AI governance

EU AI Act after the Digital Omnibus: what still applies in 2026 and what moved to 2027

The Digital Omnibus pushed the EU AI Act's high-risk rules to December 2027 and August 2028. Transparency duties did not move, and some already apply.

Short answer

The Digital Omnibus, Regulation (EU) 2026/1744, entered into force on 27 July 2026 and moved the EU AI Act's Annex III high-risk obligations from 2 August 2026 to 2 December 2027, and Annex I product-embedded AI to 2 August 2028. Article 50 transparency obligations were not delayed and have applied since 2 August 2026.

Key takeaways

  • Annex III high-risk systems (employment, credit, education, biometrics and more): 2 December 2027.
  • AI in products under Annex I legislation: 2 August 2028.
  • Article 50 transparency: in force since 2 August 2026.
  • Generative AI already on the market before 2 August 2026 has until 2 December 2026 for machine-readable marking.

The new timeline

Timeline

EU AI Act, as amended

  1. Prohibited practices apply
  2. General-purpose AI model obligations
  3. Article 50 transparency applies
  4. Marking deadline for existing generative AISystems on the market before 2 Aug 2026.
  5. Annex III high-risk obligations
  6. Annex I product-embedded AI

What moved

High-risk obligations for Annex III use cases, such as AI used in recruitment, credit scoring, education, biometrics and critical infrastructure, now apply from 2 December 2027 instead of 2 August 2026. AI built into products regulated under Annex I legislation, such as machinery or medical devices, has until 2 August 2028.

What did not move

  • Prohibited practices have applied since 2 February 2025.
  • General-purpose AI model obligations have applied since 2 August 2025.
  • Article 50 transparency obligations, such as telling people they are interacting with an AI system and labelling deepfakes, have applied since 2 August 2026.

How to use the extra time

A delay is not a reason to pause. The work that takes longest is the same in 2026 as in 2027: knowing which AI systems you have, which are high-risk, and who is accountable for each. An AI management system under ISO/IEC 42001 gives that work a structure auditors already recognise, although it does not by itself show conformity with the AI Act.

Checklist

EU AI Act next steps

0 of 6 done

Frequently asked questions

When do EU AI Act high-risk obligations apply?

After the Digital Omnibus, Annex III high-risk obligations apply from 2 December 2027 and Annex I product-embedded AI from 2 August 2028.

Were the EU AI Act transparency rules delayed?

No. Article 50 transparency obligations were not amended by the Digital Omnibus and apply from 2 August 2026.

Sources

  1. EU AI Act Omnibus agreement: postponed high-risk deadlines and other key changes, Gibson Dunn
  2. Yes, August 2 still matters: the EU approved a high-risk AI delay, but most transparency obligations remain, Jones Walker
  3. EU AI Act Article 50: transparency obligations take effect, Cloud Security Alliance