On 27 July 2026, the "Digital Omnibus on AI", Regulation (EU) 2026/1744, entered into force. With it, the timeline of the EU AI Act has shifted on one important point: the obligations for high-risk AI systems, due to apply from 2 August 2026, now apply from 2 December 2027. Since then we regularly hear the same conclusion: "The AI Act has been postponed, we still have time."
That conclusion is only half true. A large part of the AI Act already applies, and the Omnibus changes nothing about that. In this article we set out what exactly has shifted, what is already in force and what you would be wise to do in the coming months.
What the Digital Omnibus changes
The Digital Omnibus on AI was published on 24 July 2026 and entered into force on 27 July 2026. The core of the amendment is a new timeline for high-risk AI:
Earlier this year we wrote that the high-risk obligations would apply from 2 August 2026. That was the applicable timeline at the time; the Omnibus has since superseded it.
Why the postponement?
The reason is practical. Providers of high-risk AI need to be able to rely on harmonised European standards and on guidance from the European Commission. These were not ready in time. The Commission therefore ties the new dates to the availability of those standards: organisations need to know what exactly they must comply with before the obligations take effect.
What already applies (and has not been postponed)
This is where things often go wrong in practice. The Omnibus only affects the high-risk obligations. All other parts of the AI Act are simply in force:
The last of these affects many organisations. If you run a chatbot on your website, publish AI-generated text or images, or use AI in customer contact, this has applied to you since 2 August 2026.
New prohibited practices
The Omnibus does not only postpone; it also adds. New categories have been added to the list of prohibited practices, including AI that generates intimate images without consent or produces child sexual abuse material. A transitional period until 2 December 2026 applies to these new prohibitions.
The new timeline at a glance
| Element | Status | Date |
|---|---|---|
| Prohibited practices (Art. 5) | In force | 2 February 2025 |
| AI literacy (Art. 4) | In force | 2 February 2025 |
| General-purpose AI models | In force | 2 August 2025 |
| Transparency (Art. 50) | In force | 2 August 2026 |
| New prohibited practices (Omnibus) | Transitional period | 2 December 2026 |
| High-risk AI, Annex III | Postponed | 2 December 2027 |
| High-risk AI in products, Annex I | Postponed | 2 August 2028 |
Postponement is time gained, not an exemption
Those who sit back until the end of 2027 will run into trouble. The high-risk obligations are extensive: a risk management system, technical documentation, logging, human oversight and a conformity assessment. You cannot build that in a few months. Moreover, you can only determine whether you fall under the high-risk rules once you know which AI systems you actually use.
Our advice is therefore to use the time gained for the fundamentals:
How uComply helps
In uComply you manage AI compliance as part of your existing management system, not as a stand-alone project.
Summary
The Digital Omnibus gives organisations until 2 December 2027 (Annex III) and 2 August 2028 (Annex I) for the high-risk obligations. Prohibited practices, AI literacy, the rules for general-purpose AI and the transparency obligations, however, already apply. Use the time gained to inventory and classify your AI systems and to get your governance in order.
Would you like to see how to make AI compliance demonstrable in uComply? Book a no-obligation demo or view our pricing.




