AuditGround

EU defers the AI Act's high-risk deadline: what the Digital Omnibus means for compliance teams

Regulation · August 7, 2026

Twelve days before the EU AI Act's flagship high-risk obligations were due to apply, the European Parliament and Council pushed the deadline out by more than a year. Regulation (EU) 2026/1744 — the "Digital Omnibus on AI," adopted 8 July 2026 — was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. For compliance and security teams that had 2 August 2026 circled as a hard wall, that wall just moved.

The original schedule

The AI Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024 with a phased rollout: prohibited AI practices and AI-literacy obligations applied from 2 February 2025; obligations for general-purpose AI (GPAI) models and the governance framework followed on 2 August 2025. Under the original text, the general application date of 2 August 2026 was when the bulk of the Act's requirements — including obligations for the high-risk systems listed in Annex III (hiring, credit scoring, biometrics, and similar use cases) — were due to take effect. High-risk AI embedded in already-regulated products under Annex I had a later original deadline of 2 August 2027.

What the Digital Omnibus changes

Regulation (EU) 2026/1744 amends the AI Act (along with the aviation regulation 2018/1139 and the machinery regulation 2023/1230) to defer the Chapter III, Sections 1–3 high-risk obligations:

The deferral is targeted, not blanket. Article 50 transparency duties largely remained on their original 2 August 2026 schedule, and the earlier-applying obligations — Article 5 prohibited practices, GPAI model requirements, and AI-literacy duties — remain in force on their original timelines (Gibson Dunn).

The practical effect: the heaviest lift under the AI Act — conformity assessment, risk-management systems, data governance, logging, and human-oversight controls for high-risk systems — now has well over a year of additional runway. The parts of the Act already in force were not rolled back.

Why this matters for SOC 2 / ISO 27001 buyers

GRC and compliance-automation vendors have increasingly bundled EU AI Act and ISO/IEC 42001 readiness alongside SOC 2 and ISO 27001 programs, and many 2026 compliance roadmaps were built around the now-superseded 2 August 2026 date. Teams that were racing to stand up high-risk AI controls as a parallel crash program now have room to fold that work into existing ISMS and audit cycles instead — but the prohibitions, GPAI duties, and transparency requirements that are already live haven't gone anywhere, so this is a deferral of the heaviest obligations, not a reprieve from the Act as a whole.

Sources: EUR-Lex, Regulation (EU) 2026/1744 · European Commission, regulatory framework for AI · EU AI Act, Article 113 · Future of Privacy Forum · Gibson Dunn

Disclosure: AuditGround earns referral commissions from some of the platforms we cover. This never influences our reporting or recommendations. See our disclosure statement.