Regulation (EU) 2026/1744, the Digital Omnibus on AI, moved the EU AI Act’s high-risk deadlines and left most other dates where they were. Annex III high-risk obligations now apply from 2 December 2027 instead of 2 August 2026. Annex I obligations, for AI built into regulated products, move from 2 August 2027 to 2 August 2028.
The Digital Omnibus on AI is an amending regulation: it changes dates and obligations in Regulation (EU) 2024/1689, the EU AI Act, without replacing it. EUR-Lex records its adoption on 8 July 2026 and its publication in the Official Journal on 24 July 2026. On 27 July 2026 the regulation entered into force.
For most organisations, the omnibus changes less than the headlines implied. Only high-risk systems got more time. The records those systems depend on did not, and several duties unrelated to high-risk AI were already in force before the omnibus arrived.
What the omnibus actually moved
The omnibus moved three dates and added one prohibition.
In Annex III, stand-alone high-risk systems such as AI used in recruitment, credit scoring or education admissions gain 16 months: their obligations start on 2 December 2027. High-risk AI built into products regulated under Annex I, such as machinery or medical devices, gains 12 months and now starts on 2 August 2028.
Providers of generative AI systems that were already on the market before 2 August 2026 received a smaller extension, to 2 December 2026, for adding machine-readable marking to synthetic output under Article 50(2).
December 2026 also brings a ninth prohibited practice. Points (ba) and (bb), inserted into Article 5(1), ban AI systems that generate non-consensual intimate imagery of an identifiable person or child sexual abuse material.
Every EU AI Act date, old and new
Nine of the thirteen dates below read exactly as they did before 27 July 2026. Yet most coverage of the omnibus skips those rows, and they are the ones already binding you.
| Obligation | Provision | Date before 27 July 2026 | Date now | Moved? |
| Prohibited practices (the original eight) | Article 5(1)(a) to (h) | 2 February 2025 | 2 February 2025 | No |
| AI literacy | Article 4 | 2 February 2025 | 2 February 2025 | Date kept, duty rewritten |
| GPAI model obligations | Chapter V | 2 August 2025 | 2 August 2025 | No |
| Governance, notified bodies and penalties | Chapter III Section 4, Chapters VII and XII | 2 August 2025 | 2 August 2025 | No |
| General application, including Article 50 transparency | Article 113 | 2 August 2026 | 2 August 2026 | No |
| Commission fines on GPAI providers | Article 101 | 2 August 2026 | 2 August 2026 | No |
| Machine-readable marking for generative systems already on the market before 2 August 2026 | Articles 50(2) and 111(4) | 2 August 2026 | 2 December 2026 | Yes, four months |
| Ban on AI generating non-consensual intimate imagery or child sexual abuse material | Article 5(1)(ba) and (bb) | Did not exist | December 2026 | New |
| Annex III high-risk obligations | Article 6(2), Chapter III Sections 1 to 3 | 2 August 2026 | 2 December 2027 | Yes, 16 months |
| GPAI models placed on the market before 2 August 2025 | Article 111(3) | 2 August 2027 | 2 August 2027 | No |
| Annex I high-risk obligations | Article 6(1) | 2 August 2027 | 2 August 2028 | Yes, 12 months |
| High-risk systems already on the market and intended for public authorities | Article 111(2) | 2 August 2030 | 2 August 2030 | No |
| Components of the large-scale EU IT systems listed in Annex X | Article 111(1) | 31 December 2030 | 31 December 2030 | No |
For the table, the sources are the EUR-Lex consolidated text of 27 July 2026, and the European Commission for the December 2026 prohibition date.
Is August 2026 still a deadline for you?
The omnibus left 2 August 2026 in place for most of the Act. According to the European Commission, the AI Act became applicable on 2 August 2026 with some exceptions, and the Article 50 transparency rules applied from that day.
Article 50 splits those duties between two parties. Under Article 50(1) and (2), providers must design systems that interact with people so that users know they are dealing with AI, and providers of generative systems must mark synthetic output. Deployers carry the disclosure duties for emotion recognition, biometric categorisation and deepfakes, as the AI Act Service Desk sets out.
