On May 7, 2026, the European Council and Parliament reached political agreement on the Digital Omnibus, the first amendment to the AI Act since it was adopted, formally endorsed by Parliament on June 16 and approved by the Council on June 29. What it actually changed is narrower than "the AI Act got delayed" suggests, and the narrowness is the whole story. None of what follows is EU-only reading, either: the Act applies to any provider or deployer whose AI system's output is used within the EU, regardless of where the company is headquartered, which is most of the reason this keeps landing on the desks of CIOs well outside Europe.
What moved
Standalone high-risk systems under Annex III (recruitment tools, credit scoring, education, law enforcement, access to essential services) move from an August 2026 compliance date to December 2, 2027, a sixteen-month deferral. AI embedded in regulated products under Annex I (medical devices, machinery, lifts) moves further still, to August 2028. If your organisation's programme was built around getting a hiring algorithm or a credit-scoring model through conformity assessment by this August, that deadline is genuinely gone. The relief is real. It exists because harmonised conformity-assessment standards and notified-body capacity were not ready, a practical response to an unready ecosystem, not a retreat. That reason does not extend to what follows.
| Obligation | Before the Omnibus | After the Omnibus |
|---|---|---|
| Annex III (standalone high-risk) | August 2026 | December 2, 2027 |
| Annex I (product-embedded) | August 2027 | August 2028 |
| Article 50 (transparency, chatbot disclosure) | August 2, 2026 | Unchanged |
| GPAI enforcement powers (fines, investigation) | August 2, 2026 | Unchanged |
What didn't move, and applies in three weeks
Article 50 applies exactly on the original schedule. Any system that interacts with a person as a chatbot, virtual assistant, or voice agent has to disclose that fact at first contact. Any system generating synthetic text, images, audio, or video has to mark that output as machine-generated, with a four-month grace period only for systems already on the market before August, not for anything newly deployed after. What this means in practice depends on what you are running:
- Upstream platforms (Microsoft Copilot and similar): the disclosure obligation is largely handled by the vendor, though it is still worth confirming rather than assuming.
- Custom-built or commissioned systems (your own chatbot, voice agent, or content generator): implementing and documenting the disclosure is your responsibility, and "the deadline moved" is not a reason it can wait.
The enforcement gap that's closing
Foundation-model providers have been legally bound by documentation, copyright, and systemic-risk obligations since August 2025. What has been missing is not the obligation but the enforcement tools: the Commission had no statutory power to investigate or fine anyone for falling short. That changes August 2, 2026, when the Commission's supervision and enforcement powers, including fines up to €15 million or 3 percent of global turnover, come into force for the first time. Whether that newly active power can reach back and act on conduct from the 2025-2026 window is a genuinely open question; even the law firms tracking this closely describe real uncertainty about how enforcement will play out in practice. What is not uncertain is the more basic point worth taking to a board: a year of conduct that was already supposed to be compliant is about to be scrutinised for the first time, by an enforcer that previously had no tools to look.
Enforcement readiness is uneven, and that cuts one way
Roughly ten of the twenty-seven member states show advanced public implementation of the market surveillance infrastructure Article 50 enforcement depends on. Germany's implementing legislation was still moving through its second and third Bundestag readings as of early July, meaning its designated authority is not yet formally in place. An EU-wide obligation does not disappear because one member state's machinery is behind another's, and the Commission's own enforcement powers over GPAI providers are not constrained by which member states have finished their implementing legislation. A company operating across borders should expect the most prepared authority in its footprint to set the practical bar, not the least prepared one, and should not read a slow national rollout as a reason to slow its own.
Three questions worth putting to your compliance and legal team this month
- Does any system we operate disclose that it is AI when a person interacts with it, and does anything generating synthetic content mark that output as such? Article 50 applies in three weeks regardless of what happened to Annex III.
- If we build on a foundation model rather than only deploying one, is our provider's documentation and risk-assessment posture over the past year something we would want examined by a regulator newly empowered to look? Roughly two dozen providers, including Anthropic, Google, IBM, Microsoft, and Amazon, had signed the GPAI Code of Practice by June; the rest are working from their own compliance plans. Whichever category our provider falls into, are we confident in it?
- For the Annex III systems that did get sixteen months of breathing room, is that time being spent on conformity assessment and technical documentation, or is it being spent not thinking about the Act until the next deadline gets close?
None of these are questions a board answers itself. They are questions worth confirming someone else already has answers to. The question is not whether your board has heard a summary of this Omnibus. It is whether "we got more time" is the version that survives the trip up the org chart, or whether the more accurate, more useful one does.