§ AI Act · GDPR · NIS2 · DORA · DMA · ePrivacy Directive BRIEFING

The AI Act delay collapsed on April 28. The August 2 deadline is still law.

EU lawmakers wanted to push high-risk obligations to December 2027. The trilogue failed. Providers and deployers have 94 days.

Summary

The Digital Omnibus trilogue collapsed on 28 April 2026 over Annex I architecture disputes. The package would have moved high-risk AI Act obligations to December 2027 (Annex III) and August 2028 (Annex I). Without it, Article 6 high-risk requirements and Article 99 penalties take effect on 2 August 2026 as originally enacted.

A second attempt is scheduled for 13 May 2026. Until that succeeds — and any text that emerges still has to clear plenary and Council — the legal calendar has not moved. 743 AI Act obligations across 42 sectors are still on track for enforcement.

This briefing pulls the obligation map, conflict register and penalty tier directly from Fontvera's structured corpus. Every number below is the live count, not commentary.

Who this applies to
Providers, deployers, importers and distributors of high-risk AI systems under Article 6 — and any operator placing prohibited Article 5 systems on the EU market.
Compliance deadline
2 August 2026 — unchanged
§ Key articles

What the law says

Article 5
Prohibited AI practices. Highest penalty tier: up to €35,000,000 or 7% of total worldwide annual turnover.
Article 16
Provider obligations for high-risk AI systems. Up to €15,000,000 or 3% of worldwide turnover.
Article 26
Deployer obligations for high-risk AI systems. Up to €15,000,000 or 3% of worldwide turnover.
Article 50
Transparency obligations for AI systems interacting with humans, generative AI, deepfakes. Up to €15,000,000 or 3% of worldwide turnover.
Article 9
Risk management system across the entire lifecycle of a high-risk AI system. Enforced through Article 16 at €15,000,000 or 3%.
§ Detail

In depth

What happened on 28 April

The Digital Omnibus was the Commission and Council's vehicle to staircase AI Act high-risk enforcement: Annex III systems (employment, education, biometrics, critical infrastructure, essential services) would slip to December 2027; Annex I systems (regulated products — medical devices, machinery, automotive, toys) would slip to August 2028.

Trilogue broke down on the Annex I architecture. Member States wanted the staircase tied to existing sectoral conformity assessment cycles; Parliament negotiators argued that would re-open notified-body designations across MDR, IVDR, and the Machinery Regulation. With no compromise text, the file was kicked to the next round on 13 May 2026.

The legal effect of the failure is simple: the original 2 August 2026 date in Article 113(b) and the Article 99 penalty regime continue to apply. No grace period exists in the published text.

Why this matters — by the numbers Fontvera tracks

The Omnibus delay was widely treated as inevitable. It wasn't. Here is the obligation surface that just stayed in force, measured against Fontvera's structured corpus:

None of that surface area shrinks because the trilogue stalled. It just becomes enforceable on 2 August.

The four hard AI Act conflicts that did not get resolved

These are the conflicts a delay would have given Member States and the AI Office time to fix. They now arrive on 2 August in their current form. Each was extracted from primary text by Fontvera and is in the corpus today:

AI ActOther regulationSeverityWhat collides
Art 10GDPR Art 17HighAI Act allows processing of special category data for bias detection where strictly necessary; GDPR right to erasure can require its deletion once retention is no longer justified.
Art 19ePrivacy Art 6HighAI Act requires providers to retain automatically generated logs for at least six months; ePrivacy requires traffic data to be erased or anonymised once no longer needed for transmission.
Art 18DMA Art 5MediumAI Act mandates 10-year retention of technical documentation and logs; DMA forces gatekeepers to give real-time data and algorithm access on request.
Art 19GDPR Art 5MediumAI Act six-month log retention vs GDPR storage limitation principle requiring data is kept no longer than necessary.