If you built your own customer chatbot, you are normally its provider. Under Article 3, “putting into service” includes supplying a system “for own use”, so the Article 50(1) design duty is yours, and it has applied since 2 August 2026.
The omnibus moved the high-risk regime as a block. Its recital 40 covers Chapter III Sections 1 to 3: the classification rules, the requirements for high-risk systems, and the obligations of providers, deployers and other parties. Deployer duties under Article 26 and the fundamental rights impact assessment under Article 27 therefore also start on 2 December 2027 for Annex III systems.
Which date applies to an AI agent?
No separate category or date exists for AI agents in the EU AI Act. Article 3(1) defines an AI system as a machine-based system “designed to operate with varying levels of autonomy”, so an agent that plans and takes actions is an AI system like any other. Its date follows its use, not its autonomy.
| What the agent does | Where it lands in the Act | Date that applies |
| Answers customers in chat or voice | Article 50(1) transparency, a provider duty | 2 August 2026, already in force |
| Drafts text, images or audio that people will see | Article 50(2) marking, for the provider of the generative system | 2 August 2026, or 2 December 2026 for systems on the market before 2 August 2026 |
| Screens job applicants or ranks candidates | Annex III, employment | 2 December 2027 |
| Assesses the creditworthiness of individuals | Annex III, access to essential private services | 2 December 2027 |
| Performs a safety function inside a product covered by Annex I | Article 6(1) | 2 August 2028 |
| Schedules, routes tickets or enters data, with no Annex III purpose | No high-risk duties; AI literacy and the prohibitions still apply | 2 February 2025 for those two |
Role is the harder question for agent builders. If a business configures an agent on a vendor platform, such as Salesforce Agentforce or Microsoft Copilot Studio, and puts it into service under its own name for its own use, it can meet the Article 3 definition of a provider. Article 25 adds three more routes to provider status: putting your name on a high-risk system, substantially modifying one, or changing a system’s intended purpose so that it becomes high-risk.
Settle that role before planning to the new date. Providers of high-risk systems carry technical documentation, a quality management system and conformity assessment. Deployers carry oversight, monitoring and log-keeping duties instead. Where the agent runs on a general-purpose AI model, that model’s provider has carried its own Chapter V obligations since 2 August 2025, separately from yours.
Why Brussels moved the dates
Recital 40 of Regulation (EU) 2026/1744 gives two reasons: harmonised standards arrived late, and so did the national competent authorities meant to supervise the rules.
Under Article 40, a harmonised standard cited in the Official Journal gives a provider a presumption of conformity with the requirements it covers. Without one, a provider argues conformity requirement by requirement, and neither an auditor nor a market surveillance authority has an agreed reference text to test against.
CEN-CENELEC is working to a Commission standardisation request covering ten areas, and the output so far is thin. EN 18286, on quality management systems, was approved in June 2026 as the first standard approved under the AI Act, but its citation in the Official Journal has not happened yet, so it confers no presumption of conformity today. On risk management, prEN 18228 closed its public enquiry at the end of July 2026 and remains a draft.
Commission guidance is behind as well. The draft guidelines on classifying high-risk systems were published on 19 May 2026, and the targeted consultation on them ran until 23 July 2026; no final version has been adopted.
The omnibus as adopted also differs from what the Commission first proposed. Under the November 2025 proposal, the high-risk rules would have started only after a Commission decision confirming that compliance support was available, followed by six months for Annex III and twelve for Annex I. Backstop dates of 2 December 2027 and 2 August 2028 applied if the decision never came. Parliament and Council kept the backstops and removed the trigger, so the latest possible dates became the only dates.
Articles written between November 2025 and July 2026 often describe that conditional mechanism as if it were law, but it never became law.
The records that do not wait for 2027
Untouched by the omnibus are the rules on when high-risk records must exist.
Article 11(1) says technical documentation for a high-risk system “shall be drawn up before that system is placed on the market or put into service”. Take a hiring agent due to launch in the EU in December 2027. Its Annex IV file is due on launch day and describes design choices, data decisions and test results made through 2026 and 2027, so those decisions need recording as they happen rather than reconstructing later.
