Connect with us

AI

The EU Rewrote the AI Act Before High-Risk Rules Applied

The Digital Omnibus delayed high-risk AI Act duties to December 2027, after Brussels rewrote the landmark law before those rules ever applied.

Published

on

The European Union moved its high-risk AI Act duties to 2 December 2027, after rewriting the law before those rules ever applied. The Digital Omnibus on AI, the Official Journal text of the Omnibus, entered into force on 27 July 2026 as Regulation (EU) 2026/1744. Chatbot disclosure and most transparency duties still started on 2 August 2026.

Companies spent two years building toward a high-risk date that Brussels then moved by 16 months. The Commission calls the rewrite a targeted simplification of the AI rulebook that keeps safeguards for safety and fundamental rights. Rights groups call it a rollback of protections that had not yet begun.

High-Risk Rules Now Start in December 2027

The original Artificial Intelligence Act, Regulation (EU) 2024/1689, entered into force on 1 August 2024 with a staggered calendar. Standalone high-risk systems in Annex III, covering biometrics, hiring, credit scoring, education, essential services, law enforcement, migration and justice, were due to comply on 2 August 2026. AI built into regulated products in Annex I, including medical devices, machinery and aviation kit, had until 2 August 2027. The Omnibus replaces both dates with fixed later ones.

Duty Original date Date now in force
Annex III high-risk systems 2 August 2026 2 December 2027
Annex I product-embedded high-risk 2 August 2027 2 August 2028
Article 50 transparency 2 August 2026 2 August 2026, unchanged
Watermarking for systems already on sale 2 August 2026 2 December 2026
New nudifier and CSAM ban Not in the 2024 Act 2 December 2026
GPAI model duties 2 August 2025 Unchanged
Original prohibited practices 2 February 2025 Unchanged

White & Case, in an 4 August 2026 client alert, said the Omnibus was split from the rest of the Digital Omnibus package and rushed through so the new high-risk dates would bite before 2 August 2026. Parliament voted on 16 June. The Council gave final approval on 29 June. The act was signed in Strasbourg on 8 July and published on 24 July. Amendments to the GDPR, the ePrivacy Directive, NIS2 and the Data Act remain in talks and are not yet law.

Systems already on the market before the new high-risk dates can stay outside the Chapter III duties if they have not had a significant design change, according to a July briefing by Stephenson Harwood. A significant change is one that goes beyond what the provider set at the first conformity assessment and that may affect compliance. Providers and deployers of high-risk systems used by public authorities still have until 2 August 2030.

What Still Applied on 2 August

The delay did not freeze the statute. On 2 August 2026 the Act’s general application date arrived for everything the Omnibus did not move, including GPAI sanctions and the bulk of Article 50. National watchdogs, the AI Office and the European Data Protection Supervisor share that work, depending on who placed the system and who uses it.

What is live now

  • Chatbot notice: People must be told when they are interacting with an AI system.
  • Deepfake labels: Artificially generated or manipulated deepfakes must be labelled, and deployers of emotion-recognition or biometric-categorisation systems have their own disclosure duties.
  • Machine-readable marks: New generative systems placed on the market from 2 August 2026 must mark synthetic audio, image, video or text in a machine-readable form from day one.
  • Older generative systems: Those already on sale before that date have until 2 December 2026 to add the mark, a four-month grace period cut from the six months in the Commission’s November 2025 proposal.

Outputs created before 2 August 2026 do not have to be marked after the fact, according to Commission guidance on Article 50. If an older AI-written text on a matter of public interest is published on or after that date, it does need a label. The practical split is easy to miss: hiring tools and credit engines gained 16 months, while the content-labelling layer is already a live enforcement file.

Harmonised Standards Missed the Original Clock

Brussels did not hide the reason. The recitals of Regulation 2026/1744 say late standards and late national bodies made the old date unworkable.

The delayed availability of standards, common specifications, and alternative guidance and the delayed establishment of national competent authorities lead to challenges that jeopardise the effective entry into application of those obligations and that risk a significant increase in implementation costs in a way that does not justify maintaining their initial date of application, namely 2 August 2026.

Recital of Regulation (EU) 2026/1744, Official Journal, 24 July 2026

CEN and CENELEC’s joint AI committee, JTC 21, missed the original April 2025 delivery window on standardisation request M/593. In October 2025 the two bodies adopted an exceptional package to accelerate AI standards, aiming to have priority drafts available by the fourth quarter of 2026, including by skipping a separate formal vote after a positive enquiry. A CEPR column dated 23 August 2026, citing Commission material, said that as of June 2026 none of the JTC 21 harmonised standards had been cited in the Official Journal, which is the step that gives a presumption of conformity.

