This desk writes for operators outside the Union. The framing that follows is deliberate: the question is not what the EU decided, it is what a company headquartered in San Francisco, Toronto, Singapore or Sao Paulo now has to do differently, and when. Where a fact rests on the Commission's own record it is cited to it. Where it does not, it is not stated.
- The deferral attaches to obligations, not to companies. A non-EU operator in scope gets the same new dates as an EU one, and the same unchanged ones.
- Two dates moved away: Annex III stand-alone high-risk obligations to 2 December 2027, and Annex I obligations for AI embedded in regulated products to 2 August 2028.
- Two dates moved closer, both 2 December 2026: a new prohibition covering systems already on the market, and the end of the Article 50(2) machine-readable marking transitional period. The Commission's proposal had the latter running to 2 February 2027. That version was not adopted.
- Nothing about supervision was deferred. Since 2 August 2026 the transparency and governance rules apply and the AI Office and the Member State authorities hold implementation, supervision and enforcement responsibility.
- The Article 99 penalty ceilings are calculated on total worldwide annual turnover, not EU turnover. That is the provision most consistently understated in coverage written outside the Union.
The four dates, and which direction each moved
The Digital Omnibus on AI began as COM(2025) 836, presented on 19 November 2025 alongside COM(2025) 834, the broader Digital Omnibus touching the GDPR, the Data Act and NIS 2. It reached political agreement on 7 May 2026, received Council approval on 29 June 2026, and entered into force on 27 July 2026, six days before the original high-risk application date. The adopted act is Regulation (EU) 2026/1744.
| What moved | Direction | New date |
|---|---|---|
| Annex III stand-alone high-risk obligations, including the Article 26 deployer duties | Away, by sixteen months | 2 December 2027 |
| Annex I high-risk obligations for AI embedded in products under existing Union harmonisation legislation | Away, by twenty-four months | 2 August 2028 |
| New prohibitions on AI generating child sexual abuse material, and on AI depicting an identifiable person's intimate parts without consent | Created, with a compliance date for systems already on the market | 2 December 2026 |
| Article 50(2) machine-readable marking transitional period | Closer, relative to the Commission's proposal | Ends 2 December 2026 |
| Deadline for Member States to establish national AI regulatory sandboxes | Moved | 2 August 2027 |
Two further changes carry no date and are worth noting from outside. The Omnibus simplified the registration of exempted systems in the EU database, and it extended AI Office oversight to certain systems built on general-purpose models and embedded in very large online platforms and search engines. That last one reaches a specific and largely non-European population of companies, and it is the change least covered in reporting aimed at that population.
Scope first: who this reaches from outside the Union
Before any date is useful, the scope question has to be answered, and it is answered by the Act rather than by where a company is incorporated. Regulation (EU) 2024/1689 reaches providers placing AI systems on the Union market or putting them into service in the Union, irrespective of establishment, and it reaches providers and deployers established outside the Union where the output produced by the system is used in the Union. A company with no EU entity, no EU staff and no EU data centre can be squarely in scope on the strength of where its output lands.
The extraterritorial mechanics are set out at length in the extraterritorial reach guide on this site and are not repeated here. What is worth restating in the context of the Omnibus is that the deferral did nothing to narrow that scope. Nothing in Regulation (EU) 2026/1744 changed who the Act reaches. It changed when two obligation sets apply to them.
The practical sequence for a non-EU team is therefore two steps rather than one. First, which systems are in scope. Second, which obligation set each in-scope system falls into. The four dates now diverge by nearly two years, so an estate-wide answer is almost certainly wrong for part of the estate.
The marking obligation, and why it lands hardest outside the EU
Article 50 of Regulation (EU) 2024/1689 sets the transparency obligations. They applied from 2 August 2026 and were not deferred. Article 50(2) is the machine-readable marking limb: providers of AI systems generating synthetic audio, image, video or text content must ensure the outputs are marked in a machine-readable format and detectable as artificially generated or manipulated.
The Commission's Omnibus proposal attached a transitional period running to 2 February 2027. The adopted act shortened it, and it now ends on 2 December 2026.
This limb sits on providers of generative systems, which is a population concentrated outside the European Union to a degree that no other provision in the Act matches. The companies building the models, the media generation products and the developer platforms that produce synthetic content at scale are, for the most part, not European companies, and they are in scope of Article 50(2) on the strength of output reaching the Union.
Three consequences follow, and none of them is a legal argument.
The first is that marking is an engineering change with a lead time, not a policy statement. Watermarking, provenance metadata and detection signalling have to be implemented in a pipeline and then survive it. Two months of difference between the proposed and adopted transitional dates is material when the work is in a release train.
The second is that the obligation is on the provider, and the provider frequently cannot see what happens downstream. Marking applied at generation does not necessarily survive re-encoding, cropping, format conversion or passage through a customer's content system. A provider evidencing compliance needs to know what its marking does under realistic downstream handling, which is a testing question that takes longer than it sounds.
