Compliance2026-07-108 min read

The EU Just Moved the AI Act Goalposts: What the Digital Omnibus Means for Your Roadmap

On 29 June 2026 the Council of the EU gave final sign-off to the Digital Omnibus, pushing the AI Act high-risk deadline from August 2026 out to December 2027. Here is what actually got delayed, what did not, and why a compliance-minded founder should not treat this as permission to relax.

The single most important date in AI regulation just moved. On 29 June 2026 the Council of the EU gave its final green light to the Digital Omnibus, the simplification package for the AI Act, following the European Parliament formal endorsement earlier in June. The headline change is that the compliance deadline for standalone high-risk AI systems, the use-based systems listed in Annex III of the Act, has been pushed from 2 August 2026 out to 2 December 2027. For any founder who had been racing a summer clock, that is roughly sixteen extra months of runway. It is tempting to read that as a reprieve and move on, but the detail underneath the headline is where the real planning happens, and some of it cuts the other way.

Start with what got delayed, because it is more than one line. Standalone Annex III high-risk systems, the category that captures AI used in hiring, credit scoring, education, essential services and similar consequential decisions, now have until 2 December 2027 to meet the full weight of the Act: conformity assessment, risk management, data governance, logging, human oversight and registration. High-risk AI embedded in products already regulated under Annex I, think medical devices and machinery, moved a year as well, from 2 August 2027 to 2 August 2028. Member states also got until 2 August 2027, rather than this summer, to stand up the national regulatory sandboxes that smaller companies were counting on to test systems under supervision. If your product sits in an Annex III use case, your legal deadline genuinely relaxed.

Now the part that did not move, because this is where teams will get caught. The obligations for general-purpose AI models, the GPAI rules in Articles 51 to 55 that bind the providers of frontier models, took effect on 2 August 2025 and continue on their original schedule, untouched by the Omnibus. What did change for GPAI is who enforces it: supervision is being centralised at the EU AI Office rather than spread across national authorities. So if you are building on top of a large model rather than training your own, the model you depend on is already inside the regulated perimeter, and your obligations as a deployer of that capability do not vanish just because the high-risk clock for your own system slipped.

Two more things arrive sooner than the delayed headline suggests. First, the transparency rules under Article 50, the machine-readable marking and watermarking of AI-generated and manipulated content, still land in December 2026, not 2027. If your product generates synthetic images, audio, video or text, that labelling obligation is roughly five months out, not eighteen. Second, the Omnibus adds new prohibitions to Article 5 that take effect on 2 December 2026, banning AI systems whose purpose is generating non-consensual intimate imagery and child sexual abuse material, with provider liability where such output is the intended purpose or a reasonably foreseeable and reproducible outcome. Those are hard prohibitions with the Act highest penalty tier behind them, up to 35 million euros or 7 percent of global turnover, and no company should be anywhere near that line regardless of deadlines.

So the honest summary is not the AI Act got delayed, it is the AI Act got re-sequenced, and the pieces most likely to touch an early-stage company, transparency labelling, GPAI dependence and the new prohibitions, are on the near end of the calendar while the heaviest bureaucratic lift moved to the far end. The strategic risk in a deferral is complacency: a founder who hears December 2027 and closes the tab will have missed that watermarking is a 2026 problem and that building on a frontier model already carries obligations today. The extra runway is real and valuable, but it is runway to do the work properly, not runway to ignore it.

This is exactly where an AI management system standard earns its keep, and it is why we keep pointing readers toward ISO 42001. A regulatory timeline that shifts under you, moving deadlines, re-sequenced obligations, centralised enforcement, is far easier to absorb if you already run a system whose whole job is to know which AI systems you operate, what they do, what data flows to them and who is accountable for each. ISO 42001 does not track the AI Act clause by clause, but a company operating a genuine AI management system can answer a regulator or an enterprise buyer about a re-sequenced obligation in an afternoon, while a company relying on tribal knowledge has to go rediscover its own AI footprint first. Certification is not the point here, operability is.

The practical near-term move is inventory and readiness, not panic and not a stand-down. Write down every AI feature you ship, note whether any fall into an Annex III high-risk use case, flag anything that generates synthetic content for the December 2026 transparency rule, and record which external models you depend on and therefore inherit exposure from. If you already carry ISO 27001 or SOC 2, you have most of the governance skeleton for this, and the GRC platforms have leaned into that overlap: Vanta, Drata and Secureframe all now offer ISO 42001 tooling that cross-maps to your existing security controls, so a control you already evidence for SOC 2 can be reused rather than rebuilt. The deferral gives you the time to do this deliberately instead of in a fire drill, which is the best possible use of sixteen extra months.

Our read is that the Digital Omnibus is a gift with a warning label. The gift is time, a meaningful extension for the hardest high-risk obligations and the sandboxes that help you meet them. The warning is that the near-term items, watermarking in December 2026, the new Article 5 prohibitions, and the GPAI obligations that never moved, are easy to overlook precisely because the headline was about delay. Use the runway to build a real AI governance foundation now, lean on the ISO 42001 cross-mapping in the compliance platform you already pay for, and keep an inventory current enough that the next time Brussels re-sequences the calendar, and there will be a next time, it is an update rather than an emergency.

EU AI ActDigital OmnibusAI governanceISO 42001GPAIhigh-risk AI

Editorial note: AES Tech reviews are independent. Some outbound links are affiliate links and are marked sponsored; they never change our rankings. See our disclosure.

// Signal, not noise

Get the next post by email

One short email when something worth knowing ships. No spam, unsubscribe anytime.

More from the blog