EU AI Act / Digital Omnibus

The AI Act's high-risk deadlines just moved — 2 December 2027 and 2 August 2028

The EU's Digital Omnibus, approved by the Council on 29 June 2026, postponed the AI Act's high-risk conformity obligations. Standalone high-risk systems (Annex III) now have until 2 December 2027. AI embedded in already-regulated products (Annex I — medical devices, machinery) now has until 2 August 2028. The Article 50 transparency rules were not touched and still apply from 2 August 2026.

Last updated 15 August 2026

days to 2 Dec 2027 — Annex III standalone high-risk systems
days to 2 Aug 2028 — Annex I embedded high-risk AI
UnchangedArticle 50 transparency rules — still 2 Aug 2026

What the Digital Omnibus changed

The Council of the EU gave final approval to the Digital Omnibus on 29 June 2026. It pushes back the AI Act's high-risk obligations by a significant margin: Annex III standalone systems move from 2 August 2026 to 2 December 2027, a 16-month extension. Annex I embedded systems move from 2 August 2027 to 2 August 2028, a 12-month extension. Nothing else in the Act was reopened by this change.

Source: Gibson Dunn; Secure Privacy.

Annex III — standalone high-risk systems, 2 December 2027

Annex III lists specific standalone high-risk use cases: recruitment and employee management, creditworthiness assessment, biometric identification and categorisation, education and vocational training access, migration and border control, law enforcement, and administration of justice. If a product or system falls into one of these categories on its own — not as part of another regulated product — this is the deadline that applies.

Annex I — AI embedded in a regulated product, 2 August 2028

Annex I covers AI that is a safety component of, or is itself, a product already regulated under EU product-safety law — most relevantly for our clients, medical devices and machinery. The extension gives an extra year, but it doesn't decouple the AI Act obligation from the underlying CE/UKCA conformity programme for the product itself. A device that's already mid-certification under MDR or the Machinery Regulation should fold this into the same technical file, not track it separately.

Source: aiactblog.nl; VerifyWise.

What didn't move

The Digital Omnibus postpones high-risk obligations only. Article 50's transparency rules — labelling AI-generated content, disclosing chatbot interactions — were left exactly where they were: in force from 2 August 2026. A product that has both a high-risk AI component and a transparency-triggering feature (e.g. a customer-facing chatbot) still has the transparency piece due this month, even while the high-risk conformity work has more runway.

Questions

What did the Digital Omnibus change?

The Council of the EU gave final approval to the Digital Omnibus on 29 June 2026. It postpones the AI Act's high-risk conformity obligations: standalone high-risk systems under Annex III move from 2 August 2026 to 2 December 2027 (a 16-month extension), and AI that is a safety component of, or is itself, an already-regulated product under Annex I moves from 2 August 2027 to 2 August 2028 (a 12-month extension).

Does this affect our medical-device or machinery clients?

Yes — Annex I covers AI embedded in products already regulated under EU product-safety law, including medical devices and machinery. Those high-risk AI obligations now land on 2 August 2028 rather than 2 August 2027, but they still have to be worked into the same CE/UKCA conformity programme, not treated as a separate deadline that can slip.

What is Annex III and who does it cover?

Annex III lists standalone high-risk AI use cases: recruitment and employee management, creditworthiness assessment, biometric identification and categorisation, education and vocational training access, migration and border control, law enforcement, and administration of justice. These now have until 2 December 2027 to comply.

Has anything stayed on the original schedule?

Yes. The Digital Omnibus postpones the high-risk obligations only — it leaves the Article 50 transparency rules (AI-generated content labelling, chatbot disclosure) exactly where they were: 2 August 2026, unchanged.

Where we fit

The extra runway is real, but it's runway for a programme that still has to be built — mapping which of your products fall under Annex I versus Annex III, folding high-risk AI conformity into an existing CE/UKCA technical file rather than running it as a separate track, and keeping the unmoved Article 50 transparency items on their original date. We scope the gap and manage the programme end to end.

Book a scoping call