TL;DR: The EU Digital Omnibus would delay most Annex III high-risk AI obligations to December 2027, but formal adoption has not happened yet. Article 50 obligations apply August 2, 2026 regardless; GPAI model obligations have been in effect since August 2, 2025. Plan for both outcomes.
On May 7, 2026, the EU reached a provisional political agreement on the Digital Omnibus package, a sweeping set of legislative changes that includes a proposed delay of the main high-risk AI obligations under the EU AI Act. If it passes into law before August 2, 2026, deployers of most high-risk AI systems gain roughly 16 additional months to complete technical documentation, conformity assessments, and risk management procedures.
But the word "if" is carrying a lot of weight right now.
This article explains what the Digital Omnibus would change, what it would not change, what needs to happen for it to take effect, and what deployers should do while the outcome is still uncertain.
What the provisional agreement actually says
The provisional agreement reached in May 2026 contains a provision that would defer the compliance deadline for Annex III high-risk AI system obligations under Articles 9-15. Specifically, it would move the deadline from August 2, 2026 to approximately December 2, 2027.
Articles 9-15 cover the core technical obligations for high-risk AI systems:
- Article 9: Risk management system requirements
- Article 10: Data governance and data quality requirements
- Article 11: Technical documentation standards
- Article 12: Record-keeping and logging requirements
- Article 13: Transparency and provision of information to deployers
- Article 14: Human oversight measures
- Article 15: Accuracy, robustness, and cybersecurity requirements
These are the obligations that require the most significant internal work: building documentation systems, establishing audit trails, implementing human-in-the-loop controls, and in many cases commissioning third-party conformity assessments.
The proposed extension would apply to most Annex III categories, which covers AI in employment decisions, educational access, credit scoring, biometric identification outside the prohibited categories, law enforcement (with caveats), and management of critical infrastructure. The exact scope of the Omnibus text should be confirmed against the final published version when formal adoption occurs.
What does not change regardless of the Omnibus
Three categories of obligation are outside the scope of the Digital Omnibus delay and will apply on their current schedule no matter what.
Article 5: Prohibited AI practices. These have been in force since February 2, 2025. They include social scoring systems operated by public authorities, real-time remote biometric identification in public spaces (with narrow exceptions), AI systems that exploit psychological vulnerabilities or subliminal techniques to manipulate behavior, and AI used to infer sensitive characteristics from biometric data for discriminatory purposes. If you are using any system in these categories, you are already in violation and the Omnibus changes nothing about that.
Article 50: Transparency obligations. Effective August 2, 2026 with or without the Omnibus. Article 50 requires that AI systems designed to interact directly with humans notify those humans that they are interacting with an AI. It also requires disclosure when AI generates synthetic content, including images, audio, and text, and requires watermarking or machine-detectable labeling of AI-generated material. Deepfake disclosure obligations are included in this article. For most deployers, Article 50 compliance is a documentation and UX change, but it is not optional and the August deadline does not move.
GPAI obligations for model providers. In effect since August 2, 2025. General Purpose AI model providers, meaning companies that develop and make available foundation models or large language models, must prepare technical documentation, publish usage policies, implement copyright compliance procedures, and for the most capable models, conduct adversarial testing. If your organization develops or fine-tunes a general-purpose AI model that is released publicly, you are a GPAI provider and these obligations already applied before the August 2026 deadline. The Omnibus does not change or extend them.
What needs to happen for the Omnibus to take effect
A provisional political agreement between the European Parliament and the Council is not law. It is a signal of political intent between the two legislative bodies that they have reached a deal on the substance of a text. Several steps remain before the text becomes binding.
-
Legal-linguistic review. The agreed text must be finalized in all 24 official EU languages. This process typically takes weeks to a few months for a complex package.
-
Formal vote in the European Parliament. The full Parliament must vote to adopt the final text. Given that a provisional agreement was reached, this vote is expected to pass, but procedural delays or political shifts can affect timing.
-
Formal adoption by the Council. The Council of the EU must formally adopt the text as well.
-
Publication in the Official Journal of the European Union. The regulation takes effect 20 days after publication, or on the date specified in the text.
The risk is timing. If the Omnibus is not formally adopted and published in the Official Journal before August 2, 2026, the original deadline applies. There is no automatic grace period, no transitional carve-out, and no mechanism for the European Commission to unilaterally delay enforcement while adoption is pending.
EU legislative processes do not always move quickly. The gap between political agreement and formal adoption on complex packages has historically ranged from a few weeks to several months. Whether the process completes before August 2 is genuinely uncertain.
