There’s a lot of confusion right now about effective dates for EU AI Act Article 11 and EU Annex IV technical documentation.
Some sources still quote 2 August 2026, but this is no longer accurate. If you built a business case for building an AIBOM capability with EU AI Act deadlines as a driver, now is the time to revisit your business case.
Introduction to AIBOMs
An AI bill of materials is a machine-readable inventory of an AI system’s components. For each model it includes an inventory of:
- The model
- Training and fine-tuning datasets
- Software dependencies
- Provenance
- Licencing
Where the confusion comes from
Regulation (EU) 2026/1744 is the cause. Also known as the AI Omnibus, it was an EU legislative package published on 24 July 2026 that entered into force on 27 July 2026. The AI Omnibus amended the original EU AI Act to ease compliance burdens for businesses, postpone key high-risk obligation deadlines, ban harmful tools and expand the supervisory powers of the EU AI Office.
So while the original EU AI Act was to come into force on 2 August 2026, the AI Omnibus that amended it came into force 6 days earlier. Hence the confusion.
And while the EU AI Act does not explicitly mandate the use of AIBOMs, requirements for detailed technical documentation and transparency regarding training data, system architecture and provenance, elevated AIBOMs to an essential tool for compliance. Many organisations used this as a business case driver for them.
Impacts to high-risk obligation deadlines
High-risk obligations were deferred by category groupings:
- Standalone Annex III systems had deadlines updated to 2 December 2027
- AI embedded in products already regulated under EU product safety law, Annex I, had deadlines update to 2 August 2028
As a result, you’ll two sets of dates out there in published form which is something to watch out for.
Looking further, the provisions that were deferred include everything you would have likely used a a justification for AIBOMs, including in risk management systems, conformity assessment, registration, technical documentation, logging and human oversight.
What stayed the same
Three key areas:
- Article 50 transparency obligations still came into force from 2 August 2026. This means that any system that interacts with people, or, generates or manipulates content, has disclosure duty, regardless of if it’s high-risk.
- Article 50(2) extends to systems already on the market from 2 December 2026.
- Article 4 AI literacy duty has applied since 2 February 2025 without deferral.
What got added
The AI Omnibus also added prohibitions for non-consensual intimate imagery and child sexual abuse material generation, effective from 2 December 2026.
Why this matters for an Australian entity
There’s a couple of factors to consider:
- If your AIBOM business case was built with the original August 2026 EU deadline as a driver, you may be called out by your funding committee
- You should pivot to Australian obligations and developments that can serve as a forcing function instead
What to pivot to
A couple of good options exist:
- Australian Privacy Principle (APP) updates that are coming up make a good case. APP 1 (Open and transparent management of personal information) introduces transparency requirements for automated decision-making that come into force on 10 December 2026.
- APRA’s April Letter to Industry on Artificial Intelligence listed expectations on AI assurance and third-party risk. Those expectations carry no commencement date as they interpreted standards that are already in force in context of AI.
Both of these can make good cases for rolling out AIBOMs.
Sources
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), 24 July 2026
- Gibson Dunn, EU AI Act Omnibus Agreement — Postponed High-Risk Deadlines — https://www.gibsondunn.com/eu-ai-act-omnibus-agreement-postponed-high-risk-deadlines-and-other-key-changes/
- CycloneDX, Machine Learning Bill of Materials — https://cyclonedx.org/capabilities/mlbom/
