← Back to Blog
AI ActDigital OmnibusHigh-Risk AIComplianceDACHGDPR

The AI Act Delay Is Not a Reprieve: What the Digital Omnibus Actually Changed for High-Risk AI

The Digital Omnibus is now law. It defers the core Chapter III high-risk obligations to December 2027 and August 2028 — but the prohibitions, GPAI rules, Article 50 transparency duties and the GDPR are all still live. Here is what a DACH CISO/DPO must do before treating the delay as breathing room.

DS
Dr. Sait Yalazay, PhD / LLM / MBA
CISO — DPO — Author | CISM — CIPP — AAISM — LA 27001, 27701, 22301, 42001
Architect of Automated Compliance Systems for NIS2, GDPR, ISMS, BCM, DORA, Tisax & AI Act

Published on August 3, 2026

A DACH manufacturer has an AI-based CV-screening tool scheduled to go live in autumn 2026. In November 2025 the compliance lead built a plan around one date: 2 August 2026, when the AI Act’s high-risk obligations were set to bite1. Then the headlines arrived — “EU delays high-risk AI rules to 2027” — and the project Slack lit up: “Great, we have another year. Park the AI Act work until Q1.”

That instinct is the single most expensive mistake an organisation can make this summer. As of 27 July 2026 the Digital Omnibus on AI is law, and it does move the high-risk dates2. But a deferral of some obligations is not a reprieve from the regulation — and in a few places the Act actually became stricter. This article separates what changed from what didn’t, and translates it into what a CISO/DPO in Germany, Austria or Switzerland should be doing right now.

Key Takeaways

  • It is now law. Regulation (EU) 2026/1744 of 8 July 2026 was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. The deferral is no longer a proposal or a provisional political agreement2.
  • The deferral is narrower than the headlines. What moved is Chapter III, Sections 1, 2 and 3 (with the exception of Article 6(5)): stand-alone Annex III systems now apply from 2 December 2027, Annex I product-embedded systems from 2 August 2028. Chapter III, Section 4 has applied since 2 August 2025 and is unaffected — as is the rest of the Act2.
  • The prohibitions (Art. 5), the GPAI obligations, the AI-literacy duty and the Article 50 transparency rules are untouched and live — and Art. 5 was expanded with new prohibitions applying from 2 December 20263.
  • Article 50 arrived on 2 August 2026 as planned, allocated by role: providers owe the interaction disclosure and the machine-readable marking of synthetic output; deployers owe disclosure for emotion recognition, biometric categorisation, deepfakes and public-interest text. Only the provider’s Art. 50(2) marking duty for systems already on the market gets a transition to 2 December 20264.
  • GDPR is a separate legal track. Your DPIA obligations under Article 35 did not move one day5. NIS2, DORA and sector law are likewise unaffected.
  • The deferral exists because the standards and conformity infrastructure aren’t ready — not because your compliance programme is. Building one takes 12–18 months, which is roughly the headroom the delay provides6.

What actually changed

The European Commission tabled the Digital Omnibus on AI on 19 November 2025, the first substantive amendment to the AI Act since its entry into force on 1 August 20247. After a first trilogue round on 28 April 2026 collapsed, negotiators reached a provisional political agreement in early May, announced by the Council presidency on 7 May 2026; the European Parliament’s IMCO and LIBE committees endorsed it on 2 June 2026 and the plenary gave final approval on 16 June 2026. The text was published in the Official Journal on 24 July 2026 as Regulation (EU) 2026/1744 and entered into force on 27 July 20268.

The headline is the timeline. The Commission’s original proposal used a conditional “stop-the-clock” trigger — high-risk rules would apply once standards and support tools were confirmed ready. The adopted text dropped that mechanism in favour of two fixed dates, and it did so by replacing a single point of Article 1139:

ProvisionOriginal dateNew date (Omnibus)Status
Chapter III, Sections 1–3 for Annex III stand-alone high-risk systems (recruitment, credit scoring, education, law enforcement, border control)2 Aug 20262 Dec 2027Deferred
Chapter III, Sections 1–3 for Annex I product-embedded high-risk systems (medical devices, machinery, vehicles)2 Aug 20272 Aug 2028Deferred
Chapter III, Section 4 (transparency for certain high-risk systems)2 Aug 2025unchangedLive
Art. 50 transparency duties2 Aug 20262 Aug 2026 (unchanged)Live — 4-month transition only for providers’ machine-readable marking of pre-existing generative systems
Art. 5 prohibitions; new prohibitions added by the Omnibus2 Feb 2025 / newIn force; new prohibitions apply from 2 Dec 2026Live / stricter
GPAI model obligations2 Aug 20252 Aug 2025 (unchanged)Live
Commission enforcement powers over GPAI (Chapter V)2 Aug 20262 Aug 2026 (unchanged)Live

Around this core, the Omnibus bundled targeted changes: the AI-literacy duty under Article 4 was softened from guaranteeing a level of literacy to supporting its development; the legal basis for processing special-category data for bias detection was extended under a strict necessity test; the deadline for Member States to stand up regulatory sandboxes slipped to 2 August 2027; a new Article 111(4) gave providers of generative systems already on the market until 2 December 2026 for machine-readable marking; and Articles 102 to 110 were made applicable from 27 July 202610.

