Skip to content

Regulation

The Digital Omnibus delayed high-risk AI rules. What still applies in 2026

The 2026 AI Act delay covers one part of the law: the rules for high-risk AI systems. The Digital Omnibus on AI (opens in a new tab), in force since July 27, 2026, moved them to December 2, 2027 and August 2, 2028. The bans, the AI literacy duty, the rules for general-purpose AI models and the Article 50 transparency duties kept their dates and already apply.

By the KDS security engineering teamPublished 5 min read

Key takeaways

  • High-risk rules now apply from December 2, 2027 (Annex III) and August 2, 2028 (AI in regulated products).
  • Article 50 transparency duties have applied since August 2, 2026. The delay did not move them.
  • Prohibitions and the AI literacy duty have applied since February 2, 2025. The Omnibus softened AI literacy but kept it.
  • Two new bans, on intimate images made without consent and on child sexual abuse material, apply from December 2, 2026.
  • Companies that use AI agents should keep their inventory, disclosures and vendor checks moving now.
On this page

What the 2026 AI Act delay moved

The Omnibus changed Article 113 of the AI Act, which sets when each part applies. The high-risk requirements in Chapter III, Sections 1 to 3, now apply on these dates:

High-risk deadlines before and after the Digital Omnibus
High-risk groupOriginal dateNew date
AI used in the sensitive areas of Annex III, such as hiring, credit scoring, education and biometricsAugust 2, 2026December 2, 2027
AI that is a safety component of products covered by Annex I, such as medical devicesAugust 2, 2027August 2, 2028
High-risk deadlines before and after the Digital Omnibus

Recital 40 of the regulation gives the reason: standards, common specifications and guidance for high-risk systems arrived late, and national authorities were set up late. Without them, providers had little practical help to show that a high-risk system complies.

In November 2025 the Commission proposed a moving start date tied to the availability of standards, with 2027 and 2028 as the latest dates. Parliament and Council chose fixed dates instead. The European Parliament's summary of the deal (opens in a new tab) sets out the final dates.

Two smaller dates moved as well. Each Member State now has until August 2, 2027 to run a national AI regulatory sandbox. Generative AI systems placed on the market before August 2, 2026 have until December 2, 2026 to mark their outputs as AI-generated.

What the delay did not change

Most of the AI Act that affects everyday business use of AI already applies. These duties kept their dates:

  • Prohibited practices (Article 5) have applied since February 2, 2025. Harmful manipulation, social scoring and emotion recognition at work are still banned.
  • AI literacy (Article 4) has applied since February 2, 2025. The Omnibus changed the wording but kept a duty for providers and deployers.
  • General-purpose AI model duties have applied since August 2, 2025, and the Commission can fine providers of these models from August 2, 2026.
  • Article 50 transparency has applied since August 2, 2026. People must be told when they talk to an AI, and deployers must label deepfakes.
  • Penalties (Article 99) keep the same maximum amounts: up to EUR 35 million or 7% of worldwide annual turnover for prohibited practices, and up to EUR 15 million or 3% for most other breaches.

Enforcement has also started. The Commission's AI literacy Q&A (opens in a new tab) states that national market surveillance authorities supervise and enforce the rules from August 2, 2026. For a typical support, booking or sales agent, the relevant duties already apply.

What the Omnibus added

The Omnibus did not only delay. From December 2, 2026, Article 5 also bans AI systems that generate realistic intimate images of an identifiable person without explicit consent, and systems that generate child sexual abuse material. The ban covers providers whose systems are built for this, or can readily produce it and lack reasonable safeguards. It also covers deployers who use a system for this purpose.

Other changes reduce effort. SMEs and small mid-cap enterprises can use simplified technical documentation for high-risk systems, and small mid-caps now get the same lower fine cap as SMEs for most breaches. Our reference guide to the Digital Omnibus on AI lists every change with its article number.

The next AI Act dates to watch

  • December 2, 2026: the two new bans apply, and generative AI systems already on the market must mark their outputs.
  • August 2, 2027: general-purpose AI models placed on the market before August 2, 2025 must comply, and national AI regulatory sandboxes must be running.
  • December 2, 2027: high-risk rules apply to Annex III systems, such as AI used in hiring or credit scoring.
  • August 2, 2028: high-risk rules apply to AI in products covered by Annex I.

