The EU AI Act was not delayed. Part of it was, and the part that moved is not the part most agent teams assume.

Regulation (EU) 2026/1744, the Digital Omnibus on AI, is dated 8 July 2026, was published in the Official Journal on 24 July 2026, and entered into force on 27 July 2026, three days later rather than the customary twenty because the legislature was racing a 2 August deadline. The 8 July date is the signature date carried in the Official Journal header, not the vote. Parliament adopted its position on 16 June 2026 and the Council decided on 29 June 2026, both recorded in footnote 4 of the published text. The Regulation amends the AI Act across more than forty points. Some of those are deferrals. Several are not, and two of them switched on obligations rather than postponing them.

The short version: what moved is the accountability machinery. What stayed is disclosure, prohibition and enforcement. If you are building agents, that is close to the worst possible split, because the duties you can discharge with a banner arrived on schedule while the duties that require architecture were pushed two years out and will be expensive to retrofit.

What binds an AI agent, and when EU AI Act as amended by the Digital Omnibus on AI. Ordered, not to scale. TODAY 1 Aug 2024 AI Act in force 2 Feb 2025 Article 5 prohibitions 2 Aug 2025 GPAI obligations 27 Jul 2026 Digital Omnibus in force; Articles 102 to 110 apply 2 Aug 2026 General application; Article 50 transparency 2 Dec 2026 New Article 5 prohibitions; Article 50(2) legacy deadline 2 Aug 2027 National sandboxes operational 2 Dec 2027 Chapter III applies, Annex III 2 Aug 2028 Chapter III applies, Annex I
1 Aug 2024
AI Act in force
2 Feb 2025
Article 5 prohibitions
2 Aug 2025
GPAI obligations
27 Jul 2026
Digital Omnibus in force; Articles 102 to 110 apply
2 Aug 2026
General application; Article 50 transparency
2 Dec 2026
New Article 5 prohibitions; Article 50(2) legacy deadline
2 Aug 2027
National sandboxes operational
2 Dec 2027
Chapter III applies, Annex III
2 Aug 2028
Chapter III applies, Annex I

Ordered, not to scale

Which EU AI Act rules apply to AI agents right now?

Three sets of rules bind agents today. The Article 5 prohibitions have applied since 2 February 2025. General-purpose AI model obligations have applied since 2 August 2025. Article 50 transparency obligations have applied since 2 August 2026 and were not deferred.

Take Article 50 first, because it is the one that catches agents directly. If your agent interacts with a person, you must tell them they are dealing with an AI system unless it is obvious to a reasonably observant user. If it generates synthetic audio, image, video or text, that output must be marked in a machine-readable format detectable as artificially generated. If it produces deepfakes, or text published to inform the public on matters of public interest, further disclosure applies.

Customer service agents, sales agents, scheduling agents that email third parties on your behalf: all of these are in scope now, not in 2027.

General-purpose AI model obligations have been live since August 2025. Most agent teams are deployers rather than model providers and are not directly caught, but the position changes if you fine-tune substantially or place a model on the market yourself.

Then the part almost nobody has priced in. The Omnibus made Articles 102 to 110 of the AI Act applicable from 27 July 2026, and rewrote Article 75(1) to give the AI Office exclusive competence over AI systems built on general-purpose AI models where the model and the system come from the same provider or the same undertaking, subject to carve-outs for Annex I products, biometrics, law enforcement and justice. New Articles 75a and following give the AI Office the powers of a market surveillance authority, including on-site inspection, binding commitments, fines and periodic penalties, and the right to reclaim its enforcement costs.

The supervisory architecture arrived ahead of the substantive requirements. That is unusual and worth sitting with.

What exactly did the Digital Omnibus defer, and what did it leave in place?

The Omnibus deferred Chapter III, Sections 1, 2 and 3, which contain the high-risk requirements and the provider and deployer obligations attached to them. Annex III standalone systems now apply from 2 December 2027. Annex I embedded systems apply from 2 August 2028. National regulatory sandboxes moved to 2 August 2027.

One correction to the framing you will see almost everywhere. The Annex I date moved from 2 August 2027 to 2 August 2028, a slip of one year. It did not move from 2 August 2026. Only the Annex III date moved from 2026, and it moved by sixteen months. Two different journeys, frequently collapsed into one.

What sits inside the deferred sections is the point. Article 12 record-keeping. Article 14 human oversight. Article 11 technical documentation. Article 26 deployer obligations. Article 9 risk management. In other words, precisely the machinery that would tell you what an agent did, who was supposed to be watching, and whether they could intervene.

What was left untouched: the general application date of 2 August 2026, the Article 5 prohibitions, the GPAI regime, and Article 49 registration, which sits in Chapter III Section 5 and falls outside the deferral.

Two things were added rather than postponed. Article 5 gains two new prohibited practices at points (ba) and (bb), covering AI systems that generate or manipulate non-consensual intimate material or child sexual abuse material. Both apply from 2 December 2026 and sit in the highest penalty tier. For agent builders the operative limb is Article 5(1a)(a)(ii): a provider is caught not only where generation is the intended purpose but where the system's design, training, architecture or capabilities make it a reasonably foreseeable and reproducible outcome without significant technical modification, and adequate safeguards are absent. If you have wired a general image or video generation tool into an agent's tool set, that provision is addressed to you.

