EU AI ACT · DIGITAL OMNIBUS
The looming deadline just moved
to December 2027.
The EU AI Act's high-risk system obligations, due August 2, 2026, have been postponed to December 2, 2027 under the newly enacted "Digital Omnibus on AI." It is not a blanket freeze — the AI-content transparency duty already took effect on schedule this summer.
What actually got delayed
The first major amendment since the AI Act was adopted in June 2024.
As of earlier this year, many companies were still operating on the assumption that mandatory compliance for high-risk AI systems was imminent this summer. That assumption came apart when the Council of the EU and the European Parliament reached a provisional agreement on May 7, 2026 on the "Digital Omnibus on AI" — the first substantive amendment to the AI Act since its adoption in June 2024.
Parliament approved it in plenary on June 16, 2026 by a wide 423–57 margin (174 abstentions), and the Council gave final approval on June 29, 2026. Regulation (EU) 2026/1744, adopted July 8, was published in the EU Official Journal on July 24 and entered into force on July 27 — just six days before the original August 2 compliance deadline it postponed. The full legal text is available on EUR-Lex.
What changes, and by when
Standalone systems get 16 months; embedded products get 12. The deferral length differs by obligation type.
The deferral is not uniform. Standalone high-risk AI systems under Annex III move from August 2, 2026 to December 2, 2027 — a 16-month delay. High-risk AI embedded in existing products under Annex I (medical devices, machinery, etc.) moves from August 2, 2027 to August 2, 2028 — a 12-month delay. The deadline for member states to stand up national regulatory sandboxes was also pushed back one year, from August 2, 2026 to August 2, 2027.
Some obligations were not touched
Reading "delayed" as "the duty vanished" is the most dangerous misreading here.
What's easy to miss: this amendment does not touch Article 50's transparency obligations — labeling AI-generated content, disclosing chatbot interactions, and the like. That duty took effect on schedule on August 2, 2026, entirely independent of the delay debate. Only the machine-readable marking requirement for AI-generated content gets a grace period, and only for services already on the market, until December 2, 2026.
| Delayed | Not delayed |
|---|---|
| Annex III standalone high-risk AI (→2027.12.02) | Article 50 transparency & AI-content labeling (in force since 2026.08.02) |
| Annex I embedded high-risk AI (→2028.08.02) | Article 4 staff AI-literacy duty |
| National regulatory sandboxes (→2027.08.02) | New ban on non-consensual intimate deepfakes & CSAM generation (in force 2026.12.02) |
Why the EU chose to delay now
The "Digital Omnibus on AI" didn't appear out of nowhere. It was proposed as part of the broader "Digital Omnibus" simplification package the European Commission published on November 19, 2025, covering the EU's digital rulebook as a whole. GDPR, the DSA, and the AI Act all came into force in close succession, and industry pushback grew louder over "overlapping reporting and audit burdens eroding competitiveness." Concern over European firms' competitiveness against the pace of AI development in the US and China was one factor cited repeatedly in law-firm analysis of the deal, according to Gibson Dunn's commentary.
In other words, the delay reads less as regulatory retreat and more as avoiding enforcement before the implementation machinery could keep up. Multiple law-firm analyses converge on the same point: conformity-assessment bodies and the harmonized standards that standards bodies were supposed to deliver were clearly not going to be ready for the original August 2026 deadline.
Who this affects, and how
Two personas here — business and pm — and each should deprioritize a different piece.
Business leaders / executives
You can push the budget and headcount earmarked for high-risk conformity assessment and technical documentation out to late 2027. That's not a reason to drop it entirely — the practical move is to shift to a phased build-out that tracks the standards-body timeline rather than shelving it outright.
Product managers / engineering leads
Annex III work (risk-management systems, data-governance build-out) can come off the roadmap — but Article 50's AI-content disclosure and chatbot labeling cannot. If your product ships generative AI features or an automated chatbot and that disclosure isn't implemented yet, it's the highest-priority item on your list.
What to do next
Lock down transparency labeling first
Prioritize Article 50 work — labeling AI-generated content and disclosing chatbot use. The machine-readable marking requirement carries a grace period to December 2, 2026, but only for services already on the market.
Push high-risk work later in the roadmap
Re-target Annex III and Annex I conformity assessment and technical documentation for late 2027. Waiting for harmonized standards to publish before starting means less rework later.
Watch for reversal risk
This deal is a deferral, not a repeal. Keep tracking implementation guidance from the European Commission and the AI Office, and stay ready for any move to pull the timeline back in or widen scope.
A delay does not mean the obligation is gone.
December 2027 is just the next deadline.