sota.io
Join the waitlist
2026-07-22·10 min read·sota.io team

EU AI Act Digital Omnibus Final Adoption: The December 2027 Delay Explained

EU AI Act Digital Omnibus Final Adoption: The December 2027 Delay Explained

If you have been racing to hit a 2 August 2026 compliance deadline for a high-risk AI system listed in Annex III of the EU AI Act, you need to read this post before you do anything else.

On 29 June 2026, the Council of the European Union formally adopted the "Digital Omnibus on AI," a legislative package of targeted amendments to Regulation (EU) 2024/1689. The European Parliament had voted in favour on 16 June 2026. The result: the compliance deadline for most high-risk AI systems has moved — significantly.

This post is the canonical reference for that change. Many earlier posts on this blog mentioned "2 August 2026" as the high-risk AI deadline. That date was correct when those posts were written. It is no longer correct for Annex III standalone systems. This post explains what changed, what stayed the same, and what the correct dates are now.

What the Digital Omnibus Is

The Digital Omnibus is not a separate regulation. It is an amending regulation — a targeted set of changes to the existing EU AI Act text. The European Commission proposed it in February 2026 as part of a broader simplification effort aimed at reducing compliance costs for SMEs and startups without undermining the Act's risk-based approach.

The main substantive change is a two-tier extension of the application dates for high-risk AI systems. Everything else — the definitions, the prohibited practices, the transparency requirements, the GPAI obligations — remains as originally enacted.

The Complete Deadline Map After the Digital Omnibus

Here is every relevant date, updated to reflect the amended regulation:

ObligationOriginal DateNew Date
Art.5 prohibited AI practices2 February 2025Unchanged (already in force)
GPAI model obligations (Chapter V, Art.51-56)2 August 2025Unchanged (already in force since Aug 2025)
Art.4 AI literacy obligations2 August 2025Unchanged (already in force)
Art.50 transparency requirements2 August 2026Unchanged at 2 August 2026
Art.50 grace period (systems already on market before 2 Aug 2026)2 December 2026 (new, Omnibus-introduced)
AI regulatory sandboxes (Art.57-65)2 August 20262 August 2027
Annex III standalone high-risk AI systems2 August 20262 December 2027
Annex I embedded high-risk AI (safety components in regulated products)2 August 20262 August 2028

Entry into force: three days after publication in the Official Journal of the European Union. Publication was expected before the original 2 August 2026 deadline, so the extended dates apply from the moment the regulation is in force.

Annex III Standalone Systems: The Primary Change

This is the change that affects most software teams building high-risk AI.

Annex III lists the categories of high-risk AI by use case: employment and workers management, access to essential private services (including creditworthiness), education and vocational training, administration of justice, law enforcement, migration, biometric identification, and management and operation of critical infrastructure.

If you are building a standalone AI system that falls into any of these categories — a recruitment screening tool, a credit scoring model, an educational assessment system, a biometric access control product — your full compliance deadline under the EU AI Act is now 2 December 2027, not 2 August 2026.

"Full compliance" means all of these obligations that this blog has covered in depth:

All of these obligations for Annex III standalone systems now apply from 2 December 2027.

Annex I Embedded Systems: An Even Longer Runway

If your AI system is embedded in a product covered by EU product safety law — medical devices (MDR/IVDR), machinery, lifts, toys, vehicles under the type-approval framework — and it functions as a safety component, your compliance deadline is 2 August 2028.

This additional 16-month extension beyond the standalone deadline reflects the regulatory reality that embedded AI cannot be updated independently of the physical product it is integrated into, making faster timelines structurally impractical.

What Did NOT Change: The Three Things Still Due in 2026

This is the most operationally critical part of this post. The Digital Omnibus extended the high-risk AI deadlines. It did not extend everything. Three categories of obligations remain exactly as originally scheduled:

1. Article 50 Transparency Requirements — Still 2 August 2026

Art.50 requires providers and deployers of certain AI systems to implement transparency and disclosure measures: watermarking AI-generated audio, images, video, and text in machine-readable form; informing users that they are interacting with an AI; labelling synthetic media (deepfakes).

This deadline is unchanged at 2 August 2026. If you are building a chatbot, an image generator, a text synthesis tool, or a deepfake detection system, your transparency obligations — user disclosure, machine-readable content marking — apply from 2 August 2026.

The Omnibus did introduce one grace period specifically for systems already on the market before 2 August 2026: those systems have until 2 December 2026 to implement the watermarking and transparency requirements. New systems deployed from 2 August 2026 onward must comply immediately.

