ELL ADVISORY

The EU Delayed the AI Act. Five Things Still Land on Sunday.

Fawad Bhatti, Founder of Ell Advisory
Founder, Ell Advisory · Ex-Hilti Principal PM · HEC Paris MBA
22 min read

TL;DR

The EU did delay the AI Act — but only the expensive half. Regulation (EU) 2026/1744 was published in the Official Journal on 24 July and entered into force on 27 July 2026. It moves stand-alone high-risk obligations to 2 December 2027 and embedded ones to 2 August 2028. It does not move Article 50, the transparency regime, which applies from Sunday 2 August 2026. Most UK manufacturers running AI on UK-only operations are outside the EU Act entirely — the ICO route is the one that reaches them. The clause worth reading twice is Annex III(4)(b): AI that allocates jobs to engineers or scores their performance is a high-risk worker-management system. Not exempt because it is "just scheduling." Start with where your admin time actually goes.

The headline that ran through June and July was "Europe blinks on AI." It was reported as a retreat, and in the trade press it was reported as though the whole thing had been kicked into 2027.

That is half the story, and it is the wrong half. The high-risk regime moved. The transparency regime did not. If you read the coverage and concluded you have another eighteen months, you have three days.

Here is what actually changed, sourced line by line, and — more usefully — whether any of it reaches a UK company at all. Because for a large share of the mid-market firms I work with, the honest answer is no, and almost nobody writing about this is willing to say so.

27 Jul 2026

Reg. (EU) 2026/1744 entered into force

OJ publication 24 July, +3 days

2 Aug 2026

Article 50 transparency applies

Unchanged by the Omnibus

2 Dec 2027

Annex III high-risk, stand-alone

Moved from 2 Aug 2026, +16 months

€15m / 3%

Ceiling for Article 50 breaches

Lower of the two for SMEs

What moved and what did not

The instrument is the Digital Omnibus on AI, formally Regulation (EU) 2026/1744, which amends the AI Act alongside the Basic Aviation Regulation and the Machinery Regulation. Political agreement landed on 7 May 2026, Parliament voted on 16 June, the Council adopted on 29 June, and it was published in the Official Journal on 24 July. It came into force on the third day after publication — 27 July 2026.

That timing matters more than it looks. Analyses written before adoption carried a caveat that the changes had to clear the Official Journal before 2 August to take effect at all. That condition was met, with six days to spare. The deferral is real and it is law.

EU AI Act — obligation timetable

After Regulation (EU) 2026/1744, in force 27 July 2026

ObligationOriginal dateDate nowDeferred?
Prohibited practices (Art 5)2 Feb 20252 Feb 2025No — in force
AI literacy (Art 4)2 Feb 20252 Feb 2025No — in force
General-purpose AI models (Arts 51–56)2 Aug 20252 Aug 2025No — in force
Transparency (Art 50)2 Aug 20262 Aug 2026No
Art 50(2) machine-readable marking — systems already on the market2 Aug 20262 Dec 2026Grace period
High-risk, stand-alone (Annex III)2 Aug 20262 Dec 2027Yes, +16 months
High-risk, embedded in regulated products (Annex I)2 Aug 2028Yes
New Art 5 prohibition — CSAM / non-consensual intimate imageryIn force; safeguards by 2 Dec 2026New

Sources: Regulation (EU) 2026/1744, OJ 24 July 2026. Timetable cross-checked against Gibson Dunn, Freshfields and Jones Walker analyses, 28 July 2026.

The reason for the deferral is worth knowing, because it tells you something the headline does not. The obligations were not softened on their merits. They moved because the machinery to comply with them was not built: member states had not designated national competent authorities, and the harmonised standards and conformity-assessment tools that high-risk compliance depends on were unfinished. The deadline moved to meet the tooling.

That is a different signal from "the EU has changed its mind." Nothing was dropped. It was rescheduled.

Article 50, in plain English

Article 50 is the part that starts on Sunday, and it splits along a line most summaries blur — some of it binds whoever builds the system, some binds whoever uses it. If you buy AI rather than build it, the deployer paragraphs are your paragraphs.

If you provide the system:

  • 50(1) — where an AI system interacts with people, they have to be told they are dealing with AI. There is a real exemption: not required where it is already obvious to a reasonably well-informed, observant person.
  • 50(2) — systems generating synthetic audio, image, video or text must mark their outputs in a machine-readable format, detectable as artificially generated. Assistive editing and minor alterations are carved out.