Why it is not a reprieve

First: what moved is narrower than “high-risk obligations.” The amended Article 113 defers Chapter III, Sections 1, 2 and 3 — classification, the requirements for high-risk systems, and the obligations of providers and deployers — with Article 6(5) expressly excepted. Section 4 of the same chapter has applied since 2 August 2025. Reading the change as “the high-risk regime is off until 2027” is how organisations end up missing the parts that never left2.

Second: the live obligations never moved. The prohibitions in Article 5 have applied since 2 February 2025, and the Omnibus adds to them, with the new prohibitions applying from 2 December 20263. GPAI obligations have applied since 2 August 2025, and the Commission’s enforcement powers over GPAI model providers became applicable on 2 August 2026 — a date the Omnibus did not touch, which we take apart in The Date That Did Not Move. And the Article 50 transparency duties arrived on 2 August 2026 as scheduled.

That last point deserves precision, because it is the one most often garbled. Article 50 does not impose one duty on everyone. Providers of systems intended to interact directly with natural persons must design them so people are informed they are dealing with an AI system (Art. 50(1)). Providers of systems generating synthetic audio, image, video or text must mark the output in a machine-readable format, detectable as artificially generated or manipulated (Art. 50(2)) — watermarking is one technique, not the legal standard. Deployers owe disclosure only in specified cases: emotion recognition and biometric categorisation (Art. 50(3)), deepfakes, and AI-generated text published to inform the public on matters of public interest (Art. 50(4)). The new Article 111(4) transition to 2 December 2026 applies solely to the provider’s Art. 50(2) marking duty for generative systems placed on the market before 2 August 2026 — it does not postpone any deployer duty4. What that means, step by step, for an ordinary organisation — inventory, role, notice, publication check, evidence — is set out in Article 50 Implementation Strategy.

Third: GDPR is a parallel universe. Nothing in the Omnibus touches the GDPR. If your system processes personal data and is likely to result in a high risk to natural persons, your Data Protection Impact Assessment obligation under Article 35 is exactly where it was5. For high-risk AI used in credit scoring, insurance pricing or public services, the AI Act’s Fundamental Rights Impact Assessment (FRIA) layers on top of the DPIA — and the smart move is to build the two as one unified assessment now, while you have time, rather than under deadline pressure in 2027. (We mapped exactly how these two instruments interlock in DPIA vs. FRIA.) NIS2, DORA and TISAX obligations run on their own clocks and are unaffected by any of this.

Fourth: the delay is about their readiness, not yours. The co-legislators were explicit that the postponement reflects the fact that the harmonised standards, national competent authorities and conformity-assessment tooling needed to make high-risk obligations operable were not ready on the original timeline6. That is a statement about the regulatory infrastructure — not a verdict that organisations are over-prepared. Building a high-risk AI compliance programme — data governance, a risk-management system, technical documentation, logging, human oversight, post-market monitoring and a conformity assessment — is 12 to 18 months of work for a single system. The extra months are the runway, not the holiday.

What a DACH CISO/DPO should do this quarter

A note on scope before the actions: Germany and Austria are Member States, so the Regulation applies directly. A Swiss organisation is not covered merely by being in the DACH region — it falls within scope only where Article 2 is engaged, typically by placing an AI system on the Union market, putting one into service in the Union, or where the output is used in the Union11.

Treat 2 December 2027 as the date by which the programme must be operating, then work backwards. Three concrete moves:

Inventory first. Build or refresh your AI system register, classify each system against Annex III, and record for each one whether you act as provider, downstream provider or deployer — most organisations underestimate how many internal tools (HR screening, credit decisioning, access control) already fall in scope, and almost all of them under-record the role. Second, start the assessment layer that did not move: run DPIAs now for any AI touching personal data, and where FRIA applies, draft it as the same unified document. Third, close the 2 August 2026 gaps that are genuinely live — the Article 50 duties that attach to your role, the literacy programme under Article 4, and a check that none of your generative tooling drifts into the expanded Article 5 prohibitions before they apply on 2 December 2026.

The organisations that will struggle in 2027 are the ones that read “delay” as “stop.” The Act’s architecture — risk tiers, governance, conformity assessment, penalties — is fully intact12. The clock didn’t stop. It just told you how much time you have to do the work properly.

