EU AI regulation

EU's AI Act Reset Fixes a Broken Deadline, But Opens a Compliance Gap for Early Movers

EU's Digital Omnibus delays AI Act high-risk rules to 2027-28 and gives the AI Office new fining powers, but early movers may dodge oversight for good.

The AI Act's New Timeline People of Internet Research · EU Dec 2027 High-risk deadline Annex III standalone high-risk AI … Aug 2028 Embedded systems deadline High-risk AI embedded in regulated… 5% AI Office daily fine cap New Articles 75a-75d let the AI Of… 69% Business share of AI talks Business groups took part in 69% o… peopleofinternet.com
The AI Act's New Timeline People of Internet Research · EU Dec 2027 High-risk deadline Aug 2028 Embedded systems deadline 5% AI Office daily fine cap 69% Business share of AI talks peopleofinternet.com

Key Takeaways

A Deadline Nobody Was Going to Meet

Three days before the AI Act's most consequential deadline, the EU rewrote it. Regulation (EU) 2026/1744 — the "Digital Omnibus on AI" — entered the Official Journal on 24 July 2026 and takes effect on 27 July, days before the 2 August 2026 date on which Chapter III's high-risk obligations were due to bite (EUR-Lex, Regulation (EU) 2026/1744). The Commission proposed the rewrite on 19 November 2025; Parliament passed it 423-57-174 on 16 June 2026; the Council gave final sign-off on 29 June (European Parliament, Legislative Train Schedule). The trigger wasn't political cold feet — it was that the harmonised standards and accredited conformity-assessment bodies the Act depends on were not going to exist by August.

What Actually Changes

The headline shift: obligations for Annex III "high-risk" systems (credit scoring, hiring screens, biometric categorisation) now apply from 2 December 2027, and obligations for high-risk systems embedded in regulated products (Annex I — medical devices, machinery) move to 2 August 2028 (European Parliament, Legislative Train Schedule). A new Article 5 prohibition — banning AI systems that generate non-consensual intimate imagery or CSAM without the subject's "freely-given, specific, informed, unambiguous and explicit consent" — takes effect sooner, on 2 December 2026 (NicFab, "Digital Omnibus on AI"). And the AI Office, which already polices general-purpose AI models, gains exclusive jurisdiction under new Articles 75a-75d over AI systems built on GPAI models by the same provider and over AI systems integrated into very large online platforms — with power to fine up to 5% of average daily worldwide turnover, per day, for non-compliance.

The Case for Buying Time

The strongest case for delay isn't deregulatory — it's operational. A risk-classification regime is only as good as the standards and assessment bodies that make "compliance" a checkable fact rather than a guess. Harmonised standards for high-risk systems were behind schedule, and member states hadn't finished designating market-surveillance authorities or notified bodies. Forcing an August 2026 deadline onto that vacuum meant either mass non-compliance nobody had the capacity to police, or box-ticking self-certification that protects no one. A fixed, enforceable 2027/2028 date beats a symbolic 2026 one that couldn't be met.

The Case Against: A Gap That May Never Close

But the delay isn't neutral, and the sharper counter-argument is structural. Article 111's non-retroactivity rule means systems placed on the market before the new deadlines only fall under high-risk obligations if later "substantially modified." Tech Policy Press lays out the resulting incentive: providers now have a clear runway to deploy hiring, credit, and biometric systems before December 2027 specifically to lock in a permanent exemption, since an unmodified system deployed today could "remain outside the AI Act indefinitely" (Tech Policy Press, "EU's AI Act Delays Let High-Risk Systems Dodge Oversight"). Digital rights group Liberties raises a related process concern: it argues the omnibus also expands permitted use of sensitive personal data for bias-testing across all AI systems, not just high-risk ones, and thins the public high-risk registry — changes it attributes to lopsided lobbying access rather than open consultation (Liberties.eu, "Digital Omnibus Moves Forward, Trampling Fundamental Rights").

Where the Balance Lands

Both critiques land, but they argue for tightening the retroactivity carve-out, not for keeping an unenforceable 2026 deadline on the books. A rule that exists only on paper protects nobody. The more defensible complaint is that Brussels bundled a genuinely necessary sequencing fix with opportunistic scope-narrowing — sensitive-data carve-outs, thinner AI-literacy duties, a smaller public registry — inside one omnibus vote that made them hard to oppose individually without also opposing the delay itself. That's a legislative-process failure, not proof the delay was wrong.

The Bottom Line

The Digital Omnibus gets the sequencing right and the safeguards half-right. Pushing high-risk obligations to dates regulators can actually police is a defensible, arguably overdue correction to a law that outran its own implementation capacity — proportionate regulation should track enforceability, not legislative ambition alone. But a window with no retroactive bite invites a race to deploy ahead of scrutiny, and the AI Office's new 5%-of-turnover fining power over GPAI- and VLOP-linked systems only bites once that window closes. Parliament and Council have roughly 17 months before December 2027 to close the substantial-modification loophole — not to declare the job finished.

Sources & Citations

  1. EUR-Lex, Regulation (EU) 2026/1744
  2. European Parliament, Legislative Train Schedule — Digital Omnibus on AI
  3. NicFab, "Digital Omnibus on AI: Regulation (EU) 2026/1744 Is Published in the Official Journal"
  4. Tech Policy Press, "EU's AI Act Delays Let High-Risk Systems Dodge Oversight"
  5. Liberties.eu, "Digital Omnibus Moves Forward, Trampling Fundamental Rights"