AI Omnibus Comes into Force in the EU, Delaying High-Risk Obligations until December 2027

Published as Regulation 2026/1744 and effective since July 27, the AI Omnibus postpones high-risk obligations by 16 months but maintains intact the transparency rules that take effect on August 2.
Regulation (EU) 2026/1744, dubbed the Digital Omnibus on AI, was published in the Official Journal of the European Union on July 24 and came into effect three days later, on July 27. The expedited processing met a tight schedule: the main transparency obligations of the AI Act will take effect on August 2, and Brussels wanted to finalize the package ahead of that date to provide predictability for suppliers and national authorities.
What Has Been Postponed and What Has Not
The most significant postponement concerns systems classified as high-risk in Annex III of the AI Act. Biometric systems, critical infrastructure, education, employment, migration, and border control now have until December 2, 2027, to comply with obligations that were initially set to begin on August 2, 2026, a delay of 16 months. High-risk systems embedded in products already covered by sectoral legislation (for example, medical devices and toys regulated by CE) have an extended deadline until August 2, 2028.
What remains on the original date is the transparency package from Article 50 and the general purpose rules from Articles 51 to 56. Starting August 2, anyone operating corporate chatbots must inform the human interlocutor that they are speaking with AI. Those generating synthetic images, audio, or text are required to mark the output in machine-readable format. Generative systems already on the market before this date have until December 2, 2026, to adjust their watermark. Obligations for general purpose models, including the enhanced duties for providers considered to pose systemic risk, remain applicable since August 2025 and were not altered by the Omnibus.
What Has Been Added
The Omnibus is not just a postponement. It extends the absolute prohibitions of Article 5 to include so-called nudifier apps, tools that generate non-consensual intimate images, and criminalizes the use of AI systems to produce child sexual abuse material. The prohibition is immediate for new services and grants existing apps until December 2026 to exit the European market. App store providers and hyperscalers are formally responsible for blocking distribution in the region, which is expected to result in a massive takedown before the end of the year.
The reform also consolidates expanded powers for the AI Office and national supervisors, including the ability to demand information from suppliers outside the EU and to fine international value chains when a model developed in a third country is placed on the European market. Extraterritoriality was anticipated in the original text and now has a defined operational procedure.
How the Postponement Affects Markets Outside the EU
The practical impact varies by market. In Germany, where SAP, Deutsche Telekom, and automaker Bosch had already structured compliance programs targeting August 2026, the delay frees up compliance capex for 2027 and allows budget reallocation to the surviving transparency duties. The Bitkom association estimates that the deviation to the new schedule represents between €1.2 billion and €1.8 billion in avoided operational costs over two years for the 100 largest companies in the country.
In Japan, where the METI published a voluntary guide for high-risk AI operators in July, the European delay was immediately cited by representatives of Keidanren as a reason not to accelerate domestic regulation. NTT Data and Fujitsu, which sell to European clients, have gained a window to adjust their catalogs.
Brazil, whose PL 2338 replicates much of the risk structure of the AI Act, enters into an interpretative limbo. The Brazilian text currently under discussion in Congress still uses the original European dates as an informal reference for its own timeline. Law firms consulted by other outlets point out that the European delay weakens the pressure for a swift vote in the Senate and favors the sectoral thesis advocated by the CNI, which seeks longer deadlines for heavy industry and agribusiness.
What Changes for the CIO on Tuesday
The practical point is operational. Those with GenAI products aimed at end customers in Europe need to have the watermark operational by August 2, six days after the entry into force. Those operating internal assistants with autonomous components must provide clear disclosure to the interlocutor. The rest of the high-risk compliance plan, which consumed a significant part of the 2025 budget, can be rescheduled. The extended window allows time to revise architecture but removes the last excuse to delay the essentials: the transparency requirements have not been pushed back a single day.