Digital Omnibus on AI: the amended EU AI Act timetable

Digital Omnibus on AI: Regulation (EU) 2026/1744, in force 27 July 2026, and the amended AI Act timetable

In short: the Digital Omnibus on AI, Regulation (EU) 2026/1744, has been in force since 27 July 2026. It moves the EU AI Act’s high-risk obligations to 2 December 2027 for AI in listed uses such as recruitment and credit scoring, and to 2 August 2028 for AI built into a regulated product. The Article 50 transparency duties and the general-purpose model obligations keep their existing dates.

By Rob Bratby, Managing Partner, Bratby Law. Recognised in the Lexology Index as a Thought Leader for data privacy and protection. Chambers UK Band 2 (Telecommunications). Legal 500 Leading UK Telecoms Partner. 30+ years in telecoms and data protection regulation, including Oftel and senior operator roles.

A business selling an AI recruitment tool into the European Union has spent a year building towards 2 August 2026. For that product the date is now 2 December 2027. A business putting a comparable model into a piece of machinery, as a safety component, has until 2 August 2028, and will meet most of the substantive requirements under the Machinery Regulation rather than the AI Act. The Article 50 transparency duties apply to both from 2 August 2026, as before.

Regulation (EU) 2026/1744, the Digital Omnibus on AI, was signed on 8 July 2026, published in the Official Journal on 24 July 2026 and came into force on 27 July 2026, six days before the deadline it moved. Article 1 makes 43 separate amendments to Regulation (EU) 2024/1689, the AI Act. Two further articles amend the machinery and civil aviation regulations. Forty of those amendments have nothing to do with the two deferred dates.

Key findings (Regulation (EU) 2026/1744)

  • Chapter III, Sections 1, 2 and 3 of the AI Act, which carry the high-risk requirements, apply from 2 December 2027 to AI used for one of the purposes listed in Annex III, which covers recruitment and workers’ management, creditworthiness assessment, biometrics and education among other areas (Article 6(2)), and from 2 August 2028 to AI that is a safety component of, or is itself, a product covered by the EU product-safety legislation listed in Annex I (Article 6(1)). Article 6(5) is excepted and is not deferred. Source: Regulation (EU) 2026/1744, Article 1(40).
  • The 2 December 2027 and 2 August 2028 dates are fixed. Under point (c) of the third paragraph of Article 113, the obligations apply from them. The enacted text contains no confirmation decision, no conditional trigger and no mechanism by which the obligations could apply earlier. Source: AI Act Article 113, third paragraph, point (c) as amended.
  • The transparency obligations in Article 50(1) to (6) are not deferred. Only Article 50(7) is amended. A new Article 111(4) gives providers of generative systems placed on the market before 2 August 2026 until 2 December 2026 to comply with Article 50(2). Source: Regulation (EU) 2026/1744, Article 1(20) and Article 1(39).
  • Two prohibitions are added at Article 5(1), points (ba) and (bb), covering AI systems that generate or manipulate non-consensual intimate imagery and, subject to a “without right” defence under national law, child sexual abuse material. They apply from 2 December 2026. Source: Regulation (EU) 2026/1744, Article 1(7) and Article 1(40)(a).
  • The Machinery Directive is deleted from Section A of Annex I and Regulation (EU) 2023/1230 is added to Section B, so the AI Act applies to AI-enabled machinery through Article 6(1), Article 60a and Articles 102 to 112, and through Articles 57 to 59 so far as its high-risk requirements have been integrated into the Machinery Regulation. Source: Regulation (EU) 2026/1744, Article 1(2)(a) and Article 1(41).
  • New Articles 75a to 75d give the AI Office investigatory and enforcement powers over the systems within its exclusive competence, including periodic penalty payments of up to 5% of average daily income or worldwide annual turnover in the preceding financial year, per day. Source: Regulation (EU) 2026/1744, Article 1(32).
AI Act obligationApplies fromChanged by the omnibus
Prohibited practices, Article 5(1)(a) to (h)2 February 2025No
Prohibitions on non-consensual intimate imagery and child sexual abuse material, Article 5(1)(ba) and (bb)2 December 2026Yes, inserted
General-purpose AI model obligations, Chapter V2 August 2025No, apart from Article 56(6)
Transparency, Article 50(1) to (6)2 August 2026No
Article 50(2) marking, generative systems already on the market2 December 2026Yes, new Article 111(4)
High-risk requirements, AI in a listed use (Article 6(2), Annex III)2 December 2027Yes, deferred from 2 August 2026
High-risk requirements, AI in a regulated product (Article 6(1), Annex I)2 August 2028Yes, deferred from 2 August 2027
Consequential amendments to other EU instruments, Articles 102 to 11027 July 2026Yes, new point (d)

