Digital Omnibus; EU AI Act Timeline and Enforcement Delay
Definition
The Digital Omnibus is a European Commission simplification package, published on 19 November 2025, that amends several EU digital regulations through a single legislative vehicle. The package touched on the GDPR, ePrivacy, NIS2, and the Data Act alongside the EU AI Act. Its stated objective was to align implementation timelines with the availability of harmonized standards, reduce administrative burden for smaller organizations, and clarify how the AI Act interacts with existing sectoral regimes.
The instrument that amends the EU AI Act is the Digital Omnibus on AI, adopted as Regulation (EU) 2026/1744. It was published in the Official Journal of the European Union on 24 July 2026 and entered into force on 27 July 2026, six days before the AI Act’s original high-risk deadline.
The Digital Omnibus on AI is enacted law. It is not a proposal and its deadlines are not provisional.
How it was adopted
The Commission tabled the proposal on 19 November 2025, prompted by visible implementation delays: national competent authorities had not been designated in several Member States, and the harmonized standards needed for high-risk conformity assessment were not finalized.
A first political trilogue on 28 April 2026 ended without agreement. The institutions reached provisional agreement on 6 May 2026, confirmed by Member State representatives in the Council on 13 May 2026. The Council gave final approval on 29 June 2026.
The negotiation did not reopen the AI Act’s architecture. It adjusted timelines, scope boundaries, and administrative obligations.
EU AI Act timeline after the Digital Omnibus
Already applicable
- 2 February 2025. Prohibited practices (Article 5) and AI literacy (Article 4). Unaffected by the Digital Omnibus.
- 2 August 2025. General-purpose AI model obligations (Articles 51 to 55), governance bodies, penalties,s and notifying authorities. Unaffected by the Digital Omnibus.
- 2 August 2026. Article 50 transparency obligations, covering disclosure of AI interaction and labeling of synthetic content. This date did not move. Article 50(2) does not apply to systems already on the market at that date.
Still ahead
- 2 December 2026. Article 50(2) extends to systems already on the market before 2 August 2026. New prohibited practices apply, including a prohibition on AI-generated non-consensual intimate imagery.
- 2 August 2027. Member States must have at least one national AI regulatory sandbox in operation. Commission deadline for delegated acts on Annex I sectoral rules.
- 2 December 2027. High-risk obligations apply to Annex III stand-alone systems, deferred from 2 August 2026.
- 2 August 2028. High-risk obligations apply to Annex I embedded systems.
What changed beyond the dates
Two scope changes receive less attention than the deferral and have greater operational consequences.
Registration was retained. The Commission proposed removing the registration obligation for providers who self-assess a system as not high-risk, even if it operates in a listed high-risk use case. Negotiators rejected that. Those systems must still be registered in the EU database, under a simplified process.
Machinery products were carved out. AI embedded in products covered by the Machinery Regulation is exempt from direct Annex I classification under the AI Act. The Commission retains the power to impose AI-specific health and safety requirements on those products through delegated acts under the Machinery Regulation.
Common misreadings
“The EU AI Act has been delayed.” One chapter was deferred. Prohibited practices, AI literacy, GPAI obligations and Article 50 transparency all apply today.
“Nothing has changed.” The single largest near-term obligation, Annex III conformity assessment, moved by sixteen months. Planning assumptions built around 2 August 2026 are now wrong.
“We have until December 2027.” Only for systems classified as Annex III high-risk. An organization that has not classified its systems does not know which date applies.
Why it matters
The Digital Omnibus did not reduce the number of obligations under the EU AI Act. It changed their sequence.
That distinction determines what an organization should be doing now. The obligations that moved depend on external inputs: harmonized standards, conformity assessment bodies, and notified-body capacity. The obligations that stayed, and the work underneath all of them, depend on nothing external.
System inventory and classification is the clearest example. Finding every AI system in the organization, deciding which Annex III category each falls into, and keeping that inventory current as new systems ship takes the same effort in 2027 as it does today. It does not get easier when the standards are published, because it does not depend on them. It also informs every compliance decision that follows, including whether any deferred deadlines apply at all.
The constraint is classification, not the calendar.
How does Zertia assess the EU AI Act?
Zertia’s EU AI Act Assessment establishes where your AI systems sit under the regulation as it now reads, following Regulation (EU) 2026/1744.
We inventory the systems in production, classify each against Annex III and Annex I, and separate what binds today from what binds on 2 December 2027 and 2 August 2028. Systems you self-assess as not high-risk still carry a registration obligation; we identify those too.
The output is a per-system obligation map with dates, and the classification reasoning documented to the standard a supervisory authority or an accredited auditor will expect to see.
→ Zertia EU AI Act Conformity Assessments
Zertia’s EU AI Act Assessment maps your exposure and your roadmap.
Definitions that hold up under audit.
Does this term apply to your certification project? Let's talk 30 minutes, no commercial pressure.
