A targeted rewrite of the AI Act timetable

The European Union’s Digital Omnibus on AI entered into force on 27 July 2026, changing the implementation schedule for some of the AI Act’s most demanding requirements. Formally known as Regulation (EU) 2026/1744, the measure amends the AI Act and related product rules with the stated aim of making compliance more proportionate and workable as the wider regime moves into its enforcement phase.

The central practical change is a delay to obligations for high-risk AI systems. Rules for stand-alone high-risk systems listed in Annex III of the AI Act will now apply from 2 December 2027. These are systems used in fields such as employment, education, access to essential services, law enforcement, migration, justice and certain biometric uses. The previous timetable would have brought many of those obligations into application on 2 August 2026.

A separate category, high-risk AI embedded in regulated products covered by Annex I, will apply from 2 August 2028. This category covers AI components associated with products subject to EU sectoral safety law, including areas such as machinery, toys and lifts. The change gives product manufacturers and their suppliers more time to align AI compliance with established product-conformity processes.

The postponement is substantial, but it should not be read as a general suspension of the AI Act. The Omnibus changes a complicated sequence of obligations rather than replacing it with a single later deadline.

What still applies in 2026

The near-term compliance picture remains important for providers and deployers of AI in Europe. Rules for general-purpose AI models have applied since 2 August 2025, alongside the governance arrangements intended to support the Act. The AI Act’s transparency provisions are still scheduled to start applying on 2 August 2026, only days after the Omnibus entered into force.

Those transparency rules are relevant to organisations deploying systems that interact directly with people or generate certain forms of synthetic content. Businesses should therefore avoid treating the new high-risk dates as a reason to pause their overall AI governance programmes. They will still need to assess which obligations apply to their systems now, which apply later, and whether a system falls into more than one regulatory category.

The Omnibus also establishes a new prohibition concerning AI systems that generate non-consensual sexually explicit or intimate content, as well as child sexual abuse material. That prohibition is due to apply from 2 December 2026. Its inclusion illustrates the policy balance behind the legislation: the EU has delayed some complex conformity-assessment requirements while maintaining, and in this case adding, protections directed at acute risks to individuals.

Why the EU moved the high-risk deadlines

The Commission has linked the revised schedule to the availability of standards and other practical support tools needed to implement the high-risk regime. High-risk compliance is not limited to a one-off legal assessment. It can involve risk-management systems, technical documentation, record-keeping, human oversight, accuracy and cybersecurity controls, quality-management processes, registration and, in some cases, third-party conformity assessment.

For companies building or deploying affected systems, these tasks depend on detailed technical guidance, standards and an operating market of notified bodies. Delaying application can therefore reduce the risk that organisations are expected to meet requirements before the supporting infrastructure is sufficiently mature.

That rationale may improve legal predictability for businesses, but it also shifts an important burden onto regulators. The extra time will be valuable only if it results in usable standards, clear guidance, functioning supervisory capacity and more consistent interpretation across Member States. Otherwise, organisations may face the same uncertainty closer to the new deadlines.

Broader relief for smaller businesses

The Omnibus extends certain simplified approaches previously available to small and medium-sized enterprises to small mid-cap companies. This matters because businesses beyond the conventional SME threshold can still lack the compliance teams, legal budgets and engineering resources of the largest technology groups.

The revised framework also reduces some administrative prescription. It simplifies aspects of EU database registration for systems used in high-risk areas that do not themselves qualify as high-risk, and removes the requirement for a harmonised post-market monitoring plan in favour of greater flexibility. These changes do not remove the need for responsible monitoring after deployment, but they may give companies more room to integrate monitoring into existing quality and risk processes.

AI literacy has also been adjusted. Rather than relying on an open-ended obligation for all operators, the Commission and Member States are assigned a stronger role in promoting AI literacy and sharing support. Training responsibilities remain particularly relevant for deployers of high-risk systems, where competent human oversight is a core element of the wider regulatory model.

Testing, data and supervision

The law also broadens access to regulatory sandboxes and real-world testing. These supervised environments are designed to let developers and deployers test systems while engaging with regulators on compliance questions. Member States are expected to have at least one AI regulatory sandbox in operation by 2 August 2027, while an EU-level sandbox is planned from 2028.

For teams developing systems in sensitive domains, this could be more consequential than a deadline extension alone. Early testing with supervisory engagement may expose documentation, safety or governance gaps before a system reaches a wider market. It may also help organisations make better decisions about whether a proposed use case is genuinely high-risk.

The Omnibus further permits the processing of special categories of personal data for bias detection and correction, subject to safeguards. The change addresses a practical difficulty in fairness work: testing for discriminatory outcomes can require carefully controlled access to data that reveal protected characteristics. It does not create a general permission to use sensitive data freely. Organisations must still address the relevant data-protection requirements, necessity, safeguards and limits on use.

Governance is also being consolidated in important areas. The AI Office receives expanded oversight responsibilities for certain AI systems built on general-purpose models and for AI embedded in very large online platforms and search engines. The intended effect is to reduce fragmented supervision for systems that can operate across borders and at significant scale.

The practical message for AI teams

For providers, the revised timetable offers more planning room for Annex III and Annex I high-risk systems. It should be used to build a robust system inventory, map products and use cases to AI Act categories, identify the organisation’s role as provider, deployer or another actor, and establish evidence trails for design decisions and controls.

For deployers, especially employers, education providers, financial institutions and public bodies, the key task is to distinguish a deferred high-risk obligation from an obligation that is already active. Procurement and deployment policies should account for transparency duties, existing general-purpose AI requirements, upcoming content-related prohibitions and sector-specific law.

The Omnibus therefore changes the pace of the EU’s AI rulebook, not its direction. Its immediate effect is to provide time and procedural flexibility for the most complex parts of high-risk compliance. Its longer-term test will be whether regulators, standards bodies and companies use that time to make the eventual framework clearer, more consistent and more enforceable.

Sources