Regulation
The Digital Omnibus delayed high-risk AI rules. What still applies in 2026
The 2026 AI Act delay covers one part of the law: the rules for high-risk AI systems. The Digital Omnibus on AI (opens in a new tab), in force since July 27, 2026, moved them to December 2, 2027 and August 2, 2028. The bans, the AI literacy duty, the rules for general-purpose AI models and the Article 50 transparency duties kept their dates and already apply.
By the KDS security engineering teamPublished 5 min read
Key takeaways
- High-risk rules now apply from December 2, 2027 (Annex III) and August 2, 2028 (AI in regulated products).
- Article 50 transparency duties have applied since August 2, 2026. The delay did not move them.
- Prohibitions and the AI literacy duty have applied since February 2, 2025. The Omnibus softened AI literacy but kept it.
- Two new bans, on intimate images made without consent and on child sexual abuse material, apply from December 2, 2026.
- Companies that use AI agents should keep their inventory, disclosures and vendor checks moving now.
On this page
What the 2026 AI Act delay moved
The Omnibus changed Article 113 of the AI Act, which sets when each part applies. The high-risk requirements in Chapter III, Sections 1 to 3, now apply on these dates:
| High-risk group | Original date | New date |
|---|---|---|
| AI used in the sensitive areas of Annex III, such as hiring, credit scoring, education and biometrics | August 2, 2026 | December 2, 2027 |
| AI that is a safety component of products covered by Annex I, such as medical devices | August 2, 2027 | August 2, 2028 |
Recital 40 of the regulation gives the reason: standards, common specifications and guidance for high-risk systems arrived late, and national authorities were set up late. Without them, providers had little practical help to show that a high-risk system complies.
In November 2025 the Commission proposed a moving start date tied to the availability of standards, with 2027 and 2028 as the latest dates. Parliament and Council chose fixed dates instead. The European Parliament's summary of the deal (opens in a new tab) sets out the final dates.
Two smaller dates moved as well. Each Member State now has until August 2, 2027 to run a national AI regulatory sandbox. Generative AI systems placed on the market before August 2, 2026 have until December 2, 2026 to mark their outputs as AI-generated.
What the delay did not change
Most of the AI Act that affects everyday business use of AI already applies. These duties kept their dates:
- Prohibited practices (Article 5) have applied since February 2, 2025. Harmful manipulation, social scoring and emotion recognition at work are still banned.
- AI literacy (Article 4) has applied since February 2, 2025. The Omnibus changed the wording but kept a duty for providers and deployers.
- General-purpose AI model duties have applied since August 2, 2025, and the Commission can fine providers of these models from August 2, 2026.
- Article 50 transparency has applied since August 2, 2026. People must be told when they talk to an AI, and deployers must label deepfakes.
- Penalties (Article 99) keep the same maximum amounts: up to EUR 35 million or 7% of worldwide annual turnover for prohibited practices, and up to EUR 15 million or 3% for most other breaches.
Enforcement has also started. The Commission's AI literacy Q&A (opens in a new tab) states that national market surveillance authorities supervise and enforce the rules from August 2, 2026. For a typical support, booking or sales agent, the relevant duties already apply.
What the Omnibus added
The Omnibus did not only delay. From December 2, 2026, Article 5 also bans AI systems that generate realistic intimate images of an identifiable person without explicit consent, and systems that generate child sexual abuse material. The ban covers providers whose systems are built for this, or can readily produce it and lack reasonable safeguards. It also covers deployers who use a system for this purpose.
Other changes reduce effort. SMEs and small mid-cap enterprises can use simplified technical documentation for high-risk systems, and small mid-caps now get the same lower fine cap as SMEs for most breaches. Our reference guide to the Digital Omnibus on AI lists every change with its article number.
The next AI Act dates to watch
- December 2, 2026: the two new bans apply, and generative AI systems already on the market must mark their outputs.
- August 2, 2027: general-purpose AI models placed on the market before August 2, 2025 must comply, and national AI regulatory sandboxes must be running.
- December 2, 2027: high-risk rules apply to Annex III systems, such as AI used in hiring or credit scoring.
- August 2, 2028: high-risk rules apply to AI in products covered by Annex I.
What to keep doing now
Use the extra time to prepare, not to pause. For a company that uses or builds AI agents, we suggest five actions for the rest of 2026:
- Check every agent's disclosure. Each voice or chat agent should say it is an AI at the first interaction. Our AI disclosure checklist and Article 50 guide help you review scripts and screens.
- Keep your AI inventory current. Add new tools, AI features in existing software and tools staff use without approval. Record the role you play for each one.
- Confirm the risk class. If an agent screens job applicants, scores credit or prices life or health insurance, plan for the high-risk rules now. Risk management, logging, human oversight and a conformity assessment take time to build.
- Keep AI literacy records. Short role-based training and a log of who completed it give you evidence if an authority or a customer asks.
- Update vendor contracts. Ask AI vendors how they meet Article 50 marking by December 2, 2026 and what documentation they give to companies that build on their models.
The full picture of roles, risk tiers and dates is in our EU AI Act guide for businesses. In our AI security projects we test these points on live agents: whether the disclosure plays every time, whether a person can take over and whether the logs show what the agent did.
Sources
- 1.Regulation (EU) 2026/1744 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 (Digital Omnibus on AI), EUR-Lex, Publications Office of the European Union, 2026-07-24 (opens in a new tab)
- 2.Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), EUR-Lex, Publications Office of the European Union, 2024-07-12 (opens in a new tab)
- 3.AI Act: deal on simplification measures, ban on nudifier apps, European Parliament, 2026-05-07 (opens in a new tab)
- 4.AI literacy: questions and answers, European Commission, 2026-07-27 (opens in a new tab)
- 5.Guidelines for providers of general-purpose AI models, European Commission, 2026-04-28 (opens in a new tab)
- 6.AI Act: regulatory framework for AI, European Commission, 2026-08-03 (opens in a new tab)