EU AI Act Timeline After the Digital Omnibus: What Moved and What Did Not

Share Article

Table of Contents

Regulation (EU) 2026/1744, the Digital Omnibus on AI, moved the EU AI Act’s high-risk deadlines and left most other dates where they were. Annex III high-risk obligations now apply from 2 December 2027 instead of 2 August 2026. Annex I obligations, for AI built into regulated products, move from 2 August 2027 to 2 August 2028.

The Digital Omnibus on AI is an amending regulation: it changes dates and obligations in Regulation (EU) 2024/1689, the EU AI Act, without replacing it. EUR-Lex records its adoption on 8 July 2026 and its publication in the Official Journal on 24 July 2026. On 27 July 2026 the regulation entered into force.

For most organisations, the omnibus changes less than the headlines implied. Only high-risk systems got more time. The records those systems depend on did not, and several duties unrelated to high-risk AI were already in force before the omnibus arrived.

What the omnibus actually moved

The omnibus moved three dates and added one prohibition.

In Annex III, stand-alone high-risk systems such as AI used in recruitment, credit scoring or education admissions gain 16 months: their obligations start on 2 December 2027. High-risk AI built into products regulated under Annex I, such as machinery or medical devices, gains 12 months and now starts on 2 August 2028.

Providers of generative AI systems that were already on the market before 2 August 2026 received a smaller extension, to 2 December 2026, for adding machine-readable marking to synthetic output under Article 50(2).

December 2026 also brings a ninth prohibited practice. Points (ba) and (bb), inserted into Article 5(1), ban AI systems that generate non-consensual intimate imagery of an identifiable person or child sexual abuse material.

Every EU AI Act date, old and new

Nine of the thirteen dates below read exactly as they did before 27 July 2026. Yet most coverage of the omnibus skips those rows, and they are the ones already binding you.

ObligationProvisionDate before 27 July 2026Date nowMoved?
Prohibited practices (the original eight)Article 5(1)(a) to (h)2 February 20252 February 2025No
AI literacyArticle 42 February 20252 February 2025Date kept, duty rewritten
GPAI model obligationsChapter V2 August 20252 August 2025No
Governance, notified bodies and penaltiesChapter III Section 4, Chapters VII and XII2 August 20252 August 2025No
General application, including Article 50 transparencyArticle 1132 August 20262 August 2026No
Commission fines on GPAI providersArticle 1012 August 20262 August 2026No
Machine-readable marking for generative systems already on the market before 2 August 2026Articles 50(2) and 111(4)2 August 20262 December 2026Yes, four months
Ban on AI generating non-consensual intimate imagery or child sexual abuse materialArticle 5(1)(ba) and (bb)Did not existDecember 2026New
Annex III high-risk obligationsArticle 6(2), Chapter III Sections 1 to 32 August 20262 December 2027Yes, 16 months
GPAI models placed on the market before 2 August 2025Article 111(3)2 August 20272 August 2027No
Annex I high-risk obligationsArticle 6(1)2 August 20272 August 2028Yes, 12 months
High-risk systems already on the market and intended for public authoritiesArticle 111(2)2 August 20302 August 2030No
Components of the large-scale EU IT systems listed in Annex XArticle 111(1)31 December 203031 December 2030No

For the table, the sources are the EUR-Lex consolidated text of 27 July 2026, and the European Commission for the December 2026 prohibition date.

Is August 2026 still a deadline for you?

The omnibus left 2 August 2026 in place for most of the Act. According to the European Commission, the AI Act became applicable on 2 August 2026 with some exceptions, and the Article 50 transparency rules applied from that day.

Article 50 splits those duties between two parties. Under Article 50(1) and (2), providers must design systems that interact with people so that users know they are dealing with AI, and providers of generative systems must mark synthetic output. Deployers carry the disclosure duties for emotion recognition, biometric categorisation and deepfakes, as the AI Act Service Desk sets out.

If you built your own customer chatbot, you are normally its provider. Under Article 3, “putting into service” includes supplying a system “for own use”, so the Article 50(1) design duty is yours, and it has applied since 2 August 2026.

The omnibus moved the high-risk regime as a block. Its recital 40 covers Chapter III Sections 1 to 3: the classification rules, the requirements for high-risk systems, and the obligations of providers, deployers and other parties. Deployer duties under Article 26 and the fundamental rights impact assessment under Article 27 therefore also start on 2 December 2027 for Annex III systems.

Which date applies to an AI agent?