If you deploy the system:

  • 50(3) — using emotion recognition or biometric categorisation means telling the people exposed to it, and complying with data protection law on top.
  • 50(4) — deepfakes must be disclosed as artificially generated. And AI-generated text published on matters of public interest must be disclosed as such.
  • 50(5) — disclosure has to be clear, distinguishable, and made no later than the first interaction or exposure. Not buried in a footer, not on page four of the terms.
Exhibit 2 — Article 50, split by who it binds

Which duties are yours depends on whether you built it or bought it

If you provide the system

You built it, or you put your name on it

50(1)Tell people they are interacting with AI — unless it is obvious to a reasonably well-informed, observant person.
50(2)Mark synthetic audio, image, video and text in a machine-readable format. Assistive editing and minor alterations carved out.

If you deploy the system

You bought it and use it — most readers of this post

50(3)Using emotion recognition or biometric categorisation: inform the people exposed, and comply with data protection law.
50(4)Disclose deepfakes. Disclose AI-generated text on matters of public interest — unless a named human reviewed it and holds editorial responsibility.
50(5)Disclosure must be clear and made no later than first interaction or exposure.

Article 50 of Regulation (EU) 2024/1689 (the AI Act) as amended by Regulation (EU) 2026/1744. Provider and deployer allocation per the article text; verified 28 July 2026. Applies from 2 August 2026, except the 50(2) marking duty for systems already on the market, which runs to 2 December 2026.

That second half of 50(4) is the one that catches people, and it also contains the escape hatch nobody reads to the end of. The disclosure duty for AI-generated public-interest text does not apply where the content has undergone human review or editorial control and a person holds editorial responsibility for it.

Read that as a governance requirement rather than a technical one. A manufacturer publishing AI-drafted market commentary, spec explainers or thought-leadership with a named human who reviews and owns it is outside the duty. The same manufacturer auto-publishing straight from a model is inside it. The difference is not the tool. It is whether anyone signed off.

There is one grace period, and it is narrow. For systems placed on the market before 2 August 2026, the provider-side marking duty under 50(2) — and only that duty — runs to 2 December 2026. Everything else in Article 50 starts on Sunday.

The clause that covers your dispatch software

Now the part that got deferred, because deferred is not the same as gone, and this one lands inside the life of a contract you might sign this quarter.

Annex III lists the stand-alone high-risk categories. Point 4 covers employment and worker management, and it classifies as high-risk:

  • (a) recruitment and selection — targeted job advertising, filtering applications, evaluating candidates;
  • (b) decisions affecting the terms of work-related relationships, promotion and termination, allocation of tasks based on individual behaviour or personal traits or characteristics, and monitoring and evaluating performance and behaviour.

Read 4(b) again with a field-service operation in mind.

Software that assigns jobs to engineers based on how they have performed on past jobs is allocating tasks on the basis of individual behaviour. A dashboard that scores engineers on first-time-fix rate and surfaces the ranking to a manager is monitoring and evaluating performance. Both sit in Annex III point 4(b). Neither is exempt for being "just scheduling" or "just reporting," and the vendor's marketing page describing it as optimisation does not change the classification.

The procurement consequence

Annex III obligations now apply from 2 December 2027. A three-year field-service platform contract signed in 2026 runs straight through that date. The question to put to a vendor today is not "are you compliant" — nobody is, because the harmonised standards are not finished. It is: what is your plan for December 2027, is it in the roadmap or a paid module, and who carries the conformity assessment burden, you or me? Get the answer in the contract, not the sales deck.

But does any of this reach you?

Here is where most coverage of the AI Act stops being useful, because manufacturing urgency is easier than doing the scoping work.

The Act's scope provision reaches organisations that place AI systems on the EU market or put them into service in the EU, regardless of where the organisation is established, and extends to providers and deployers outside the EU where the output of the system is used in the EU. Being a UK company is not a defence.

But being a UK company is also not, by itself, an inclusion. If you manufacture in Birmingham, sell to UK customers, and run an AI model over your own job sheets to cut admin time, no output of that system is used in the EU and nothing is placed on the EU market. You are outside the AI Act.

