EU AI Act timeline pushed back as Omnibus delays high-risk compliance to 2027 and 2028

Image / fpf.org
The European Union has changed the clock on one of its most consequential technology rules, giving companies more time before the toughest AI obligations take effect — but also adding new bans, broader data-processing powers for bias work, and stronger central oversight.
What changed in the AI Act timeline
The European Union’s AI Act is no longer moving on the original schedule for high-risk systems. According to the Future of Privacy Forum, the recently adopted AI Omnibus pushes most compliance obligations for high-risk AI systems to 2 December 2027 for systems listed in Annex III and to August 2028 for systems listed in Annex I. Those deadlines had previously been set to begin on 2 August 2026.
That shift matters for companies building, deploying, importing, or integrating AI in the EU, because the high-risk tier carries the heaviest operational burden: technical documentation, risk management, data governance, logging, human oversight, accuracy and cybersecurity requirements, and post-market monitoring. The delay gives organizations more runway to build compliance programs, but it does not erase the obligations themselves.
The AI Omnibus was published in the Official Journal of the EU on 24 July 2026, after the European Parliament adopted the agreed text on 16 June 2026 and the Council of the European Union adopted it on 29 June 2026. The European Commission had proposed the Omnibus in November 2025, saying the goal was to reduce administrative burden and provide more time to comply.
For technology leaders, the practical message is straightforward: the AI Act is still live, but its hardest deadlines have moved.
What is already in force
The AI Act entered into force in August 2024, and several parts are already applying.
That includes the rules on prohibited AI practices, the AI literacy obligation, and the duties for providers of general-purpose AI models. The law is being rolled out in phases, so the compliance picture is not all at once. Some companies are already inside the regime, while others are waiting for later deadlines.
The Future of Privacy Forum notes that the first institutional deadlines began quickly after adoption. By November 2024, Member States were required to identify the public authorities responsible for supervising or enforcing the rules protecting fundamental rights, publish the list, and notify the European Commission and other Member States. In practice, this has not been uniform across the EU, with national implementation moving at different speeds.
The next governance milestone came on 2 August 2025, when Member States were required to designate at least one market surveillance authority and at least one notifying authority. The FPF notes that some countries, including Italy and Ireland, have established market surveillance authorities and communicated their Single Points of Contact to the European Commission, but several Member States still have not appointed national competent authorities for supervision of certain AI systems.
That uneven setup matters because the law is only as workable as the authorities that enforce it. Companies operating across multiple EU markets may face different levels of readiness depending on the country.
New rules added by the Omnibus
The AI Omnibus does more than delay deadlines. It also changes the substance of the law.
One of the changes is a new prohibited AI practice covering systems that generate child sexual abuse material and non-consensual intimate material. That is a clear expansion of the AI Act’s ban list and signals a stronger line on abusive synthetic content.
The Omnibus also revises the AI literacy obligation. Under the updated language in Article 4, providers and deployers are no longer required to ensure a “sufficient level” of AI literacy. Instead, they must support the development of AI literacy for staff and other people dealing with the operation and use of an AI system.
That wording matters for compliance teams. “Ensure” suggests a harder obligation and a more direct duty to reach a particular state of readiness. “Support the development” is softer, but still leaves organizations with a concrete expectation to train relevant personnel and build understanding around AI use.
The law also broadens the legal basis for processing special category personal data for bias detection and correction. FPF says this is now expanded to providers and deployers of all AI systems and models, rather than only high-risk AI. For companies, that can create more room to test and correct discriminatory outputs, but it also means the privacy and governance rules around sensitive data processing need careful attention.
Why the delay is not a free pass
The most important commercial takeaway is that the delay buys time, not immunity.
Most of the high-risk obligations have been postponed to 2 December 2027, with Annex I obligations moving to August 2028. But organizations should not assume the extra time means the law is on hold. The AI Act has already entered into force, and several parts are already applicable. Companies that wait until the new deadlines may find themselves scrambling to classify systems, map suppliers, update documentation, and put governance controls in place.
This is especially relevant for firms that sell into Europe from outside the EU. If a product is likely to be categorized as high-risk, the longer timeline should be used to plan, not to pause. The lead time will still be consumed by model testing, risk assessments, internal accountability mapping, and procurement changes.
The AI Omnibus also expands the powers of the AI Office. FPF says the Office will have exclusive competence over systems built on general-purpose AI models not only when both the system and the model are developed by the same provider, but also when they are developed by providers within the same undertaking. That broadens the reach of centralized oversight and may matter for multinational groups with connected product lines.
Who gets relief, and who does not
The Omnibus reflects a competitiveness and innovation agenda. FPF says it ensures that certain exemptions, including simplified technical documentation, apply to small and medium-sized companies as well as start-ups and small mid-caps.
That helps smaller vendors and emerging AI firms, which often have the least compliance capacity. But the relief is targeted. It does not eliminate core obligations, and it does not apply equally to every market participant.
For enterprise buyers, this creates a familiar tension: suppliers may face lighter paperwork in some cases, but procurement teams still need evidence that the systems they buy or embed are compliant. Documentation may be simpler, but diligence still matters.
For regulated industries, the delays may also change rollout plans. Organizations that were preparing to launch or upgrade high-risk AI products before August 2026 now have a longer window. But internal governance should still move ahead on classification, use-case mapping, and contractual controls, because the future compliance burden has merely been deferred.
What compliance teams should do now
The new timeline gives businesses room, but not room to drift.
Teams should first determine whether any current or planned systems fall into the high-risk categories affected by the new deadlines. They should then check whether those systems are listed under Annex III or Annex I, because the new compliance dates differ.
Next, companies should review whether they are already subject to the parts of the AI Act that are in force now, including prohibited practices, AI literacy, and general-purpose AI model obligations. Those rules are not delayed by the Omnibus.
They should also map whether any use of sensitive personal data for bias detection or correction could now rely on the expanded legal basis, and make sure privacy controls, access restrictions, and accountability records are updated accordingly.
Finally, multinational organizations should watch the national enforcement landscape. Member States are still filling in supervisory roles, and enforcement readiness may vary. That means the compliance burden is not just legal; it is operational and geographic.
The EU has given the AI sector more time, but it has also made the rulebook more detailed. For companies that treat the delay as a planning window rather than a reprieve, the new schedule may be manageable. For those that do not, the extra months will disappear quickly.
- The AI Act implementation timeline: What changes under the AI Omnibus?fpf.org / Mainstream / Published JUL 28, 2026 / Accessed JUL 30, 2026