No separate category or date exists for AI agents in the EU AI Act. Article 3(1) defines an AI system as a machine-based system “designed to operate with varying levels of autonomy”, so an agent that plans and takes actions is an AI system like any other. Its date follows its use, not its autonomy.

What the agent doesWhere it lands in the ActDate that applies
Answers customers in chat or voiceArticle 50(1) transparency, a provider duty2 August 2026, already in force
Drafts text, images or audio that people will seeArticle 50(2) marking, for the provider of the generative system2 August 2026, or 2 December 2026 for systems on the market before 2 August 2026
Screens job applicants or ranks candidatesAnnex III, employment2 December 2027
Assesses the creditworthiness of individualsAnnex III, access to essential private services2 December 2027
Performs a safety function inside a product covered by Annex IArticle 6(1)2 August 2028
Schedules, routes tickets or enters data, with no Annex III purposeNo high-risk duties; AI literacy and the prohibitions still apply2 February 2025 for those two

Role is the harder question for agent builders. If a business configures an agent on a vendor platform, such as Salesforce Agentforce or Microsoft Copilot Studio, and puts it into service under its own name for its own use, it can meet the Article 3 definition of a provider. Article 25 adds three more routes to provider status: putting your name on a high-risk system, substantially modifying one, or changing a system’s intended purpose so that it becomes high-risk.

Settle that role before planning to the new date. Providers of high-risk systems carry technical documentation, a quality management system and conformity assessment. Deployers carry oversight, monitoring and log-keeping duties instead. Where the agent runs on a general-purpose AI model, that model’s provider has carried its own Chapter V obligations since 2 August 2025, separately from yours.

Why Brussels moved the dates

Recital 40 of Regulation (EU) 2026/1744 gives two reasons: harmonised standards arrived late, and so did the national competent authorities meant to supervise the rules.

Under Article 40, a harmonised standard cited in the Official Journal gives a provider a presumption of conformity with the requirements it covers. Without one, a provider argues conformity requirement by requirement, and neither an auditor nor a market surveillance authority has an agreed reference text to test against.

CEN-CENELEC is working to a Commission standardisation request covering ten areas, and the output so far is thin. EN 18286, on quality management systems, was approved in June 2026 as the first standard approved under the AI Act, but its citation in the Official Journal has not happened yet, so it confers no presumption of conformity today. On risk management, prEN 18228 closed its public enquiry at the end of July 2026 and remains a draft.

Commission guidance is behind as well. The draft guidelines on classifying high-risk systems were published on 19 May 2026, and the targeted consultation on them ran until 23 July 2026; no final version has been adopted.

The omnibus as adopted also differs from what the Commission first proposed. Under the November 2025 proposal, the high-risk rules would have started only after a Commission decision confirming that compliance support was available, followed by six months for Annex III and twelve for Annex I. Backstop dates of 2 December 2027 and 2 August 2028 applied if the decision never came. Parliament and Council kept the backstops and removed the trigger, so the latest possible dates became the only dates.

Articles written between November 2025 and July 2026 often describe that conditional mechanism as if it were law, but it never became law.

The records that do not wait for 2027

Untouched by the omnibus are the rules on when high-risk records must exist.

Article 11(1) says technical documentation for a high-risk system “shall be drawn up before that system is placed on the market or put into service”. Take a hiring agent due to launch in the EU in December 2027. Its Annex IV file is due on launch day and describes design choices, data decisions and test results made through 2026 and 2027, so those decisions need recording as they happen rather than reconstructing later.

From launch, retention runs for a decade. Under Article 18(1), providers keep that documentation available to national authorities for ten years after the system is placed on the market, and Article 19(1) requires automatically generated logs to be kept for at least six months. Logging therefore has to be designed into the system, not added in 2027.

For legacy systems, the burden is quieter. Recitals to Regulation (EU) 2026/1744 state that a significant change to the design of a high-risk system already on the market should trigger full compliance. Anyone relying on that rule has to show the design did not change significantly, which takes a versioned change record kept from the start.

Each of these duties produces a named record with an owner and a retention period, and the obligation-to-evidence map lists them article by article.

