AI governance

The EU AI Act deadline moved to 2027. What still applies now?

The deadline everyone planned around moved, and the obligation everyone cited as the reason to train their staff got weaker. Should either change what you do in the next six months?

Yes, you should still sprint, but not toward the deadline you were sprinting toward. The Digital Omnibus deferred the AI Act high-risk chapter by sixteen months and rewrote the AI literacy duty into an obligation of effort. Neither change touches the rules that are producing enforcement today, and the largest AI-related fine in European history was issued under the GDPR while the AI Act sat unused.

By PharosBioPublished on 14 min read

Key takeaways

  • Regulation (EU) 2026/1744 moved Annex III high-risk obligations to 2 December 2027 and Annex I to 2 August 2028.
  • Nothing currently producing enforcement against European deployers was deferred by the Omnibus.
  • The Dutch authority fined Uber 824,990,000 euro in August 2026 under the GDPR, not the AI Act.
  • Article 4 now asks providers to support AI literacy rather than guarantee any specific level.
  • Article 50 transparency applied from 2 August 2026, with the watermarking grace period ending 2 December 2026.
  • Foodinho was ordered to provide human review in 2021, then fined 5 million euro in 2024 for still lacking it.
  • The 70.9 percent skills barrier describes 7.76 percent of all EU enterprises once the base is corrected.

What actually changed, and what did not

The Digital Omnibus

Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force since 27 July. It pushed stand-alone high-risk obligations under Annex III to 2 December 2027 and high-risk AI embedded in regulated products under Annex I to 2 August 2028, and it rewrote the AI literacy duty in Article 4.

It also, more quietly, changed what Article 4 asks of you. Where providers and deployers previously had to ensure, to their best extent, a sufficient level of AI literacy, they must now take measures to support the development of AI literacy, with an explicit clarification that this does not require them to guarantee any specific level for any individual. That is a shift from an obligation of result to an obligation of effort.

Read either change as permission to stand down and you have misread which law was ever going to reach you first. Human oversight of automated decisions, prohibited-practice screening and transparency are all live today, under the General Data Protection Regulation and under Articles 5 and 50 of the AI Act. The conformity-assessment machinery is what moved. Build the first, re-plan the second.

The quick guide

Do these now

All three conditions are already true for each one: the law applies, regulators are enforcing it, and the fines are large.

  • Inventory every automated decision that affects a person's money, work or access to a service.

    Not every AI system. Every consequential automated decision, hand-coded rules included. GDPR Article 22 does not care whether the logic was learned or written.

  • Put a named human with authority to reverse in the loop, and tell the affected person they can contest.

    Uber was fined 824,990,000 euro in August 2026 for deactivating driver accounts without it.

  • Screen your existing estate against the Article 5 prohibitions.

    In force since February 2025. Workplace emotion recognition is the one most organisations forget they own.

  • Train the people who operate the systems, not the whole company.

    The Garante's own remedy language is that decisions be verified by adequately trained operators. That is a small, specific population.

Re-sequence these

Conformity assessments, technical documentation and registration for Annex III systems now sit against December 2027. Annex I product-embedded systems sit against August 2028. So does anything whose cost is dominated by harmonised standards that do not yet exist.

Do not defer these, even though they feel like paperwork

Article 50 transparency obligations for AI-generated content still applied from 2 August 2026, with only a short grace period for watermarking existing systems, running to 2 December 2026.

The framework: what actually gates you

The useful axis is not high-risk or not. It is enforced today or not, crossed with deferred by the Omnibus or not.

The top-right cell is empty, and that is the entire argument. Nothing currently generating enforcement action against European deployers was postponed.
Not deferredDeferred
Enforced todayGDPR Article 22; AI Act Article 5Nothing
Not yet enforcedAI Act Article 50; Article 4, softenedAnnex III, December 2027; Annex I, August 2028

Why not simply move the programme eighteen months

That is the obvious alternative, and two pieces of evidence say no.

First, the file is contested rather than settled. Parliament adopted the agreement on 16 June 2026 by 423 votes to 57, with 174 abstentions. Planning on the assumption that deferral is the direction of travel is a bet on politics, not on law.

Second, and this is where the usual talent framing comes apart, the skills gap is real but it is being measured on a very small base. Eurostat reports that among EU enterprises which considered AI and decided against it, 70.9 percent cited lack of relevant expertise, the single largest obstacle, ahead of legal uncertainty at 52.5 percent and data-protection concerns at 48.8 percent. But only 19.95 percent of EU enterprises used AI at all in 2025. Measured across all enterprises in scope rather than that subgroup, Eurostat puts the same expertise barrier at 7.76 percent. Anyone quoting the first number as though it describes European industry is inflating a subgroup share into a population one.

