The EU Delayed the AI Act. Five Things Still Land on Sunday.
TL;DR
The EU did delay the AI Act — but only the expensive half. Regulation (EU) 2026/1744 was published in the Official Journal on 24 July and entered into force on 27 July 2026. It moves stand-alone high-risk obligations to 2 December 2027 and embedded ones to 2 August 2028. It does not move Article 50, the transparency regime, which applies from Sunday 2 August 2026. Most UK manufacturers running AI on UK-only operations are outside the EU Act entirely — the ICO route is the one that reaches them. The clause worth reading twice is Annex III(4)(b): AI that allocates jobs to engineers or scores their performance is a high-risk worker-management system. Not exempt because it is "just scheduling." Start with where your admin time actually goes.
The headline that ran through June and July was "Europe blinks on AI." It was reported as a retreat, and in the trade press it was reported as though the whole thing had been kicked into 2027.
That is half the story, and it is the wrong half. The high-risk regime moved. The transparency regime did not. If you read the coverage and concluded you have another eighteen months, you have three days.
Here is what actually changed, sourced line by line, and — more usefully — whether any of it reaches a UK company at all. Because for a large share of the mid-market firms I work with, the honest answer is no, and almost nobody writing about this is willing to say so.
27 Jul 2026
Reg. (EU) 2026/1744 entered into force
OJ publication 24 July, +3 days
2 Aug 2026
Article 50 transparency applies
Unchanged by the Omnibus
2 Dec 2027
Annex III high-risk, stand-alone
Moved from 2 Aug 2026, +16 months
€15m / 3%
Ceiling for Article 50 breaches
Lower of the two for SMEs
What moved and what did not
The instrument is the Digital Omnibus on AI, formally Regulation (EU) 2026/1744, which amends the AI Act alongside the Basic Aviation Regulation and the Machinery Regulation. Political agreement landed on 7 May 2026, Parliament voted on 16 June, the Council adopted on 29 June, and it was published in the Official Journal on 24 July. It came into force on the third day after publication — 27 July 2026.
That timing matters more than it looks. Analyses written before adoption carried a caveat that the changes had to clear the Official Journal before 2 August to take effect at all. That condition was met, with six days to spare. The deferral is real and it is law.
After Regulation (EU) 2026/1744, in force 27 July 2026
| Obligation | Original date | Date now | Deferred? |
|---|---|---|---|
| Prohibited practices (Art 5) | 2 Feb 2025 | 2 Feb 2025 | No — in force |
| AI literacy (Art 4) | 2 Feb 2025 | 2 Feb 2025 | No — in force |
| General-purpose AI models (Arts 51–56) | 2 Aug 2025 | 2 Aug 2025 | No — in force |
| Transparency (Art 50) | 2 Aug 2026 | 2 Aug 2026 | No |
| Art 50(2) machine-readable marking — systems already on the market | 2 Aug 2026 | 2 Dec 2026 | Grace period |
| High-risk, stand-alone (Annex III) | 2 Aug 2026 | 2 Dec 2027 | Yes, +16 months |
| High-risk, embedded in regulated products (Annex I) | — | 2 Aug 2028 | Yes |
| New Art 5 prohibition — CSAM / non-consensual intimate imagery | — | In force; safeguards by 2 Dec 2026 | New |
Sources: Regulation (EU) 2026/1744, OJ 24 July 2026. Timetable cross-checked against Gibson Dunn, Freshfields and Jones Walker analyses, 28 July 2026.
The reason for the deferral is worth knowing, because it tells you something the headline does not. The obligations were not softened on their merits. They moved because the machinery to comply with them was not built: member states had not designated national competent authorities, and the harmonised standards and conformity-assessment tools that high-risk compliance depends on were unfinished. The deadline moved to meet the tooling.
That is a different signal from "the EU has changed its mind." Nothing was dropped. It was rescheduled.
Article 50, in plain English
Article 50 is the part that starts on Sunday, and it splits along a line most summaries blur — some of it binds whoever builds the system, some binds whoever uses it. If you buy AI rather than build it, the deployer paragraphs are your paragraphs.
If you provide the system:
- 50(1) — where an AI system interacts with people, they have to be told they are dealing with AI. There is a real exemption: not required where it is already obvious to a reasonably well-informed, observant person.