The deferral is fixed, and narrower than it looks

The general date of application in the second paragraph of Article 113 is untouched. The AI Act still applies from 2 August 2026. What changed is the third paragraph, which carves individual chapters out of that date, and the carve-out now splits the high-risk regime in two. Systems that are high-risk because of what they do, listed in Annex III, have until 2 December 2027. Systems that are high-risk because they are a safety component of a product covered by the EU product-safety legislation listed in Annex I have until 2 August 2028. The AI Act always staggered those two dates, at 2 August 2026 and 2 August 2027; the interval between them has narrowed from twelve months to eight.

Under Recital 40, standards, common specifications and guidance were not available and national competent authorities had not been established, so the original date would have raised implementation costs without a corresponding benefit. The new dates are not tied to the arrival of those standards. Under point (c) of the third paragraph of Article 113, as amended, the obligations apply from those two dates, with no confirmation decision and no earlier trigger (Regulation (EU) 2026/1744, Article 1(40)). There is no mechanism in the enacted text by which the obligations could bind sooner.

The prohibitions, the general-purpose model obligations and the transparency duties all keep their existing dates. Article 5 has applied since 2 February 2025. The Chapter V obligations on general-purpose AI model providers have applied since 2 August 2025, and the European Commission has been able to fine those providers since 2 August 2026, set out in detail at general-purpose AI enforcement. Article 50 covers chatbot disclosure, synthetic content marking and deepfake labelling, and binds only the providers and deployers named in its own paragraphs. Its date is 2 August 2026 as before, and it is set out in detail at Article 50.

Which of the two dates applies to your system

An AI system is high-risk under the AI Act on either of two grounds, and the omnibus has given them different dates. Under Article 6(1), a system is high-risk where it is a safety component of, or is itself, a product covered by one of the product-safety laws listed in Annex I, and that product must be assessed by a third party before it goes on the market. Those requirements bind the provider from 2 August 2028.

It is worth being precise about what Annex I contains, because it is commonly described as a list of products and it is not. It is a list of EU product-safety laws. They cover medical devices and in vitro diagnostics, toys, lifts, radio equipment, pressure equipment, personal protective equipment, gas appliances, cableway installations, recreational craft, equipment for explosive atmospheres, machinery, motor vehicles, agricultural and two or three-wheeled vehicles, marine equipment, rail systems and civil aviation. A product outside all of them falls outside Article 6(1).

Annex I is divided into two sections, and the division matters more than the date. Section A holds the consumer and medical product laws, and the full high-risk regime applies to a system covered by one of them. Section B holds the transport and machinery laws, and under the amended Article 2(2) only Article 6(1), the new Article 60a and Articles 102 to 112 of the AI Act apply to a system covered by one of those, together with Articles 57 to 59 on regulatory sandboxes so far as the AI Act’s high-risk requirements have been integrated into that sectoral legislation. Its substantive requirements otherwise come from that legislation. The move of machinery from Section A to Section B, described below, leaves machinery within the AI Act but subject to much less of it.

The second ground does not depend on the product at all. Under Article 6(2), a system is high-risk where it is used for one of the purposes listed in Annex III, whatever it is built into. Those requirements bind the provider from 2 December 2027. Annex III sets out the areas below.

