07.05.2026

6 Min. Read

On 7 May 2026, the Council, Parliament and Commission reached a provisional agreement on the Digital Omnibus to the AI Act, pushing back the strictest obligations for high-risk AI. Once the package is formally confirmed, the core requirements for application-layer high-risk systems will not take effect until 2 December 2027 instead of August 2026. For many organisations, that sounds like room to breathe. But that is precisely where the trap lies: anyone who freezes their governance work now is accumulating compliance debt that will come due with interest in 2027.

Key Takeaways

  • More time, same obligation. The high-risk requirements under Annex III have been moved from August 2026 to December 2027, and those under Annex I to August 2028.
  • New prohibitions too. The Omnibus adds to Article 5 a ban on AI-generated child sexual abuse material, which takes effect without a transition period as soon as the package enters into force. It is the high-risk deadline that has been postponed – not the AI Act as a whole.
  • The decision for leaders is binary. Freeze the programme and scramble to catch up in 2027 under time pressure – or use the extended deadline as a runway to build governance properly.

Related:Improvised AI Strategy: What the Supervisory Board Must Demand  /  BlackRock and Morgan Stanley Assess AI Governance

What the Omnibus Actually Shifts

The agreement is the first amendment to the AI Act since its adoption in 2024. It does not postpone the law as a whole, but specifically targets the deadlines for high-risk systems. That is an important distinction that tends to get lost in the initial sense of relief.

What is the AI Act Omnibus? The Digital Omnibus to the AI Act is an amendment package that EU institutions provisionally agreed on 7 May 2026. It shifts several compliance deadlines, allows the Commission to suspend duplicate requirements where existing sectoral rules already cover the same ground, and introduces new prohibitions. The provisional agreement still needs to be formally confirmed and published in the Official Journal.

Two groups are directly affected. Application-based high-risk systems under Annex III receive an additional 16 months – their obligations now take effect on 2 December 2027. Product-regulated systems under Annex I, such as those in medical devices or lifts, are pushed back by one year to 2 August 2028. The obligation on member states to establish national AI regulatory sandboxes is also delayed to August 2027.

AI Act Timeline After the Omnibus (subject to final confirmation)
07.05.2026
The Council, Parliament, and Commission reach a provisional agreement on the Digital Omnibus.
02.08.2027
National AI regulatory sandboxes become mandatory, delayed from August 2026.
02.12.2027
High-risk obligations under Annex III take effect, delayed from August 2026.
02.08.2028
High-risk obligations under Annex I (product-regulated systems) take effect, delayed from August 2027.

A Delay Is Not an All-Clear

The reflex to pause an AI governance programme when more time appears is understandable – and expensive. The requirements themselves do not change with the delay, only their deadline. Organisations that wait until late 2027 to tackle risk classification, documentation, and human oversight will face exactly the same workload, only under time pressure and in a market where consulting capacity is at a premium.

There is also a market-concentration effect to consider. When every company shares the same December 2027 deadline, they will ultimately compete for the same scarce auditing and advisory resources. Starting early sidesteps that bottleneck and means not negotiating at the most expensive possible moment.

Where the Omnibus Actually Tightens the Rules

The postponement is only one side of the package. On the other, the Omnibus introduces a new prohibition in Article 5 targeting AI-generated child sexual abuse material – one that takes effect immediately when the package enters into force, with no transition period. The list of banned practices is therefore getting longer, not shorter.

There is also a simplification with consequences: the Commission will be able to suspend duplicate requirements by implementing act where sectoral rules already cover the same subject matter. That reduces red tape, but it requires organisations to map their AI systems cleanly to the correct regulatory framework. Losing track of that mapping does not eliminate compliance obligations – it merely moves them to a different file.

What Leadership Must Decide Now

At its core, the decision is binary. Either the company freezes its compliance program and scrambles to catch up in 2027 under pressure – or it uses these 16 months as a structured head start. The second option is not only lower risk; it is usually cheaper.

Three steps are worth taking regardless of the deadline. First, the AI inventory: which systems in the organization actually fall into a high-risk category? Second, the gap analysis: where is documentation, risk management, and human oversight – as required by the AI Act – still missing? Third, accountability: AI governance belongs at the leadership level, not in a project that dies with the first budget round. The extended deadline is a gift for those who treat it as preparation time, and a trap for those who mistake it for a pause.

Frequently Asked Questions

When was the AI Act Omnibus agreed?

On 7 May 2026, the Council, Parliament, and Commission reached a provisional agreement. It is the first amendment to the AI Act since its adoption in 2024. Formal confirmation and publication in the Official Journal are still pending.

Which deadlines does the Omnibus actually shift?

High-risk obligations under Annex III move from August 2026 to 2 December 2027; those under Annex I shift from August 2027 to 2 August 2028. The requirement for national AI regulatory sandboxes is pushed back to August 2027.

Does the postponement mean the AI Act is suspended?

No. Only the high-risk deadlines have been deferred. The prohibition tier remains active, and the Omnibus even adds a new prohibition in Article 5. The fundamental requirements for high-risk AI are unchanged – only their deadline has moved.

Why is a wait-and-see approach risky for businesses?

Because the workload does not shrink – it merely shifts. Organizations that set up risk classification, documentation, and oversight only shortly before December 2027 will be working under time pressure and competing for scarce advisory capacity. Deferred obligations become compliance debt.

What should leadership do now?

Build an AI inventory, analyze gaps in documentation and oversight, and elevate responsibility for AI governance to the executive level. That turns the extended deadline into preparation time rather than a missed milestone.

Read more on Digital Chiefs

Digital ChiefsAI Agents: ROI or Pilot Graveyard?Digital ChiefsAutonomous AI: How CIOs Can Manage Black-Box RisksDigital ChiefsDGX Cost Trap: Power OPEX Div

More from the MBF Media Network

cloudmagazinPlatform Engineering for Compliance: IDPs Enforce NIS2 and DORA mybusinessfutureEU AI Act from August 2026: What SMEs Must Label Now securitytodaySelf-Replication: AI Agents Jump from 6 to 81 Percent

Image source: AI-generated (June 2026), C2PA certificate embedded in image

Share this article:

Also available in

More Articles

15.07.2026

Token-OPEX: Inference Controls, Not the Seat Budget

Angelika Beierlein

9 Min. read time Token costs aren’t a line item in SaaS contracts. They’re variable OPEX per workflow-and ...

Read Article
15.07.2026

Hardware Outperforms Software Deals – Rethinking Capital Expenditure Priorities

Benedikt Langer

9 Min. read time IBM reports a 7% decline in infrastructure for Q2, while distributed infrastructure ...

Read Article
13.07.2026

Sovereign AI: Responsibility Stays In-House

Eva Mickler

7 Min. Reading time Who brings an AI model into productive operation bears responsibility for its behavior, ...

Read Article
12.07.2026

Five Points Where Supply Chain Software Fails

Bernhard Liebl

6 Min. reading time Companies buy supply chain suites to combat master data chaos, media disruptions, ...

Read Article
12.07.2026

Managed Services: The Bill No One Is Footing

Angelika Beierlein

7 min read CIOs almost always compare managed services and in-house operations based solely on the nominal ...

Read Article
12.07.2026

When the factory hall and the data center become a network

Benedikt Langer

8 min read For decades, production was its own isolated world. Controls, sensors and machines ran on ...

Read Article
A magazine by Evernine Media GmbH