On July 27, 2026, the EU’s AI Omnibus entered into force, the first substantive amendment to the AI Act since 2024. It delays the high-risk AI deadline that was set for August 2, 2026, but leaves transparency and enforcement obligations on their original date. Standalone high-risk systems now have until December 2, 2027. Product-embedded high-risk systems have until August 2, 2028. Article 50 transparency rules, general purpose AI (GPAI) enforcement powers, and market surveillance authority all still take effect August 2, 2026.
If your compliance roadmap was built around the original date, the pressure just eased. The Omnibus was built as simplification, not rollback, though, and three obligations were left untouched.
Who This Affects
- Any organization whose AI system’s output reaches EU users, customers, or citizens, regardless of where the company is headquartered
- Providers, the organizations building or placing AI systems on the market, and deployers, the organizations using them, carry distinct obligations under the Act
- General purpose AI (GPAI) obligations apply to anyone providing a general purpose model and to anyone embedding one, including off the shelf models integrated into a product
- Prohibited practices apply universally regardless of sector or size, and have been in force since February 2025
- Anexo III high-risk obligations apply to specific use cases: employment and worker management, credit scoring and insurance access, education, critical infrastructure, law enforcement, migration and border control
- Article 50 transparency applies broadly, to any organization running a chatbot, generating synthetic content, or using AI in customer-facing interactions, whether or not the underlying system counts as high-risk
The Two Dates the Omnibus Reset
- High-risk deadline, standalone Annex III systems: August 2026 to December 2, 2027
- High-risk deadline, product-embedded Annex I systems: August 2026 to August 2, 2028
- AI literacy requirement: loosened from “ensure sufficient literacy” to “take measures supporting the development of literacy”
- Watermarking obligations: four-month transitional period added for systems already on the market before August 2026
What August 2, 2026 Still Requires
- Article 50 transparency obligations: disclosure when someone is interacting with an AI system, labeling for AI-generated content, marking for deepfakes
- National market surveillance authorities gain power to investigate and sanction AI Act breaches
- The European Commission’s enforcement powers over GPAI providers activate
- GPAI compliance obligations, in force since August 2025, become subject to real penalties
- Separately, a new prohibition on non-consensual intimate imagery and deepfake-generating AI takes effect December 2, 2026, on its own clock
The AI Office has already opened an enforcement action on synthetic media before the high-risk phase even arrived, evidence the enforcement layer is operating now, not waiting for 2027.
Standards Bodies Are Still Behind Schedule
This is the first amendment to the Act since it was adopted, and harmonized technical standards for high-risk compliance are still behind schedule, part of why the delay happened in the first place. Treating December 2027 as fixed is a bet that nothing else moves between now and then.
High-risk conformity work, data governance documentation, risk management, human oversight design, takes years to build properly. The added runway is only worth something if it’s used to build that foundation now instead of waiting until the deadline is close again.
None of that changes what’s due in days. Any company with a customer-facing chatbot, a content generation feature, or an embedded third-party model needs Article 50 disclosure and labeling working before August 2, regardless of whether its high-risk systems were affected by the delay.
Inventory First, Everything Else Follows
- Inventory every AI system in use across the organization, including tools procurement never formally approved
- Classify each system against prohibited, high-risk, GPAI, and transparency-obligation categories
- Confirm Article 50 disclosure and labeling mechanisms are live for anything customer-facing
- Re-baseline the high-risk roadmap to the new dates without pausing the underlying data governance work
- Assign ownership of ongoing regulatory monitoring, since this framework has already changed once this year
A Four-Year Sequence, Not a Single Date
- Now through August 2, 2026: finalize AI system inventory and classification; confirm Article 50 mechanisms are live; document GPAI usage across the vendor stack
- Through end of 2026: build the data governance foundation for Annex III systems, training data documentation, lineage, access controls, on the new timeline
- Through 2027: complete conformity assessments and technical documentation for standalone high-risk systems ahead of December 2, 2027
- Through 2028: extend the same work to product-embedded high-risk systems ahead of August 2, 2028
Como o BigID ajuda
Every obligation in this framework, current or deferred, rests on the same question: does the organization know what data is feeding its AI systems, where it came from, and who can touch it.
- Annex III data governance documentation: descobre e classifica the training, validation, and testing data behind an AI system, so “the data is representative and error-free” is a documented finding instead of an assertion
- IA Sombra and system inventory: surfaces the models and AI tools actually running across the environment, including the ones nobody submitted a request for, closing the gap most classification exercises start with
- Data lineage into and out of AI pipelines: maps how sensitive and regulated data moves into training, fine-tuning, and prompts, and where model outputs land afterward
- Governança de acesso for training and output data: shows who and what can reach the data behind a model, the access control evidence Annex III oversight requirements ask for
- Article 50 readiness: the same discovery layer that finds shadow AI is what identifies which systems are generating content in the first place
- Audit and conformity evidence: turns inventory, classification, and lineage work into documentation that holds up when a market surveillance authority asks for it
A Template Other Regulators Are Watching
O Lei de IA da UE was supposed to be the definitive template for AI regulation, the way RGPD became the template for privacy. The Omnibus complicates that story without weakening it. It shows a regulator responding to the gap between what it legislated and what standards bodies and companies could deliver on schedule, while holding firm on the parts it considers non-negotiable: prohibitions, transparency, enforcement authority.
The pattern worth watching, in the EU and anywhere else drafting AI rules: dates tied to fundamental rights and public trust move first and stay fixed, dates tied to technical conformity move on the timeline reality allows. The data governance foundation is the one investment that holds regardless of which individual deadline shifts next.
Prepare for the Next Phase of AI Compliance
The EU AI Act continues to evolve, but one requirement remains constant: organizations need visibility into their AI systems, the data they use, and the risks they introduce. Discover how BigID helps inventory AI assets, classify sensitive data, and build a trusted foundation for AI governance and regulatory compliance.
