View all articles
eu-ai-actcomplianceregulationdigital-omnibus

EU AI Act After the Omnibus: What Applies Now and What to Do

JG
Jacobo González Jaspe
|

Reviewed:

Abstract illustration: concentric rings of a vault mechanism with amber light in the seams. Safe and legal
Illustration generated with AI on our own machine.

Archived article, published September 9, 2026. Kept for the record; figures and deadlines may have changed. See the current guides.

This article is also available in Spanish:EU AI Act tras el Ómnibus: qué aplica ya y qué hacer ahora

The Digital Omnibus (Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force since 27 July 2026) moved the EU AI Act’s high-risk dates. Annex III high-risk systems (AI used in employment, credit scoring, education, law enforcement, biometrics or critical infrastructure) now apply from 2 December 2027. AI embedded in regulated products (Annex I) follows on 2 August 2028 (it was 2 August 2027). Two new prohibited practices the Omnibus adds to Article 5 (AI that generates non-consensual intimate images of an identifiable person, and child sexual abuse material) apply from 2 December 2026.

Three sets of rules already apply today: the prohibited practices and the AI literacy duty (since 2 February 2025), the general-purpose AI model obligations (since 2 August 2025), and the Article 50 transparency obligations (since 2 August 2026).

That leaves you until December 2027 to build the high-risk file without a rush. Here is how to use the time, phase by phase.

EU AI Act implementation timeline

Is Your AI High-Risk? A Self-Assessment

Before anything else, you need to determine whether your AI systems fall under Annex III. Use this table to check:

High-Risk CategoryExamplesAnnex III Reference
Employment & worker managementCV screening tools, automated interview scoring, workforce monitoring, promotion algorithmsAnnex III, 4(a)-(b)
Credit & financial assessmentCredit scoring models, loan approval automation, insurance risk profilingAnnex III, 5(b)
Education & vocational trainingAutomated grading, student admission algorithms, learning path assignmentAnnex III, 3(a)-(b)
Law enforcementPredictive policing, evidence analysis, suspect profiling, recidivism risk scoringAnnex III, 6(a)-(g)
Biometric identificationFacial recognition for access control, emotion detection in interviews, remote biometric IDAnnex III, 1(a)-(b)
Critical infrastructureAI managing energy grids, water treatment, traffic control, telecom networksAnnex III, 2(a)-(b)
Migration & border controlVisa application screening, border surveillance, asylum claim processingAnnex III, 7(a)-(d)
Justice & democratic processesSentencing assistance tools, AI used in elections or referendum processesAnnex III, 8(a)-(b)

If any of your AI systems touch these categories, you are subject to the full high-risk compliance framework. If you are unsure, settle it early: a short classification memo written now saves rework in 2027.

For a deeper look at the risk classification system, read our AI Risk Classification Guide.

What Compliance Actually Requires

The EU AI Act mandates specific, documented, auditable actions:

  • Risk management system: a living process to identify, evaluate, and mitigate risks throughout the AI system’s lifecycle.
  • Data governance: documented data quality standards, bias testing, and training data provenance.
  • Technical documentation: detailed descriptions of the system’s purpose, architecture, training methodology, performance metrics, and known limitations.
  • Logging requirements (Article 12): AI agents and automated systems must maintain traceable logs of their decision-making processes. As of the April 16, 2026 guidance update, this explicitly includes agentic AI systems that take autonomous actions.
  • Transparency obligations (Article 50): chatbot notices, machine-readable marking of generated content, and disclosure of deepfakes and emotion recognition; the detail is in Phase 1.
  • Human oversight: mechanisms that allow a human operator to understand, monitor, and override AI decisions.
  • Conformity assessment: a formal evaluation that your system meets all requirements, resulting in CE marking.
  • EU database registration: high-risk AI systems must be registered in the EU’s public database before deployment.

For a complete compliance walkthrough, see our EU AI Act Compliance Guide.

