The Digital Omnibus on AI is adopted. The European Parliament endorsed the agreed text on 16 June 2026 and the Council gave its final approval on 29 June 2026; the amending regulation enters into force on the third day after its publication in the Official Journal. Stand-alone high-risk obligations under Annex III move from 2 August 2026 to 2 December 2027. High-risk AI embedded in regulated products under Annex I moves from 2 August 2027 to 2 August 2028. The Article 50 transparency duties keep their 2 August 2026 date. This article lists every date that moved, every date that held, the registration and Annex VIII changes, and what a governance program can finish in the sixteen extra months. Orientation only; not legal advice.
Every application date, before and after the Omnibus
The Omnibus is a timing and simplification instrument. It reopened Article 113, the article that sets when each chapter of the EU AI Act starts to apply, and moved the high-risk application dates. It left the substance of Chapter III intact: the same risk management, data governance, technical documentation, logging, transparency, human oversight, accuracy, and quality management obligations arrive later, in the same shape.
The Commission had originally proposed a conditional trigger tied to the availability of harmonised standards, with a backstop date. The adopted text uses fixed calendar dates, so there is one timeline to plan against.
| Obligation | Original date | Date after the Omnibus |
|---|---|---|
| Chapter III obligations for stand-alone high-risk AI systems (Annex III) | 2 August 2026 | 2 December 2027 |
| Article 27 fundamental rights impact assessment (FRIA) for deployers | 2 August 2026 | 2 December 2027 |
| Article 49 registration and the Article 71 EU database | 2 August 2026 | 2 December 2027 |
| High-risk AI as a safety component of products under Annex I legislation | 2 August 2027 | 2 August 2028 |
| At least one operational AI regulatory sandbox per Member State (Article 57) | 2 August 2026 | 2 August 2027 |
| Article 50 transparency duties for providers and deployers | 2 August 2026 | 2 August 2026 (unchanged) |
| Machine-readable marking for generative systems already on the market | 2 August 2026 | 2 December 2026 (grace period) |
| New Article 5 prohibitions on CSAM and non-consensual intimate imagery | Added by the Omnibus | 2 December 2026 |
| Prohibited practices under Article 5 as originally enacted | 2 February 2025 | 2 February 2025 (unchanged) |
| General-purpose AI model obligations (Chapter V) | 2 August 2025 | 2 August 2025 (unchanged) |
August 2026 still lands, for a smaller set of duties
Anything customer-facing is on the original clock. Article 50 requires providers to tell people when they are interacting with an AI system, to mark synthetic audio, image, video, and text in a machine-readable format, and requires deployers to disclose deepfakes and AI-generated text published to inform the public on matters of public interest. Emotion recognition and biometric categorisation systems must inform the people exposed to them. All of that applies from 2 August 2026.
The single concession is a short grace period: generative systems already placed on the market before 2 August 2026 have until 2 December 2026 to implement machine-readable marking. Systems placed on the market after that date have no runway.
The Article 5 prohibitions have been enforceable since 2 February 2025, and the Omnibus adds two more: AI systems that generate child sexual abuse material and systems that generate non-consensual intimate imagery, both prohibited from 2 December 2026. General-purpose AI model obligations have applied since 2 August 2025. The Omnibus also broadened the AI Office supervisory remit to AI systems built on general-purpose AI models, and reworded the Article 4 AI literacy duty into an obligation to promote and encourage AI literacy through proportionate measures.
For most enterprises running assistants, copilots, and customer-facing agents, the August 2026 work item narrows to disclosure, labelling, and the evidence that both are happening in production.
Registration survived with a lighter payload
The Commission proposed removing the Article 49(2) duty to register Annex III systems that a provider self-assesses as not high-risk under Article 6(3). Parliament and the Council rejected the deletion and reinstated the obligation with a smaller data set.
Two entries in Annex VIII Section B are deleted. Point 7 was the short summary of the grounds on which the system is considered not high-risk under the Article 6(3) procedure. Point 9 was the list of Member States in which the system has been placed on the market, put into service, or made available in the Union.
Point 6 survives, so a provider still has to name which Article 6(3) condition its system meets. The underlying assessment is unchanged: Article 6(3) still requires the provider to document the assessment before placing the system on the market, and Article 80 still lets a market surveillance authority reopen the classification. The database field is gone. The file that justifies the decision still has to exist.
Registration itself now follows the Annex III date of 2 December 2027, along with the Article 71 EU database. The registration guide covers who registers what, and how the Annex VIII payload differs from the Annex IV technical file.
