August 2, 2026 was meant to mark the major turning point for the text. But six days before the deadline, part of the timeline shifted: the heaviest obligations were pushed back to the end of 2027. As a result, some now say that "the AI Act has been postponed." That shortcut is misleading, and dangerous for any company tempted to see it as a reason to ease up on vigilance.
This article details what this new timeline concretely changes for the cloud, data and AI sector, and for our clients in banking, insurance and luxury.
What is the AI Act?

Adopted in 2024, the European regulation on artificial intelligence rests on a simple principle: the greater the risk an AI system poses to fundamental rights or people's safety, the heavier the obligations placed on it.
Four levels are distinguished: prohibited uses, strictly regulated high-risk uses, limited-risk uses subject to transparency rules, and everything else, with no specific obligation.
Table of risk levels under the AI Act

What changes in 2026 with the Omnibus regulation
Since July 27, 2026, the Omnibus regulation has been in force to simplify the European AI regulatory framework and support innovation. It accompanies the AI Act's effective application from August 2, 2026, sanctions included. Prohibited practices, meanwhile, have been applicable since February 2025.
Why this measure? And how does it play out?
By late 2025, the reality became clear: neither the timeline nor the method were workable. Companies were unable to document their systems because technical standards were not finalized, and not all national supervisory authorities were in place. The European Commission then opted for targeted adjustments rather than a full overhaul of the text.
Some obligations are therefore postponed: those weighing on high-risk AI systems, from automated recruitment to credit scoring to insurance pricing. They will come into force on December 2, 2027 for most cases, and August 2, 2028 for systems already integrated into regulated products.
The postponement concerns compliance obligations for high-risk systems:
- Continuous risk management
- Governance of training data
- Technical documentation
- Logging of executions
- Effective human oversight
- Robustness and cybersecurity
- Fundamental rights impact assessment
- Registration in a European database
In its initial version, the Commission's proposal made these obligations conditional on the availability of European technical standards, with a fallback deadline in case of delay. That conditional mechanism disappeared during negotiations: the final text sets firm dates. The obligations will therefore apply on December 2, 2027 and August 2, 2028, whether or not the standards are ready.
But the rest of the text has not moved: transparency and sanctions have been fully operational since August 2, 2026. Sanctions remain graduated and dissuasive: up to €35 million or 7% of global turnover for prohibited practices, up to €15 million or 3% for most other breaches, including transparency obligations. And the Omnibus regulation does not just push back deadlines, it has also created new ones.
Companies now have until December 2, 2026 to put in place adequate safeguards against the generation of child sexual abuse material and the creation of images, videos or audio content depicting the intimate parts (or any other sexually explicit content) of an identifiable person without their consent, under penalty of the maximum sanctions provided for in the text.
By the same date, content generators placed on the market before August 2026 will need to embed machine-readable metadata specifying that the content is AI-generated. This is the only grace period granted on the transparency front, and it does not apply to systems deployed after August 2.
What the AI Act changes for technical teams
What's coming in 2027 is about documentation and organization, and it's something to prepare for starting today. But before talking about 2027, there is already a project underway: transparency, applicable since August 2, 2026.
Flagging that content is AI-generated is not a legal notice tacked on at the end, like a signature. It's an architectural constraint. The notice must be verifiable not just by a user but by a machine, which requires machine-readable metadata, applied at the moment of generation and carried through storage all the way to distribution. A generated_by field added after the fact does not meet the requirement: the regulation mandates marking at the source, before any delivery or publication.
Two distinct rules coexist here, and they are unambiguous.
First rule: the obligation is not retroactive. The Commission's guidelines confirm it: content generated before August 2, 2026 does not need to be marked after the fact, the generation date is what counts.
Second rule: for any content generated from that date onward, the marking must be applied at creation. Content produced without marking can no longer be reliably brought into compliance afterward, because nothing can prove after the fact that a file actually came from a model. The operational challenge is therefore twofold: mark everything generated from now on, and be able to date what already exists, in order to demonstrate that content predating August 2 was not subject to the obligation.
The remaining obligations to prepare for 2027 concern elements that cannot be manufactured retroactively:
The logs (execution records) required by late 2027 will concern systems that are already running. On infrastructures where default retention is measured in weeks, the question is not "when do we need to be compliant" but "since when should we have been keeping the records."
The AI Act requires documenting the origin of training datasets and the processing they have undergone. The text's objective is clear on this point: traceable data governance, detailed enough to allow effective oversight.
The scope itself keeps shifting. An updated model, an extended feature, a use diverted by users, and a component previously out of scope falls into a regulated category. Without an inventory or version history, no one will be able to say on what date the shift happened.
The impact of the AI Act on banking, insurance and luxury
The AI Act and the banking sector
In this sector, the heaviest topic has been postponed. A credit scoring engine that determines access to a loan qualifies as high-risk: model documentation, training data traceability, the ability to explain an individual decision, human oversight of decisions. This project now plays out by the end of 2027. The urgency lies elsewhere: a conversational assistant deployed on a customer portal has had to be identified as an AI system since August 2, just like automatically generated case summaries. These are often components deployed quickly, sometimes by a business unit, that appear in no technical inventory.
The impact of the AI Act on the insurance sector
Here, exposure is broader. Algorithmic pricing and health risk assessment qualify as high-risk, and therefore fall under the 2027 timeline. Automated customer relationship management, letter generation, or claims-processing assistance, however, fall within the transparency scope, applicable now. The sector is also already subject to strong auditability requirements: a system feeding into a pricing decision must be reconstructable in its exact state at a given date, which means retaining far more than the final model, and therefore dedicating a team to maintaining and monitoring the data.Et pour les entreprises du luxe : quelles nouveaux enjeux entraînent l’IA Act ?
And for luxury companies: what new challenges does the AI Act bring?
In the luxury sector, high-risk cases are rare, but transparency obligations have been active since August 2, 2026, and stack on two levels: machine-readable technical marking, the responsibility of generation tool providers, and visible flagging of deepfake-like content, the responsibility of the house distributing it. The stock of visuals predating August 2, 2026 is exempt from the obligation (since the rule is not retroactive). But that's exactly where the problem shifts: for houses producing considerable volumes of content through multiple agencies and tools, it still has to be possible to prove that a visual predates the deadline, or that it has not been AI-retouched since. Without provenance metadata or reliable dating attached at creation, the honest answer to "is this visual subject to the obligation?" is often: we don't know.
Transparency-related sanctions have applied since August 2026 and can reach €15 million or 3% of global turnover depending on the breach. At that scale, the gap between "we think we're compliant" and "we can prove it" becomes a real financial risk.
Conclusion
The postponement is therefore not a pause on companies' compliance duties. It's additional time granted to organizations to meet legal obligations and put good AI development and product management practices in place.
The urgency today lies in transparency, particularly for components and systems already deployed. Most are modest in scale and rarely recorded as fully-fledged AI systems. The reprieve granted until the end of 2027 will allow companies to catch up and meet the traceability and documentation requirements the EU demands for the highest-risk systems.
This is a topic we follow closely at Lenstra, as it concretely reshapes the pipelines and retention strategies we put in place for our clients in banking, insurance and luxury. We are already supporting them on this mapping and traceability exercise, and we will document the results here in the coming months to help you too.
Questions on the topic? Get in touch!