On May 7, 2026, the European Council and Parliament reached political agreement on the Digital Omnibus, the first amendment to the AI Act since it was adopted, formally endorsed by Parliament on June 16 and approved by the Council on June 29. What it actually changed is narrower than "the AI Act got delayed" suggests, and the narrowness is the whole story. None of what follows is EU-only reading, either: the Act applies to any provider or deployer whose AI system's output is used within the EU, regardless of where the company is headquartered, which is most of the reason this keeps landing on the desks of CIOs well outside Europe.

What moved

Standalone high-risk systems under Annex III (recruitment tools, credit scoring, education, law enforcement, access to essential services) move from an August 2026 compliance date to December 2, 2027, a sixteen-month deferral. AI embedded in regulated products under Annex I (medical devices, machinery, lifts) moves further still, to August 2028. If your organisation's programme was built around getting a hiring algorithm or a credit-scoring model through conformity assessment by this August, that deadline is genuinely gone. The relief is real. It exists because harmonised conformity-assessment standards and notified-body capacity were not ready, a practical response to an unready ecosystem, not a retreat. That reason does not extend to what follows.

ObligationBefore the OmnibusAfter the Omnibus
Annex III (standalone high-risk)August 2026December 2, 2027
Annex I (product-embedded)August 2027August 2028
Article 50 (transparency, chatbot disclosure)August 2, 2026Unchanged
GPAI enforcement powers (fines, investigation)August 2, 2026Unchanged

What didn't move, and applies in three weeks

Article 50 applies exactly on the original schedule. Any system that interacts with a person as a chatbot, virtual assistant, or voice agent has to disclose that fact at first contact. Any system generating synthetic text, images, audio, or video has to mark that output as machine-generated, with a four-month grace period only for systems already on the market before August, not for anything newly deployed after. What this means in practice depends on what you are running:

The enforcement gap that's closing

Foundation-model providers have been legally bound by documentation, copyright, and systemic-risk obligations since August 2025. What has been missing is not the obligation but the enforcement tools: the Commission had no statutory power to investigate or fine anyone for falling short. That changes August 2, 2026, when the Commission's supervision and enforcement powers, including fines up to €15 million or 3 percent of global turnover, come into force for the first time. Whether that newly active power can reach back and act on conduct from the 2025-2026 window is a genuinely open question; even the law firms tracking this closely describe real uncertainty about how enforcement will play out in practice. What is not uncertain is the more basic point worth taking to a board: a year of conduct that was already supposed to be compliant is about to be scrutinised for the first time, by an enforcer that previously had no tools to look.

Enforcement readiness is uneven, and that cuts one way

Roughly ten of the twenty-seven member states show advanced public implementation of the market surveillance infrastructure Article 50 enforcement depends on. Germany's implementing legislation was still moving through its second and third Bundestag readings as of early July, meaning its designated authority is not yet formally in place. An EU-wide obligation does not disappear because one member state's machinery is behind another's, and the Commission's own enforcement powers over GPAI providers are not constrained by which member states have finished their implementing legislation. A company operating across borders should expect the most prepared authority in its footprint to set the practical bar, not the least prepared one, and should not read a slow national rollout as a reason to slow its own.

Three questions worth putting to your compliance and legal team this month

None of these are questions a board answers itself. They are questions worth confirming someone else already has answers to. The question is not whether your board has heard a summary of this Omnibus. It is whether "we got more time" is the version that survives the trip up the org chart, or whether the more accurate, more useful one does.

Related: What the EU AI Act Actually Requires of Your CIO covers the Annex III architecture obligations in depth. This piece picks up where that one leaves off, on the parts of the Act that didn't get the sixteen-month extension.