The FRIA moves with Annex III
The Article 27 fundamental rights impact assessment is a deployer duty attached to Annex III high-risk systems, so it follows the new date of 2 December 2027. It applies to bodies governed by public law, private entities providing public services, and deployers of AI used for creditworthiness assessment or credit scoring and for risk assessment and pricing in life and health insurance.
Two things about the FRIA are worth planning around even with the later date. The assessment describes the deployment process, the period and frequency of use, the categories of people affected, the specific risks of harm to them, the human oversight measures, and the remedies if a risk materialises. Most of that content only exists once the system is designed and the oversight model is decided, which puts the drafting work upstream of the deadline by months.
The second is Article 27(4): a data protection impact assessment carried out under the GDPR can be complemented by the FRIA rather than duplicated. Teams that already run DPIAs for credit scoring or insurance pricing have a usable starting point. The FRIA template guide walks through the six sections, and the free FRIA generator drafts a structured first pass.
What the extra sixteen months leave in place
The Omnibus moved dates in one regulation. The exposure that makes an AI agent risky in a regulated function sits across several.
- Article 50 lands on schedule. Disclosure and content marking apply from 2 August 2026 to every AI system that talks to a person or produces synthetic content.
- Sector regimes are untouched. DORA operational resilience duties, the EU AML package, the GDPR, national supervisory expectations, and prudential model risk rules apply to an AI-driven decision the same way they apply to any other.
- GDPR Article 22 still governs automated decisions. A credit or claims decision made without meaningful human involvement carries a right to human review, an explanation, and a route to contest, regardless of when Chapter III starts to apply.
- Incidents keep their own schedule. A wrongly closed alert, an over-permissioned tool call, or an agent that acts on a prompt-injected instruction produces customer harm and a supervisory conversation on the day it happens.
- Conformity capacity does not expand with the deadline. Notified bodies, harmonised standards, and internal audit teams all move at the same speed. The queue for 2 December 2027 is the same queue, further out.
- Harmonised standards are still in draft. prEN 18286 (quality management), prEN 18228 (risk management), prEN 18283 (bias), and prEN 18284 (data governance) are unpublished. The standards timeline tracks where each one sits.
What sixteen months are enough to build
A compliance program passes an audit when the organisation can show what a system actually did on a specific date, who authorised it, which controls fired, and what a human decided. That evidence has to be produced while the work happens, by the systems doing the work.
Sixteen months is enough time to move governance from documentation into the execution path. The work below is useful on its own merits and it is the same work Chapter III will ask for in December 2027.
- Inventory and classify. Name every AI system, its intended purpose, its provider or deployer role, and its Annex III status. Record the Article 6(3) reasoning where you claim a system is not high-risk. This is the input to registration, the FRIA, and the technical file.
- Put policy in the execution path. Encode the limits an agent operates under as enforceable rules that run before a tool call, so the record of a blocked action exists because the block happened. The `KLA Policy Engine` evaluates each Decision Request at the point of action.
- Make human oversight an operating surface. Article 14 oversight is a person who can interpret output, override it, and stop the system. That needs a queue, an owner, a service level, and a record of what was decided. `Decision Desk` is where those Decision Requests are worked.
- Capture lineage as the run happens. Inputs, tool calls, model versions, policy decisions, approvals, and outcomes belong on one record per run. `Lineage Explorer` reconstructs a specific case; `Audit Trail` holds the tamper-evident history behind it.
- Build the evidence package once. Article 11 technical documentation, Article 12 logging, Article 17 quality management records, and the Article 72 post-market monitoring plan draw on the same underlying runs. `Evidence Room` produces a Sealed Evidence Bundle a third party can verify without access to your systems.
- Govern change. A substantial modification under Article 3(23) reopens conformity assessment. Version, review, and approve releases now so the link between a production version and its evidence holds later.
- Map controls to frameworks you already report against. `Control Mapping` lines EU AI Act articles up with ISO/IEC 42001, DORA, and internal control libraries so one control test answers several reviewers.
