Skip to content

Regulation

The AI Act was not delayed. Two of its dates were

The Digital Omnibus moved Annex III to December 2027 and left three duties in force since 2025. Where automation lands, and who actually holds the duty.

Published
Reading
8 min
Based on
Regulation (EU) 2024/1689 as amended by the Digital Omnibus on AI, applicable 27 July 2026 — article-level reading, not legal advice; boundary at the end

A management team reads that the AI Act has been pushed to 2028 and closes the workstream. Two floors down, HR is trialling a CV-ranking tool that sits inside Annex III, and a Dynamics update has switched on three AI features nobody classified because nobody knew they arrived.

None of that is a breach today. Some of it will be — and not on the dates in the decision that closed the file.

“Delayed” is true of two dates and false of the three already in force

The Digital Omnibus on AI has applied since 27 July 2026 and amended 42 articles and 3 annexes of Regulation (EU) 2024/1689. Any deck citing 2 August 2026 as the high-risk date is out of date.

What moved: standalone Annex III high-risk obligations to 2 December 2027; high-risk AI embedded in Annex I regulated products to 2 August 2028; Article 6(1) obligations to 2 August 2027; regulatory sandboxes to 2 August 2027. Article 50 transparency and synthetic-content marking moved from 2 August 2026 to 2 December 2026 — four months, not four years.

What did not move: the Article 5 prohibitions, in force since 2 February 2025. Article 4 AI literacy, same date, binding on providers and deployers. GPAI obligations under Articles 51–55, since 2 August 2025.

The reason matters, because it says whether to expect another slip: CEN-CENELEC JTC 21 has not published the four harmonised standards carrying presumption of conformity. The compliance route was not buildable yet. Nobody re-scored the risk.

Most business automation is minimal-risk; the exception is usually already in HR

Invoice extraction, warehouse slotting, demand forecasting, an internal RAG assistant over your own documentation — minimal risk, no tier-specific obligations beyond Article 4 literacy and whatever GDPR already demanded. That is the honest answer for most of what a mid-market company automates.

Annex III lists eight domains: biometrics, critical infrastructure, education and vocational training, employment and worker management, access to essential private and public services, law enforcement, migration and border control, administration of justice. Three reach ordinary firms that have never touched a public tender.

Employment, point 4, is the one that surprises people: CV screening and ranking, task allocation, decisions on promotion and termination, monitoring or evaluating performance and behaviour. A team that enabled a “smart ranking” toggle in an existing ATS acquired an Annex III system without a procurement decision, a classification, or a file.

Point 5 captures creditworthiness evaluation and risk pricing for life and health insurance. Point 3 captures admissions, evaluation of learning outcomes and exam monitoring — which reaches training providers, not only schools. Emotion inference sits under biometrics and surfaces quietly inside contact-centre analytics. And vendors enable AI features by default in Dynamics, Salesforce, ServiceNow and Zendesk releases: an inventory listing only what you commissioned is already wrong.

Article 6(3) is a genuine exit and a public filing

Appearing in Annex III does not settle classification. Article 6(3) allows a system to be assessed as not high-risk where it poses no significant risk to health, safety or fundamental rights and does one of exactly four things: a narrow procedural task; an improvement to the result of a previously completed human activity; detection of decision-making patterns or deviations without replacing or influencing the human assessment; or a preparatory task to an assessment.

Two conditions on that route get skipped in practice.

Profiling of natural persons is always high-risk — no derogation, however narrow the task looks.

And Article 49(2) requires a self-assessed non-high-risk Annex III system to be registered in the public EU database. The “we concluded it is not high-risk” note is not an internal memo — it is a searchable filing with your name on it. Write it to that standard: name the condition relied on, keep the reasoning legible to someone hostile.