There is a more uncomfortable reading of the skills data, and our view is that it is closer to true. Deloitte’s 2026 survey of 3,235 director-to-C-suite respondents states flatly that insufficient worker skills are seen as the biggest barrier to integrating AI into the business, and attaches no percentage to it at all. The same survey found that 84 percent of companies have not redesigned jobs or the nature of work around AI capabilities, and only 25 percent have moved 40 percent or more of their experiments into production. That is an operating-model failure being reported as a skills failure, and training will not fix a workflow nobody redesigned.

Deutsche Telekom sequenced it the other way round

Deutsche Telekom has run AI training since 2018, and the numbers are staged rather than announced all at once: 66,000 employees took AI training courses in 2023; 30,000 were trained in prompting in 2024 and again in 2025; its growth hub platform had 110,000 registered users at its November 2025 launch; and there were 52,000 participations in AI sessions through its Learning from Experts programme in 2025 alone.

The targets are the interesting part. Ninety percent of employees using AI tools regularly by 2026. One hundred percent with the skills to use AI confidently, responsibly and in a way that adds value by 2028, which is the year the Annex I obligations bite.

But the training is not the governance. Separately, Telekom built a risk-classification process with clear rules for the classification, evaluation and assessment of its AI systems, signed the EU AI Pact, and audited its estate against Article 5, publishing the result: no evidence of prohibited AI within the company or its products. Literacy at scale on a 2028 clock. Prohibited-practice screening, already done, against a 2025 clock. Two programmes, two deadlines, and that is the shape to copy.

Bosch has a harder number on the training side. Around 100,000 associates have completed AI Academy training, and its 18-month expert programme, a mid-five-figure investment per participant, returns ten times its cost in project value within five years on Bosch’s own internal analysis. That is company-reported and not audited: direction, not a business case you can lift.

What the missing human costs: Foodinho, fined twice for the same gap

On 5 July 2021, Italy’s data protection authority fined Foodinho, the Glovo subsidiary, 2.6 million euro. Among the orders: give riders ways to challenge decisions made using the algorithm, and guarantee procedures protecting the right to obtain human intervention.

On 13 November 2024, the same authority fined the same company 5 million euro, affecting more than 35,000 riders. Riders still lacked the right to obtain human intervention, express their opinion and contest the decision. Automatic account blocks were communicated by a single standard message that did not tell riders they could contest it. The excellence score governing shift-booking priority had no human review. The remedy ordered was that algorithmic decisions be verified by adequately trained operators.

Three years, one instruction, nearly double the fine. That remedy, trained operators with authority to overrule a model, is Article 4 literacy plus Article 14 human oversight, arriving in 2021 through the GDPR. It has been enforceable in Europe the entire time.

The scale of what comes through this channel is now unmistakable. On 21 August 2026 the Dutch data protection authority fined Uber 824,990,000 euro for deactivating driver accounts through fully automated processes without adequate human review, the second largest GDPR fine ever issued. The conduct ran from 2018 to 2022. The case began with one French driver, deactivated in 2019, who gathered testimony from 170 others. Deputy chair Monique Verdier: a computer should not make decisions on its own that have such major consequences. Uber is appealing.

Not one euro of that was levied under the AI Act.

The direction of travel runs the other way too. In April 2022 Hungary’s authority fined a bank roughly 670,000 euro for running emotion analysis over recorded customer service calls. The bank had done a Data Protection Impact Assessment and had correctly identified the processing as high-risk profiling, but the assessment failed to present substantial solutions to address those risks. Workplace emotion recognition is now prohibited outright under Article 5. A 2022 fine became a 2025 ban, and it is worth assuming the same trajectory for anything sitting near the prohibition line today.

The capability worth building is the ability to say no

Two cases show what competent governance actually produces, and it is not always a launch.

Amsterdam spent roughly 535,000 euro, about 500,000 in-house plus a 35,000 euro Deloitte contract, building Smart Check, a welfare-application risk model. It did everything the responsible-AI playbook asks: excluded 15 demographic characteristics, avoided proxies such as postcode, reweighted training data to correct historical caseworker bias, consulted external groups. Pre-deployment testing in May 2022 showed the model was nearly twice as likely to wrongly flag applicants of non-Western nationality, and reweighting equalised that. Then the live pilot ran from March to November 2023 over about 1,600 applications, and the bias reversed. The system now wrongly flagged applicants with Dutch nationality, women, and applicants with children, and it did not beat caseworkers at finding actual fraud. Amsterdam stopped it.