The third is a documentation trap specific to this period. Anyone whose Article 50 planning was set between November 2025 and July 2026 is likely to be working to 2 February 2027, because that was the correct answer for eight months and became wrong on 27 July without anything visible happening. It is worth searching internal planning documents for that date directly.
The prohibitions, and how they differ from everything else in the Act
The Omnibus added a prohibition covering AI systems that generate child sexual abuse material and AI systems that depict an identifiable person's intimate parts without consent. Systems already on the market must comply by 2 December 2026.
A prohibition behaves differently from the rest of this regulation and the difference is worth stating plainly for teams whose compliance function has spent two years building documentation practices. The high-risk regime is conditional: it permits an activity provided specified things are done and can be evidenced. A prohibition permits nothing. No risk management system, oversight arrangement or technical file converts a prohibited practice into a lawful one, and the compliance question is answered by what the system can produce rather than by what the organisation has written about it.
For most operators the exposure here is not a purpose-built system. It is general-purpose image or video generation capability exposed to users, where the assessment of what it will produce when asked has been delegated to an upstream vendor's acceptable use policy. That is not an assessment. The window between now and 2 December 2026 is the period in which to establish, by testing, and record what a deployment can and cannot generate.
Penalties, calculated on a base most coverage understates
The Article 99 ceilings are: up to EUR 35,000,000 or 7 per cent of total worldwide annual turnover for the Article 5 prohibited practices; up to EUR 15,000,000 or 3 per cent for other operator obligations; and up to EUR 7,500,000 or 1 per cent for supplying incorrect, incomplete or misleading information. In each case the applicable figure is whichever is higher, and for SMEs and start-ups the applicable ceiling is the lower of the two rather than the higher. National market surveillance authorities enforce this regime.
Article 101 is a separate regime for providers of general-purpose AI models, with fines not exceeding 3 per cent of annual total worldwide turnover or EUR 15,000,000, whichever is higher, including for supplying incorrect, incomplete or misleading information. The AI Office holds that one.
The provision most consistently understated in coverage written outside the Union is the base. These are worldwide turnover figures, not European turnover figures. A company with a small European revenue line and a large global one does not have a proportionally small exposure ceiling, and internal risk assessments that scale the exposure to EU revenue are working from an assumption the Act does not make. That distinction, more than any date in this article, is what makes the EU regime a board-level question for a non-EU company rather than a regional compliance line item.
What the Omnibus did not touch at all
Directive (EU) 2024/2853, the revised Product Liability Directive, must be transposed by Member States by 9 December 2026. It is a separate instrument with a separate legal basis and nothing in the Omnibus reaches it. How it affects any specific operator depends on national transposition and on how the product reaches the European market, and this desk does not state a general answer to that because there is not one.
What can be said generally is the reasoning error to avoid. A company that concluded in late July that its European AI liability exposure had moved to 2027 has, without examining it, also concluded something about an instrument that did not move. The two regimes were never linked, and the documentation an operator would have built for the AI Act is largely the same documentation that becomes evidentially relevant under a product liability regime. Standing that work down produces a reduction in regulatory exposure for 2027 and an increase in evidential exposure for 2027, which is rarely the trade intended.
Also untouched: the Article 5 prohibitions as they stood, which have applied since 2 February 2025 and not, as two trackers on this site previously stated, from February 2026. The general-purpose AI provider obligations, which have applied since 2 August 2025. And the Article 4 AI literacy duty, which was amended rather than repealed: the obligation remains on providers and deployers, no specific level is mandated, and the Commission and Member States take a stronger promotion role.
A working sequence for a non-EU team
Now to end September 2026
- Answer the scope question per system, not per company. Output used in the Union is the limb most often missed by teams with no EU entity.
- Identify every generative capability exposed to users and test it against the two new prohibited categories. A vendor policy is not the evidence.
- Search internal planning documents for 2 February 2027. That date came from the proposal, not from the act.
October to November 2026
- Close the Article 50(2) marking position: what is applied, in what format, and whether it survives realistic downstream handling. Test the pipeline end to end rather than confirming the feature exists.
- Fix Article 50 disclosure at the point of interaction rather than in a terms page. The obligation concerns what the person in front of the system is told, when they are in front of it.
- Recalculate the Article 99 exposure on worldwide turnover and put the number in front of whoever owns risk. It is usually larger than the internal assumption.
December 2026 onward
- Treat the Annex III work as deferred rather than cancelled. Sixteen months is one procurement cycle plus one implementation, which is roughly what the obligation set takes.
- Keep the documentation running on its own logic. It is the evidence base for coverage and for disputes regardless of what any regulatory date does next.
