 2027.

What changed in August 2026?

August 2nd, 2026, was the main general application date for the AI Act. From that date, the Act’s transparency rules for certain AI systems became applicable, and the enforcement powers of national authorities and the AI Office began to apply to provisions already in force. This includes rules covering prohibited AI practices, GPAI models, and certain transparency obligations.

There is one important exception to the immediate application of Article 50. Providers of generative AI systems that had already been placed on the market before August 2nd, 2026, received until 2 December 2026 to comply with the marking and detection requirement in Article 50(2).

What changes on 2 December 2026?

The first change concerns Article 50 transparency requirements. The rules have applied since August 2nd, 2026, but providers of relevant generative AI systems that were already on the market before that date received additional time to implement machine-readable marking of AI-generated content. That transition period ends on December 2nd.

This does not create a general requirement to go back and label content generated in the past. Content generated before August 2nd, 2026, does not have to be labeled retrospectively. The December 2nd deadline concerns providers bringing covered pre-existing systems into compliance with Article 50(2).

The second change is more substantive. From December 2nd, the AI Act will prohibit AI systems used to generate or manipulate non-consensual sexually explicit or intimate content and child sexual abuse material (CSAM). The European Commission has described this as a ban on “nudification” applications and other systems that generate such material.

These prohibitions apply independently of the high-risk framework. An AI system does not need to qualify as high-risk under Annex III for these uses to be prohibited.

Most of the AI Act is already applicable

The December date should therefore not be interpreted as the point at which companies suddenly become subject to the wider AI Act. AI literacy requirements under Article 4 have applied since February 2025, while the governance rules and obligations for GPAI models have applied since August 2025. These include requirements covering transparency to downstream providers and copyright, with additional requirements for GPAI models presenting systemic risk.

The original prohibited AI practices under Article 5 have also applied since February 2025, with enforcement powers from August 2026. Meanwhile, the broader Article 50 transparency requirements have applied since August 2026.

So what has actually been delayed?

The major postponement concerns Chapter III and the high-risk AI regime. The EU said the infrastructure needed to implement the high-risk rules — including standards, guidance and conformity-assessment capacity — was not ready. The deadlines were therefore moved to give companies and regulators more time to prepare.

Under the Digital Omnibus, the core high-risk requirements — including risk management, data governance, technical documentation, human oversight, accuracy, robustness and cybersecurity — now apply from:

  • December 2nd, 2027, for AI systems classified as high-risk under Article 6(2) and Annex III; and
  • August 2nd, 2028, for AI systems classified as high-risk under Article 6(1) and Annex I, including AI embedded in regulated products.

The first category covers high-risk use cases in areas including employment, education, essential services, critical infrastructure, migration and law enforcement. The second covers AI systems integrated into products subject to EU product-safety legislation, including areas such as medical devices, machinery, toys and lifts.

The final Omnibus text sets these dates directly in Article 113. The Commission's original proposal had considered linking the application of the high-risk rules to the availability of standards and other support measures, but the final legislation established the dates above instead. The Omnibus was proposed by the Commission in November 2025. EU institutions reached political agreement on May 7th, 2026, and Regulation (EU) 2026/1744 entered into force on July 27th, 2026.  

What should companies do now? Has the compliance burden been reduced?

The delay should not be treated as a compliance pause. Companies should still identify the AI systems they use or provide, determine which rules apply, and flag systems that could fall under the high-risk framework.

Does the delay actually reduce the compliance burden? To some extent. The Omnibus introduces targeted simplifications alongside the postponed deadlines. Some requirements previously limited to SMEs now also apply in simplified form to small mid-cap companies, including certain documentation requirements. Some registration and conformity-assessment procedures have also been simplified.

The AI literacy requirement is now less prescriptive: companies still need to take measures to support AI literacy, but the rules no longer set a specific level that individual employees must achieve.

For large companies, however, these changes are unlikely to remove the main compliance work. The additional time is therefore best used to prepare for the high-risk requirements, including risk management, documentation, data governance and human oversight.

FAQ

Is most of the AI Act delayed to 2027?

No. AI literacy requirements and prohibited-practice rules have applied since February 2025, GPAI obligations since August 2025, and Article 50 transparency requirements since August 2026. The main delay concerns the Chapter III high-risk regime.

What exactly moves to December 2nd, 2027?

The Chapter III Sections 1–3 requirements for AI systems classified as high-risk under Article 6(2) and Annex III.

Do Annex I systems have the same deadline?

No. For high-risk AI systems classified under Article 6(1) and Annex I, including AI embedded in regulated products, the relevant date is August 2nd, 2028.

Does the December 2026 deadline mean old AI-generated content must be labeled?

No. Content generated before August 2nd, 2026, does not need to be labeled retrospectively. The 2 December deadline applies to providers of systems already on the market before 2 August 2026 that need to bring those systems into compliance with the Article 50(2) marking and detection requirement.

How Speyside Group Helps

Speyside Group helps companies navigate regulatory environments where compliance requirements, political negotiations and implementation timelines are evolving simultaneously. We support clients with monitoring of EU and national guidance and stakeholder engagement around emerging AI regulation.

Conclusion

December 2nd, 2026 is not a new general compliance deadline for the EU AI Act. It closes a specific Article 50 transition period and brings two additional Article 5 prohibitions into application. The more significant change is the postponement of the main high-risk obligations to December 2027 and August 2028.  

For companies, this means more time to prepare. The high-risk deadlines have moved, but businesses should use the extra time to identify affected systems and put the necessary governance and controls in place.

Recent News

View All News
Technology

EU AI Act: What Companies Need to Know for December 2026 and What’s Delayed

Speyside Group provides a practical explanation of what the EU AI Act will require from companies on December 2nd, 2026, following the postponement of the main high-risk obligations to 2027. While the delay gives businesses more time to prepare for the most demanding compliance requirements, it does not represent a broader pause to the AI Act. The December 2nd, 2026 milestone remains relevant, bringing the end of a specific transition period and two additional prohibited AI practices into scope.
Read post
Latin America

How Do Elections Affect Business in Emerging Markets? Lessons from Latin America

Speyside Group provides a strategic perspective on how geopolitical risk shapes electoral outcomes and business operating environments across Latin America. Elections test whether governments can govern, not merely their ideological direction. Institutional capacity, legislative coalitions, and external pressures reshape the investment landscape more than electoral mandates alone, requiring investors to assess each country's capacity to implement policy.
Read post
APAC

Why Australia is No Longer a Two-Speed Economy

Speyside Group provides a strategic perspective on why the traditional Australian two-speed economy framing no longer describes the country adequately. Western Australia produced 45.4 per cent of national goods exports in 2025, but other important divisions cut across State and Territory lines: between metropolitan, regional and remote communities, and between established property owners, renters and prospective buyers. For investors and corporate affairs leaders, mapping the wrong divides produces the wrong engagement strategy
Read post