May 07, 2026 · View original article
EU Reaches Provisional Deal to Delay High-Risk AI Act Obligations to 2027–2028
On 7 May 2026 the Council and Parliament agreed the Digital Omnibus on AI, pushing stand-alone high-risk duties to December 2027 and embedded-product duties to August 2028.
On 7 May 2026 the Council presidency and the European Parliament announced a provisional agreement on the AI-related part of the "Omnibus VII" simplification package. The deal amends the EU AI Act before its most demanding provisions take effect, and negotiators said they treated the file with top priority because the original high-risk deadline of 2 August 2026 was less than three months away.
The headline change is timing. Obligations for stand-alone high-risk AI systems (Annex III use cases such as recruitment, credit scoring, education and critical infrastructure) now apply from 2 December 2027. High-risk systems embedded in regulated products such as medical devices, machinery and toys move to 2 August 2028. Member states get until 2 August 2027 to stand up at least one AI regulatory sandbox. In the other direction, the grace period for labelling AI-generated content under the transparency rules was cut from six months to three, fixing 2 December 2026 as the date by which providers must have technical marking solutions in place.
Several substantive amendments ride along with the deadline shift. A new prohibition targets AI systems built to generate non-consensual intimate imagery or child sexual abuse material. Relief measures previously reserved for SMEs are extended to small mid-caps. Providers and deployers gain a clearer legal basis for processing special-category personal data where strictly necessary to detect and correct bias. The AI Office's role over general-purpose AI is reinforced, with carve-outs for law enforcement and financial supervisors, and a coordination mechanism is created to resolve overlaps between the AI Act and sector-specific product legislation.
The agreement follows the Commission's November 2025 omnibus proposal, which was triggered by delays in harmonised standards and by pressure from industry and several member states. It does not reopen the risk-based architecture, the list of prohibited practices already in force since February 2025, or the general-purpose AI obligations that have applied since August 2025. The text still needed formal endorsement by both institutions and legal-linguistic revision before publication in the Official Journal; the Council gave its final approval on 29 June 2026.
For compliance teams the message is nuanced. The extra 16 to 24 months are real, but the transparency deadline moved earlier, the prohibitions expanded, and national authorities have been told to accelerate sandboxes. Organisations that paused Annex III readiness work in anticipation of the delay should note that conformity assessment, technical documentation and post-market monitoring requirements are unchanged in substance.
What it means for leaders
- Re-baseline the roadmap, do not shelve it. Update AI inventories with the new dates (2 Dec 2027 / 2 Aug 2028) and keep high-risk classification, risk management and data governance work moving; an ISO/IEC 42001 management system remains the most practical scaffold for Article 9 to 17 obligations.
- Bring the content-marking deadline forward. Any system generating synthetic text, audio, image or video for EU users needs watermarking or provenance controls by 2 December 2026, a tighter window than many programmes assumed.
- Review prohibited-use screening. Add the new ban on non-consensual intimate imagery and CSAM generation to acceptable-use policies, model evaluations and vendor due diligence.
- Use the bias-detection clarification carefully. The ability to process sensitive data for fairness testing is bounded by strict necessity; document the legal basis and safeguards under GDPR before running such analyses.
- Track sector overlap guidance. Firms shipping AI inside medical devices, vehicles or industrial equipment should watch how the new coordination mechanism allocates obligations between the AI Act and product regulators.
