EU AI Act / Digital Omnibus
The EU's Digital Omnibus, approved by the Council on 29 June 2026, postponed the AI Act's high-risk conformity obligations. Standalone high-risk systems (Annex III) now have until 2 December 2027. AI embedded in already-regulated products (Annex I — medical devices, machinery) now has until 2 August 2028. The Article 50 transparency rules were not touched and still apply from 2 August 2026.
Last updated 15 August 2026
The Council of the EU gave final approval to the Digital Omnibus on 29 June 2026. It pushes back the AI Act's high-risk obligations by a significant margin: Annex III standalone systems move from 2 August 2026 to 2 December 2027, a 16-month extension. Annex I embedded systems move from 2 August 2027 to 2 August 2028, a 12-month extension. Nothing else in the Act was reopened by this change.
Source: Gibson Dunn; Secure Privacy.
Annex III lists specific standalone high-risk use cases: recruitment and employee management, creditworthiness assessment, biometric identification and categorisation, education and vocational training access, migration and border control, law enforcement, and administration of justice. If a product or system falls into one of these categories on its own — not as part of another regulated product — this is the deadline that applies.
Annex I covers AI that is a safety component of, or is itself, a product already regulated under EU product-safety law — most relevantly for our clients, medical devices and machinery. The extension gives an extra year, but it doesn't decouple the AI Act obligation from the underlying CE/UKCA conformity programme for the product itself. A device that's already mid-certification under MDR or the Machinery Regulation should fold this into the same technical file, not track it separately.
Source: aiactblog.nl; VerifyWise.
The Digital Omnibus postpones high-risk obligations only. Article 50's transparency rules — labelling AI-generated content, disclosing chatbot interactions — were left exactly where they were: in force from 2 August 2026. A product that has both a high-risk AI component and a transparency-triggering feature (e.g. a customer-facing chatbot) still has the transparency piece due this month, even while the high-risk conformity work has more runway.
The Council of the EU gave final approval to the Digital Omnibus on 29 June 2026. It postpones the AI Act's high-risk conformity obligations: standalone high-risk systems under Annex III move from 2 August 2026 to 2 December 2027 (a 16-month extension), and AI that is a safety component of, or is itself, an already-regulated product under Annex I moves from 2 August 2027 to 2 August 2028 (a 12-month extension).
Yes — Annex I covers AI embedded in products already regulated under EU product-safety law, including medical devices and machinery. Those high-risk AI obligations now land on 2 August 2028 rather than 2 August 2027, but they still have to be worked into the same CE/UKCA conformity programme, not treated as a separate deadline that can slip.
Annex III lists standalone high-risk AI use cases: recruitment and employee management, creditworthiness assessment, biometric identification and categorisation, education and vocational training access, migration and border control, law enforcement, and administration of justice. These now have until 2 December 2027 to comply.
Yes. The Digital Omnibus postpones the high-risk obligations only — it leaves the Article 50 transparency rules (AI-generated content labelling, chatbot disclosure) exactly where they were: 2 August 2026, unchanged.
The extra runway is real, but it's runway for a programme that still has to be built — mapping which of your products fall under Annex I versus Annex III, folding high-risk AI conformity into an existing CE/UKCA technical file rather than running it as a separate track, and keeping the unmoved Article 50 transparency items on their original date. We scope the gap and manage the programme end to end.
Book a scoping call