Back to blogAI

The AI Act after the Digital Omnibus: the new timeline and what already applies

uComply

Team uComply

Author

September 24, 2026

Published

On 27 July 2026, the "Digital Omnibus on AI", Regulation (EU) 2026/1744, entered into force. With it, the timeline of the EU AI Act has shifted on one important point: the obligations for high-risk AI systems, due to apply from 2 August 2026, now apply from 2 December 2027. Since then we regularly hear the same conclusion: "The AI Act has been postponed, we still have time."

That conclusion is only half true. A large part of the AI Act already applies, and the Omnibus changes nothing about that. In this article we set out what exactly has shifted, what is already in force and what you would be wise to do in the coming months.

What the Digital Omnibus changes

The Digital Omnibus on AI was published on 24 July 2026 and entered into force on 27 July 2026. The core of the amendment is a new timeline for high-risk AI:

  • Stand-alone high-risk AI systems (Annex III), such as AI for recruitment and selection, credit scoring, education and critical infrastructure: the obligations apply from 2 December 2027 instead of 2 August 2026.
  • High-risk AI in regulated products (Annex I), such as medical devices and machinery: moves from 2 August 2027 to 2 August 2028.
  • Earlier this year we wrote that the high-risk obligations would apply from 2 August 2026. That was the applicable timeline at the time; the Omnibus has since superseded it.

    Why the postponement?

    The reason is practical. Providers of high-risk AI need to be able to rely on harmonised European standards and on guidance from the European Commission. These were not ready in time. The Commission therefore ties the new dates to the availability of those standards: organisations need to know what exactly they must comply with before the obligations take effect.

    What already applies (and has not been postponed)

    This is where things often go wrong in practice. The Omnibus only affects the high-risk obligations. All other parts of the AI Act are simply in force:

  • Prohibited practices (Article 5), since 2 February 2025. Think of social scoring, manipulative AI and mass facial recognition.
  • AI literacy (Article 4), since 2 February 2025. Organisations must ensure that staff working with AI systems have sufficient knowledge of their capabilities and risks.
  • Obligations for providers of general-purpose AI models, such as large language models, since 2 August 2025.
  • Transparency obligations (Article 50), since 2 August 2026. Users must know that they are interacting with an AI system. Deepfakes and AI-generated content must be recognisable as such.
  • The last of these affects many organisations. If you run a chatbot on your website, publish AI-generated text or images, or use AI in customer contact, this has applied to you since 2 August 2026.

    New prohibited practices

    The Omnibus does not only postpone; it also adds. New categories have been added to the list of prohibited practices, including AI that generates intimate images without consent or produces child sexual abuse material. A transitional period until 2 December 2026 applies to these new prohibitions.

    The new timeline at a glance

    ElementStatusDate
    Prohibited practices (Art. 5)In force2 February 2025
    AI literacy (Art. 4)In force2 February 2025
    General-purpose AI modelsIn force2 August 2025
    Transparency (Art. 50)In force2 August 2026
    New prohibited practices (Omnibus)Transitional period2 December 2026
    High-risk AI, Annex IIIPostponed2 December 2027
    High-risk AI in products, Annex IPostponed2 August 2028

    Postponement is time gained, not an exemption

    Those who sit back until the end of 2027 will run into trouble. The high-risk obligations are extensive: a risk management system, technical documentation, logging, human oversight and a conformity assessment. You cannot build that in a few months. Moreover, you can only determine whether you fall under the high-risk rules once you know which AI systems you actually use.

    Our advice is therefore to use the time gained for the fundamentals:

    1.Inventory your AI systems. Record in an AI register which systems you develop, procure or use, including AI embedded in existing software. Note the owner, purpose and supplier.
    2.Classify the risk. Determine for each system whether it falls under a prohibition, is high-risk, carries transparency obligations or poses minimal risk.
    3.Arrange transparency. Make sure users know when they are communicating with AI and that AI-generated content is recognisable. This already applies.
    4.Work on AI literacy. Organise training for staff who work with AI and record who has completed which training.
    5.Prepare your governance. ISO/IEC 42001, the international standard for AI management systems, offers a structured framework that closely matches the requirements of the AI Act. Those who start now will have a working management system by the end of 2027 instead of a pile of loose documents.

    How uComply helps

    In uComply you manage AI compliance as part of your existing management system, not as a stand-alone project.

  • AI register and risk classification: record AI systems with owner and classification and link the risks you have identified to each system. You see at a glance which systems fall under which obligations.
  • Legal obligations linked to controls: you link the obligations from the AI Act, such as transparency and AI literacy, to concrete controls, evidence and owners. If you combine the AI Act with ISO 27001 or NIS2, you link one control to several requirements and avoid duplicate work.
  • ISO/IEC 42001 Content Pack: ready-made controls, risk analysis templates and policy documents for AI governance, as a starting point for your AI management system.
  • Flightdeck: the dashboard shows progress per standard and the compliance status per legal obligation, so that the board and the regulator can see where you stand.
  • Responsible AI in the uComply Bot: the AI assistant in uComply runs entirely within your own Microsoft 365 tenant. Your compliance data never leaves your organisation.
  • Summary

    The Digital Omnibus gives organisations until 2 December 2027 (Annex III) and 2 August 2028 (Annex I) for the high-risk obligations. Prohibited practices, AI literacy, the rules for general-purpose AI and the transparency obligations, however, already apply. Use the time gained to inventory and classify your AI systems and to get your governance in order.

    Would you like to see how to make AI compliance demonstrable in uComply? Book a no-obligation demo or view our pricing.

    Sources

  • European Commission: Regulatory framework for AI
  • EUR-Lex: Regulation (EU) 2026/1744, Digital Omnibus on AI
  • EUR-Lex: Regulation (EU) 2024/1689, AI Act