- Watch the sandbox deadline of 2 August 2027 if a regulated European deployment is on your roadmap. Non-EU operators are the population most likely to benefit from that route and the least likely to be tracking it.
Questions
Does the EU AI Act delay apply to companies outside the European Union?
The deferral applies to the obligations, not to a category of company, so a non-EU operator inside the scope of the Act gets the same new dates as an EU one. Regulation (EU) 2026/1744 moved the Annex III stand-alone high-risk obligations to 2 December 2027 and the Annex I obligations for AI embedded in regulated products to 2 August 2028. What did not move is everything else, including the transparency obligations that applied from 2 August 2026 and the supervisory architecture that took effect on the same date.
What changed for non-EU operators that got closer rather than further away?
Two things, both dated 2 December 2026. The Omnibus added a prohibition on AI systems generating child sexual abuse material and on systems depicting an identifiable person's intimate parts without consent, with systems already on the market required to comply by that date. It also shortened the transitional period for the Article 50(2) machine-readable marking obligation, which now ends on 2 December 2026 rather than on the 2 February 2027 date in the Commission's proposal. For a global provider of generative capability, the second is the more operationally significant of the two.
Did the Omnibus defer the EU AI Act's enforcement powers?
No. From 2 August 2026 the transparency and governance rules apply, and the AI Office and the authorities of the Member States are responsible for implementing, supervising and enforcing the AI Act. A non-EU operator reading the deferral as a pause on supervision is reading it wrongly. The supervisory apparatus stood up on schedule; what moved is when two specific obligation sets become applicable.
What are the penalties under the EU AI Act for a company outside the EU?
The Article 99 ceilings are set by reference to total worldwide annual turnover rather than to EU turnover, which is the point most often missed from outside the Union. Prohibited practices under Article 5 attract up to EUR 35,000,000 or 7 per cent of total worldwide annual turnover, whichever is higher. Other operator obligations attract up to EUR 15,000,000 or 3 per cent. Supplying incorrect, incomplete or misleading information attracts up to EUR 7,500,000 or 1 per cent. For SMEs and start-ups the applicable ceiling is the lower of the two figures rather than the higher. A separate regime in Article 101 applies to providers of general-purpose AI models.
Does the EU Product Liability Directive deadline affect non-EU companies?
The transposition deadline of 9 December 2026 for Directive (EU) 2024/2853 is a deadline on Member States, and the substantive effect on any given operator depends on how each Member State transposes it and on how the product reaches the EU market. What can be said without qualification is that the directive is a separate instrument with a separate legal basis, that nothing in the AI Omnibus touched it, and that a global company treating the AI Act deferral as general relief on European AI liability has drawn a conclusion about an instrument it did not read.
What should a non-EU company do first?
Separate scope from timing before doing anything else. Establish which of your systems are in scope of the Act at all, then establish which obligation set each falls into, because the four dates now diverge by nearly two years. Teams that skip the first step and adopt a single new deadline across the estate tend to adopt 2 December 2027, which is the wrong date for prohibitions, for transparency, for general-purpose model obligations and for the marking transitional period.
Sources
- Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), OJ L, 12.7.2024.
- Regulation (EU) 2026/1744, the Digital Omnibus on AI, OJ L, 2026/1744. Proposal COM(2025) 836 of 19 November 2025, presented alongside COM(2025) 834; political agreement 7 May 2026; Council final approval 29 June 2026; entry into force 27 July 2026. European Commission, AI Omnibus enters into force, checked 17 August 2026.
- European Commission, AI Act Service Desk. Timeline for implementation of the EU AI Act, checked 17 August 2026. Source for 2 February 2025, 2 August 2025, 2 August 2026, 2 December 2026, 2 August 2027, 2 December 2027 and 2 August 2028.
- European Commission. Regulatory framework for AI, checked 17 August 2026. Source for the statement that from 2 August 2026 the transparency and governance rules apply and the AI Office and the authorities of the Member States are responsible for implementing, supervising and enforcing the AI Act.
- Article 99, Regulation (EU) 2024/1689. European Commission, AI Act Service Desk, Article 99, checked 17 August 2026.
- Article 101, Regulation (EU) 2024/1689. European Commission, AI Act Service Desk, Article 101, checked 17 August 2026.
- Article 4, Regulation (EU) 2024/1689, as amended. European Commission, AI literacy questions and answers, checked 17 August 2026.
- Article 50, Regulation (EU) 2024/1689. Transparency obligations, including the Article 50(2) machine-readable marking duty and its transitional period ending 2 December 2026.
- Directive (EU) 2024/2853 of the European Parliament and of the Council on liability for defective products, OJ L, 18.11.2024. National transposition deadline 9 December 2026.
- General-Purpose AI Code of Practice, final version published 10 July 2025, in three chapters: transparency, copyright, and safety and security. European Commission, contents of the GPAI Code of Practice, checked 17 August 2026.