Without that citation, a provider of a high-risk system still has to prove compliance the hard way. Extra time on the calendar does not write the technical tests. It only moves the date on which missing tests become a legal problem.

How the rewrite beat the old deadline

  1. 1 August 2024: The AI Act enters into force, with high-risk Chapter III set for 2 August 2026.
  2. 19 November 2025: The Commission tables the Digital Omnibus on AI as a separate file from the wider digital package.
  3. 7 May 2026: Parliament and Council reach a political agreement, less than six months after the proposal.
  4. 16 June and 29 June 2026: Parliament then the Council give formal approval.
  5. 24 July and 27 July 2026: Publication, then entry into force three days later, in time to move the 2 August high-risk clock.

A VoxEU column by CEPR also noted a Reuters report from November 2025 that the Commission proposed the delay after pushback from large technology firms. The legal text itself points to standards and national authorities, not to that lobbying. Both can be true at once, and the recital is the reason the Union wrote into law.

The New Mid-Cap Threshold of 750 Staff

The other quiet rewrite sits in company size. Privileges that used to stop at the SME ceiling now reach “small mid-cap enterprises,” a category the Commission defined in Recommendation (EU) 2025/1099 of 21 May 2025. An SMC is not an SME, employs fewer than 750 staff and €150 million in annual turnover, or has a balance-sheet total no higher than €129 million.

Category Staff Turnover or balance sheet
Medium-sized SME Under 250 €50 million turnover or €43 million balance sheet
Small mid-cap Under 750, and not an SME €150 million turnover or €129 million balance sheet
Large At or above those SMC ceilings Full AI Act treatment

White & Case said the extra relief includes simplified technical documentation, proportionate quality-management duties, mitigated penalties and priority access to regulatory sandboxes. Stephenson Harwood added that micro-enterprise simplifications for quality-management systems now spread to all SMEs and start-ups. The Commission’s own notice says some measures once reserved for SMEs now cover SMCs, and that an EU-level sandbox will sit alongside national ones. Member States have until 2 August 2027 to have those national sandboxes running.

For a firm that crossed 250 employees and had budgeted as if the full regime applied, the new band is real money and real paperwork. For a group at 800 staff, nothing in this clause changes the file.

Why the Nudifier Ban Starts in December

The Omnibus is not only a delay statute. Co-legislators added a new Article 5 ban, absent from the Commission’s November 2025 proposal, on AI systems that generate or manipulate non-consensual intimate or sexually explicit content of identifiable people, and on systems that generate child sexual abuse material. It covers images, video and audio. It applies from 2 December 2026, the same day the watermarking grace period ends.

The ban reaches systems whose intended purpose is that generation, and systems that lack reasonable technical safeguards where that outcome is reasonably foreseeable. Political groups in Parliament sold the clause as a response to “nudifier” apps. The Center for Democracy and Technology, in a 17 June 2026 analysis after the Parliament vote, said the ban still leaves gaps: cartoonish depictions sit outside it, and a recital list of intimate parts is narrower than other Union sex-crime law. CDT also said the clause would not cover many bikini or underwear images of the kind that, as Politico reported, drove the push after the Grok episode.

CDT’s wider verdict was that the ban “fails to compensate for the overall public interest backsliding.” The same analysis flags the grandfathering rule as a reason to rush systems onto the market before December 2027, because an unchanged high-risk tool already on sale can miss the heavy duties altogether. That incentive is now written into the calendar.

AI Literacy Becomes a Support Duty

Article 4 still binds providers and deployers, and the new wording applied from 27 July 2026. They must take measures to support the development of AI literacy among staff and others who operate systems on their behalf, taking account of technical knowledge, experience, education, training and the people the system is used on. They no longer have to “ensure” a sufficient level. The Commission’s literacy FAQ states that providers face no specific level of AI literacy as a mandated outcome. The Commission and the Member States now share a duty to back those efforts, including with practical examples on a single information platform.

The Commission had wanted to move the whole literacy duty onto governments. Co-legislators refused that, which CDT recorded as a near-miss. The compromise still lowers the enforcement risk when an individual worker has not reached a given skill level. Training files still need to exist. They no longer have to prove that every operator crossed a line the law no longer draws.

A new Article 4a widens who may process special-category personal data, including racial or ethnic origin and health data, to detect and correct bias. The 2024 Act limited that path mainly to providers of high-risk systems. The Omnibus extends it, on a strict-necessity basis and with safeguards, to providers and deployers of other systems and models, and to deployers of high-risk systems. Processing is allowed only where other data, including synthetic or anonymised data, cannot do the job. CDT warned that the wider exception can be misused against marginalised groups, and that the Act still lumps bias detection together with bias correction.

