Mar 13, 2026 · View original article
EU Council backs fixed 2027 and 2028 deadlines for AI Act high-risk rules (March 2026)
On 13 March 2026 the Council of the EU adopted its negotiating position on the Digital Omnibus on AI, proposing to delay high-risk obligations to December 2027 and August 2028 and adding a new prohibited practice.
On 13 March 2026 the Council of the European Union agreed its general approach on the Digital Omnibus on AI, the Commission's November 2025 proposal to amend the EU AI Act before its main obligations bite. The Council mandate replaces the Commission's idea of a flexible adjustment period of up to 16 months with a fixed calendar: obligations for stand-alone high-risk AI systems (Annex III use cases such as recruitment, credit scoring and critical infrastructure) would apply from 2 December 2027, and obligations for high-risk systems embedded in regulated products (Annex I) from 2 August 2028. Under the original Act both were due to start on 2 August 2026.
The Council text goes beyond timing. It adds a new prohibited practice covering AI that generates non-consensual intimate or sexual imagery and child sexual abuse material. It reinstates a mandatory registration requirement for systems that providers judge to be exempt from the high-risk category, and brings back a "strict necessity" test for processing special-category personal data for bias detection. Relief measures originally reserved for SMEs are extended to small mid-caps. The AI Office's powers are strengthened, with explicit carve-outs where national authorities keep oversight, including law enforcement, border management, the judiciary and financial institutions. The deadline for member states to stand up regulatory sandboxes moves to 2 December 2027, and the Commission is asked to issue guidance that minimises compliance burden for high-risk providers.
With the Council position settled, the presidency was cleared to open trilogue negotiations with the European Parliament, whose committees were still finalising their own report in March. Given the August 2026 cliff edge, the legislative timetable was tight and market participants were left with several months of uncertainty over which dates would ultimately apply.
The move fits a broader pattern of European simplification: the Commission's omnibus packages have targeted sustainability reporting, data rules and now AI, responding to industry and member-state pressure over compliance cost and the late arrival of harmonised standards. But the Council's insistence on fixed dates, rather than a "stop-the-clock" tied to standards availability, signals that the delay is a postponement, not a retreat. Obligations already in force since February 2025 (prohibited practices, AI literacy) and the GPAI rules that started in August 2025 are untouched.
What it means for leaders
- Do not pause high-risk readiness. A fixed 2027 date is close enough that risk-management systems, data governance, technical documentation and human-oversight design (Articles 9 to 15) still need to be built in 2026; use the extra time to test them, not to defer them.
- Watch the registration obligation. If you rely on the Article 6(3) exemption to classify a system as not high-risk, expect to document and register that decision.
- Map your systems to the two calendars. Product-embedded AI (machinery, medical devices, vehicles) and stand-alone systems now diverge by eight months; procurement contracts should reference the correct one.
- Align with ISO/IEC 42001. A certified AI management system remains the most efficient way to evidence the Act's risk, monitoring and accountability requirements whatever the final dates.
- Track the trilogue. Parliament's position may differ on deadlines and scope; treat the Council text as the floor, not the final answer.
