This site's earlier coverage of the Digital Omnibus, written during trilogue, was necessarily provisional. It is now possible to state the outcome as settled fact rather than a negotiating position. This piece supersedes that provisional coverage with the confirmed timeline, and separates what the Omnibus changed from the substantial part of the AI Act's calendar that it left entirely alone.

Key takeaways

  • The Digital Omnibus on AI entered into force on 27 July 2026, following political agreement on 7 May 2026 and Council final approval on 29 June 2026. It is adopted law, not a pending proposal.
  • Annex III high-risk AI obligations, the provider duties under Articles 9 through 17 and the deployer duties under Article 26, move from 2 August 2026 to 2 December 2027. Annex I obligations for AI embedded in regulated products move from 2 August 2027 to 2 August 2028.
  • Article 5 prohibited practices, in force since 2 February 2025, and general-purpose AI obligations under Articles 53 and 55, in force since 2 August 2025, are unaffected. Article 50 transparency duties for new systems still activate on 2 August 2026.
  • The Product Liability Directive's 9 December 2026 transposition deadline is a separate legislative instrument, entirely outside the AI Act, and is not affected by the Omnibus in any way.
  • The content of the Article 26 operator file, a risk record, an oversight register, an instructions-for-use map, a logging schedule, and an incident protocol, has not changed. Only the date by which Annex III deployers must have it ready has moved.

What the Digital Omnibus actually is

The Digital Omnibus on AI is a targeted amendment to Regulation (EU) 2024/1689, the EU AI Act, presented by the European Commission on 19 November 2025 under reference COM(2025) 836, as part of a broader Digital Omnibus package that also touched GDPR, the Data Act, and NIS 2. Its stated purpose was to simplify implementation of the AI Act by deferring the Annex III high-risk obligations, softening the AI literacy requirement from a binding duty toward encouragement, expanding the AI Office's supervisory role for integrated general-purpose AI systems, and extending proportionate penalty provisions to small mid-cap companies alongside SMEs.

The legislative process that followed ran through most of 2026. The European Parliament and the Council reached political agreement on 7 May 2026. The Council gave its final approval on 29 June 2026. The text was published in the Official Journal and entered into force on 27 July 2026. As of this article's publication, three weeks later, the Omnibus is settled law, and any coverage, on this site or elsewhere, that still describes it as pending trilogue is describing a stage of the process that has already closed.

The confirmed timeline

The central change is a deferral of application dates for two categories of high-risk AI obligation, not a change to what the obligations require once they apply.

Annex III systems, used in employment and worker management, education and vocational training, access to essential private and public services including credit scoring and insurance risk assessment, law enforcement, migration and border control, and the administration of justice, now face the full set of provider obligations under Articles 9 through 17 and the deployer obligations under Article 26 from 2 December 2027, rather than 2 August 2026. This is the deferral that matters to most compliance teams reading this site, because Annex III is where the majority of enterprise deployer obligations sit.

Annex I systems, AI embedded in products already regulated under existing EU product safety law, medical devices, machinery, toys, and aviation equipment among them, move from 2 August 2027 to 2 August 2028. An acceleration clause allows the European Commission to bring either date forward if harmonised standards and conformity assessment infrastructure become available sooner than the default schedule assumes, though no such acceleration has been exercised as of this article's publication.

What the Omnibus left completely untouched

Coverage of "the AI Act delay" in general media has sometimes implied a blanket postponement. That is not accurate, and getting this wrong has real consequences for a compliance team deciding what to build first. Four obligation clusters were not touched by the Omnibus at all.

Article 5 prohibited practices, covering AI systems that exploit vulnerabilities of specific groups, social scoring by public authorities, most real-time remote biometric identification in public spaces for law enforcement, and predictive policing based solely on profiling, entered force on 2 February 2025 and have been enforceable since that date. Nothing in the Omnibus reopens this.

General-purpose AI model obligations under Articles 53 and 55 of Chapter V have applied since 2 August 2025, governing the foundation model providers whose systems most deployers build on. This is a provider-facing obligation in the first instance, but it is directly relevant to any deployer assessing a vendor's compliance posture, and it was never part of the deferred timeline.

Article 50 transparency duties, requiring disclosure that a person is interacting with an AI system, machine-readable marking of synthetic content, disclosure of emotion recognition or biometric categorisation systems, and labelling of deepfake content, apply to any system first placed on the market after 2 August 2026, regardless of Omnibus adoption. The Omnibus does introduce one specific, narrow modification: a six-month grace period for the machine-readable marking requirement under Article 50(2) specifically, applying only to systems already on the market by 2 August 2026, running until 2 February 2027. A new customer-facing chatbot launched after 2 August 2026 must comply with disclosure obligations from day one, delay or no delay.

The revised Product Liability Directive, Directive 2024/2853, is not part of the AI Act package at all and was never subject to the Omnibus negotiation. Every Member State must transpose it into national law by 9 December 2026, applying strict liability to defective products, now including AI software, with a rebuttable presumption of defect under Article 10 and expanded rights to evidence disclosure under Article 9. This deadline is closer to this article's publication date than the original 2 August 2026 AI Act deadline was when this site's earlier coverage was written, and it deserves more attention from compliance teams than it has generally received relative to the volume of commentary on Annex III.

