EU adopts Digital Omnibus on AI: extended timelines and simplified compliance

Back

Extended timelines

The Digital Omnibus on AI provides additional time for compliance with requirements applying to high-risk AI systems. The revised timetable distinguishes between standalone high-risk systems and AI systems embedded in products governed by EU product-safety legislation.

  • 2 December 2027 for certain standalone high-risk AI systems; and
  • 2 August 2028 for high-risk AI systems embedded in regulated products.

Companies should verify the classification and legal basis applicable to each system rather than relying on a single organisation-wide deadline.

 

Key simplifications

  • Selected proportionate measures previously reserved for SMEs are extended to small mid-cap companies.
  • Access to regulatory sandboxes and testing opportunities is expanded, including through an EU-level sandbox.
  • The interaction between the AI Act and other EU legislation is clarified.
  • Procedures involving conformity-assessment bodies are simplified.
  • The AI Office receives extended oversight powers for certain systems, including systems built on general-purpose AI models and embedded in large online platforms or search engines.

 

What has not changed

The Digital Omnibus on AI does not remove the AI Act’s risk-based framework or delay every obligation. Transparency duties under Article 50 apply according to their separate timetable, and the rules on prohibited AI practices, general-purpose AI and other governance obligations must be assessed independently.

The additional time for high-risk systems should therefore be used to complete inventories, governance structures, risk-management processes, technical documentation and vendor controls.

 

What businesses should do now

  1. Update implementation roadmaps. Reflect the revised high-risk timelines while retaining the deadlines that have not changed.
  2. Confirm system classification. Distinguish standalone high-risk systems from AI embedded in regulated products.
  3. Continue governance work. Maintain AI inventories, accountability structures, risk assessments, and human-oversight arrangements.
  4. Review vendor contracts. Align documentation, audit, cooperation, and change-management obligations with the revised timetable.
  5. Assess available support. Determine whether the company qualifies for SME or small mid-cap simplifications or can benefit from regulatory sandboxes.

 

FAQ

Has the EU AI Act been postponed?

No. The Omnibus extends certain timelines and simplifies selected requirements, but the AI Act remains in force and several obligations continue to apply under their existing or separate timelines.

When do the high-risk AI rules apply?

The revised timetable generally points to 2 December 2027 for certain standalone high-risk systems and 2 August 2028 for high-risk AI systems embedded in regulated products. The precise date must be assessed for each system and legal category.

Should companies pause their AI Act projects?

No. Implementation programmes should be adjusted, not stopped. The additional time should be used to improve AI inventories, governance, technical documentation, contracting and operational readiness.

Sources

  • Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026, Official Journal of 24 July 2026.