- 50(2) — systems generating synthetic audio, image, video or text must mark their outputs in a machine-readable format, detectable as artificially generated. Assistive editing and minor alterations are carved out.
If you deploy the system:
- 50(3) — using emotion recognition or biometric categorisation means telling the people exposed to it, and complying with data protection law on top.
- 50(4) — deepfakes must be disclosed as artificially generated. And AI-generated text published on matters of public interest must be disclosed as such.
- 50(5) — disclosure has to be clear, distinguishable, and made no later than the first interaction or exposure. Not buried in a footer, not on page four of the terms.
Which duties are yours depends on whether you built it or bought it
If you provide the system
You built it, or you put your name on it
If you deploy the system
You bought it and use it — most readers of this post
Article 50 of Regulation (EU) 2024/1689 (the AI Act) as amended by Regulation (EU) 2026/1744. Provider and deployer allocation per the article text; verified 28 July 2026. Applies from 2 August 2026, except the 50(2) marking duty for systems already on the market, which runs to 2 December 2026.
That second half of 50(4) is the one that catches people, and it also contains the escape hatch nobody reads to the end of. The disclosure duty for AI-generated public-interest text does not apply where the content has undergone human review or editorial control and a person holds editorial responsibility for it.
Read that as a governance requirement rather than a technical one. A manufacturer publishing AI-drafted market commentary, spec explainers or thought-leadership with a named human who reviews and owns it is outside the duty. The same manufacturer auto-publishing straight from a model is inside it. The difference is not the tool. It is whether anyone signed off.
There is one grace period, and it is narrow. For systems placed on the market before 2 August 2026, the provider-side marking duty under 50(2) — and only that duty — runs to 2 December 2026. Everything else in Article 50 starts on Sunday.
The clause that covers your dispatch software
Now the part that got deferred, because deferred is not the same as gone, and this one lands inside the life of a contract you might sign this quarter.
Annex III lists the stand-alone high-risk categories. Point 4 covers employment and worker management, and it classifies as high-risk:
- (a) recruitment and selection — targeted job advertising, filtering applications, evaluating candidates;
- (b) decisions affecting the terms of work-related relationships, promotion and termination, allocation of tasks based on individual behaviour or personal traits or characteristics, and monitoring and evaluating performance and behaviour.
Read 4(b) again with a field-service operation in mind.
Software that assigns jobs to engineers based on how they have performed on past jobs is allocating tasks on the basis of individual behaviour. A dashboard that scores engineers on first-time-fix rate and surfaces the ranking to a manager is monitoring and evaluating performance. Both sit in Annex III point 4(b). Neither is exempt for being "just scheduling" or "just reporting," and the vendor's marketing page describing it as optimisation does not change the classification.
The procurement consequence
Annex III obligations now apply from 2 December 2027. A three-year field-service platform contract signed in 2026 runs straight through that date. The question to put to a vendor today is not "are you compliant" — nobody is, because the harmonised standards are not finished. It is: what is your plan for December 2027, is it in the roadmap or a paid module, and who carries the conformity assessment burden, you or me? Get the answer in the contract, not the sales deck.
But does any of this reach you?
Here is where most coverage of the AI Act stops being useful, because manufacturing urgency is easier than doing the scoping work.
The Act's scope provision reaches organisations that place AI systems on the EU market or put them into service in the EU, regardless of where the organisation is established, and extends to providers and deployers outside the EU where the output of the system is used in the EU. Being a UK company is not a defence.
But being a UK company is also not, by itself, an inclusion. If you manufacture in Birmingham, sell to UK customers, and run an AI model over your own job sheets to cut admin time, no output of that system is used in the EU and nothing is placed on the EU market. You are outside the AI Act.
Does the EU AI Act reach your system?
Do you sell the AI system, or a product containing it, into the EU?
1If yes, you are a provider placing a system on the EU market. In scope. This includes embedding AI in machinery you export.
Do you have an EU establishment that uses it?
2An EU subsidiary, branch or site deploying the system puts that deployment in scope, even where the system was built in the UK.
Is the system's output used in the EU?
3The subtle one. Output produced in the UK but relied on by people in the EU — an EU-based customer, an EU distributor acting on your AI-generated allocations — can pull you in.