2. GPAI Chapter V Obligations — Already Applied Since 2 August 2025

General-purpose AI model providers (Chapter V, Art.51-56) were always on an accelerated timeline. These obligations — technical documentation for GPAI providers, transparency to downstream deployers, copyright summary requirements, systemic risk assessments for frontier models — became applicable on 2 August 2025 and were not part of the Digital Omnibus amendments.

If you are building on top of a GPAI API (OpenAI, Anthropic, Google, etc.), the provider's Chapter V compliance obligations have already been in effect for a year. Your deployer-side contractual protections and due-diligence requirements around those obligations are unchanged.

3. Article 5 Prohibited Practices — Already in Force Since February 2025

The prohibitions — subliminal manipulation, exploitation of vulnerabilities, social scoring by public authorities, real-time remote biometric identification in public spaces (with narrow exceptions), emotion recognition in workplaces and education — have been in force since 2 February 2025. The Digital Omnibus does not touch Art.5.

What This Means for Teams That Were Already Preparing

If your team was on track to hit 2 August 2026 for high-risk AI compliance, you have a decision to make.

Option A: Continue the current pace. You arrive at full compliance 16 months early. That is not wasted effort — it is a competitive advantage. Compliance documentation for Annex III systems is expected to become part of procurement requirements in the enterprise and public sector long before the legal deadline. Early movers will win regulated-sector contracts.

Option B: Rebalance priorities. Use the extended runway to do the compliance work properly rather than at sprint pace. A rushed QMS, a superficial FRIA, or incomplete technical documentation creates legal exposure even if submitted on time. Quality compliance beats early compliance.

Option C: Delay until 2027. This is the highest-risk option. Regulatory sandboxes, notified body capacity, and legal interpretive guidance from national authorities will all develop through 2026-2027. Teams that wait until late 2027 to start will face resource bottlenecks at the same time as every other operator in the same sector.

The practical recommendation: continue your compliance work, but deprioritize anything purely cosmetic (documentation formatting, certification ceremony preparation) and invest the extra 16 months in substantive quality.

A Note on Entry Into Force

The Omnibus amending regulation enters into force three days after its publication in the Official Journal of the European Union. As of the date of this post, publication had not yet occurred, though it was expected imminently (the Council's adoption on 29 June 2026 cleared the final procedural hurdle).

Until the OJ publication date, the original 2 August 2026 deadline is technically the law still in effect. In practice, operators are reasonable to plan against the extended dates given the unambiguous legislative adoption. For formal compliance documentation, cite the OJ publication reference once it is available.

The Two Earlier Omnibus Posts on This Blog

Two posts from May 2026 covered the Digital Omnibus while it was still in proposal stage:

Both were written before the Council vote and referenced a working deadline of "February 2027" that appeared in an earlier draft. The correct date, per the finally adopted text, is 2 December 2027 for standalone Annex III systems. This post supersedes those earlier analyses.

Sources

All deadline figures in this post are drawn from:

  1. EU Council formal adoption, 29 June 2026 (Licentium analysis)
  2. Digital Omnibus on AI: Parliament votes, deadlines redrawn (Dastra)
  3. EU Council gives final approval to AI Act simplification — NicFab analysis
  4. EU lawmakers reach provisional agreement to delay key EU AI Act obligations — Sidley Data Matters
  5. Client Alert: Council gives final green light to Digital Omnibus on AI — Shumaker Loop & Kendrick
  6. EU AI Act — Regulation (EU) 2024/1689 full text, EUR-Lex

Summary

The Digital Omnibus on AI is now final law (Council adoption 29 June 2026, EP vote 16 June 2026). For Annex III standalone high-risk AI systems, the compliance deadline moved from 2 August 2026 to 2 December 2027. For Annex I embedded systems, it moved to 2 August 2028.

Three things did not change: Art.50 transparency requirements remain at 2 August 2026 (with a grace period to 2 December 2026 for systems already on the market); GPAI Chapter V obligations have been in force since 2 August 2025; Art.5 prohibited practices have been in force since 2 February 2025.

If you have been reading this blog's high-risk AI compliance series — on Art.9, Art.14, Art.16, Art.17, Art.26, Art.71 — the substance of those posts remains accurate. The deadline context has changed. You now have until December 2027 to implement the practices they describe for Annex III standalone systems. Use that time well.

EU-Native Hosting

Ready to move to EU-sovereign infrastructure?

sota.io is a German-hosted PaaS — no CLOUD Act exposure, no US jurisdiction, full GDPR compliance by design. Deploy your first app in minutes.