Annex III areaWhat it includes
Biometrics, so far as permitted by lawRemote biometric identification, categorising people by sensitive or protected characteristics, and emotion recognition. Verifying that someone is who they say they are is excluded.
Critical infrastructureSafety components in the management and operation of critical digital infrastructure, road traffic, and the supply of water, gas, heating and electricity.
Education and vocational trainingDeciding admission or access, evaluating learning outcomes, and monitoring candidates for prohibited behaviour during tests.
Employment and workers’ managementRecruitment and selection, and decisions on promotion, termination and the allocation of work.
Access to essential public and private servicesEligibility for public assistance and healthcare, and creditworthiness and credit-scoring assessment.
Law enforcement, so far as permitted by lawAssessing a person’s risk of offending or of becoming a victim, and tools used in support of investigations.
Migration, asylum and border control, so far as permitted by lawTools used by public authorities to assess security or irregular-migration risk.
Administration of justice and democratic processesAssisting a judicial authority in researching and applying the law, and influencing the outcome of an election or the behaviour of voters.

Falling inside one of those areas is not the end of the question. Article 6(3) takes a system back out again where it does not pose a significant risk of harm to health, safety or fundamental rights, which covers a system performing a narrow procedural task, improving the result of a completed human activity, detecting patterns in earlier decisions without replacing the human assessment, or preparing an assessment rather than making it. That derogation has a hard limit: a system that profiles individuals is always high-risk. A provider relying on Article 6(3) has to document the assessment before the system goes on the market and register the system under Article 49(2).

If your system is both a regulated product and a listed use

A system can meet both tests at once, and where it does the earlier date governs. Article 6(2) opens “In addition to the high-risk AI systems referred to in paragraph 1”, so Article 6(2) adds to Article 6(1) rather than displacing it. A system within the scope of Annex III is high-risk on that ground whether or not it is also high-risk under Article 6(1). Point (c)(i) of the third paragraph of Article 113 then applies the 2 December 2027 date to a system classified as high-risk under Article 6(2) and Annex III, and carries no words excluding a system that is also classified under Article 6(1).

Take an AI function inside a medical device that supports diagnosis and also performs emotion recognition on the patient. The device is covered by the Medical Devices Regulation, which sits in Section A of Annex I, so Article 6(1) is engaged and the conformity assessment is the one required by the Medical Devices Regulation. The amended Article 43(3) says so in terms: where a system is covered by Section A legislation and falls within one of the categories listed in Annex III, the provider follows the conformity assessment procedure required by that Section A legislation. That provision settles the assessment procedure. It does not alter the classification, and emotion recognition keeps the system within the first area of Annex III. The Chapter III requirements therefore bind the provider from 2 December 2027, not 2 August 2028.

The classification test changed as well as the date

Under the amended Article 3(14) and Article 6, fewer products become high-risk in the first place. A safety component now requires that the component’s intended purpose is to prevent or mitigate a risk to health and safety of persons or property. Under new Article 6(1a), a system used solely for non-safety functions such as performance optimisation, service efficiency or quality control is not a safety component. Under new Article 6(1c), a product falls outside the Article 6(1)(b) condition where its third-party assessment requirement exists for reasons other than health and safety, such as radio spectrum or electromagnetic interference. Under new Article 6(1b), a product remains within scope where a failure would endanger health and safety.

For AI-enabled machinery the omnibus goes further than the classification test. Point 1 of Section A of Annex I, which listed the Machinery Directive, is deleted, and Regulation (EU) 2023/1230 is added to Section B. For a Section B product the amended Article 2(2) applies Article 6(1), the new Article 60a and Articles 102 to 112 of the AI Act, and Articles 57 to 59 only so far as the AI Act’s high-risk requirements have been integrated into the sectoral legislation. The substantive requirements for AI-enabled machinery therefore come through the Machinery Regulation, with the Commission required to add AI-specific health and safety requirements to its Annex III by delegated acts that must apply by 2 August 2028, and an interim presumption of conformity for anyone meeting AI Act harmonised standards in the meantime. A manufacturer of AI-enabled machinery therefore complies through the Machinery Regulation and not through an AI Act conformity assessment against Annex I.

What it means for a UK provider selling into the EU

A UK business placing a high-risk AI system on the EU market is a third-country provider and has to appoint an authorised representative established in the Union under Article 22. Article 22 is in Section 3 of Chapter III, so that obligation moves with the rest of the section, to 2 December 2027 or 2 August 2028 according to which of the two grounds applies. The appointment is a commercial arrangement that takes time to put in place. The later dates give a UK provider more time to appoint a representative. They do not remove the requirement.

