Skip to main content
All policy updates
Regulatory

Digital Omnibus in force: high-risk AI obligations deferred to December 2027

The EU's Digital Omnibus on AI was published in the Official Journal on 24 July 2026 and entered into force on 27 July. Obligations for stand-alone high-risk systems (Annex III) move from 2 August 2026 to 2 December 2027, and for AI embedded in already-regulated products (Annex I) to 2 August 2028. The deferral is now law rather than proposal, which matters: many compliance plans were still being written against the original August 2026 date.

The Digital Omnibus on AI was published in the Official Journal of the European Union on 24 July 2026 and entered into force on 27 July 2026.

What moved

  • Annex III — stand-alone high-risk systems. Deferred from 2 August 2026 to 2 December 2027.
  • Annex I — AI embedded in products already covered by EU safety legislation. Deferred to 2 August 2028.

What did not move

  • Article 50 transparency obligations, which applied from 2 August 2026.
  • The Article 5 prohibitions, which were extended to cover "nudifier" applications and the generation of child sexual abuse material.
  • General-purpose AI model obligations, in effect since 2 August 2025.

The omnibus also softened the Article 4 AI literacy duty to requiring measures supporting AI literacy rather than guaranteeing competence, and extended the deadline for member states to establish regulatory sandboxes to 2 August 2027.

Why we are flagging it

Until late July this was a provisional agreement, not law, and a number of published compliance timelines still assumed high-risk obligations landing in August 2026. That assumption is now wrong by sixteen months for Annex III systems.

The useful reading is not that the pressure is off. Sixteen months is roughly the lead time an organisation needs to build a defensible conformity story for a high-risk system — evidence, documentation, human oversight arrangements — rather than assemble one retrospectively. The deferral is an argument for starting, not for waiting.

Certifying the human behind the algorithm

AIC certifies that a named human remains accountable for the automated decisions that matter, and publishes the result so anyone can check it.

Contact us