Your Phased Plan to December 2027

Phase 1 (now to December 2026): Audit, classify, and meet what already applies

  • Inventory all AI systems in your organization, including third-party tools and embedded AI features in SaaS products
  • Classify each system against the Annex III categories above
  • Identify your role for each system: are you a provider (developer) or deployer (user)?
  • Assign a compliance lead: someone must own this process internally
  • Review prohibited practices: confirm none of your systems fall under the 8 banned categories (these have been enforceable since February 2025), nor under the two the Omnibus adds from 2 December 2026
  • Check Article 50 transparency: chatbot disclosure (a provider duty) and your own duties as a deployer for deepfakes and published AI text apply since 2 August 2026; only the Article 50(2) marking by providers of systems already on the market before that date runs to 2 December 2026
  • Cover AI literacy (Article 4): take measures to support the AI literacy of the people who operate AI, suited to their knowledge and the context of use; this has applied since February 2025, and since Regulation (EU) 2026/1744 it does not require you to guarantee any individual’s level

Phase 2 (January to April 2027): Document and assess

  • Draft technical documentation for every high-risk system: architecture, training data, performance benchmarks, known limitations
  • Conduct bias and fairness testing on training datasets and model outputs
  • Implement logging that meets Article 12 requirements: traceable, timestamped, tamper-resistant
  • Map your data governance: where does training data come from? How is it validated? How is it stored?
  • Begin conformity assessment preparation: self-assessment for most categories, third-party audit for biometric systems

Phase 3 (May to August 2027): Implement and test

  • Set up post-market monitoring: how you will collect incidents and performance drift once the system is live
  • Build human oversight controls: manual override capabilities, monitoring dashboards, escalation procedures
  • Run the conformity assessment: complete the formal evaluation process
  • Prepare CE marking documentation
  • Train your staff: operators of high-risk AI must understand the system’s capabilities, limitations, and override procedures

Phase 4 (September to November 2027): Register and verify

  • Register high-risk systems in the EU database
  • Conduct a final compliance review: walk through every requirement against your documentation
  • Test incident reporting procedures: you must be able to report serious incidents to national authorities
  • Verify third-party compliance: if you use AI tools from vendors, confirm they have completed their provider obligations
  • Document everything: if it is not written down, it did not happen

Who Enforces This?

The European AI Office oversees general-purpose AI models and coordinates cross-border enforcement. National competent authorities in each EU member state handle high-risk AI system supervision. In Spain, the designated supervisory authority operates under the Agencia Española de Supervisión de Inteligencia Artificial (AESIA).

The Omnibus moved dates, not penalties. The Article 99 structure: up to EUR 35M or 7% of global revenue for prohibited practices, EUR 15M or 3% for most other obligations, EUR 7.5M or 1% for incorrect or misleading information, and the lower of the two figures for SMEs (Article 99).

Why Start Now When the Date Is December 2027

If you have not started, the most useful thing you can do this quarter is know what you are dealing with. Classify your systems. Understand your obligations. Then build a plan.

Starting early pays in four ways. You do the inventory once, at your own pace, instead of in a rush. You can choose or replace tools while contracts come up for renewal. Your documentation matures alongside the harmonised standards and AESIA guidance still being published. And the transparency and AI literacy duties already apply, so Phase 1 is useful today whatever happens to the high-risk date.

For detailed guidance, start with our comprehensive EU AI Act resource page.

Sources: Regulation (EU) 2026/1744 on EUR-Lex, Regulation (EU) 2024/1689 on EUR-Lex, Gibson Dunn: EU AI Act Omnibus: postponed high-risk deadlines, European Commission: AI Omnibus enters into force, artificialintelligenceact.eu, legalnodes.com, secureprivacy.ai


Work with us

We review your AI systems, classify their risk level and leave you a phased plan. Thirty minutes is usually enough to start: book a call or see how we work in consulting.

Diagram
Share: LinkedIn X
Veredicto semanal

Get new guides before anyone else

Subscribe and we tell you when new guides, templates and workflows go up. One email a week, no spam.

Already published: 69 guides and 25 templates. All free, no signup.

Bonus: the EU AI Act checklist, ready to complete
Once a week No spam Unsubscribe anytime

See what you get

The EU AI Act now applies: a checklist you can complete

Tell us what you want to run

Tell us what you want to run and on what budget. We will tell you which hardware you need, which model fits, and what to expect from it, before you spend anything.

First call free, 15 min Local-first: your data stays on your network Open tools and guides

69 free guides · 17 compliance templates