The Omnibus also softened Article 4. AI literacy is now an obligation to take measures supporting development of literacy, with an express statement that providers and deployers need not guarantee any specific level for any individual. That is a genuine reduction in burden and one of the few unambiguously easier items in the instrument.

On why the deferral happened, the recitals are unusually candid. Recital 2 records delayed preparation of standards and delayed establishment of governance and conformity assessment frameworks at national level. Recital 40 says the same again. The obligations did not become less demanding. The infrastructure to assess compliance with them was not built.

One consequence deserves emphasis. The Commission's November 2025 draft would have tied the new dates to a decision confirming that harmonised standards were available. The co-legislators dropped that trigger. These are unconditional calendar dates. Moving them again requires a fresh legislative procedure, and nobody involved wants to run this one twice.

Was Article 50 deferred?

No, with one narrow exception that most summaries flatten. Article 50 sits in Chapter IV and applied from 2 August 2026. A four-month transitional period applies only to the machine-readable marking duty in Article 50(2), and only for providers who had already placed their systems on the market before 2 August 2026.

Recital 38 states the reasoning: sufficient time for providers of generative AI systems already on the market to adapt without disrupting the market. Four months from 2 August 2026 gives 2 December 2026, sitting in a new Article 111(4).

The precision matters in both directions.

Systems placed on the market on or after 2 August 2026 get no transition at all. Marking was due on day one. A team that shipped a generative agent in September and read a summary saying "Article 50(2) has until December" has misread its own position.

And the transition covers only 50(2). The disclosure duty in 50(1), the deepfake labelling in 50(4), the obligation to disclose AI-generated text published to inform the public: all live since 2 August 2026, for legacy and new systems alike.

The common formulation, that Article 50 was not deferred, is right in substance and wrong in detail. It is worth getting right, because the version of the claim that matters commercially is the one that tells a legacy provider they have until December, and that version is only true of one sub-paragraph.

Is my AI agent high-risk under Annex III?

Probably not, and the Omnibus narrowed the surrounding definitions rather than widening them. Annex III covers biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration and administration of justice. Most agents doing scheduling, coding, support triage or internal workflow automation sit outside it.

Annex I is a different route and applies where an AI system is a safety component of a regulated product. New Article 6(1a) removes from that category systems used solely for non-safety related user assistance, performance optimisation, service efficiency, automation, convenience or quality control, with Article 6(1b) preserving the classification where failure would endanger health and safety. Article 3(14) was rewritten to match. That is a meaningful narrowing for anyone whose agent sits alongside a regulated product without performing a safety function.

Where agents do land in Annex III, it is usually through employment, meaning CV screening and candidate evaluation, or through essential services, meaning creditworthiness and eligibility assessment. If your agent decides who gets an interview or who gets a loan, you are in Annex III and 2 December 2027 is your date.

One trap for continuously deployed products. The Omnibus clarified the Article 111(2) grace period at recital 39: it turns on when the first unit of a type and model was placed on the market, and applies only as long as the design remains unchanged. Any significant change to design after the relevant date triggers full compliance, including conformity assessment. For a product that ships weekly, "design remains unchanged" is not a condition you can satisfy. Agent teams should treat the legacy grace period as unavailable rather than as a runway.

A smaller point, flagged rather than asserted. Recital 43 introduces horizontal AIH codes covering the underlying types and technologies of AI systems, populated in a new Annex XIV. Published commentary reports that agentic AI appears among those codes, which would be the first time Union law names the category. I have not verified that against the annex text and would check it before relying on it.

What should agent teams do with the time before December 2027?

Build the record now. Article 12 requires automatic logging over the system's lifetime. Article 14 requires that a human be able to understand the system's capacities, monitor operation, interpret output, decide not to act on it, and intervene or interrupt. Neither is a document you write in November 2027.

The deferral is a design window, not a reprieve, and the reason is architectural rather than legal. An agent that cannot stop mid-plan cannot be made to stop by adding a policy. An agent that logs tokens rather than decisions cannot be made to produce a decision trace by adding a retention schedule. Oversight and record-keeping are properties of how a system is built, and retrofitting them into a deployed multi-step agent is the expensive version of this work.

There is also a nearer reason. The AI Office now holds enforcement powers over systems built on general-purpose models, and it holds them today. The high-risk requirements are not yet enforceable, but the prohibitions and the transparency duties are, and the body that will assess them has inspection and fining powers as of 27 July 2026.

Three dates to put in the calendar and stop worrying about the rest. 2 December 2026: the two new Article 5 prohibitions bind, and legacy generative systems must meet Article 50(2). 2 December 2027: Chapter III applies to Annex III systems. 2 August 2028: Chapter III applies to Annex I systems.

Everything between those dates is preparation, and the useful test of whether preparation is going well is not whether the policies exist. It is whether you can answer, for a run that happened last Tuesday, what the agent decided, which human could have stopped it, and whether they saw it.

Truveil scores AI agents against the EU AI Act and five other frameworks, and produces the evidence described here.