The AI Act timeline moved: Regulation (EU) 2026/1744 and what still applies to banks
The AI Omnibus deferred Annex III high-risk obligations to 2 December 2027. Nearly all published competitor content assumes the old calendar. Here is the corrected timeline.
What changed
Regulation (EU) 2026/1744, the AI Omnibus, entered into force on 27 July 2026. It deferred Annex III high-risk obligations, including credit scoring of natural persons, from 2 August 2026 to 2 December 2027.
The deferral is real. The deferral is not a reprieve.
What competitors missed
Nearly all published AI Act content for banks assumes the old August 2026 deadline. That content is now wrong. The deferral moves conformity deadlines, not supervisory exposure. National competent authorities and the ECB Supervisory Board have not adjusted their expectations downward. They have adjusted them sideways: the AI Act headline date moved, but existing banking law did not.
What still applies today
ECB supervision expects significant institutions to address AI-enabled cybersecurity threats. Action plans are due 31 October 2026. This deadline comes from the SSM's 2024 cyber resilience expectations and the Digital Operational Resilience Act (DORA), not from the AI Act's Annex III.
Three obligations are in force now, independent of the AI Act deferral:
- DORA Article 6 ICT risk management framework must address AI-enabled attack surfaces. This is current law, not future law.
- GDPR Article 22 automated decision-making constraints apply to any credit scoring model that produces legal or similarly significant effects. Banks using ML-based scoring already face these constraints today.
- ECB cyber resilience expectations require significant institutions to maintain threat modelling that accounts for adversarial AI use. The 31 October 2026 action plan deadline is not deferred.
What the deferral actually moved
The deferral applies to Annex III high-risk AI systems: credit scoring of natural persons, life and health insurance risk assessment, and creditworthiness assessment. The conformity assessment, post-market monitoring, and registration obligations for these systems now start on 2 December 2027.
Annex IV high-risk systems (AI used in critical infrastructure, education, employment) were not deferred. Their original timelines remain.
What to build now
Banks that treated the August 2026 deadline as the starting gun have lost four months. Banks that started in 2024 have gained four months of runway. The gap between these two groups will widen.
The work that matters now is not AI Act conformity documentation. It is the operational integration of AI risk into existing DORA, GDPR, and SSM frameworks. The AI Act conformity layer sits on top of that integration. It does not replace it.
Sources
- Regulation (EU) 2026/1744, OJ L 2026/1744, 27 July 2026 (in force)
- ECB Guide to operational resilience, November 2023
- DORA, Regulation (EU) 2022/2554, in force 17 January 2025
- GDPR, Regulation (EU) 2016/679, Article 22
EN draft. SME review pending (regtech lead). No SME quotes or credentials fabricated.
Related articles
PSD3/PSR status, as of August 2026: what is agreed, what is not yet law, what to build anyway
The Council published final compromise texts on 23 April 2026. PSD3 and the PSR are adopted in principle but not yet in force. Here is what is settled, what is not, and what to build now.
2026-08-04RegulatoryDORA's first enforcement year in numbers: what 3,383 incidents change in your 2027 budget
The ESAs published the first DORA incident report on 3 June 2026: 3,383 major ICT incidents reported by 2,847 financial entities. The data changes how 2027 resilience budgets should be built.
2026-08-04