Provider versus deployer is the distinction most summaries get wrong

A provider develops an AI system, or has one developed, and places it on the market under its own name or trademark. A deployer uses one under its own authority. Most companies are deployers, and Article 26 duties are concrete and unglamorous:

  • Use the system per its instructions for use, and assign human oversight to named people with the competence, training and authority to actually stop it.
  • Ensure input data is relevant and sufficiently representative for the intended purpose — the one substantive duty entirely inside the deployer’s control.
  • Retain automatically generated logs for at least six months under Article 26(6), configured in the live platform rather than promised in a policy.
  • Inform workers and their representatives before workplace use under Article 26(7) — an HR and works-council step with a lead time, not a checklist item.

A deployer becomes a provider — with the Annex IV technical file and conformity assessment that implies — in three ways: putting its own name or trademark on a high-risk system, changing the intended purpose of one already on the market, or substantially modifying it. Fine-tuning a vendor model on internal data and shipping it under your own product name is the common accidental route.

Deployer compliance also inherits from the quality of the provider’s Article 13 instructions for use: if a vendor cannot produce them, its customer cannot satisfy Article 26. Demand them before signature, not after go-live.

Article 50 is the nearest date and it lands on marketing

2 December 2026. Article 50 requires that people are told when they are interacting with an AI system unless it is obvious from context; that synthetic audio, image, video and text is marked machine-readably as artificially generated; and that deep fakes and AI-generated text published to inform the public on matters of public interest are labelled.

In practice: the website chatbot, the voice agent on the support line, generated imagery in campaigns. Cheap to comply with, conspicuous to be caught ignoring, and a full year ahead of Annex III.

The enforcement machinery is behind the obligations, in Bulgaria more than most

Article 27 adds a Fundamental Rights Impact Assessment for public bodies, private entities providing public services, and users of credit-scoring or life/health-insurance pricing systems: deployment context, frequency of use, affected groups, specific harms, human oversight as implemented, complaint mechanism — notified to the market surveillance authority, distinct from a GDPR DPIA.

Article 99 penalties: up to €35M or 7% of worldwide annual turnover for prohibited practices; €15M or 3% for provider and deployer obligations under Articles 16, 22–26, 31, 33–34 and 50; €7.5M or 1% for supplying misleading information to authorities. For SMEs and start-ups the fine is the lower of the fixed amount and the percentage, not the higher — a reliable test of whether an adviser read Article 99 or a summary of it.

In Bulgaria the Ministry of Electronic Governance leads, and Council of Ministers Decision No. 398 of 18 June 2025 designated seven fundamental-rights bodies including the Ombudsman and the Commission for Personal Data Protection. As of early 2026 there was still no national sanctions regime and no designated market surveillance authority for high-risk systems. Obligations attach on the Regulation’s timetable regardless, and the machinery will exist well before December 2027. Non-enforcement is not non-liability — it is a queue that has not started moving.

Where this stops applying

This is a reading of the Regulation, not legal advice. Classification at the margin — whether a screening tool influences a human assessment, whether a change is a substantial modification — is a lawyer’s call, and the honest move is to buy an hour of one rather than write a confident memo.

The work that takes time is not the paperwork. It is the inventory, and it is incomplete everywhere: MIT’s Project NANDA found roughly 40% of surveyed companies had bought an official LLM subscription while workers at over 90% reported regular personal AI use for work. You cannot classify what nobody has admitted to using.

And the boundary about us. Palamed has four deliverable engagements: a European car marketplace with 300,000+ listings, a platform for an AI automation agency, the Ministry of Education and Science dictionary at beron.mon.bg, and email automation for a beauty brand. None is a high-risk system — the dictionary is a search interface over an editorial corpus, exactly the determination worth writing down rather than assuming. We have not taken a client through an Annex III conformity assessment or filed an Article 49(2) registration. If a bidder tells you it is all delayed to 2028, ask which article governs your system and from what date.

Abstract warm light on a dark field

Is this the problem you are living with?

If this article describes your situation, the fastest next step is a call with the person who wrote it.

30 minutes, no obligation, and you keep whatever we work out.