What this means for a deployer's operator file

A deployer of an Annex III high-risk system now has until 2 December 2027 rather than 2 August 2026 to have its full operator file in place: a risk record documenting the system's known limitations, an oversight register naming trained and authorised human overseers, an instructions-for-use map, a logging schedule meeting the retention requirements, and a tested incident protocol. What has not changed is the content of that file. The Omnibus adjusted a date. It did not adjust what Article 26 requires once that date arrives, and it did not touch the Article 99 penalty regime that attaches to non-compliance once the obligation is live.

The practical implication is that a compliance programme already underway, built to the original 2 August 2026 standard covered in this site's earlier 100-day operator checklist and final three-week checklist, remains fully usable against the new December 2027 date. Nothing in that work is wasted. A deployer that had not yet started, by contrast, gains genuine additional runway, but should use it deliberately rather than treat it as a reason to deprioritise the work, particularly given that the Product Liability Directive's strict liability standard arrives in December 2026, a full year before Annex III now does, and is not contingent on AI Act classification at all.

This is also the point at which compliance evidence and insurance underwriting evidence converge, a relationship covered in detail in the EU AI Act and Product Liability Directive double-exposure guide on this site. Carriers writing AI liability cover in the European market, including Munich Re's aiSure and Armilla's Lloyd's-backed programme, were never underwriting against the Annex III date, and the deferral does not change what they ask an applicant to demonstrate. For the market-facing view of how this news actually landed with European insurers, see how the Digital Omnibus is changing AI agent insurance on agentinsured.eu.

What to do with the confirmation

Three actions follow directly from the Omnibus now being settled rather than pending. First, correct internal planning documents and vendor communications that still cite 2 August 2026 as the Annex III deadline; using a superseded date in a compliance file or a customer-facing representation is now avoidably wrong, not merely provisional. Second, re-sequence any compliance programme that had been treating 2 August 2026 as the forcing function, moving the Product Liability Directive's 9 December 2026 deadline into the position of nearest fixed date requiring readiness. Third, treat the additional runway on Annex III as capacity to do the operator file work more thoroughly rather than as a reason to defer starting it, since the underlying documentation remains the same evidence base insurers, enterprise counterparties, and eventually national supervisors will all expect to see.

Frequently asked questions

Is the Digital Omnibus on AI now formally adopted?

Yes. Political agreement was reached on 7 May 2026, the Council gave final approval on 29 June 2026, and the Digital Omnibus entered into force on 27 July 2026. It is adopted law amending Regulation (EU) 2024/1689, and the deferred dates it sets are now the operative ones for Annex III and Annex I high-risk obligations.

What is the new deadline for Annex III high-risk AI obligations?

Annex III high-risk AI obligations now apply from 2 December 2027 rather than 2 August 2026. This covers the provider obligations under Articles 9 through 17 and the deployer obligations under Article 26. Annex I obligations, for AI embedded in already-regulated products, move from 2 August 2027 to 2 August 2028.

What obligations were not affected by the Digital Omnibus at all?

Article 5 prohibited practices have been in force since 2 February 2025. General-purpose AI model obligations under Articles 53 and 55 have applied since 2 August 2025. Article 50 transparency duties apply to systems first placed on the market after 2 August 2026, with only a narrow grace period until 2 February 2027 for machine-readable marking of content from systems already on the market. The Product Liability Directive's 9 December 2026 deadline is entirely outside the AI Act and unaffected.

Does the Digital Omnibus reduce what a deployer needs to document now?

It changes the timeline, not the content. A deployer building toward 2 December 2027 still needs the same operator file: a risk record, an oversight register, an instructions-for-use map, a logging schedule, and an incident protocol. The Product Liability Directive's strict liability standard, unaffected by the Omnibus, means the commercial case for having this documentation ready does not wait for the Annex III date.

References

  1. Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), OJ L, 12.7.2024.
  2. Digital Omnibus on AI, COM(2025) 836, European Commission proposal presented 19 November 2025, amending Regulation (EU) 2024/1689. Political agreement 7 May 2026. Council final approval 29 June 2026. Entered into force 27 July 2026.
  3. Article 5, Regulation (EU) 2024/1689. Prohibited AI practices, in force and enforceable since 2 February 2025.
  4. Articles 53 and 55, Regulation (EU) 2024/1689. General-purpose AI model obligations, applicable since 2 August 2025.
  5. Article 50, Regulation (EU) 2024/1689. Transparency obligations for certain AI systems.
  6. Articles 9 to 17, Regulation (EU) 2024/1689. Risk management, data governance, technical documentation, logging, transparency, human oversight, accuracy, robustness, cybersecurity, and quality management obligations for providers of high-risk AI systems.
  7. Article 26, Regulation (EU) 2024/1689. Obligations of deployers of high-risk AI systems.
  8. Article 99, Regulation (EU) 2024/1689. Penalties.
  9. Directive (EU) 2024/2853 of the European Parliament and of the Council on liability for defective products, OJ L, 18.11.2024. National transposition deadline 9 December 2026.