The high-risk deadline just moved: the AI Act omnibus, decoded
The EU's Digital Omnibus on AI is final: high-risk obligations slip from August 2026 to December 2027 and beyond. What changes, what does not, and why stopping your governance build would be the wrong lesson.
TL;DR
- The EU's Digital Omnibus on AI is now final: the European Parliament adopted the text on 16 June and the Council on 29 June 2026, with entry into force this month.
- The AI Act's high-risk obligations, originally applying from 2 August 2026, are deferred to 2 December 2027 for stand-alone Annex III systems and to 2 August 2028 for AI embedded in regulated products.
- The reprieve is about the EU's own readiness, not a change of destination. The obligations themselves survive largely intact.
In our June note on AI governance we wrote that the EU AI Act's consequential stage would arrive on 2 August 2026. That date has now moved. After a provisional agreement in May, the EU institutions adopted the final Digital Omnibus on AI in late June, and with it the most watched compliance deadline in European technology law slipped by sixteen months or more.
What actually changed
| Obligation | Old date | New date |
|---|---|---|
| High-risk AI systems, stand-alone (Annex III) | 2 August 2026 | 2 December 2027 |
| High-risk AI embedded in regulated products (Annex I) | 2 August 2027 | 2 August 2028 |
| GPAI obligations, governance, penalties (in force since 2 August 2025) | unchanged | unchanged |
The stated rationale is capacity, not conviction. Member states were behind on designating competent authorities, and the harmonised standards companies need in order to demonstrate conformity were not finished. Legislators chose to move the deadline rather than enforce rules nobody could yet comply with, alongside targeted simplification of documentation duties and some adjusted prohibitions.
The wrong lesson and the right one
The tempting conclusion is that AI governance just became next year's problem. We would argue the opposite, for three reasons.
First, the destination is unchanged. The high-risk requirements, technical documentation, data governance, human oversight, logging, and monitoring, survive with their substance intact. A sixteen-month deferral of an operating capability you have not started building is not generous.
Second, the market is not waiting. Enterprise buyers, insurers, and auditors have spent two years writing AI assurance into procurement and contracting. Those private-law deadlines did not move on 29 June, and for most Swiss suppliers they bind earlier and harder than the regulation does.
Third, for Swiss companies specifically, the calculus we described in June still holds: the Act's extraterritorial reach makes EU rules the effective floor for anyone serving EU clients, while Switzerland's own consultation draft on AI regulation is still expected by the end of 2026. Firms mid-way through building an AI inventory, risk classification, and oversight process now get something rare: enough runway to finish properly instead of certifying in a panic.
What to do with the extra time
- Keep the governance build on schedule and re-baseline it against the omnibus text, since documentation duties were simplified in places.
- Use the runway to move from paper compliance to operating capability: run the oversight process on real systems before anyone requires it.
- Watch the standards work. Harmonised standards will define what "good" looks like in practice, and arriving after they settle is a competitive disadvantage.
Deadlines move. The direction of travel has not, and neither has what your clients will ask you to prove.
Related reading
- The Digital Omnibus: proposed deferral of high-risk AI obligations (DLA Piper)
- AI governance after the rulebook: what 2 August 2026 means
Source: EU AI Act Omnibus Agreement — Postponed High-Risk Deadlines and Other Key Changes, Gibson Dunn.