· Zenous Team  · 6 min read

The High-Risk Deadline Moved to December 2027. Your Programme Plan Should Not.

The Digital Omnibus on AI pushed the EU AI Act's high-risk obligations from August 2026 to December 2027. In delivery terms that is a schedule change on one external milestone with the scope unchanged. How to re-baseline in two weeks, the nearest date that did not move, and the three misreadings to avoid.

The Digital Omnibus on AI pushed the EU AI Act's high-risk obligations from August 2026 to December 2027. In delivery terms that is a schedule change on one external milestone with the scope unchanged. How to re-baseline in two weeks, the nearest date that did not move, and the three misreadings to avoid.

On 27 July 2026, Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force and moved the EU AI Act’s high-risk deadline. Obligations for stand-alone high-risk systems under Annex III (employment, education, credit, essential services, law enforcement and the rest of that list) now apply from 2 December 2027 instead of 2 August 2026. Obligations for high-risk AI embedded in products covered by EU product legislation under Annex I move to 2 August 2028.

Not everything moved. The transparency duties in Article 50 applied on 2 August 2026 as planned: telling people they are dealing with an AI system, and marking synthetic content. The one concession is a transitional period, not a deferral. Providers of systems generating synthetic audio, image, video or text that were already on the market before 2 August 2026 have until 2 December 2026 to comply with the marking duty in Article 50(2). The prohibited practices in Article 5 have applied since February 2025, with two newly inserted prohibitions applying from 2 December 2026. General-purpose model obligations have applied since August 2025.

In delivery terms this is a schedule change on one external milestone with the scope unchanged. Programmes that read it as anything else are about to make one of three mistakes.

What moved and what did not

ObligationBefore the OmnibusNow
Annex III high-risk systems (stand-alone)2 August 20262 December 2027
Annex I high-risk systems (embedded in regulated products)2 August 20272 August 2028
Article 50 transparency (AI interaction disclosure, synthetic content)2 August 20262 August 2026. Systems already on the market before that date have until 2 December 2026 for the Article 50(2) marking duty
Article 5 prohibited practicesIn force since 2 February 2025Unchanged
General-purpose AI model obligationsIn force since 2 August 2025Unchanged

The Omnibus also narrowed the definition of a safety component to exclude systems that merely assist a user, and extended the SME exemptions to small mid-cap enterprises. Both can change a system’s classification. Neither removes the requirements for a system that stays high-risk.

Three ways a programme misreads a deferral

Reading it as a pause. The first reaction we see is a steering committee pulling the compliance workstream’s funding for two quarters. The requirements did not change: risk management, data governance, technical documentation, logging, human oversight, and the Article 15 requirements on accuracy and cybersecurity are all still in the text. Only the date enforcement starts moved. A workstream that stops for two quarters restarts in Q2 2027 with the same scope, a colder team and eight fewer months.

Reading it as “the old date still stands.” A large share of vendor and consultancy content published before July still says the deadline is 2 August 2026, and some of it is being republished unchanged. More dangerous: supplier contracts and internal policies written in 2025 reference the old date. A model vendor’s warranty tied to “compliance by 2 August 2026” is now tied to a date that no longer exists in law. Someone has to find those clauses.

Reading the classification as settled. The 2025 classification exercise was done against the original annexes. The safety-component narrowing and the mid-cap exemption mean some systems have moved category. A programme that does not re-run classification is carrying either wasted controls or an unrecognised obligation, and will not know which.

Re-baselining in two weeks

This is a fortnight of work for a programme that already had a compliance plan, and the output is a decision, not a document set.

  1. Re-date the milestone, then find every dependency on the old date. Plan, contracts, vendor SLAs, internal policy, board papers. Each reference to 2 August 2026 gets a decision: re-date, remove, or keep deliberately (a supplier holding to the earlier date is not a problem; a supplier who silently stops work is).
  2. Re-run classification per system against the amended annexes and the narrowed safety-component definition. One page per system: category, reason, the article that puts it there, the date it now attracts.
  3. Keep Article 50 live. Any customer-facing agent or assistant placed on the market after 2 August 2026 discloses that it is an AI system, and synthetic outputs are marked. If your generative system was already on the market before that date, the marking duty under Article 50(2) falls due on 2 December 2026, which is eleven weeks from now. This is the obligation most agentic-AI programmes were treating as part of the deferred bundle, and it is the one with the nearest date on it.
  4. Convert the sixteen months into an architecture budget. Logging, human-oversight controls, data-lineage records and technical documentation can be built into the platform once, or assembled as evidence in a panic in Q3 2027. The fintech programmes that treat regulation as an architecture constraint rather than a closing checklist ship with the controls already producing evidence. The deferral is the time to do that properly, which most programmes never get.
  5. Write the decision down. “We are using the deferral to build X into the platform by Q1 2027. We are not deferring Article 50 work, classification, or vendor re-papering.” A dated decision with an owner beats a slide, and it gives the next steering committee something to hold the programme to. If your programme measures decision latency, this is a decision that should close in days, not months.

What we check in an audit

When we audit an AI-native programme after the Omnibus, four questions cover the regulatory exposure:

  • Has every system been re-classified against the amended annexes, and is the reasoning written down?
  • Which contracts, policies and plans still reference 2 August 2026, and who owns each one?
  • Is Article 50 disclosure and content marking live on everything customer-facing that shipped after 2 August 2026, and is anything that predates it on track for 2 December 2026?
  • Is the compliance workstream funded through to December 2027 on a plan that builds controls into the platform, or is it parked?

A programme that can answer all four is using the deferral. A programme that cannot has taken a sixteen-month extension and spent it.

Start Monday

Pull the contract register and search it for the old date. That one afternoon usually surfaces the first surprise. Then book the classification re-run. If you want an independent pass over the four questions above, a delivery audit covers it in 7-14 days, or book a consultation and bring the classification list.


Sources: Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI), OJ L, 2026/1744, 24.7.2026. The dates above come from its amendment to Article 113 of the AI Act, which sets Chapter III Sections 1 to 3 to apply from “2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III” and “2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I”, and from the transitional paragraph it adds for Article 50(2). Verified against the text on EUR-Lex on 11 September 2026. Attributed to that text, not proprietary Zenous data. This is delivery guidance, not legal advice; the classification of any specific system is a question for counsel.

Back to Blog

Related Posts

View All Posts »