According to the security firm usd's summary, the so-called AI Omnibus entered into force on 27 July 2026. The European Parliament adopted it on 16 June and the Council approved it on 29 June. It amends the EU AI Act in several places — above all its deadlines.

What the Omnibus changes

High-risk AI obligations are postponed because standards and support tools are still missing. In the experts' assessment, the substantive requirements themselves remain largely intact: risk management, data governance, technical documentation and human oversight.

The new deadlines

  • Stand-alone high-risk systems (Annex III): 2 December 2027 at the latest (previously 2 August 2026)
  • AI embedded in regulated products (Annex I): 2 August 2028 at the latest

What does not wait

The transparency duties under Art. 50 still apply from 2 August 2026; for machine-readable labelling of AI content in systems placed on the market before that date, a deadline runs until 2 December 2026. Fines for providers of general-purpose AI models have also been enforceable since August 2026. The AI literacy duty (Art. 4) was softened: instead of ensuring a sufficient level, companies must take measures to promote it.

A postponed deadline is not postponed risk: the AI tools are already in use inside your company.

Conclusion

The postponement buys time but does not replace an inventory. Anyone who does not know which AI services are used in-house can assess neither data protection nor compliance. The first step remains an inventory plus clear usage rules — see also our article on shadow AI.

Note: Status as of October 2026, not legal advice. The legal text is authoritative.