Does the EU AI Act reach your system?

Do you sell the AI system, or a product containing it, into the EU?

1

If yes, you are a provider placing a system on the EU market. In scope. This includes embedding AI in machinery you export.

Do you have an EU establishment that uses it?

2

An EU subsidiary, branch or site deploying the system puts that deployment in scope, even where the system was built in the UK.

Is the system's output used in the EU?

3

The subtle one. Output produced in the UK but relied on by people in the EU — an EU-based customer, an EU distributor acting on your AI-generated allocations — can pull you in.

None of the above?

4

You are outside the AI Act. Your obligations are UK ones — UK GDPR, the Data (Use and Access) Act 2025, and forthcoming ICO expectations. Those are covered below, and for most UK-only mid-market operations they are the ones that actually bite.

I am not making a case for complacency. I am making a case against spending a compliance budget on a regime that does not apply to you while ignoring the one that does.

The UK picture

The UK has no AI Act and no plan for one. The approach stayed sector-led: existing regulators — the ICO, FCA, Ofcom, CMA, MHRA — applying cross-sector principles inside their own frameworks. For most manufacturers and field-service businesses, that means the ICO, and it means data protection law rather than product law.

Two developments matter.

The statutory duty exists; the code does not yet. The Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026, SI 2026/425, require the Commissioner to prepare a code of practice on good practice in processing personal data in relation to developing and using AI, and to automated decision-making — extending to children's personal data. The Regulations come into force 21 days after the day they were laid (reported as 12 May 2026; the instrument itself fixes no calendar date).

The distinction that gets lost: this creates the duty to write a code. The code itself has not been published. Anyone telling you there is now a binding UK AI code of practice to comply with is ahead of the facts.

ICO guidance on automated decision-making is close. The ICO consulted on updated draft guidance on automated decision-making and profiling, reflecting the changes the Data (Use and Access) Act 2025 made to the ADM rules. That consultation closed on 29 May 2026, and the final guidance is due Winter 2026 — not summer, as several secondary write-ups have it. The ICO has flagged transparency, explainability, bias mitigation and redress as its focus areas, and is setting expectations specifically around automated decision-making in recruitment.

Which closes a loop. A UK manufacturer using AI to filter job applications faces ICO expectations on that use now, whether or not the EU Act ever reaches it. The EU calls it Annex III point 4(a). The ICO calls it automated decision-making in recruitment. Same activity, two regimes, and the UK one has no 2027 deferral attached.

Penalties, stated properly

The tiers under Article 99:

InfringementMaximum
Prohibited practices (Art 5)€35,000,000 or 7% of total worldwide annual turnover, whichever is higher
Other obligations, including Article 50 and deployer duties€15,000,000 or 3%, whichever is higher
Supplying incorrect or misleading information to authorities€7,500,000 or 1%, whichever is higher

Now the part that routinely gets cut, and whose omission misrepresents the risk for exactly the companies reading this: for SMEs, including start-ups, each fine is capped at the percentage or the amount, whichever is lower.

For a large multinational the ceiling is the higher of the two, which is where the frightening €35m headline comes from. For a mid-market UK manufacturer it inverts. On a £40m turnover business, an Article 50 breach is bounded by 3% of turnover rather than €15m. Still serious. Not existential, and not what the headlines describe.

What to actually do this week

A four-item scoping exercise, not a compliance programme

Inventory where AI touches a customer or a worker

01

Not every model in the business — only the ones that speak to a person, generate published content, allocate work, or evaluate someone. That list is usually much shorter than people expect, and it is the whole scope of your exposure under both regimes.

Name a human editorial owner for AI-assisted public content

02

The cheapest control on this list. A named reviewer with editorial responsibility takes AI-generated public-interest text outside the Article 50(4) disclosure duty. Write it into the publishing process, not into a policy document nobody opens.

Check your chat and voice interfaces for a disclosure

03

Article 50(1) applies from Sunday. If a customer can talk to something on your site or your phone system that is AI, they need to know at first contact — unless it is genuinely obvious. If you are relying on 'obvious', have someone outside the project judge that, not the person who built it.

Put December 2027 into platform procurement

04

Any field-service, workforce-management or scheduling platform you are buying now will be live when Annex III bites. Ask who carries conformity assessment and whether compliance is roadmap or upsell. Get it answered before signature.