Two-path planning framework
Given the uncertainty, the most practical approach is to identify the actions that are required or beneficial under both scenarios and complete those now. Then identify the actions that are only required if the Omnibus fails, and assess whether the cost of completing them now is justified by the risk of the deadline holding.
Path A: Omnibus passes before August 2, 2026. The full Articles 9-15 technical obligations for Annex III high-risk AI move to December 2, 2027. You have 16 more months to complete conformity assessments, technical documentation, and risk management system implementation. However, Article 50 and GPAI obligations still apply August 2.
Path B: Omnibus fails before August 2, 2026. The original deadline holds. Full Articles 9-15 compliance is required immediately for all high-risk AI systems already deployed. This means risk management documentation, data governance evidence, technical documentation, and for systems in certain categories, third-party conformity assessment, must be in place.
Actions that help under both scenarios
These are the investments worth making right now regardless of which path the Omnibus takes.
Complete your AI tool inventory and risk classification. You cannot plan compliance without knowing which tools you have and which Annex III categories they fall into. This exercise is required in either scenario. It takes time if you have deployed AI broadly across the organization. Start now.
Implement Article 50 transparency notices. Since Article 50 applies August 2, 2026 regardless, any AI system your organization deploys that interacts with users needs a disclosure notice. For most teams, this is a short text notice added to the user interface. The work is limited and the deadline is firm.
Document human oversight procedures. Article 14 requires deployers to implement human oversight. Even if the technical documentation deadline moves to 2027, having documented oversight procedures is good governance practice, reduces liability risk in case of AI-related incidents, and forms the foundation of the documentation you will need to complete later.
Conduct fundamental rights impact assessments. Article 27 requires deployers of high-risk Annex III AI systems in certain categories to complete a fundamental rights impact assessment before deploying the system. This obligation is separate from the Articles 9-15 technical obligations. Check whether it applies to your tools and conduct the assessment if so.
Review your GPAI vendor relationships. If you are deploying tools built on general-purpose AI models, your vendors have obligations under GPAI rules that take effect August 2. Request their technical documentation summaries and confirm they have published usage policies. Their compliance status affects your documentation.
What deployers should not do
Do not interpret the provisional Omnibus agreement as permission to stop working on EU AI Act compliance. The agreement is not final. If it fails or if adoption is delayed past August 2, the original deadline applies and there is no ability to retroactively compress months of compliance work into days.
Do not assume that the delay, if it passes, gives you 16 months of inaction. The December 2027 deadline is not far off, and conformity assessments for high-risk AI in regulated sectors can take many months to arrange and complete. Use the extension as time to do the work properly, not as permission to deprioritize it.
Do not overlook the overlap between EU AI Act obligations and GDPR requirements. Many of the data governance requirements under Article 10 mirror GDPR data quality and minimization principles. Your GDPR documentation is a head start on EU AI Act technical documentation, not a substitute.
How to track Omnibus adoption status
Monitor the EUR-Lex legislative observatory for the Digital Omnibus package. When the formal text is published in the Official Journal, the entry into force date will be specified explicitly. Sign up for updates from your national data protection authority or AI supervisory authority, as many publish plain-language guidance on implementation timelines. The AI Policy Desk AI regulation deadline calendar 2026 tracks key dates as they are confirmed.
One practical note on monitoring: the Official Journal publication date and the entry-into-force date are different. A Regulation typically enters into force 20 days after publication in the Official Journal, and then application dates may be staggered within the text itself. When the Omnibus is published, look for the Article that specifies application dates, not just the preamble summary, because the preamble can be ambiguous about which provisions apply when.
For a complete breakdown of what applies August 2 versus what is being debated, see What is delayed vs what applies, EU AI Act August 2026. For deployers focused on the GPAI layer, the EU AI Act GPAI compliance checklist August 2 deadline covers that category specifically. For evidence gaps that SMEs commonly face, see EU AI Act deployer evidence gaps SME August 2026.
Related reading
- EU AI Act Annex IV technical documentation guide: all 9 sections
- EU AI Act compliance guide for small teams
- EU AI Act August 2026 compliance checklist
- EU AI Act Article 50 watermarking and deepfake disclosure
- EU digital omnibus AI Act deadline extension 2026
- ISO 42001 vs NIST AI RMF for small teams
- AI regulation deadline calendar 2026
- EU AI Act prohibited AI practices Article 5 guide
- EU AI Act: what is delayed vs what applies August 2026
- EU AI Act August 2026 Deadline Extended to December 2027: What It Means
- EU AI Act enforcement starts August 2, 2026: what it means and what to d
- EU AI Act high-risk AI documentation templates for August 2026 (Articles
