Artificial Intelligence · AI Governance & AI Act
AI Act Compliance for B2B Companies: What Changed in 2026


Back in early 2026, plenty of companies were counting down to August 2, 2026 — the date full obligations for high-risk AI systems under the EU AI Act were set to take effect. That date has since moved, and moved significantly. If your compliance budget was planned around the August deadline, it’s worth updating your assumptions — though that doesn’t mean the topic can wait.
What actually changed
On May 7, 2026, the EU Council and European Parliament reached a provisional political agreement under the so-called Digital Omnibus, pushing back part of the AI Act’s timeline. Under that agreement, obligations for standalone high-risk systems under Annex III (recruitment, credit scoring, critical infrastructure, and similar) moved from August 2, 2026 to December 2, 2027 — a 16-month extension. AI systems embedded in products governed by EU product-safety law (Annex I) gained an extra 12 months, now due August 2, 2028. Moving in the other direction, rules on labeling synthetic content were actually pulled forward, from August to December 2, 2026.
One important caveat: as of this article’s publication, the agreement remains provisional — it still requires formal approval from the Council and European Parliament, followed by publication in the EU’s Official Journal. Major law firms are already treating these dates as reliable for planning purposes, but the process isn’t formally closed.
What’s already in force regardless
This is the part that matters most: the delay only applies to some obligations. Two key pieces of the AI Act have been in force for a while and already apply to any company operating in the EU market, regardless of further schedule changes.
First, the prohibited practices under Article 5 — in force since February 2, 2025. These cover things like manipulative techniques exploiting specific groups’ vulnerabilities, social scoring, and unchecked emotion recognition in the workplace. The Omnibus also added a new prohibition targeting systems that generate non-consensual intimate imagery, with a safe-harbour exception for systems with effective preventive safeguards.
Second, obligations for general-purpose AI models (GPAI) under Articles 51-55 — in force since August 2, 2025. These primarily target providers of large language models, but they matter indirectly for companies that use those models commercially in their own products, particularly around documentation, transparency, and managing systemic risk.
What this means for a B2B company using AI
If your company isn’t building a system that falls into a high-risk category (recruitment, scoring, critical infrastructure), the push to December 2027 buys real breathing room. But if you’re using AI in HR processes, customer evaluation, or automating decisions that affect people, it’s worth checking now which risk category that process actually falls into — the classification itself hasn’t changed, only the deadline for meeting some of the obligations tied to it.
On top of that, if you’re producing or publishing AI-generated content aimed at end customers — images, video, synthetic voice — the December 2026 deadline for labeling that content is closer than it might seem, and that’s specifically the deadline that got moved earlier, not later.
A practical recommendation
Rather than reacting to each schedule change as it happens, it’s worth doing one thorough inventory: which processes in your company use AI, which risk category each falls into, and what obligations already apply to them today — regardless of whether those obligations kick in during 2025, 2026, or 2027. That approach protects you from being caught off guard whenever the next deadline is formally confirmed, or shifts again.
At Unomage, we work with B2B clients for whom AI is already part of marketing and sales processes — and we see that the question of regulatory compliance now comes up right alongside the question of effectiveness. If you’re weighing how your own use of AI stacks up against the current state of the rules, our team in Warsaw is happy to talk through your specific case.
This article is for informational purposes and is not legal advice. For decisions about risk classification and AI Act compliance specific to your business, consult a lawyer specializing in technology law.
This article was created with the help of the Unomage AI platform.
