Summary
- The AI Omnibus moves important high-risk AI obligations into December 2027 and August 2028.
- Transparency, general-purpose AI, and other parts of the Act continue on separate timetables.
- Additional preparation time leaves system inventories, contracts, documentation, training, and oversight firmly on the agenda.
European businesses have gained more time to prepare for some of the AI Act’s most demanding requirements, although the revised timetable does not amount to a general pause in the bloc’s regulation of artificial intelligence.
Regulation (EU) 2026/1744, commonly described as the AI Omnibus, entered into force on 27 July after publication in the EU’s Official Journal. High-risk systems used in fields including employment, education, critical infrastructure, migration, and biometrics will now face the relevant obligations from 2 December 2027, while AI embedded in regulated products is due to follow on 2 August 2028.
Companies therefore have longer to establish risk management, data governance, logging, technical documentation, human oversight, and post-market monitoring. However, several other parts of the AI Act retain different schedules, so an organisation that interprets the amendment as a blanket delay could still miss nearer obligations covering general-purpose models, transparency, or synthetic content.
The European Commission says the revised timetable is intended to ensure that high-risk requirements apply when businesses have access to supporting standards, guidance, and conformity assessment arrangements. The final regulation is available through EUR-Lex.
Implementation had begun without the full toolkit
Much of the pressure for delay came from a practical difficulty rather than a simple objection to regulation. Businesses were being asked to prepare for detailed compliance duties while several technical standards, assessment processes, and sector-specific interpretations remained incomplete, leaving buyers and suppliers uncertain about what regulators would regard as adequate evidence.
Procurement exposes that uncertainty quickly because responsibility can be spread across several organisations. A bank buying credit software, an employer acquiring a recruitment platform, or a public authority procuring biometric technology must identify which party acts as provider, importer, distributor, or deployer, and which duties follow each role.
Contracts also need to establish who supplies logs, explains model changes, maintains technical documentation, investigates incidents, and supports regulatory enquiries. Where a product relies on a general-purpose model supplied by another company, the immediate vendor may not control every component needed to answer those questions.
The longer timetable gives buyers and vendors more room to settle those arrangements, yet it also extends the period during which systems will be deployed under an evolving rulebook. Flexible audit rights, change controls, access to evidence, and clear exit provisions will consequently remain important in AI contracts signed before the high-risk regime applies in full.
Changes to the Act’s AI literacy language also reduce some uncertainty without eliminating employers’ responsibilities. Providers and deployers are expected to take measures supporting an appropriate level of knowledge among staff and others operating systems on their behalf, although organisations do not have to guarantee that every individual reaches a prescribed standard.
That more proportionate wording still leaves employers responsible for matching training and supervision to the work being undertaken. Someone using AI to reorganise an internal document presents a different risk from an employee relying on a model during recruitment, professional advice, safety decisions, or access to public services.
The highest-risk tier covers only part of the market
Although the high-risk timetable dominates discussion, most business software will not fall into that classification. Routine forecasting, spam filtering, office productivity, and many customer service systems may sit in lower-risk categories, while remaining subject to data protection, employment, consumer, sectoral, and contractual requirements.
Generative AI deployments must also be separated into their different regulatory layers. Rules affecting general-purpose AI models began applying earlier, while transparency provisions governing interaction with machines and identifiable synthetic output continue towards their own application dates.
Under the amended transitional arrangements, providers of some systems placed on the market before 2 August 2026 have until 2 December 2026 to make relevant synthetic output machine-readable. Companies producing or distributing automated content therefore have a nearer implementation question even as the high-risk deadlines move further away.
The Omnibus also extends some simplified requirements previously available to small and medium-sized businesses to small mid-cap companies. A larger group of European suppliers may benefit from more proportionate documentation formats, although a lighter process does not remove the underlying need to understand risks, retain records, and cooperate with customers or authorities.
Public authorities face a longer transition for certain existing high-risk systems, extending to August 2030 in defined circumstances. Long procurement cycles reduce the comfort that date provides because systems acquired now may remain operational when the full requirements arrive, while replacing software that cannot produce the necessary evidence could become expensive and disruptive.
Governance cannot be reconstructed afterwards
Organisations that have already begun AI Act programmes can use the revised timetable to replace hurried legal checklists with controls that follow systems throughout their working lives. An inventory recording where AI is used, which decisions it influences, what data it handles, who owns it, and how failures are escalated remains useful regardless of the final application date.
Testing and documentation are similarly difficult to create retrospectively. Where software affects recruitment, safety, regulated decisions, or access to services, evidence about performance, bias, oversight, and change management needs to be collected while the system is designed and operated.
A deadline extension cannot recreate logs that were never retained, explain a supplier model whose documentation was never obtained, or identify training data after a contractual relationship has ended. Delayed compliance work can therefore increase future cost even where the immediate enforcement risk has fallen.
The revised timetable gives Europe’s AI market more room to prepare, but the direction of the legislation remains unchanged. Regulation is moving from broad principles into product governance, market surveillance, and enforceable operating controls, while systems entering production during the transition will still have to satisfy the rules that follow.






