The 2026 Digital Omnibus moved four AI Act deadlines, not two: Annex III to 2 December 2027, Annex I to 2 August 2028, national sandboxes to 2 August 2027, and content marking to 2 December 2026. Prohibited practices, GPAI rules and Art. 50 transparency were untouched.
Update — 2 August 2026. The Omnibus deferred the high-risk regime but not the transparency regime, which is now live and enforceable. Read what changed on 2 August 2026.
What the 2026 Digital Omnibus on AI changed
The Digital Omnibus on AI moved four application dates. Two are widely reported; the other two are the ones that catch compliance programmes out.
| Provision | Before omnibus | After omnibus | Basis |
|---|---|---|---|
| High-risk AI — Annex III (standalone) | 2 August 2026 | 2 December 2027 | Art. 6(2), Annex III |
| High-risk AI — Annex I (embedded in regulated products) | 2 August 2026 | 2 August 2028 | Art. 6(1), Annex I |
| National regulatory sandboxes | 2 August 2026 | 2 August 2027 | Art. 57–63 |
| Content marking — systems already on the market | 2 August 2026 | 2 December 2026 | Art. 50(2) |
Everything else kept its date. The omnibus did not create new obligations, remove existing ones, or introduce derogations or exemptions.
What kept its original date
| Provision | Applies since | Status |
|---|---|---|
| Prohibited practices (Art. 5) | 2 February 2025 | In force |
| GPAI model obligations (Chapter 5, Art. 51–56) | 2 August 2025 | In force |
| Transparency duties (Art. 50) | 2 August 2026 | In force |
| Commission enforcement over GPAI providers | 2 August 2026 | In force |
The sandbox deferral is the one most often got wrong. Article 57 requires each Member State to have a national AI regulatory sandbox operational; that obligation moved to 2 August 2027. It is regularly listed among the provisions the omnibus left alone. It is not one of them — see the national implementation tracker for where each Member State currently stands.
Why the Commission extended the deadlines
Three official reasons:
-
Standards not ready — Harmonised technical standards needed for conformity assessments under AI Act Art. 40 were not finalised by the original August 2026 deadline. Without these standards, conformity assessments could not be completed properly.
-
Enforcement infrastructure gap — Notified bodies needed designation and accreditation. National competent authorities required resources and guidelines. The EU AI Office needed operational capacity. An August 2026 deadline would have been unenforceable in practice.
-
Industry and SME readiness — Particularly for smaller providers in medtech, HR technology, and financial services, the parallel burden of AI Act, DORA (January 2025), and NIS2 (October 2024) compliance was cited as excessive.
What the omnibus does NOT do
The omnibus extension is commonly misread as reducing the regulatory burden. It does not:
- Remove any obligation
- Create an exemption for any sector or company size
- Reduce fines for non-compliance after the new deadlines
- Change the scope of what constitutes high-risk AI under Annex III or Annex I
- Affect GPAI rules, prohibited practice bans, or transparency obligations
What this means for a compliance programme
The deferral changes when you must be ready, not what ready means. Three consequences follow, and they run in opposite directions depending on which annex you fall under.
If your system is stand-alone high-risk (Annex III) — recruitment scoring, credit assessment, biometric identification, education, essential services — you have until 2 December 2027. That sounds distant. It is roughly one conformity-assessment cycle: a notified body engagement plus the technical documentation of Annex IV typically runs 12 to 18 months, and notified bodies are still being designated. The deferral removes the crisis, not the lead time.
If your AI is a safety component of a regulated product (Annex I) — medical devices, machinery, civil aviation, vehicles — you have until 2 August 2028, but your sectoral conformity assessment is already running on its own cycle. The practical question is whether your next MDR, Machinery or type-approval submission falls before or after that date, because aligning the two is far cheaper than doing them twice.
If you deploy a chatbot or generate synthetic content, none of this applies to you. Article 50 has been enforceable since 2 August 2026, and the only omnibus concession was a grace period to 2 December 2026 for systems already on the market. That is the nearest real deadline for most organisations, and it is the one the deferral headlines have obscured.
