EU defers the AI Act's high-risk deadline: what the Digital Omnibus means for compliance teams
Twelve days before the EU AI Act's flagship high-risk obligations were due to apply, the European Parliament and Council pushed the deadline out by more than a year. Regulation (EU) 2026/1744 — the "Digital Omnibus on AI," adopted 8 July 2026 — was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. For compliance and security teams that had 2 August 2026 circled as a hard wall, that wall just moved.
The original schedule
The AI Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024 with a phased rollout: prohibited AI practices and AI-literacy obligations applied from 2 February 2025; obligations for general-purpose AI (GPAI) models and the governance framework followed on 2 August 2025. Under the original text, the general application date of 2 August 2026 was when the bulk of the Act's requirements — including obligations for the high-risk systems listed in Annex III (hiring, credit scoring, biometrics, and similar use cases) — were due to take effect. High-risk AI embedded in already-regulated products under Annex I had a later original deadline of 2 August 2027.
What the Digital Omnibus changes
Regulation (EU) 2026/1744 amends the AI Act (along with the aviation regulation 2018/1139 and the machinery regulation 2023/1230) to defer the Chapter III, Sections 1–3 high-risk obligations:
- Stand-alone Annex III high-risk systems — deadline moves from 2 August 2026 to 2 December 2027.
- High-risk AI embedded in regulated products (Annex I) — deadline moves from 2 August 2027 to 2 August 2028.
The deferral is targeted, not blanket. Article 50 transparency duties largely remained on their original 2 August 2026 schedule, and the earlier-applying obligations — Article 5 prohibited practices, GPAI model requirements, and AI-literacy duties — remain in force on their original timelines (Gibson Dunn).
Why this matters for SOC 2 / ISO 27001 buyers
GRC and compliance-automation vendors have increasingly bundled EU AI Act and ISO/IEC 42001 readiness alongside SOC 2 and ISO 27001 programs, and many 2026 compliance roadmaps were built around the now-superseded 2 August 2026 date. Teams that were racing to stand up high-risk AI controls as a parallel crash program now have room to fold that work into existing ISMS and audit cycles instead — but the prohibitions, GPAI duties, and transparency requirements that are already live haven't gone anywhere, so this is a deferral of the heaviest obligations, not a reprieve from the Act as a whole.
Sources: EUR-Lex, Regulation (EU) 2026/1744 · European Commission, regulatory framework for AI · EU AI Act, Article 113 · Future of Privacy Forum · Gibson Dunn