A deferral of the deadline is not a dismissal of the duty. Use the runway — don’t park on it.

What’s the one Annex III system in your estate you can’t yet prove is compliant? That’s where the next sixteen months should start.


  1. Regulation (EU) 2024/1689 (Artificial Intelligence Act), Article 113. High-risk obligations for Annex III systems were originally set to apply 24 months after entry into force, i.e. from 2 August 2026; Annex I product-embedded systems from 2 August 2027. Official Journal text

  2. Regulation (EU) 2026/1744 of 8 July 2026 (Digital Omnibus on AI), published in the Official Journal on 24 July 2026, in force 27 July 2026. It replaces Article 113, third paragraph, point (c) of the AI Act so that “Chapter III, Sections 1, 2, and 3, with the exception of Article 6(5), shall apply from: (i) 2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III; and (ii) 2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I”, and adds “(d) Articles 102 to 110 shall apply from 27 July 2026”. Chapter III, Section 4 is unaffected. Regulation (EU) 2026/1744, OJ text 2 3 4

  3. AI Act, Article 5 (prohibited practices), applicable since 2 February 2025. The Omnibus inserts further prohibited practices into Article 5, which apply from 2 December 2026 under the amended Article 113, third paragraph, point (a). Sources: Regulation (EU) 2026/1744 · Inside Privacy (Covington), EU AI Act Update: Timeline Relief, Targeted Simplification, and New Prohibitions 2

  4. AI Act, Article 50 allocates transparency duties by role: 50(1) providers of systems intended to interact directly with natural persons; 50(2) providers of systems generating synthetic audio, image, video or text — outputs “marked in a machine-readable format and detectable as artificially generated or manipulated”; 50(3) deployers of emotion-recognition or biometric-categorisation systems; 50(4) deployers, for deep fakes and for AI-generated text published to inform the public on matters of public interest. Regulation (EU) 2026/1744 inserts a new Article 111(4): providers of AI systems generating synthetic content “that have been placed on the market before 2 August 2026 shall take the necessary steps in order to comply with Article 50(2) by 2 December 2026”. Sources: Regulation (EU) 2024/1689 · Regulation (EU) 2026/1744 2

  5. GDPR (Regulation (EU) 2016/679), Article 35 (Data Protection Impact Assessment). Unaffected by the Digital Omnibus on AI. See also our analysis of the DPIA/FRIA interaction: DPIA vs. FRIA 2

  6. The co-legislators stated the deferral was prompted by delays in finalising harmonised standards, designating national competent authorities and providing the compliance tools needed for high-risk requirements. Council of the EU press release, Artificial intelligence: Council and Parliament agree to simplify and streamline rules, 7 May 2026 2

  7. European Commission, Digital Omnibus on AI proposal, tabled 19 November 2025. The AI Act entered into force on 1 August 2024; its provisions enter into application on a staggered basis (Recital 1, Regulation (EU) 2026/1744). Maples Group, The Digital Omnibus Package: Understanding the EU’s Proposals

  8. Legislative history: a first trilogue on 28 April 2026 ended without agreement; a provisional political agreement followed in early May, confirmed in the Council on 13 May 2026 and announced by the Council presidency on 7 May 2026 (n. 6). The IMCO and LIBE committees endorsed it on 2 June 2026; the European Parliament adopted it in plenary on 16 June 2026; publication in the Official Journal followed on 24 July 2026. European Parliament Legislative Train, Digital Omnibus on AI · Regulation (EU) 2026/1744

  9. The Commission’s original proposal used a conditional “stop-the-clock” trigger tied to the availability of standards and tools; the adopted text replaced it with fixed application dates (2 December 2027 / 2 August 2028). Inside Privacy (Covington), EU AI Act Update: Timeline Relief, Targeted Simplification, and New Prohibitions

  10. Targeted changes: Article 4 AI-literacy obligation softened to “supporting” the development of literacy; bias-detection legal basis for special-category data extended under a strict necessity standard; regulatory-sandbox establishment deadline postponed to 2 August 2027; new Article 111(4) transition for Article 50(2); Articles 102 to 110 applicable from 27 July 2026. Sources: Regulation (EU) 2026/1744 · Gibson Dunn, EU AI Act Omnibus Agreement — Postponed High-Risk Deadlines and Other Key Changes, 27 May 2026

  11. AI Act, Article 2 (scope), including application to providers placing AI systems on the Union market or putting them into service in the Union irrespective of establishment, and to providers and deployers in third countries where the output produced by the system is used in the Union. Regulation (EU) 2024/1689

  12. “It is, however, a deferral rather than a dismantling: the fundamental architecture of the AI Act — its risk-based approach, its governance structure, and its core obligations — remains intact.” Gibson Dunn (n. 10)