Skip to content

Digital Omnibus: what the EU AI Act delay actually means for you

6 min read by John Bagnall

If you have seen the headline, it probably read “EU delays the AI Act.” That is half the story, and the missing half is the half that can catch you out. The EU’s Digital Omnibus does defer the AI Act’s high-risk obligations, by more than a year, but it leaves several duties exactly where they were, it is not yet law, and it is emphatically not a reason to stop. This post is what actually changed, what did not, and what a sensible organisation does with the extra runway.

This is a dated readiness explainer (August 2026), not legal advice. We keep the canonical calendar current in the EU AI Act deadlines.

What the Digital Omnibus is

The Digital Omnibus is an EU package that amends the AI Act, largely to postpone the high-risk obligations. The stated reason is practical rather than political: the harmonised standards and the support tools organisations need in order to comply with the high-risk requirements were not going to be ready for the original deadline. A political agreement was reached in 2026 and confirmed by the Council.

The one nuance that matters: at the time of writing it is agreed but pending formal adoption. It becomes legally binding only once it is formally adopted and published in the Official Journal, expected around August 2026. So the new dates are settled policy, not yet settled law. Plan around them; watch for the final text.

What actually moved

Two deadlines shifted, both on the high-risk regime:

  • Standalone high-risk systems (Annex III), the ones most organisations worry about (AI in hiring, credit, education, essential services), move from 2 August 2026 to 2 December 2027.
  • High-risk AI built into already-regulated products (Annex I) moves from 2 August 2027 to 2 August 2028.

That is a real extension, roughly sixteen months for the Annex III duties. If your exposure is a standalone high-risk system, the core deployer duties, responsible use (Article 26) and a fundamental-rights impact assessment where required (Article 27), now apply from December 2027.

What did not move

This is the part the headline skips, and the part that catches people out. The Omnibus did not touch:

  • Prohibited practices (Article 5). Banned outright since February 2025, still banned. Using one is still the fastest route to the heaviest penalties.
  • AI literacy (Article 4). In force since February 2025, unchanged. You still have to ensure the people using or affected by your AI understand it well enough to use it responsibly. We cover it in the Article 4 duty in practice.
  • General-purpose AI model rules. Applied from August 2025, unchanged; models on the market before then still have until August 2027 to come into line.
  • Transparency (Article 50), still 2 August 2026. Telling people when they are interacting with an AI, and labelling AI-generated or deepfake content, was not deferred. If your AI talks to customers or produces content, this one lands on the original date.

So if you were mentally filing “the EU AI Act” under a single 2026 deadline, note that literacy and prohibitions bite now, transparency bites in August 2026, and only the high-risk regime moved to 2027.

The catch: agreed, not yet law

It is worth being precise, because your prospects and auditors will be. The Digital Omnibus is a done political deal, but until it is published in the Official Journal it has not amended the Act in law. The practical risk of the final text differing from the agreement is low, but it is not zero, and the original 2 August 2026 high-risk date remains the legal position until publication replaces it. The grown-up posture is to plan on December 2027 while keeping an eye on the gazette.

What the delay means for you

Strip away the noise and it comes to this:

  • If you deploy standalone high-risk AI: you have genuinely more time, to December 2027, for the heaviest obligations. Use it to do the work properly rather than to postpone starting it.
  • If your AI is customer-facing or generates content: nothing changed for you that matters. Article 50 transparency still lands in August 2026. Get that in place.
  • Everyone: the duties already in force are unaffected. Not using anything prohibited, and meeting the AI literacy duty, were never 2026 problems and still are not.

The trap is reading “delayed” as “deprioritised.” The delay changes one date. It does not change the fact that most of the work, knowing what AI you run and being able to show it is governed, is the same work you would do anyway, and the same work your customers are already asking about.

What to do with the runway

The best use of sixteen extra months is the unglamorous groundwork that makes the high-risk duties a checklist rather than a scramble:

  1. Inventory the AI you use and build. You cannot govern what you have not mapped.
  2. Classify each system by risk. That tells you which of these dates actually apply to you, and most systems are not high-risk.
  3. Meet the duties that already bite: confirm nothing is prohibited, do the literacy work, and stand up Article 50 transparency for August 2026.
  4. For anything high-risk, design in human oversight and the evidence trail now, while you have the time, so December 2027 is a formality.

Done this way, the extension is a gift rather than an excuse: the same governance that satisfies the regulator in 2027 is what wins the enterprise deal in 2026.

The short version

The Digital Omnibus defers the AI Act’s high-risk obligations, standalone Annex III systems to 2 December 2027 and regulated-product Annex I systems to 2 August 2028, and it is agreed but pending formal adoption. It does not delay the rest: prohibited practices and AI literacy remain in force now, general-purpose AI rules are unchanged, and the Article 50 transparency duties still apply from 2 August 2026. So the honest read is not “the AI Act is delayed, relax.” It is “one date moved, the others held, and the work that earns you the extra time is the work your customers already want to see.” Treat the runway as time to get it right, not time to wait.

Not sure which of these dates apply to you? The free EU AI Act check maps your systems to the obligations that actually attach, in about ten minutes, no email required. When you want to turn the timeline into a plan, our AI governance consulting builds the governance that holds up to a regulator and a customer alike. For the full picture, see the EU AI Act guide.

Frequently asked questions

What is the Digital Omnibus?

The Digital Omnibus is an EU package that amends the AI Act, mainly to postpone the high-risk obligations because the harmonised standards and support tools needed to comply were not ready in time. A political agreement was reached in 2026 and confirmed by the Council. It becomes legally binding only once formally adopted and published in the Official Journal, expected around August 2026, so at the time of writing it is agreed but pending formal adoption.

Has the EU AI Act been delayed?

Partly. The Digital Omnibus defers the core high-risk obligations, but it does not delay the whole Act. The prohibited-practice ban and the AI literacy duty have applied since February 2025 and are unchanged. General-purpose AI model rules (since August 2025) are unchanged. And the transparency duties under Article 50 still apply from 2 August 2026. What moved is the high-risk regime, not everything.

What are the new high-risk deadlines?

Under the Digital Omnibus, the core obligations for standalone high-risk systems (Annex III, such as AI in hiring, credit or essential services) are deferred from 2 August 2026 to 2 December 2027. High-risk AI built into already-regulated products (Annex I) is deferred from 2 August 2027 to 2 August 2028. These are the agreed dates; they become binding on formal adoption and publication in the Official Journal.

What did NOT get delayed?

Quite a lot. Prohibited practices (Article 5) remain banned now. The AI literacy duty (Article 4) still applies now. General-purpose AI model obligations still apply from August 2025. And, importantly, the Article 50 transparency duties (telling people they are dealing with AI, labelling AI-generated content) still land on 2 August 2026. If you were treating "the AI Act" as one 2026 deadline, several parts of it still bite regardless of the delay.

Does the delay mean we can wait?

No, for three reasons. First, the duties already in force (literacy, prohibitions) and the transparency duties in August 2026 are unaffected, so "later" is already wrong for those. Second, the high-risk work, inventorying your AI, classifying it, standing up oversight and evidence, takes months, so December 2027 is closer than it sounds. Third, enterprise buyers are asking vendors to prove AI governance now, well ahead of any legal deadline, so the commercial clock runs faster than the regulatory one.


Building something you need to govern?

Start with a fixed-scope AI Opportunity & Risk Audit.

Meet an Expert