Nov 19, 2025 · View original article

EU Proposes Digital Omnibus: High-Risk AI Act Obligations Could Slip to 2027

The European Commission's 19 November 2025 Digital Omnibus on AI would tie high-risk obligations to the availability of standards, with backstop dates of December 2027 and August 2028, and widen SME relief to small mid-caps.

On 19 November 2025 the European Commission published its Digital Omnibus on AI, a legislative proposal to amend the EU AI Act before its most demanding provisions take effect. The headline change concerns high-risk AI systems. Under the current text, obligations for Annex III use cases (employment, credit, education, essential services, law enforcement and others) apply from 2 August 2026, and obligations for AI embedded in regulated products from 2 August 2027. The proposal would make both dates conditional on the availability of harmonised standards and common specifications, with hard backstops of 2 December 2027 for Annex III systems and 2 August 2028 for product-embedded systems.

The mechanism is notable. Rather than a simple postponement, the Commission would decide when adequate compliance measures exist, after which providers would receive a six-to-twelve-month window to comply. Systems already lawfully on the market before the rules apply could continue unchanged provided the design is not modified, sparing legacy deployments from retrofits. The proposal also broadens the reduced-burden regime beyond SMEs to small mid-caps of fewer than 750 employees and up to 150 million euros turnover, including simplified documentation, proportionate quality management systems and capped penalties.

Other elements reshape enforcement and testing. The AI Office would gain exclusive supervisory authority over general-purpose AI models and over AI systems embedded in very large online platforms and search engines, reducing the role of national market surveillance authorities in those cases. An EU-level regulatory sandbox would sit alongside national sandboxes, and Article 60 real-world testing would be extended to high-risk systems in product-regulated sectors before certification.

The proposal responds to a year of pressure from industry and several member states, who argued that the CEN-CENELEC standards needed to demonstrate conformity would not be ready in time, leaving providers to comply with obligations that lack an agreed technical yardstick. Critics, including civil-society groups and some MEPs, characterised the package as deregulation by another name and warned that fundamental-rights safeguards were being traded for competitiveness. Importantly, nothing changes until the Parliament and Council adopt the text. The Commission's own timing makes that a race: without agreement before August 2026, the original deadlines apply.

For governance teams the practical message is not to stop. The prohibited-practice and AI-literacy provisions already apply, general-purpose AI obligations took effect in August 2025, and the high-risk requirements are being deferred, not removed. Organisations that use the extra time to build the risk management, data governance and human-oversight capabilities the Act describes will be ready whichever date ultimately holds.

What it means for leaders

  • Do not pause high-risk readiness programmes. The deferral is a proposal, and the backstop dates are firm. Continue building risk management, technical documentation and logging capabilities, ideally anchored to ISO/IEC 42001 so the work remains valuable regardless of the final calendar.
  • Re-scope your inventory. Confirm which systems fall under Annex III versus product legislation, since the two now carry different conditional timelines and grace-period rules.
  • Track the standards, not just the law. The trigger for obligations becomes the availability of harmonised standards; assign someone to monitor CEN-CENELEC JTC 21 outputs.
  • Mid-sized firms should model the SMC relief. Companies under 750 staff may qualify for lighter documentation and capped fines, which changes the cost side of compliance planning.
  • Expect enforcement to centralise for GPAI and platforms. Providers of general-purpose models and large platforms should prepare for a single supervisor in the AI Office rather than 27 national regulators.

Comments

No comments yet. Be the first to comment.