The AI Act Omnibus Delay: Relief or a Trap for Small Teams?
The EU AI Act's high-risk rules were pushed to 2027 and 2028 by the Digital Omnibus. Here's why teams that stop preparing now are making a mistake.
The headline version of the 2026 Digital Omnibus on AI is simple: the EU pushed the high-risk rules back. Stand-alone high-risk systems now have until 2 December 2027, and high-risk systems embedded in regulated products until 2 August 2028 — both later than the original 2 August 2026 date. I think that headline is going to cost some small teams a compliance scramble in eighteen months, because they will read “delayed” as “cancelled” and stop preparing.
That is the trap. The delay is real, adopted, and confirmed by the co-legislators. It is not relief from the obligations — it is more runway to build the same obligations properly, plus a few genuine simplifications. Treat it as the former and you will be starting from zero in late 2027.
What actually happened, precisely
On 19 November 2025 the European Commission published a proposal to amend the AI Act as part of a wider Digital Omnibus package. Parliament and Council reached a trilogue agreement on 7 May 2026. Member States’ ambassadors (Coreper) approved it on 13 May 2026, Parliament’s IMCO and LIBE committees approved it on 2 June 2026, and Parliament’s plenary adopted it on 16 June 2026 with 423 votes in favour, 57 against, and 174 abstentions.
That is not a proposal sitting in a drawer. It is agreed text, working through the final formal steps to publication in the Official Journal.
What actually changed
The co-legislators agreed fixed deadlines, not the conditional “once standards are ready” mechanism the Commission originally floated:
- 2 December 2027 — stand-alone high-risk AI systems (the Annex III use cases: recruitment, worker management, credit scoring, and similar)
- 2 August 2028 — high-risk AI systems that are safety components of products already regulated under other EU law (Annex I)
- 2 December 2026 — extended transitional period for marking AI-generated content on generative AI systems already on the market before 2 August 2026 (previously due 2 August 2026)
Alongside the timeline shift, the agreed text also: replaced the mandatory AI-literacy obligation with a requirement for the Commission and Member States to promote literacy initiatives; extended the SME simplified-documentation and penalty regime to small mid-caps; removed the obligation to register systems a provider has concluded are not high-risk; expanded the scope for testing high-risk systems in real-world conditions via regulatory sandboxes; and added a new prohibition on AI systems that generate non-consensual intimate content or CSAM.
The Commission’s own estimate: the amendments could save businesses up to €429.5 million per year in administrative costs, with €68–204 million of that from the timeline change alone. That is a real number, but it is a saving on when you spend, not on whether you eventually comply.
Why “delayed” is not “removed”
Nothing in the agreed text removes the high-risk obligations themselves. Conformity assessment, technical documentation, the quality management system, human oversight, post-market monitoring — all of it still applies to Annex III and Annex I high-risk systems. What moved is the date by which you must be ready.
Eighteen months feels like a long time until you notice what has to happen inside it: harmonised standards need to be finalised, notified bodies need capacity to run conformity assessments at scale, and your own system needs to be built to a specification that does not yet fully exist in published, stable form. Waiting until late 2027 to start is waiting until the queue for assessment is already full.
Who is actually cheering, and who is worried
The reaction split is informative. Industry groups broadly welcome the change — Connect Europe and GSMA called it “a positive first step,” and some, like CCIA Europe, wanted the fixed dates precisely because certainty beats a conditional trigger. SME United’s position was narrower and more useful for small teams: it argued application dates should be tied to harmonised standards and guidance actually being available, not just a calendar date.
On the other side, the European Data Protection Board and European Data Protection Supervisor issued a joint opinion opposing the removal of registration requirements and calling for strict limits on the new bias-correction data provisions. Consumer group BEUC and several civil-society organisations went further, warning the changes weaken protections built into the original Act. Whichever side is right on balance, both agree on one thing: the substance of the obligations has not disappeared, only their timing and some procedural detail.
What I would do with the extra time
The delay is a genuine gift if you use it to build rather than to relax. Concretely:
Finish your classification now, not in 2027. Work out which of your systems are high-risk under Annex III while there is no deadline pressure distorting the judgment. The Annex III test takes an afternoon; doing it under a looming deadline takes longer and produces worse decisions.
Track the harmonised standards as they publish, rather than waiting for a single announcement that “compliance is now possible.” Standards will land in stages, and the teams that start building against draft guidance early will not be starting from scratch when the final versions appear.
Use the sandbox provisions while sandboxes are quiet. Article 62 gives SMEs and start-ups priority access to national AI regulatory sandboxes, which must be operational by 2 August 2026. Getting in early, before every other high-risk provider in the EU is queuing for the same conformity assessment capacity in 2027, is a genuine advantage this delay hands you.
Do not delay the parts that were never delayed. Article 5 prohibitions have applied since February 2025. GPAI model rules have applied since August 2025. Article 50 transparency duties apply from August 2026 regardless of the high-risk timeline. The Omnibus did not touch these.
The Digital Omnibus bought small teams real time. What it did not buy is permission to stop thinking about the Act until the new dates arrive. Treat 2027 and 2028 as the deadline for being audited, and treat the months between now and then as the only realistically calm window you will get to build toward it properly.
If you are trying to work out what the Omnibus changes actually mean for your specific systems, that is exactly the kind of mapping worth doing before the calm window closes. Get in touch →
Related reading on The Science Talk
This piece pairs with ERC Reverses Resubmission Rule Changes After Community Feedback for a sense of how EU processes revise rules mid-stream — and with the EPRS’s own tracked timeline for the Act, AI Act Implementation Timeline (At a Glance), for the pre-Omnibus statutory baseline this piece updates.
Browse all Perspectives or get in touch →
Found this useful? Share it or read more perspectives.