The through-line here is the same one that runs through why AI projects fail: the hard part is almost never the model. It is knowing which of your processes the thing is actually touching. Firms that can answer "where does AI touch a person in this business" in an afternoon will find this regulation mostly administrative. Firms that cannot are going to discover their exposure the expensive way — not because the law is harsh, but because they cannot see their own operations clearly enough to scope it.

That is a process-visibility problem wearing a compliance costume. It usually is.

This is not legal advice

Ell Advisory is an operations and AI consultancy, not a law firm. Everything above is sourced to the instrument, the Official Journal, legislation.gov.uk or the ICO, and was verified on 28 July 2026 — but scope questions under the AI Act turn on specifics that a blog post cannot assess. If you have concluded you may be in scope, take qualified legal advice on that conclusion before acting on it.

Where to start

The scoping exercise above takes an afternoon and needs no lawyer: find every place AI touches a customer or a worker. That is the same inventory that tells you where your admin time is going, which is why we built the hidden waste audit around it. If you would rather walk through your own operation with someone, book a call.

Frequently Asked Questions

Has the EU AI Act been delayed?

Partly. Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It defers stand-alone high-risk obligations under Annex III to 2 December 2027, and high-risk AI embedded in already-regulated products to 2 August 2028. It does not defer the Article 50 transparency obligations, which apply from 2 August 2026, nor the prohibitions, AI literacy duty or general-purpose AI rules, which were already in force.

What applies from 2 August 2026?

Article 50, the transparency regime. Providers must disclose when a person is interacting with an AI system unless that is obvious, and must mark synthetic audio, image, video and text in a machine-readable format. Deployers must inform people exposed to emotion recognition or biometric categorisation, disclose deepfakes, and disclose AI-generated text published on matters of public interest unless it has had human review and a person holds editorial responsibility. Disclosure must be made no later than first interaction or exposure.

Is there any grace period?

One, and it is narrow. For AI systems placed on the market before 2 August 2026, the provider-side machine-readable marking duty under Article 50(2) — and only that duty — runs to 2 December 2026. Every other Article 50 obligation applies from 2 August 2026.

Does the EU AI Act apply to UK companies?

It can. The Act reaches organisations that place AI systems on the EU market or put them into service in the EU regardless of where they are established, and extends to providers and deployers outside the EU where the output of the system is used in the EU. A UK manufacturer that exports AI-enabled machinery, has an EU subsidiary using the system, or produces output relied on in the EU is in scope. A UK company running AI over its own operations for UK customers only is not.

Is AI scheduling software for field engineers high-risk?

Under Annex III point 4(b), AI used to allocate tasks on the basis of individual behaviour or personal traits, or to monitor and evaluate performance and behaviour, is high-risk. Dispatch software that assigns jobs to engineers based on past performance, and dashboards that score engineer productivity, fall inside that description. Those obligations now apply from 2 December 2027 rather than 2 August 2026.

What are the penalties under the EU AI Act?

Breaching the Article 5 prohibitions carries up to €35,000,000 or 7% of total worldwide annual turnover, whichever is higher. Other obligations, including Article 50 transparency and deployer duties, carry up to €15,000,000 or 3%, whichever is higher. Supplying incorrect or misleading information to authorities carries up to €7,500,000 or 1%. For SMEs including start-ups, each fine is capped at the percentage or the amount, whichever is lower — the inverse of the headline rule.

Does the UK have its own AI Act?

No. The UK approach remains sector-led, with existing regulators applying cross-sector principles. The Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026, SI 2026/425, require the Information Commissioner to prepare a code of practice on AI and automated decision-making, but that code has not yet been published. The ICO's updated guidance on automated decision-making and profiling, reflecting the Data (Use and Access) Act 2025, closed for consultation on 29 May 2026 and is due in Winter 2026.


Sources. Regulation (EU) 2026/1744, published in the Official Journal 24 July 2026, in force 27 July 2026 — via EU Law Live and lawandtechnology.eu. Timetable and Article 50 treatment cross-checked across Gibson Dunn, Freshfields and Jones Walker. Article 50, Article 99 and Annex III text via artificialintelligenceact.eu. UK instruments via legislation.gov.uk and the ICO. All URLs fetched and verified 28 July 2026.