A sixteen-month sequence
The sequence below assumes an enterprise with AI already in a regulated function and a 2 December 2027 target for Annex III obligations. Adjust the front end if Article 50 disclosure work is still open.
| Window | Outcome to have finished |
|---|---|
| Now to 2 August 2026 | Article 50 disclosure and content marking live in every customer-facing system, with logs that show the disclosure was served. AI system inventory complete with role and Annex III classification. |
| Q4 2026 | Article 6(3) assessments documented for every system claimed as not high-risk. Machine-readable marking closed out by 2 December 2026. Oversight owners named per system. |
| H1 2027 | Risk management (Article 9) and data governance (Article 10) operating with evidence. Logging (Article 12) capturing the fields the technical file will need. FRIA drafts started for in-scope deployments. |
| H2 2027 | Annex IV technical documentation assembled. Quality management system (Article 17) running with internal audit evidence. Conformity assessment route chosen and, where a notified body is required, booked. |
| By 2 December 2027 | Registration payload submitted, FRIA notified to the market surveillance authority under Article 27(3), post-market monitoring plan (Article 72) operating, declaration of conformity signed. |
| By 2 August 2028 | The same package completed for high-risk AI embedded in Annex I products, aligned with the sectoral conformity assessment already required for that product. |
How this changes the 2026 budget conversation
The most likely response to a sixteen-month deferral is a paused program and a reassigned team. That converts a scheduling change into a capability gap, because the parts of the work with the longest lead time are the ones that get cut first: instrumentation, evidence capture, oversight staffing, and the classification decisions that everything else depends on.
A defensible position for 2026 keeps the execution-layer work funded and lets the documentation work follow the new dates. Instrumentation has to be designed into systems while they are being built. Retrofitting evidence capture into an agent that has been running for a year is the expensive version of the same project.
The EU AI Act requirements guide holds the full obligation map, and the deadline timeline shows the phased dates against your own system profile.
Frequently Asked Questions
Is the EU AI Act delayed?
The high-risk obligations are. The Digital Omnibus on AI, endorsed by the European Parliament on 16 June 2026 and adopted by the Council on 29 June 2026, moves Chapter III obligations for stand-alone Annex III high-risk systems from 2 August 2026 to 2 December 2027, and high-risk AI embedded in Annex I products from 2 August 2027 to 2 August 2028. The prohibitions, the general-purpose AI model rules, and the Article 50 transparency duties keep their original dates.
What is the new EU AI Act deadline for high-risk AI systems?
2 December 2027 for stand-alone high-risk systems listed in Annex III, and 2 August 2028 for high-risk AI that is a safety component of a product covered by the Annex I harmonisation legislation. The Article 27 FRIA and the Article 49 registration duty follow the Annex III date.
Did the Omnibus delay the Article 50 transparency obligations?
No. Article 50 applies from 2 August 2026 as originally enacted. The only concession is a grace period to 2 December 2026 for machine-readable marking of generative AI systems already placed on the market before 2 August 2026.
When is the FRIA required under the new timeline?
The Article 27 fundamental rights impact assessment is a deployer duty tied to Annex III high-risk systems, so it applies from 2 December 2027. It covers bodies governed by public law, private entities providing public services, and deployers of AI used for credit scoring or for risk assessment and pricing in life and health insurance.
Do we still have to register a system we self-assess as not high-risk under Article 6(3)?
Yes. The Commission proposed deleting that duty and the co-legislators kept it, with a smaller payload. Annex VIII Section B points 7 and 9 are deleted, removing the short summary of the grounds for the Article 6(3) determination and the list of Member States where the system has been made available. Point 6 remains, so the provider still names the Article 6(3) condition relied on, and the underlying assessment still has to be documented before the system goes on the market.
When do the new AI regulatory sandboxes have to be operational?
Each Member State must have at least one AI regulatory sandbox operational by 2 August 2027 under Article 57, moved from 2 August 2026.
Should we pause our EU AI Act program until 2027?
The parts with the longest lead time are worth keeping funded: system inventory and classification, Article 50 disclosure work that lands in August 2026, runtime logging and evidence capture, and named human oversight owners. Documentation and conformity assessment can follow the new dates. Instrumentation is far cheaper to design in than to retrofit.
Key Takeaways
The Digital Omnibus on AI moved the high-risk application dates and simplified the registration payload for systems self-assessed as not high-risk. Chapter III arrives on 2 December 2027 for Annex III systems and 2 August 2028 for Annex I products, with the same obligations it always carried. Article 50 disclosure and content marking still land on 2 August 2026. The sixteen months are enough to move governance out of documents and into the execution path, where the evidence an auditor asks for is produced while the agent runs. Start with the EU AI Act hub for the current phased timeline, or check your own dates with the deadline timeline. This article is general information and not legal advice; confirm your obligations with qualified counsel and re-check the Official Journal text before relying on any date.