The AI Office also grows. It becomes the exclusive supervisor for many AI systems built on a general-purpose model by the same provider, and for systems that are, or sit inside, very large online platforms and very large search engines under the Digital Services Act. National authorities keep files such as law enforcement, borders, courts and finance, according to the policy writer Luiza Jarovsky’s 2 August rundown of the enforcement split. Fragmentation does not disappear. It moves.

A Sectoral Exit for Machines and Lifts

Product-safety overlap was the other fight. The Omnibus lets the Commission, through delegated acts, limit the AI Act where sectoral law already sets equivalent AI-specific requirements. It also narrows “safety component”: a tool that only helps a user or tunes performance is not automatically high-risk if its failure does not create health or safety risks, White & Case said.

Machinery is the test case. After pressure from that sector, products under the Machinery Regulation leave the AI Act’s direct high-risk list. The Commission must fold equivalent health and safety requirements into that regulation instead. CDT called this a crack in the Act’s horizontal logic and a precedent other sectors will try to copy, and noted a separate December proposal that could still pull medical devices into a similar conversation. Conformity-assessment bodies, for their part, may file one application for designation under the AI Act and under other Union product law, and some notified bodies already designated in a sector may assess high-risk AI for a transitional period.

Fundamental-rights authorities lost a direct path as well. Requests for provider or deployer files now go through the market surveillance authority, which must pass them on without undue delay. Equality bodies have said that extra step can clash with existing Union equality law if the surveillance authority becomes a bottleneck. The delay of high-risk duties already stretches the period in which those files do not have to exist in the AI Act form.

Spain has not waited for 2027 to rewrite the local manuals. On 21 August 2026 the Agencia Española de Supervisión de Inteligencia Artificial said its support guides now follow the Omnibus and are posted in English.

https://x.com/agenciaAESIA/status/2090719245768237475

The instruction manuals are moving. The high-risk systems they describe still have until December 2027, unless they were already on sale and nobody changes them.

Frequently Asked Questions

Who signed the Digital Omnibus on AI into law?

European Parliament President Roberta Metsola and Council President T. Byrne, Ireland’s minister of state for European affairs and defence, signed the regulation in Strasbourg on 8 July 2026, during the first plenary of Ireland’s Council presidency. The act is binding in all Member States without national transposition.

When must national AI regulatory sandboxes be in place?

Competent authorities at national level have until 2 August 2027 to establish the sandboxes required under the AI Act, a date the Omnibus moved. The AI Office may also set up an EU-level sandbox with real-world testing, and real-world testing outside sandboxes is opened to more Annex I systems through frameworks that Member States notify to the Commission.

Can a firm use health or ethnicity data to de-bias an AI system that is not high-risk?

Yes, but only under new Article 4a and only so far as it is strictly necessary to detect and correct bias that is likely to affect health, safety or fundamental rights or to cause discrimination banned by Union law. The bias work cannot be done effectively with other data, including synthetic or anonymised sets, and the GDPR, Law Enforcement Directive and EU-institution data rules still apply on top of those conditions.

How do Annex I and Annex III high-risk systems differ after the Omnibus?

Annex III is a list of use cases, so a standalone hiring screener or a credit-scoring engine is high-risk because of what it is used for, and those duties now apply from 2 December 2027. Annex I is a list of product-safety laws, so the AI is high-risk because it sits in a medical device, toy, lift or similar product, and those duties now apply from 2 August 2028, with machinery pulled onto a sectoral track of its own.

Does the Digital Omnibus rewrite the GDPR as well?

Not yet. The AI file was cut out of the wider Digital Omnibus package and adopted on its own. Proposed changes to the GDPR, the ePrivacy Directive, NIS2 and the Data Act were still in negotiation in the Parliament and the Council as of August 2026 and have no effect until that separate process finishes.

Disclaimer: This article is news reporting and analysis of Regulation (EU) 2026/1744 and the EU AI Act. It is informational only and is not legal advice, a compliance programme, or a substitute for counsel on how the rules apply to a specific system, model or deployment. Readers who develop, import, distribute or use AI in the Union should consult a qualified EU regulatory lawyer or their national competent authority before changing product design, contracts or filing plans. Dates, duties and enforcement practice reflect the official texts and secondary sources as of 24 August 2026 and may change through guidelines, delegated acts or further legislation.

Logan Pierce is a writer and web publisher with over seven years of experience covering consumer technology. He has published work on independent tech blogs and freelance bylines covering Android devices, privacy focused software, and budget gadgets. Logan founded Oton Technology to publish clear, no nonsense tech news and reviews based on real hands on testing. He has personally tested and reviewed dozens of mid range and budget Android phones, written extensively about app privacy, and built and managed multiple WordPress publications over the past decade. Logan holds a bachelor's degree in English and studied digital marketing at a certificate level.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending