Regulatory

The AI Act timeline moved: Regulation (EU) 2026/1744 and what still applies to banks

The AI Omnibus deferred Annex III high-risk obligations to 2 December 2027. Nearly all published competitor content assumes the old calendar. Here is the corrected timeline.

avanto.team·2026-08-04·As of 2026-08-04
in force

What changed

Regulation (EU) 2026/1744, the AI Omnibus, entered into force on 27 July 2026. It deferred Annex III high-risk obligations, including credit scoring of natural persons, from 2 August 2026 to 2 December 2027.

The deferral is real. The deferral is not a reprieve.

What competitors missed

Nearly all published AI Act content for banks assumes the old August 2026 deadline. That content is now wrong. The deferral moves conformity deadlines, not supervisory exposure. National competent authorities and the ECB Supervisory Board have not adjusted their expectations downward. They have adjusted them sideways: the AI Act headline date moved, but existing banking law did not.

What still applies today

ECB supervision expects significant institutions to address AI-enabled cybersecurity threats. Action plans are due 31 October 2026. This deadline comes from the SSM's 2024 cyber resilience expectations and the Digital Operational Resilience Act (DORA), not from the AI Act's Annex III.

Three obligations are in force now, independent of the AI Act deferral:

  1. DORA Article 6 ICT risk management framework must address AI-enabled attack surfaces. This is current law, not future law.
  2. GDPR Article 22 automated decision-making constraints apply to any credit scoring model that produces legal or similarly significant effects. Banks using ML-based scoring already face these constraints today.
  3. ECB cyber resilience expectations require significant institutions to maintain threat modelling that accounts for adversarial AI use. The 31 October 2026 action plan deadline is not deferred.

What the deferral actually moved

The deferral applies to Annex III high-risk AI systems: credit scoring of natural persons, life and health insurance risk assessment, and creditworthiness assessment. The conformity assessment, post-market monitoring, and registration obligations for these systems now start on 2 December 2027.

Annex IV high-risk systems (AI used in critical infrastructure, education, employment) were not deferred. Their original timelines remain.

What to build now

Banks that treated the August 2026 deadline as the starting gun have lost four months. Banks that started in 2024 have gained four months of runway. The gap between these two groups will widen.

The work that matters now is not AI Act conformity documentation. It is the operational integration of AI risk into existing DORA, GDPR, and SSM frameworks. The AI Act conformity layer sits on top of that integration. It does not replace it.

Sources

  • Regulation (EU) 2026/1744, OJ L 2026/1744, 27 July 2026 (in force)
  • ECB Guide to operational resilience, November 2023
  • DORA, Regulation (EU) 2022/2554, in force 17 January 2025
  • GDPR, Regulation (EU) 2016/679, Article 22

EN draft. SME review pending (regtech lead). No SME quotes or credentials fabricated.