None of the above?
4You are outside the AI Act. Your obligations are UK ones — UK GDPR, the Data (Use and Access) Act 2025, and forthcoming ICO expectations. Those are covered below, and for most UK-only mid-market operations they are the ones that actually bite.
I am not making a case for complacency. I am making a case against spending a compliance budget on a regime that does not apply to you while ignoring the one that does.
The UK picture
The UK has no AI Act and no plan for one. The approach stayed sector-led: existing regulators — the ICO, FCA, Ofcom, CMA, MHRA — applying cross-sector principles inside their own frameworks. For most manufacturers and field-service businesses, that means the ICO, and it means data protection law rather than product law.
Two developments matter.
The statutory duty exists; the code does not yet. The Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026, SI 2026/425, require the Commissioner to prepare a code of practice on good practice in processing personal data in relation to developing and using AI, and to automated decision-making — extending to children's personal data. The Regulations come into force 21 days after the day they were laid (reported as 12 May 2026; the instrument itself fixes no calendar date).
The distinction that gets lost: this creates the duty to write a code. The code itself has not been published. Anyone telling you there is now a binding UK AI code of practice to comply with is ahead of the facts.
ICO guidance on automated decision-making is close. The ICO consulted on updated draft guidance on automated decision-making and profiling, reflecting the changes the Data (Use and Access) Act 2025 made to the ADM rules. That consultation closed on 29 May 2026, and the final guidance is due Winter 2026 — not summer, as several secondary write-ups have it. The ICO has flagged transparency, explainability, bias mitigation and redress as its focus areas, and is setting expectations specifically around automated decision-making in recruitment.
Which closes a loop. A UK manufacturer using AI to filter job applications faces ICO expectations on that use now, whether or not the EU Act ever reaches it. The EU calls it Annex III point 4(a). The ICO calls it automated decision-making in recruitment. Same activity, two regimes, and the UK one has no 2027 deferral attached.
Penalties, stated properly
The tiers under Article 99:
| Infringement | Maximum |
|---|---|
| Prohibited practices (Art 5) | €35,000,000 or 7% of total worldwide annual turnover, whichever is higher |
| Other obligations, including Article 50 and deployer duties | €15,000,000 or 3%, whichever is higher |
| Supplying incorrect or misleading information to authorities | €7,500,000 or 1%, whichever is higher |
Now the part that routinely gets cut, and whose omission misrepresents the risk for exactly the companies reading this: for SMEs, including start-ups, each fine is capped at the percentage or the amount, whichever is lower.
For a large multinational the ceiling is the higher of the two, which is where the frightening €35m headline comes from. For a mid-market UK manufacturer it inverts. On a £40m turnover business, an Article 50 breach is bounded by 3% of turnover rather than €15m. Still serious. Not existential, and not what the headlines describe.
What to actually do this week
A four-item scoping exercise, not a compliance programme
Inventory where AI touches a customer or a worker
01Not every model in the business — only the ones that speak to a person, generate published content, allocate work, or evaluate someone. That list is usually much shorter than people expect, and it is the whole scope of your exposure under both regimes.
Name a human editorial owner for AI-assisted public content
02The cheapest control on this list. A named reviewer with editorial responsibility takes AI-generated public-interest text outside the Article 50(4) disclosure duty. Write it into the publishing process, not into a policy document nobody opens.
Check your chat and voice interfaces for a disclosure
03Article 50(1) applies from Sunday. If a customer can talk to something on your site or your phone system that is AI, they need to know at first contact — unless it is genuinely obvious. If you are relying on 'obvious', have someone outside the project judge that, not the person who built it.
Put December 2027 into platform procurement
04Any field-service, workforce-management or scheduling platform you are buying now will be live when Annex III bites. Ask who carries conformity assessment and whether compliance is roadmap or upsell. Get it answered before signature.
The through-line here is the same one that runs through why AI projects fail: the hard part is almost never the model. It is knowing which of your processes the thing is actually touching. Firms that can answer "where does AI touch a person in this business" in an afternoon will find this regulation mostly administrative. Firms that cannot are going to discover their exposure the expensive way — not because the law is harsh, but because they cannot see their own operations clearly enough to scope it.
