← Blog
compliancefinancial-servicespolicy

The EU AI Act Clock Banks Are Using Is Already Wrong

Annex III high-risk duties under the EU AI Act now apply from 2 December 2027. 2 August 2026 still carries Article 50 transparency and enforcement, which trade pages keep getting wrong.

MightyBot ·
Two unmarked overlapping clock faces out of phase, one amber hand pointing to a different tick than the navy hands.

Summary: The EU AI Act became applicable on 2 August 2026. Transparency duties and enforcement started that day. After the AI Omnibus entered into force on 27 July 2026, Annex III high-risk obligations moved to 2 December 2027. Trade copy still treats 2 August 2026 as the high-risk deadline. U.S. banks with EU customers, branches, or models that touch EU residents remain on the August clock for disclosure and enforcement. The high-risk file sits on 2027, as human-in-the-loop guidance already records.

The clock still on page one is the pre-Omnibus clock

Bank-facing searches for an August 2026 EU AI Act deadline still rank the pre-Omnibus calendar. A Responsible AI Labs explainer dated 9 April 2026 still says that on 2 August 2026 Annex III high-risk requirements take effect alongside Article 50, conformity assessments, CE marking, and AI Office enforcement. It added that until the Omnibus was formally enacted, the original deadline remained binding. That caveat is stale after 27 July 2026.

An eyreact timeline last updated in March 2026 still lists 2 August 2026 as the Annex III high-risk day and still calls the Digital Omnibus a proposal.

A Finextra post from May 2026 told firms the date was fixed and that high-risk obligations would become fully enforceable on 2 August 2026. A 3 August 2026 roundup still carried that line after the date had passed. An AliceLabs page for banks and insurers still circulates the same high-risk deadline. Those pages remain a ranking exhibit of the wrong clock.

The live Commission clock after 27 July 2026

The Commission’s regulatory framework page states that the AI Act entered into force on 1 August 2024 and became applicable on 2 August 2026. The AI Omnibus entered into force on 27 July 2026, after publication in the Official Journal on 24 July 2026 as Regulation (EU) 2026/1744.

Commission news states that Annex III high-risk rules apply from 2 December 2027 and that Annex I product-embedded high-risk rules apply from 2 August 2028. The AI Act Service Desk timeline lists the same milestones.

DateWhat starts
2 August 2026Applicability, Article 50, enforcement
2 December 2027Annex III high-risk rules
2 August 2028Annex I product-embedded high-risk rules

What still lands on 2 August 2026

From 2 August 2026, the European Commission’s AI Office, together with national authorities, will begin enforcing the Act. On the same date, new transparency rules start to apply. Chatbots and other interactive AI systems have to tell users they are dealing with AI. Deepfakes have to be labelled. AI-generated or altered content has to carry machine-readable marks.

The Service Desk lists Article 50 transparency rules as starting that day, together with enforcement concerning general-purpose AI models, prohibitions, transparency, and AI literacy.

White & Case is explicit that the Chapter III deferral does not cover Article 50. AI systems that generate synthetic audio, image, video, or text and that were placed on the market before 2 August 2026 have until 2 December 2026 to meet the watermarking obligation. Systems placed on the market on or after 2 August 2026 must comply from that date. The Service Desk lists the same 2 December 2026 Article 50(2) transition.

That August file is the live one for AI governance this year: disclosure, labelling, and supervision.

What moved to 2027 and 2028, and why a U.S. firm with EU exposure still cares

White & Case calls the Chapter III high-risk extension the most significant change for the majority of businesses. Annex III rules now start on 2 December 2027. Annex I product-embedded rules start on 2 August 2028.

The Commission policy page lists, among high-risk examples of access to essential private and public services, credit scoring that denies citizens the opportunity to obtain a loan. That is a Commission example of an Annex III category, and it is a 2 December 2027 file.

U.S. banks and insurers with EU customers, branches, or models that touch EU residents still have an August 2026 file: disclosure, labelling, and enforcement. The high-risk file is a 2027 file, and a 2028 file for product-embedded systems.

How to rebuild the board timeline from primary sources

White & Case tells firms to update compliance roadmaps to the new dates, 2 December 2027 for stand-alone Annex III systems and 2 August 2028 for Annex I embedded systems, and to prioritise obligations that continue from 2 August 2026, notably Article 50.

Boards should read the Commission policy page and the Service Desk timeline first. Vendor decks that still show 2 August 2026 as the high-risk date should come off the pack, since the remaining August clock is transparency and enforcement.

FAQ

Frequently Asked Questions

When do Annex III high-risk obligations apply after the AI Omnibus?

Rules for high-risk AI systems in Annex III apply starting 2 December 2027. The European Commission and the AI Act Service Desk both list that date after the Omnibus entered into force.

What EU AI Act rules still apply on 2 August 2026?

From 2 August 2026 the AI Office and national authorities begin enforcing the Act. Article 50 transparency rules start the same day, including duties to disclose AI interaction and to label AI-generated or altered content.

When did the AI Omnibus enter into force, and what is the regulation number?

The AI Omnibus entered into force on 27 July 2026. White & Case identifies the instrument as Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026.

Do chatbots have to disclose they are AI from 2 August 2026?

Yes. From 2 August 2026, chatbots and other interactive AI systems have to tell users they are dealing with AI rather than a human. Deepfakes have to be labelled, and AI-generated or altered content has to carry machine-readable marks.

Is there a watermarking grace period for systems already on the market?

Yes. White & Case states that AI systems generating synthetic content that were placed on the market before 2 August 2026 must meet the watermarking obligation by 2 December 2026. Systems placed on the market on or after 2 August 2026 must comply from that date.

When do Annex I product-embedded high-risk rules apply?

Rules for high-risk AI embedded in physical products in Annex I apply starting 2 August 2028. The Commission Omnibus news and the AI Act Service Desk both list that date.