July 20, 2026·5 min read

EU AI Act 2026: What the May Omnibus Actually Delayed, and What Didn't

The May 2026 Digital Omnibus pushed the EU AI Act's high-risk obligations for credit scoring, insurance, and HR out to December 2027. It did not move the Article 50 transparency duties or the GPAI systemic-risk rules, both of which still land on August 2, 2026. Here is the precise split.

EU AI ActAI RegulationAI ComplianceGPAIAI TransparencyHigh-Risk AI
EU AI Act 2026: What the May Omnibus Actually Delayed, and What Didn't

A product team reads a headline in May: the EU AI Act's high-risk deadline just slipped sixteen months, to December 2027. They close the tab. The compliance thing they'd been half-dreading is now a 2027 problem, and there's a release to ship.

They just walked past the one obligation in the Act that actually applies to them, and it's still due August 2, 2026.

A lot of content still circulating gets this wrong in one of two directions. Some of it never got the memo and still lists August 2, 2026 as the high-risk deadline. More of it got the memo and over-read it, treating "deadline delayed" as "the AI Act is on hold." Both are wrong, and the gap between them is where the actual obligations live. Here is what moved and what didn't.

What the omnibus actually delayed

The Digital Omnibus on AI is real and the delay is real. After a failed trilogue on April 28, the EU institutions reached a provisional political agreement on May 6, 2026, the Council confirmed it days later, the European Parliament endorsed it on June 16, and the Council gave final adoption on June 29. It is adopted law now, heading into the Official Journal, not a rumor or a proposal.

What it moved is specific. The obligations for standalone Annex III high-risk systems, the use-case list that includes credit scoring, insurance underwriting, HR and recruitment, biometric identification, and law enforcement, education, and border control, shifted from August 2, 2026 to December 2, 2027. That is a sixteen-month deferral. High-risk AI embedded in regulated products under Annex I moved further out, to August 2, 2028.

If you're building a credit-decision agent or an underwriting model for the EU market, that is genuine breathing room on the most expensive compliance work in the Act. The relief is real. It is also narrower than the headline makes it sound.

What the omnibus left exactly where it was

The Act was never a single deadline. It's a stack of separate obligations on separate clocks, and the omnibus moved some of them while leaving others untouched.

Think of the paperwork on a big work truck you actually depend on. The emissions-test extension the state just granted doesn't push back your registration, your insurance renewal, or your annual safety inspection. Those are separate dates on separate clocks, and hearing that one of them moved tells you nothing about the others.

Two of the other clocks are still ticking toward August 2, 2026.

The first is Article 50, the transparency and disclosure obligations, and it's the single most broadly applicable rule in the entire Act. It requires you to tell users when they're interacting with an AI system, to mark AI-generated content as machine-readable, and to label deepfakes and synthetic media. It doesn't care whether your system is high-risk. If you deploy a user-facing chatbot to people in the EU, or generate content for EU audiences in a professional context, this applies to you, and it was not deferred by a single day.

The second clock is general-purpose AI. The obligations on GPAI providers under Articles 51 through 56 took effect back on August 2, 2025, and the omnibus left them alone. For models assessed to carry systemic risk, that includes adversarial testing and model evaluation, plus incident tracking and reporting. If your product is built on, or fine-tunes, a frontier model in that category, none of the requirements around evaluating and stress-testing it moved either.

Obligation Applies from Moved by the omnibus?
Prohibited practices (Article 5) Feb 2, 2025 No
GPAI obligations, incl. systemic-risk testing (Arts. 51-56) Aug 2, 2025 No
Transparency and disclosure (Article 50) Aug 2, 2026 No
Standalone high-risk: credit scoring, insurance, HR (Annex III) Dec 2, 2027 (was Aug 2, 2026) Yes, +16 months
Embedded high-risk in regulated products (Annex I) Aug 2, 2028 Yes

The European Commission's own AI Act page tracks these dates if you want the primary source rather than a summary of one.

What to actually do, now versus later

The split maps cleanly onto two different kinds of work.

The August 2, 2026 obligations are mostly product changes, and they're small. Article 50 disclosure is a UI and provenance problem: a visible "you're talking to an AI" state, machine-readable marking on generated media, deepfake labeling. That's an engineering ticket, not a legal binder, and it's the kind of thing that's genuinely fast to do on purpose and genuinely embarrassing to get caught not doing. If you touch frontier models flagged for systemic risk, the evaluation and incident-reporting expectations are ongoing and also didn't move.

The December 2027 obligations are the heavy build: the risk management system, data governance, logging and traceability, human oversight, and third-party conformity assessment that a high-risk credit or insurance system needs. The extension is real runway. It is also runway for work that takes the better part of two years to do properly, which is the whole reason it's expensive. "Delayed to 2027" is not "start in 2027." A conformity assessment you begin the month before it's due is a conformity assessment you fail.

The mistake worth not making

The deferral is good news for exactly the teams building high-risk systems, and it's good news precisely because that work is enormous. Nothing here argues the extension was a mistake or that you should pretend it didn't happen.

The mistake is a category error: reading a delay on the most expensive obligation as a delay on all of them, and quietly standing down a program that had a live disclosure requirement due next month. The Act didn't get postponed. The costliest slice of it did, and the cheapest, broadest slice, the one that applies to almost everyone shipping AI into the EU, kept its original date. The only real question is whether you read that fine print before or after someone asks why your chatbot never disclosed it was one.

Working on a similar infrastructure challenge?

We embed with AI teams to harden agent systems and build production data platforms. Tell us what you're building.

Start a Conversation →