The deferred high-risk dates do not move a UK provider’s other obligations. Article 50 is not a general transparency duty. It binds providers of systems intended to interact directly with people and providers of systems generating synthetic content, and deployers of emotion recognition and biometric categorisation systems and of deepfakes. Where a system is within one of those, the duty applies from 2 August 2026 whatever the provider’s place of establishment. The new Article 5 prohibitions apply from 2 December 2026 and are not deferred. Where a UK business builds its product on another company’s general-purpose model, that model provider’s Chapter V obligations have been enforceable since 2 August 2026, which affects what a UK business can expect from its supplier and what it can obtain by contract. The allocation of responsibility between a UK business and its model supplier is set out at AI and automated decision-making.

Supply agreements signed in 2025 and early 2026 carry the practical exposure. They were drafted against 2 August 2026, and many contain compliance warranties, delivery milestones and termination rights keyed to that date. Those clauses now sit eighteen months or two years ahead of the obligation they were written for. Where a UK supplier’s contract fixes it to AI Act conformity by a date the AI Act no longer uses, the contract binds the supplier on that date whatever the Regulation now says. The AI and data governance advice page sets out the scope of a contract review.

Viewpoint

In my view the omnibus changes the shape of the AI Act’s timetable rather than excusing anyone from part of it. Nothing that bound a provider on 1 August 2026 has stopped binding it. Article 5 has applied since 2 February 2025 and gains two further prohibitions on 2 December 2026. Article 50 has applied since 2 August 2026, subject to the narrow relief in Article 111(4). The Chapter V obligations on general-purpose model providers have applied since 2 August 2025 and have been enforceable since 2 August 2026.

What has moved is Chapter III, Sections 1 to 3, and only for the systems the amended Article 113 identifies: the conformity assessment, the technical documentation and the quality management system a provider of a high-risk system must have in place. For AI-enabled machinery even those requirements now come from the Machinery Regulation.

Frequently asked questions

Has the EU AI Act been delayed?

Only in part. The AI Act still applies from 2 August 2026. The requirements for high-risk AI systems in Chapter III, Sections 1 to 3 apply from 2 December 2027 to AI used for one of the purposes listed in Annex III, and from 2 August 2028 to AI in a product covered by the legislation listed in Annex I. The prohibitions, the general-purpose AI model obligations and the Article 50 transparency duties keep their original dates.

Could the high-risk obligations apply earlier than 2 December 2027?

Not under the enacted text. The obligations apply from two fixed dates under point (c) of the third paragraph of Article 113, as amended. Regulation (EU) 2026/1744 contains no confirmation decision by the Commission, no conditional trigger tied to the availability of standards, and no mechanism by which the obligations could apply before those dates.

Do the Article 50 transparency obligations still apply from 2 August 2026?

Yes. Article 50(1) to (6) is unamended and undeferred. The only change is to Article 50(7), which moves responsibility for facilitating codes of practice to the Commission and replaces the power to approve a code by implementing act with a duty to assess whether adherence to it is adequate. Providers of generative AI systems placed on the market before 2 August 2026 have until 2 December 2026 to meet the Article 50(2) marking requirement, under the new Article 111(4).

My system is both a regulated product and a listed use. Which date applies?

2 December 2027. Article 6(2) adds to Article 6(1) rather than displacing it, and point (c)(i) of the third paragraph of Article 113 applies the earlier date to a system classified under Article 6(2) and Annex III without excluding one that is also classified under Article 6(1). The amended Article 43(3) requires the conformity assessment for such a system to be the one prescribed by the Annex I Section A legislation, but that settles the procedure rather than the classification.

Is AI-enabled machinery still covered by the AI Act?

Through the provisions listed in the amended Article 2(2), being Article 6(1), Article 60a and Articles 102 to 112, and through Articles 57 to 59 so far as the AI Act’s high-risk requirements have been integrated into the Machinery Regulation. Regulation (EU) 2023/1230 has moved from Section A to Section B of Annex I, so the substantive requirements for AI-enabled machinery come through the Machinery Regulation and the delegated acts the Commission must make under it.


For advice on AI Act classification, EU market access for AI products or the contractual consequences of the amended timetable, contact Rob Bratby at Bratby Law. The enforcement position is set out at AI Office enforcement.

Select topics of interest

Similar Posts