That is a process-visibility problem wearing a compliance costume. It usually is.
This is not legal advice
Ell Advisory is an operations and AI consultancy, not a law firm. Everything above is sourced to the instrument, the Official Journal, legislation.gov.uk or the ICO, and was verified on 28 July 2026 — but scope questions under the AI Act turn on specifics that a blog post cannot assess. If you have concluded you may be in scope, take qualified legal advice on that conclusion before acting on it.
Where to start
The scoping exercise above takes an afternoon and needs no lawyer: find every place AI touches a customer or a worker. That is the same inventory that tells you where your admin time is going, which is why we built the hidden waste audit around it. If you would rather walk through your own operation with someone, book a call.
Related reading
- Why 70% of AI Projects Fail — And What the 30% Do Differently
- The UK Manufacturing Productivity Gap: 40 Statistics
- Ghost Workflows: The Hidden Manual Tasks Nobody Owns
- Why AI Fails Differently in Manufacturing, Logistics and Services
- The 2026 UK Manufacturing AI Adoption Report
Frequently Asked Questions
Has the EU AI Act been delayed?
Partly. Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It defers stand-alone high-risk obligations under Annex III to 2 December 2027, and high-risk AI embedded in already-regulated products to 2 August 2028. It does not defer the Article 50 transparency obligations, which apply from 2 August 2026, nor the prohibitions, AI literacy duty or general-purpose AI rules, which were already in force.
What applies from 2 August 2026?
Article 50, the transparency regime. Providers must disclose when a person is interacting with an AI system unless that is obvious, and must mark synthetic audio, image, video and text in a machine-readable format. Deployers must inform people exposed to emotion recognition or biometric categorisation, disclose deepfakes, and disclose AI-generated text published on matters of public interest unless it has had human review and a person holds editorial responsibility. Disclosure must be made no later than first interaction or exposure.
Is there any grace period?
One, and it is narrow. For AI systems placed on the market before 2 August 2026, the provider-side machine-readable marking duty under Article 50(2) — and only that duty — runs to 2 December 2026. Every other Article 50 obligation applies from 2 August 2026.
Does the EU AI Act apply to UK companies?
It can. The Act reaches organisations that place AI systems on the EU market or put them into service in the EU regardless of where they are established, and extends to providers and deployers outside the EU where the output of the system is used in the EU. A UK manufacturer that exports AI-enabled machinery, has an EU subsidiary using the system, or produces output relied on in the EU is in scope. A UK company running AI over its own operations for UK customers only is not.
Is AI scheduling software for field engineers high-risk?
Under Annex III point 4(b), AI used to allocate tasks on the basis of individual behaviour or personal traits, or to monitor and evaluate performance and behaviour, is high-risk. Dispatch software that assigns jobs to engineers based on past performance, and dashboards that score engineer productivity, fall inside that description. Those obligations now apply from 2 December 2027 rather than 2 August 2026.
What are the penalties under the EU AI Act?
Breaching the Article 5 prohibitions carries up to €35,000,000 or 7% of total worldwide annual turnover, whichever is higher. Other obligations, including Article 50 transparency and deployer duties, carry up to €15,000,000 or 3%, whichever is higher. Supplying incorrect or misleading information to authorities carries up to €7,500,000 or 1%. For SMEs including start-ups, each fine is capped at the percentage or the amount, whichever is lower — the inverse of the headline rule.
Does the UK have its own AI Act?
No. The UK approach remains sector-led, with existing regulators applying cross-sector principles. The Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026, SI 2026/425, require the Information Commissioner to prepare a code of practice on AI and automated decision-making, but that code has not yet been published. The ICO's updated guidance on automated decision-making and profiling, reflecting the Data (Use and Access) Act 2025, closed for consultation on 29 May 2026 and is due in Winter 2026.
Sources. Regulation (EU) 2026/1744, published in the Official Journal 24 July 2026, in force 27 July 2026 — via EU Law Live and lawandtechnology.eu. Timetable and Article 50 treatment cross-checked across Gibson Dunn, Freshfields and Jones Walker. Article 50, Article 99 and Annex III text via artificialintelligenceact.eu. UK instruments via legislation.gov.uk and the ICO. All URLs fetched and verified 28 July 2026.