Why it matters
  • Delay. The EU’s Digital Omnibus, which entered into force July 27, 2026, pushed the compliance deadline for high-risk AI systems under Annex III of the EU AI Act from August 2, 2026 to December 2, 2027 — a 16-month postponement.
  • Scope. The deferral covers AI systems used in employment, credit decisions, education, and law enforcement — the categories with the highest compliance burden, including mandatory risk management frameworks, data-governance audits, and human-oversight requirements.
  • Still active. Article 50 transparency obligations — covering AI-generated content labelling and synthetic-media disclosure — took effect on August 2 as originally scheduled, along with the EU AI Office’s enforcement powers.

The European Council gave final approval to the Digital AI Omnibus on June 29, 2026, and the package entered into force less than a month later. For companies operating high-risk AI systems with users in the EU — including non-European firms — the deadline for complying with Articles 9 through 17 of the AI Act shifted from August 2, 2026 to December 2, 2027, according to DLA Piper and compliance trackers. Those articles govern risk management systems, data-governance standards, technical documentation, accuracy logging, and human-oversight requirements. A second tier of postponement applies to AI components embedded in EU-regulated products — medical devices, toys, lifts, radio equipment — where obligations are deferred to August 2, 2028.

What Remained On Schedule

The postponement does not represent a wholesale retreat on AI governance. Transparency obligations under Article 50, which require providers to disclose AI-generated content and label synthetic audio, images, and video, took effect on August 2 as planned. The EU AI Office — which holds enforcement authority over general-purpose AI models, including the GPAI code of practice — also became fully operational on August 2. Companies deploying AI chatbots, image-generation services, and synthetic-media tools remain subject to these requirements without delay.

Why Brussels Pulled Back

European policymakers cited a readiness gap facing enterprises, particularly small and medium-sized businesses, as the primary justification for the extension. Research from the Cloud Security Alliance found that a significant proportion of EU firms subject to the high-risk regime had not completed the required conformity assessments or established the internal audit infrastructure the Act demands by the original deadline.

The delay also reflects broader competitive anxiety within EU institutions. Brussels has watched the United States and China accelerate AI deployment while European firms have faced what industry lobbies characterised as an asymmetric compliance burden. The Digital Omnibus was designed in part to address that concern — buying time for adaptation without abandoning the substantive rules. AI regulation is advancing on parallel tracks: as the EU extends its compliance window, the United States is pursuing its own accountability framework for AI, including threatened sanctions against foreign firms accused of intellectual property theft through model distillation.

For enterprises that had already begun compliance programmes in anticipation of the August 2 deadline, the extension offers breathing room but creates an internal governance question: whether to maintain the compliance pace now that the legal deadline has moved. Most legal advisers recommend continuing implementation rather than pausing — given that the December 2027 date can shift again and that the EU AI Office has signalled it will use the intervening period to increase guidance and supervisory engagement.