From launch, retention runs for a decade. Under Article 18(1), providers keep that documentation available to national authorities for ten years after the system is placed on the market, and Article 19(1) requires automatically generated logs to be kept for at least six months. Logging therefore has to be designed into the system, not added in 2027.
For legacy systems, the burden is quieter. Recitals to Regulation (EU) 2026/1744 state that a significant change to the design of a high-risk system already on the market should trigger full compliance. Anyone relying on that rule has to show the design did not change significantly, which takes a versioned change record kept from the start.
Each of these duties produces a named record with an owner and a retention period, and the obligation-to-evidence map lists them article by article.
Other changes in the same regulation
- AI literacy: the omnibus rewrote Article 4, which used to require providers and deployers to “take measures to ensure, to their best extent, a sufficient level of AI literacy”. Article 4 now asks them to “take measures to support the development of AI literacy” and adds that no specific level has to be guaranteed. The 2 February 2025 date is unchanged.
- Safety components: the omnibus added Article 6(1a), under which AI used solely for non-safety user assistance, performance optimisation, service efficiency, automation, convenience or quality control does not count as a safety component. The change removes some product-embedded AI from the Annex I route, so check what high-risk classification now means before assuming a product feature is high-risk.
- SMEs and small mid-caps: Article 3 now defines SMEs and small mid-cap enterprises (SMCs), and the simplified technical documentation in Article 11 and lighter quality management in Article 63 extend to firms that did not qualify before.
- Registration: the omnibus simplified registration for systems a provider has assessed as not high-risk under Article 6(3). Documenting that assessment before placing the system on the market is still required.
Put simply, the omnibus moved two high-risk deadlines and one marking deadline, added two prohibitions and softened the AI literacy duty. Prohibitions, GPAI duties, Article 50 transparency and every retention period stayed where they were. December 2027 is when a high-risk file gets inspected; 2026 is when it gets written.
Govern365 provides tooling for the EU regime for teams tracking these dates across many systems, recording each system’s risk tier, owner and evidence in one registry. Scope, risk tiers and penalties are covered in the EU regime in full.
Frequently asked questions
Is the Digital Omnibus on AI already law?
Regulation (EU) 2026/1744 is in force. Parliament and Council adopted it on 8 July 2026, and it entered into force on 27 July 2026, three days after publication in the Official Journal. Its dates bind every provider and deployer in scope of the EU AI Act, and it is an adopted regulation, not a proposal.
Did the omnibus delay the Article 50 transparency rules?
The omnibus left Article 50 on its original date of 2 August 2026. Only providers of generative AI systems placed on the market before 2 August 2026 got more time: until 2 December 2026 to apply machine-readable marking to their outputs. Chatbot disclosure duties have applied since 2 August 2026.
Does the EU AI Act have a separate deadline for AI agents?
The Act has no agent-specific category or deadline. An agent is an AI system under Article 3(1), so its date depends on its use. Since 2 August 2026, Article 50 has covered customer-facing agents. From 2 December 2027, Annex III covers agents that screen job candidates or score credit.
Does the high-risk delay apply to deployers as well as providers?
Yes. Recital 40 moves Chapter III Sections 1 to 3 together, and those sections contain the obligations of providers and deployers alike. A deployer of an Annex III system, including one that owes a fundamental rights impact assessment under Article 27, now works to 2 December 2027 rather than 2 August 2026.
Is the AI literacy obligation still in force?
Article 4 has applied since 2 February 2025, and the omnibus did not move that date. The wording changed: providers and deployers must now take measures to support AI literacy, and the text says no specific level has to be guaranteed. A record of the measures taken remains the practical evidence if a regulator asks.
Could the high-risk dates move again?
Only another amending regulation could move them. Under the November 2025 proposal, a Commission decision would have set the start date. The adopted text removed that mechanism and wrote both dates into Article 113, so no Commission decision can now bring either date forward or push it back.
When do the new bans on nudification apps apply?
The European Commission states that the ninth prohibited practice, covering AI that generates non-consensual intimate content or child sexual abuse material, comes into effect in December 2026. Regulation (EU) 2026/1744 inserted it into Article 5(1) as points (ba) and (bb).
