BLOG · REGULATION

The Digital Omnibus moves the AI Act deadlines: what really stays for August 2026

Regulation
  • #regulation
  • #ai-act
  • #digital-omnibus
  • #compliance
  • #gpai
  • #operator-lens

The European Parliament voted through the Digital Omnibus — a package that moves high-risk AI obligations from August 2026 to December 2027 and August 2028. It isn't law yet, and part of the timeline stays on August 2026: Article 50 transparency and enforcement against GPAI model providers. What the deferral means for your compliance plan, and what to do this week.

Adam WszendybyłAI operator-architect

What happened

On 16 June 2026 the European Parliament voted through the Digital Omnibus on AI — a package of amendments to the AI Act that moves the heaviest part of the compliance calendar. The vote passed 423 to 57, with 174 abstentions. Obligations for high-risk systems under Annex III (the standalone ones, such as tools in recruitment or credit scoring) will now apply from 2 December 2027 instead of 2 August 2026; for systems embedded in products under sector-specific regulation (Annex I), from 2 August 2028.

Before anyone files this under "sorted": it isn't law yet. Parliament adopted the text, but the Council still has to formally approve it — expected within days — and the new dates only start to bind once the package is published in the EU Official Journal and enters into force three days later. Until then the original calendar formally still stands. Both sides say they will close the process before 2 August 2026.

The deadline didn't vanish — it split in two

It's easy to read the headline "high-risk deferred" as "the AI Act is off the agenda for two years." That misreading can get expensive. The package gives real relief exactly where the heaviest work sat — classifying high-risk systems and building the conformity assessment — and you gain a year and change for it. But the part that stays on 2 August 2026 touches what most companies already have running in production:

  • Article 50 transparency takes effect 2 August 2026: disclosing that you're talking to a bot, labeling AI-generated content, marking deepfakes. Watermarking itself (Article 50(2)) gets a window to 2 December 2026 — but disclosure does not.
  • General-purpose AI (GPAI) model providers. The GPAI obligations themselves have applied since August 2025; from August 2026 the AI Office gains enforcement tools, fines included. If you build on someone else's model, the documentation the provider owes you is your contractual line item — not someone else's problem.
  • A new prohibition. The package bans AI systems that generate child sexual abuse material and non-consensual intimate imagery — in force from 2 December 2026.

The operator's read is simple: a deferral isn't a release from thinking, just a change of order. You don't shelve your high-risk preparation because the date moved — you reschedule it, and point this summer's attention where the clock is still ticking.

What changes for you

Private Equity

For a portfolio company the deferral is, above all, a cash-flow break: you don't have to fund a full high-risk conformity build this year. But the due-diligence question shifts — from "are you high-risk compliant" to "do you have the transparency track and GPAI-provider documentation closed for August, and a credible 2027 plan." A company that says "the AI Act is handled" should be able to draw both tracks; if it can't, you've just found an item for the portfolio value map.

Enterprise

The boardroom relief is partial, not total. This summer's work is the transparency track and GPAI documentation, not a freeze on the compliance program. You keep the system register and the classification either way — but the audit and conformity build can be safely rebased to 2027 instead of forced for August. That's exactly the move we wrote about in a year of the AI Act in boardroom conversations — only now the calendar makes it easier.

SMB / mid-market

Here there's nothing to wait for. Article 50 applies to you regardless of the high-risk deferral: a chatbot on your site, a generator-made image or video in a campaign, all need labeling and disclosure, on the August track (watermarking alone — to December). You don't need a compliance department for this; you need a walk through your customer-facing surfaces and one decision: what you label, and how.

One step you can take this week

Take your AI Act plan and cut it into two tracks. The August track, to do now: a list of every customer-facing surface and every piece of AI-generated content, the labeling and disclosure on them, plus written confirmation that the documentation from your model provider actually reaches you. The 2027 track, to rebase: the heavy high-risk conformity assessment — you keep the register and classification, but you have more time to build. If today you have one "AI Act plan" document, after this exercise you have two deadlines and you know which one is for now.

One closing note: until the text is in the Official Journal, this is still a legislative stage, not binding law. Prepare the plan now, but anchor the actual date change to publication, not to a headline.

Describe your case

If you're not sure which of your systems land on August and which genuinely bought time to 2027, bring the list of your AI use cases. We start from something concrete: we separate what's for now from what's for later, and we write it down so it survives a conversation with a client or an auditor. Describe your case: mailto:[email protected]?subject=Rozmowa%20z%20Aurora%20AI.

LET'S START

Bring the process, not the slides.

If you read our blog and spot an area you want to improve in your own organization — write to us. We start every conversation from something concrete.