EU AI Act: high-risk rules pushed back to December 2027
The EU has formally delayed the toughest parts of the AI Act. Regulation (EU) 2026/1744, the “Digital Omnibus on AI”, was published in the Official Journal on 24 July 2026 and is now in force. It moves the start date for stand-alone high-risk AI systems (the Annex III list, which includes recruitment tools and credit scoring) from 2 August 2026 to 2 December 2027. High-risk AI built into regulated products (Annex I) moves from 2 August 2027 to 2 August 2028.
What didn’t move matters just as much. The transparency duties in Article 50 still apply from 2 August 2026, so if you run a customer chatbot or publish AI-generated content in the EU, those rules start on Sunday.
How we got here
The Commission proposed the omnibus on 19 November 2025 as part of its digital simplification package. The Council agreed its position in March 2026, and the institutions reached a political deal on 7 May. The European Parliament voted it through on 16 June 2026, the Council adopted it on 29 June, and it was signed on 8 July. The timing was tight: without it, the high-risk rules would have started on 2 August 2026 with many of the supporting standards and guidance still unfinished.
What changed and what didn’t
| Obligation | Original date | Date now |
|---|---|---|
| Prohibited practices and AI literacy | 2 February 2025 | Unchanged |
| General-purpose AI models | 2 August 2025 | Unchanged |
| Transparency (Article 50) | 2 August 2026 | Unchanged, with a grace period to 2 December 2026 for marking AI output from systems already on the market |
| High-risk systems in Annex III | 2 August 2026 | 2 December 2027 |
| High-risk systems in products (Annex I) | 2 August 2027 | 2 August 2028 |
The omnibus also does a few other things:
- A new ban. It adds AI systems that generate non-consensual intimate imagery or child sexual abuse material to the list of prohibited practices. Law firm summaries give 2 December 2026 as the date this applies.
- Machinery. AI in machinery products comes out of the direct high-risk regime and is handled under the Machinery Regulation instead.
- Sandboxes. The deadline for each country to set up an AI regulatory sandbox moves to 2 August 2027.
The penalty levels don’t appear to have changed. Prohibited practices can still cost up to €35 million or 7% of worldwide turnover, whichever is higher. Most other breaches, including the Article 50 transparency duties, can cost up to €15 million or 3%. SMEs pay whichever of the two figures is lower.
One point is unclear. Commentators disagree on whether the omnibus softened the Article 4 AI literacy duty (the obligation to make sure staff who use AI understand it). One major firm reads the final text as asking companies to “support” literacy rather than ensure it. Another lists the duty as unchanged. Read the Official Journal text before you rewrite a training plan either way.
Who it affects
The AI Act applies to providers who put AI systems on the EU market and to deployers who use them in the EU. Location doesn’t get you out. A US or UK company whose AI system’s output is used in the EU can be in scope. The delay helps anyone building or buying Annex III systems, which include AI used in hiring and managing staff, in education, in creditworthiness checks, in biometrics and in critical infrastructure.
A worked example
TalentBridge, a Dublin recruitment agency, uses a vendor’s AI tool to rank CVs and a chatbot to answer candidates’ questions on its website.
- The CV ranking tool is an Annex III high-risk use (employment). TalentBridge had planned to finish its deployer checks (human oversight, logging, telling candidates) by August 2026. It now has until 2 December 2027.
- The chatbot is different. Under Article 50, people have to be told they’re dealing with an AI unless that’s obvious. That duty applies from 2 August 2026, so TalentBridge needs the disclosure live now.
My take: the extra 16 months is useful, but don’t treat it as a holiday. Vendors are going to push contract changes on high-risk tools through 2027, and buyers who already know what they need from a provider (documentation, logs, instructions for use) will negotiate better terms.
What to do now
- Inventory the AI systems you build or use, and tag each one as prohibited, high-risk (Annex III or Annex I), transparency-only or minimal.
- Make sure chatbots disclose that they’re AI and that synthetic content you publish is labelled where Article 50 requires it.
- Move your high-risk project plans to the new dates, but keep vendor due diligence moving.
- Check any AI tool that could generate intimate imagery against the new prohibition before December 2026.
- Review your AI literacy training against the final text of Article 4.
- Update your supplier contracts so AI Act duties and cooperation obligations are clear. Our representations and warranties and indemnification glossary entries are a good starting point.
Sources
- EU Publications Office: Regulation (EU) 2026/1744 (Digital Omnibus on AI)
- European Parliament Legislative Train: Digital Omnibus on AI
- AI Act, Article 99: penalties
- Gibson Dunn: AI Act omnibus agreement and postponed high-risk deadlines
- Freshfields: the final Digital Omnibus on AI
This article is general information, not legal or tax advice. Laws differ between countries and states and change over time, so check the rules that apply to you or speak to a qualified professional.