The classification question comes first
Every date above depends on a determination you may not have made: whether your system is high-risk at all. Most are not. Annex III point 5(b) explicitly carves out AI used to detect financial fraud; point 1 excludes one-to-one biometric verification; algorithmic trading appears nowhere in the annex.
Working through classification before buying anything is the difference between a proportionate programme and an expensive one. The risk classifier walks the Annex III categories, and providers vs deployers settles which set of obligations attaches to your role.
Detailed guide to deadline changes
For the obligation-by-obligation breakdown and a compliance programme timeline, see AI Act Omnibus 2026: New Deadlines Explained →.
Editorial, not legal advice.
Official AI Act Compliance Deadline Calendar
Updated · Sources: Regulation (EU) 2024/1689 and the 2026 Digital Omnibus on AI.
| Obligation | Applies to | Original date | New date | Status | Countdown | Legal basis |
|---|---|---|---|---|---|---|
| Prohibited Practices (Art. 5) | All providers and deployers | active | — | AI Act Art. 5 | ||
| GPAI Rules (Chapter 5) | GPAI model providers | active | — | AI Act Art. 51-56 | ||
| Commission Enforcement Powers over GPAI | GPAI model providers | active | — | AI Act Art. 88-94, 101 | ||
| Transparency Obligations (Art. 50) | Providers and deployers of chatbots, generative, emotion recognition systems | active | — | AI Act Art. 50 | ||
| New Art. 5 Prohibition (CSAM / non-consensual intimate imagery) | Providers and deployers of generative AI systems | active | — | AI Omnibus 2026 Art. 5 | ||
| AI-Generated Content Marking (pre-existing systems) | Providers of generative AI systems on the market before 2 Aug 2026 | active | — | AI Act Art. 50(2) — transitional | ||
| Regulatory Sandboxes | National competent authorities | deferred | — | AI Omnibus 2026 Art. 57 | ||
| High-risk AI — Annex III (standalone) | Providers of standalone Annex III systems | deferred | — | AI Omnibus 2026 Art. 6(2) | ||
| High-risk AI — Annex I (embedded) | AI embedded in Annex I regulated products | deferred | — | AI Omnibus 2026 Art. 6(1) |
⬇ Download JSON · CC BY 4.0
AI Act meets DORA and NIS2
Is your organisation subject to both the AI Act and DORA? The two regulations intersect on the operational resilience of financial AI systems. Our sister site regulation-dora.eu covers DORA in depth — including what the AI Act adds on top of an existing DORA programme.
The AI Act for financial institutions ↗ Explore regulation-dora.eu ↗Frequently Asked Questions
The Digital Omnibus on AI is an EU legislative act adopted in mid-2026 that amended Regulation (EU) 2024/1689 (the AI Act). Its primary effect was extending two compliance deadlines — for Annex III standalone high-risk AI to 2 December 2027, and for Annex I embedded high-risk AI to 2 August 2028 — to allow time for harmonised standards and enforcement infrastructure to be established.
No. The omnibus is a temporal extension only. All obligations — conformity assessment, QMS, technical documentation, CE marking, EU database registration, fundamental rights impact assessments — remain identical. Only the deadlines shifted.
Prohibited practices (Art. 5, in force since 2 February 2025), GPAI model obligations (Chapter 5, in force since 2 August 2025) and the Art. 50 transparency duties (applicable since 2 August 2026) were all left in place. Note that the national regulatory sandbox obligation WAS moved, from 2 August 2026 to 2 August 2027 — it is often listed as unchanged, and it is not.
Four. Annex III standalone high-risk AI to 2 December 2027; Annex I embedded high-risk AI to 2 August 2028; the national regulatory sandbox obligation to 2 August 2027; and the content-marking grace period for systems already on the market to 2 December 2026. The first two are the ones usually reported; the other two catch organisations out.
Stay ahead of AI Act changes
Get compliance alerts when deadlines or obligations change.
No spam. One-click unsubscribe.
Take compliance further with the AI Act Academy
Templates, training modules, and live Q&A — everything needed to implement AI Act compliance.