Norway’s labour and welfare administration, NAV, took a sick-leave prediction model into the data protection authority’s regulatory sandbox. The exit report concluded NAV had a legal basis to use AI as decision support, but faced unresolved uncertainty over whether that basis permitted using personal data to develop the algorithm at all, and that proceeding would require a clear and explicit supplementary legal basis founded in legislation.

Both reached a no. Both reached it cheaply, early, and with a documented reason. The 535,000 euro no is the cheapest outcome in this article. That capability, stopping a project on evidence, is what the skills conversation is actually about, and no amount of prompting training delivers it.

Where each rule comes from

Rule in the quick guideThe case that paid for it
Inventory consequential automated decisions, not AI systemsUber, 824,990,000 euro under GDPR Article 22, with no AI Act involvement
Named human with authority to reverse; tell people they can contestFoodinho, ordered in 2021 and fined 5 million euro in 2024 for still not having it
Screen the existing estate against Article 5 prohibitionsDeutsche Telekom's published audit; the Hungarian bank's emotion analysis, fined 2022 and banned 2025
Train operators, not everyone, for the oversight dutyThe Garante's remedy: decisions verified by adequately trained operators
Broad literacy on the long clock, governance on the short oneDeutsche Telekom: 100 percent AI-competent by 2028, Article 5 audit already done
Build the capability to say no, and say it earlyAmsterdam at 535,000 euro; NAV's sandbox exit report
Do not defer Article 50 transparencyThe watermarking grace period ends 2 December 2026

Glossary

TermWhat it means
Digital OmnibusRegulation (EU) 2026/1744, published 24 July 2026 and in force from 27 July, which deferred the AI Act high-risk deadlines and rewrote Article 4
Annex IIIStandalone high-risk uses such as employment, credit and essential services; conformity obligations now apply from 2 December 2027
Annex IHigh-risk AI embedded in products already covered by EU product-safety law; obligations apply from 2 August 2028
Article 4The AI literacy duty, now to take measures supporting literacy rather than to guarantee any level of it
Article 5The prohibited-practices list, including workplace emotion recognition, in force since February 2025
Article 50Transparency duties for AI-generated content, applied from 2 August 2026 with watermarking grace to 2 December 2026
GDPR Article 22The right not to be subject to solely automated decisions with legal or similarly significant effects, in force since 2018
Conformity assessmentThe pre-market procedure demonstrating a high-risk system meets AI Act requirements, deferred by the Omnibus
DPIAData Protection Impact Assessment: the prior risk analysis required for high-risk processing under GDPR Article 35
Regulatory sandboxA supervised environment in which a regulator and an organisation test a system before deployment, as NAV did with Norway's authority

The closing point

The softening of Article 4 will be read by a lot of boards as the regulator conceding that AI literacy was overreach. It was not a concession about whether people need to understand these systems. It was a concession about whether a regulator can audit a level of understanding.

The requirement that someone competent reviews a consequential automated decision did not come from Article 4, has never depended on it, and is currently generating the largest privacy fines in Europe. Deutsche Telekom is training toward 2028 and audited against February 2025. That is the correct shape.

Sprint for the obligations that are already live. Walk, deliberately and with a written plan, toward December 2027.

Which of your automated decisions would survive an Article 22 review?

Most organisations can answer that for the systems they built and not for the ones they bought. We work with companies on exactly this: where the data and the decisions actually create leverage, what to build first, and how to sequence a programme against the deadlines that are live rather than the ones that moved.

Frequently asked questions

Did the Digital Omnibus delay the whole EU AI Act?

No. Regulation (EU) 2026/1744 deferred the high-risk chapter: Annex III standalone systems to 2 December 2027 and Annex I product-embedded systems to 2 August 2028. The Article 5 prohibitions, in force since February 2025, and the Article 50 transparency duties, applied from August 2026, were untouched.

Does the softened Article 4 mean AI literacy training is optional?

No. Article 4 became an obligation of effort rather than result, so a regulator will not audit a level of understanding. The separate requirement that a competent person reviews consequential automated decisions comes from GDPR Article 22 and has been enforceable since 2018.