What to keep doing now

Use the extra time to prepare, not to pause. For a company that uses or builds AI agents, we suggest five actions for the rest of 2026:

  1. Check every agent's disclosure. Each voice or chat agent should say it is an AI at the first interaction. Our AI disclosure checklist and Article 50 guide help you review scripts and screens.
  2. Keep your AI inventory current. Add new tools, AI features in existing software and tools staff use without approval. Record the role you play for each one.
  3. Confirm the risk class. If an agent screens job applicants, scores credit or prices life or health insurance, plan for the high-risk rules now. Risk management, logging, human oversight and a conformity assessment take time to build.
  4. Keep AI literacy records. Short role-based training and a log of who completed it give you evidence if an authority or a customer asks.
  5. Update vendor contracts. Ask AI vendors how they meet Article 50 marking by December 2, 2026 and what documentation they give to companies that build on their models.

The full picture of roles, risk tiers and dates is in our EU AI Act guide for businesses. In our AI security projects we test these points on live agents: whether the disclosure plays every time, whether a person can take over and whether the logs show what the agent did.

Sources

  1. 1.Regulation (EU) 2026/1744 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 (Digital Omnibus on AI), EUR-Lex, Publications Office of the European Union, 2026-07-24 (opens in a new tab)
  2. 2.Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), EUR-Lex, Publications Office of the European Union, 2024-07-12 (opens in a new tab)
  3. 3.AI Act: deal on simplification measures, ban on nudifier apps, European Parliament, 2026-05-07 (opens in a new tab)
  4. 4.AI literacy: questions and answers, European Commission, 2026-07-27 (opens in a new tab)
  5. 5.Guidelines for providers of general-purpose AI models, European Commission, 2026-04-28 (opens in a new tab)
  6. 6.AI Act: regulatory framework for AI, European Commission, 2026-08-03 (opens in a new tab)

Get a free 30-minute assessment

Walk us through the AI tools and agents you use or plan to launch. We'll point out the biggest risks and the first fixes, in plain words.

Frequently asked questions

Did the EU delay the AI Act in 2026?

Only in part. The Digital Omnibus on AI, Regulation (EU) 2026/1744, moved the high-risk rules to December 2, 2027 for Annex III systems and August 2, 2028 for AI in regulated products. Prohibitions, AI literacy, duties for general-purpose AI models and the Article 50 transparency duties kept their original dates and already apply.

Do Article 50 transparency rules apply in 2026?

Yes. Article 50 has applied since August 2, 2026. AI systems that talk with people must tell them they are dealing with an AI unless it is obvious, and deployers must label deepfakes. Only the machine-readable marking duty for generative AI systems already on the market before August 2, 2026 has a short extension, to December 2, 2026.

Is the AI literacy requirement still in force after the Omnibus?

Yes, in a softer form. Since July 27, 2026, Article 4 requires providers and deployers to take measures to support the AI literacy of their staff and others who use AI on their behalf. The new text states that no specific level has to be guaranteed. The Commission and Member States must support companies, in particular SMEs, in meeting the duty.

Should we pause our AI Act compliance work?

In most cases, no. The delay only affects high-risk systems, and even for those the new dates leave limited time to build risk management, documentation and human oversight. Transparency, AI literacy and the bans already apply, and national authorities supervise them from August 2, 2026. Use the extra time to finish your inventory and prepare any high-risk system properly.

Services and use cases

  • Service

    AI security and red teaming

    AI security consulting for AI agents and LLM apps: red teaming, prompt injection testing, shadow AI discovery and EU AI Act and ISO/IEC 42001 readiness.

    Explore AI security consulting

Free 30-minute assessment

Find the one workflow worth automating first.

Tell us how your team works. We'll come back with two or three AI opportunities, the risks to watch and a rough payback estimate. No obligation.

  • A senior engineer replies within one business day
  • We can sign an NDA before you share details
  • No fixed packages, every quote tailored to you
What can we help with?
About your company

Company size

When would you like to start?

How can we reach you?

Encrypted in transit · read only by our team · never sold

Free 30-minute AI assessmentGet it →

Before you go

Find out where AI can save your team time

Book a free 30-minute assessment. A senior engineer reviews one workflow with you and sends back the opportunities, the risks and a rough payback estimate.