Verify Credential

Home/News

EU AI Act Digital Omnibus Enters Into Force — High-Risk Deadlines Deferred to 2027 and 2028

The EU's Digital Omnibus on AI entered into force on 27 July 2026, finalising a set of amendments to the AI Act that had been under negotiation since earlier this year. The headline change: the compliance timeline for high-risk AI systems has been pushed back substantially, giving organisations more runway — but not a reprieve from the obligations themselves.

What actually changed

Under the Omnibus, obligations for high-risk AI systems listed in Annex III — the category that explicitly covers AI used in employment, worker management and access to essential services — now apply from 2 December 2027, deferred from the original 2 August 2026 date. High-risk AI embedded in regulated physical products (machinery, toys, lifts and similar) moves to 2 August 2028. The Commission describes the package as "targeted simplification" rather than a weakening of core protections, and has paired the deferral with practical support measures: expanded regulatory sandboxes, an EU-level testing environment, and extended exemptions for small mid-cap companies alongside SMEs.

What did not change

Three things are easy to miss in headlines about "deadlines pushed back." First, Article 50 transparency obligations — the requirement to disclose when a person is interacting with an AI system — remain on schedule for 2 August 2026, unchanged. Second, the Article 5 prohibitions on unacceptable-risk AI, in force since February 2025, continue to apply, and the Omnibus adds a new one: a ban on AI systems that generate non-consensual intimate imagery or child sexual abuse material, taking effect 2 December 2026. Third, the AI Office's oversight powers over general-purpose AI models and large platforms have been strengthened, not reduced.

Why the deferral isn't a reprieve for workplace AI

It's a natural but risky reading to treat a ~16–24 month deadline extension as "the pressure is off." For organisations deploying AI in employment and worker-management contexts specifically — the Annex III use case named in the Act — the more accurate read is that the deadline moved, but the destination didn't: full high-risk compliance is still coming, transparency obligations arrive first regardless, and the intervening period is compliance-readiness time, not a pause. Building the internal governance, documentation and, critically, the qualified human oversight the Act requires takes longer than most organisations expect once they start.

We covered the Omnibus while it was still a Commission proposal in our earlier piece on the AI Act's high-risk rules; this is the confirmed, in-force outcome of that process.

Why this matters for AI-safety competence

Every version of this timeline — proposed, negotiated, now final — has kept the same underlying requirement in place: organisations need people who can actually design, evidence and exercise meaningful human oversight of AI in safety- and employment-relevant contexts. That is precisely the competence validated by credentials such as the Certified AI Safety Professional (AISP®) and Certified AI Risk Management Professional (AIRP®). A longer runway to comply is an opportunity to build that capability properly, not a reason to defer starting.

Validate your AI-safety competence

Explore the AI Safety Council's globally recognised, competency-based certifications.

Explore Certifications