What's at stake — the five highest-penalty obligations

From Fontvera's 743 mapped AI Act obligations, sorted by Article 99 penalty tier:

  1. Article 5 — Prohibited AI practices. Up to €35,000,000 or 7% of worldwide annual turnover, whichever is higher. Covers eight prohibited categories including subliminal manipulation, exploitation of vulnerabilities, social scoring, predictive policing, untargeted facial-image scraping, emotion inference at workplace and school, biometric categorisation by sensitive attributes, and real-time remote biometric identification in public spaces by law enforcement.
  2. Article 16 — Provider obligations for high-risk AI. Up to €15,000,000 or 3%. Covers conformity assessment, registration in the EU database, post-market monitoring, technical documentation, transparency to deployers and the Article 9 risk management system.
  3. Article 26 — Deployer obligations for high-risk AI. Up to €15,000,000 or 3%. Use the system per provider instructions, ensure human oversight, monitor operation, retain logs, and conduct fundamental rights impact assessments where Article 27 applies.
  4. Article 50 — Transparency obligations. Up to €15,000,000 or 3%. Disclose AI interaction to natural persons; label generative AI output as artificially generated; mark deepfakes; inform users of emotion recognition and biometric categorisation.
  5. Article 9 — Risk management system. Enforced through Article 16 at €15,000,000 or 3%. A continuous, iterative process across the entire lifecycle: hazard identification, residual-risk evaluation, mitigation testing, and updates from post-market monitoring.

Authorised representatives, importers, distributors and notified bodies sit on the same €15M / 3% tier under Articles 22, 23, 24 and 31/33 respectively. Supplying incorrect, incomplete or misleading information to authorities sits one rung lower at €7,500,000 or 1%.

What companies should actually do in the next 94 days

The work doesn't change because the delay failed. It just doesn't get optional any more. In order:

  1. Classify your systems against Article 5 and Annex III. Run Fontvera's free AI Act high-risk diagnostic to get a defensible classification with the specific articles that apply.
  2. Lock the four hard conflicts above into legal review now. They will not be resolved by 2 August. Decisions on log retention, special-category processing and deepfake disclosure should be made and documented before, not during, an enforcement inquiry.
  3. Pull your obligation list against the 743 we have mapped. Fontvera links every obligation to its source article, the obligated entity and the penalty tier. Search the corpus for your sector and entity role at the homepage.
  4. If you are a deployer relying on a non-EU provider: Article 22 means you may inherit authorised representative obligations. This is one of the four "high severity" gaps in the cross-regulatory register and is not waiting for the trilogue.
  5. Treat the 13 May trilogue as informational, not strategic. Even a successful second attempt has to clear plenary and Council before any deadline shifts. Plan against the unchanged 2 August date.

Why this page is harder to copy than it looks

The narrative of "Omnibus failed, deadline holds" is on every newsletter. The numbers above are not. They come from 312,758 current documents, 33,602 with full structured extraction, 743 AI Act obligations, 219 cross-regulatory references and 41 AI-Act-specific collisions sitting in Fontvera's production database. We track them because the corpus is built to answer cross-border regulatory questions in seconds, and we expose them here because the Omnibus failure is exactly the moment the surface becomes operational risk.

If your team is mapping AI Act exposure for 2 August, the obligation register, conflict descriptions and penalty tiers above are the inputs you need — and they are what the homepage search returns.

Run your free AI Act compliance diagnostic

Five minutes. No login. Returns your classification (Prohibited, High-Risk Annex III, High-Risk Annex I, Limited-Risk or Minimal-Risk) and the specific articles that apply.

→ Run the AI Act diagnostic

Search 316,000+ regulatory documents

The corpus that produced these numbers is searchable from the homepage. Cross-border, cross-regulation, cross-jurisdiction.

→ Search Fontvera

§ Action items

Practical steps

01
Run the high-risk diagnostic against your live systems and document the result with article references.
02
Resolve the four hard AI Act conflicts (logs, special-category data, gatekeeper access, storage limitation) in writing before 2 August.
03
Build the Article 9 risk management process now; conformity assessment under Article 16 cannot be backfilled in the last week of July.
04
If you deploy a non-EU provider's system, confirm Article 22 authorised representative arrangements in writing.
05
Treat the 13 May trilogue as an information event, not a strategic input. Plan against the unchanged 2 August deadline.
§ What Fontvera found

Documents in our corpus

ai_office EU Fetched 2026-04
imy SE Fetched 2026-04
§ Cross-references

Related Fontvera intelligence

Need a cross-border briefing on this?
Search Fontvera ↵ Run the AI Act diagnostic
AI Act enforcement
94 days
until 2026-08-02, when most AI Act provisions begin to apply.