Other changes in the same regulation

  • AI literacy: the omnibus rewrote Article 4, which used to require providers and deployers to “take measures to ensure, to their best extent, a sufficient level of AI literacy”. Article 4 now asks them to “take measures to support the development of AI literacy” and adds that no specific level has to be guaranteed. The 2 February 2025 date is unchanged.
  • Safety components: the omnibus added Article 6(1a), under which AI used solely for non-safety user assistance, performance optimisation, service efficiency, automation, convenience or quality control does not count as a safety component. The change removes some product-embedded AI from the Annex I route, so check what high-risk classification now means before assuming a product feature is high-risk.
  • SMEs and small mid-caps: Article 3 now defines SMEs and small mid-cap enterprises (SMCs), and the simplified technical documentation in Article 11 and lighter quality management in Article 63 extend to firms that did not qualify before.
  • Registration: the omnibus simplified registration for systems a provider has assessed as not high-risk under Article 6(3). Documenting that assessment before placing the system on the market is still required.

Put simply, the omnibus moved two high-risk deadlines and one marking deadline, added two prohibitions and softened the AI literacy duty. Prohibitions, GPAI duties, Article 50 transparency and every retention period stayed where they were. December 2027 is when a high-risk file gets inspected; 2026 is when it gets written.

Govern365 provides tooling for the EU regime for teams tracking these dates across many systems, recording each system’s risk tier, owner and evidence in one registry. Scope, risk tiers and penalties are covered in the EU regime in full.

Frequently asked questions

Is the Digital Omnibus on AI already law?

Regulation (EU) 2026/1744 is in force. Parliament and Council adopted it on 8 July 2026, and it entered into force on 27 July 2026, three days after publication in the Official Journal. Its dates bind every provider and deployer in scope of the EU AI Act, and it is an adopted regulation, not a proposal.

Did the omnibus delay the Article 50 transparency rules?

The omnibus left Article 50 on its original date of 2 August 2026. Only providers of generative AI systems placed on the market before 2 August 2026 got more time: until 2 December 2026 to apply machine-readable marking to their outputs. Chatbot disclosure duties have applied since 2 August 2026.

Does the EU AI Act have a separate deadline for AI agents?

The Act has no agent-specific category or deadline. An agent is an AI system under Article 3(1), so its date depends on its use. Since 2 August 2026, Article 50 has covered customer-facing agents. From 2 December 2027, Annex III covers agents that screen job candidates or score credit.

Does the high-risk delay apply to deployers as well as providers?

Yes. Recital 40 moves Chapter III Sections 1 to 3 together, and those sections contain the obligations of providers and deployers alike. A deployer of an Annex III system, including one that owes a fundamental rights impact assessment under Article 27, now works to 2 December 2027 rather than 2 August 2026.

Is the AI literacy obligation still in force?

Article 4 has applied since 2 February 2025, and the omnibus did not move that date. The wording changed: providers and deployers must now take measures to support AI literacy, and the text says no specific level has to be guaranteed. A record of the measures taken remains the practical evidence if a regulator asks.

Could the high-risk dates move again?

Only another amending regulation could move them. Under the November 2025 proposal, a Commission decision would have set the start date. The adopted text removed that mechanism and wrote both dates into Article 113, so no Commission decision can now bring either date forward or push it back.

When do the new bans on nudification apps apply?

The European Commission states that the ninth prohibited practice, covering AI that generates non-consensual intimate content or child sexual abuse material, comes into effect in December 2026. Regulation (EU) 2026/1744 inserted it into Article 5(1) as points (ba) and (bb).

Stay ahead of the curve

Join 5,000+ industry leaders who receive our weekly briefing on AI governance and secure enterprise collaboration.

About the Author

Dr Faiz Rasool

Director at the Global AI Certification Council (GAICC) and PM Training School

Globally certified instructor in ISO/IEC, PMI®, TOGAF®, and Scrum.org disciplines with hands-on experience in ISO/IEC 42001 AI governance across the US, EU, and Asia-Pacific.

Summarize with AI

AI-Powered Data Governance Platform

Secure, Govern, and Collaborate on Sensitive Data—All Within Microsoft 365

Further Reading

Related Insights

ai-regulations

Global AI Regulation Tracker: Which Countries Have Binding AI Law in 2026

Five claims about global AI regulation are repeated so widely that they have stopped being

Read More →
ai-evidence

AI Compliance Evidence: The Records That Prove an AI Obligation Was Met

AI compliance evidence is the set of dated, attributable records that show an AI obligation

Read More →
ai-governance-united-states-laws-frameworks-evidence

AI Governance in the United States: Laws, Frameworks and Evidence Requirements

By March 2026, lawmakers in 45 states had introduced 1,561 AI-related bills, more than the

Read More →

Summarize with AI

Transforming AI Risks into Strategic Assets.

Request a Personalized Demo

Our governance experts will walk you through the platform and help you map out your ISO 42001 or EU AI Act roadmap.