What is the largest AI-related fine in Europe so far?

The Dutch data protection authority fined Uber 824,990,000 euro on 21 August 2026 for deactivating driver accounts through fully automated processes without adequate human review. It was issued under the GDPR, involved no AI Act provision, and Uber is appealing.

Which obligations should a European deployer build first?

The ones already enforced. Inventory consequential automated decisions, place a named human with authority to reverse in the loop, tell affected people they can contest, and screen the existing estate against the Article 5 prohibitions, which have applied since February 2025.

Is emotion recognition in the workplace still allowed in the EU?

No. It is a prohibited practice under Article 5 of the AI Act, in force since February 2025. Hungary fined a bank roughly 670,000 euro in 2022 for emotion analysis of customer service calls under the GDPR, three years before the outright ban arrived.

How much should we read into the AI skills gap statistics?

Less than the headline suggests. Eurostat's 70.9 percent expertise barrier is a share of enterprises that considered AI and declined, which is a subgroup of the 19.95 percent using AI at all. Measured across all in-scope enterprises the same barrier is 7.76 percent.

Sources

  1. 1.White & Case, EU AI Omnibus enters into force, amending the AI Act. Regulation (EU) 2026/1744, Official Journal 24 July 2026, in force 27 July 2026. whitecase.com/insight-alert/eu-ai-omnibus-enters-force-amending-ai-act
  2. 2.Council of the European Union, press release, 29 June 2026, Artificial Intelligence: Council gives final green light to simplify and streamline rules. The EUR-Lex entry is at eur-lex.europa.eu/eli/reg/2026/1744/oj; the consolidated text did not render, so article-level wording is cited to sources quoting it.
  3. 3.Law & Technology, AI literacy: the Digital Omnibus rewrites Article 4 of the AI Act. lawandtechnology.eu/en/ai-literacy-digital-omnibus-article-4-ai-act/
  4. 4.artificialintelligenceact.eu, Article 4: AI literacy. Unofficial consolidation maintained by the Future of Life Institute, not an EU source.
  5. 5.TechCrunch, 23 August 2026, Uber faces fine of nearly $1B over automated driver suspensions. The Dutch authority announced the fine on 21 August 2026 at 824,990,000 euro; its own release returned HTTP 403, so the decision is cited to press coverage. Uber is appealing.
  6. 6.Deutsche Telekom, The EU AI Act at Deutsche Telekom. Company self-disclosure, not independently audited.
  7. 7.Garante per la protezione dei dati personali, decision of 13 November 2024, Foodinho S.r.l. Italian original; quotations translated.
  8. 8.Gibson Dunn, EU AI Act Omnibus Agreement: Postponed High-Risk Deadlines and Other Key Changes.
  9. 9.European Parliament, Legislative Train Schedule, Digital Omnibus on AI. Plenary vote 16 June 2026: 423 in favour, 57 against, 174 abstentions.
  10. 10.Eurostat, Use of artificial intelligence in enterprises, Statistics Explained, 2025 reference year. The obstacle percentages describe only enterprises that considered AI and did not adopt it; Eurostat gives 7.76 percent for the same barrier measured across all in-scope enterprises.
  11. 11.Deloitte, State of AI in the Enterprise 2026. 3,235 director-to-C-suite respondents, 24 countries, fieldwork August to September 2025.
  12. 12.Deutsche Telekom, Corporate Responsibility Report 2025, Employee development. Targets exclude T-Mobile US. Company-reported.
  13. 13.Bosch, AI training: upskilling the workforce. The tenfold-return figure is Bosch internal analysis, company-reported and not independently audited.
  14. 14.A&O Shearman, Italian data protection authority fines 2 food delivery companies for non-compliant processing. Foodinho 2.6 million euro, 5 July 2021. Law firm summary; the 2021 Garante decisions were not opened.
  15. 15.DLA Piper Advocatus, April 2022, Record GDPR fine by the Hungarian data protection authority for the unlawful use of artificial intelligence. Neither the account nor the decision names the bank; the common attribution to Budapest Bank is unverified and not made here.
  16. 16.MIT Technology Review, 11 June 2025, Inside Amsterdam's high-stakes experiment to create fair welfare AI. Reported with Lighthouse Reports, which dates the shelving to autumn 2024; the pilot dates here are MIT Technology Review's.
  17. 17.Datatilsynet, NAV: prediction of the development of sick leave, regulatory sandbox exit report. The page does not state the sandbox dates, so none is asserted here.