August 2026 · 6 min read
EU AI Act Omnibus: High-Risk Delayed, Transparency In Force

Key Definitions
Digital Omnibus on AI Regulation (EU) 2026/1744, adopted 8 July 2026 and in force 27 July 2026, amending the AI Act and related product-safety regulations to simplify implementation. It reschedules high-risk AI obligations but does not change the substance of obligations already in force, such as transparency.
Article 50 Transparency Obligations Under Article 50 of the AI Act, chatbots and other interactive AI systems must tell users they are dealing with AI; deepfakes (AI-generated or altered images, audio, video) must be labelled; and AI-generated or altered content must carry machine-readable marks so it can be detected.
High-Risk AI Systems Classified under the AI Act into two groups: Annex III standalone high-risk systems (used in employment, education, law enforcement, critical infrastructure) and Annex I AI systems embedded in products regulated by product-safety law (medical devices, toys, lifts). The Omnibus delays each group's obligations separately.
On 27 July 2026, the Digital Omnibus (Regulation (EU) 2026/1744) entered into force. It pushed the AI Act's most consequential provisions—the high-risk AI system obligations—back to 2 December 2027 and 2 August 2028. But for most enterprises the more important signal is the other half of the story: Article 50 transparency obligations and the entire market-surveillance and enforcement framework took effect on 2 August 2026. Not delayed, not deferred—in force and enforceable now.
High-Risk Obligations: Delayed to 2027 and 2028
The Omnibus sets a new timetable for high-risk AI obligations. Annex III standalone high-risk systems—used in employment, education, law enforcement, critical infrastructure—move from the original 2 August 2026 to 2 December 2027. Annex I AI systems embedded in product-safety-regulated products (medical devices, toys, lifts) move to 2 August 2028. Machinery takes a different path, shifted from Annex I category A to category B and transposed into the machinery regulation through a delegated act due by 2 August 2028.
The rationale is concrete: delayed standards and common specifications, and national competent authorities that are not yet established, made the compliance burden heavier than expected. The Commission needs this time to finalize guidance, standards, codes of practice and conformity-assessment frameworks. But this is not license to relax—it merely moves the heaviest obligations back, and explicitly asks enterprises to use the window to advance, not shelve, governance.
Transparency and Supervision: In Force Since 2 August
August 2 was the AI Act's general application date, bringing the transparency and information obligations that apply regardless of risk classification into an enforceable state: chatbots and other interactive AI systems must tell users they are dealing with AI, not a human; deepfakes (AI-generated or edited images, audio, video) must be labelled; and AI-generated or altered content must carry machine-readable marks so it can be detected. The Omnibus extends the marking deadline only for legacy generative systems already on the market before 2 August 2026, to 2 December 2026.
At the same time, the market-surveillance and enforcement framework went operational. National market-surveillance authorities may investigate potentially non-compliant AI systems, require access to information and documentation (and, in defined circumstances, data or source code), and order corrective action, restriction, withdrawal or recall. The Commission, through the AI Office, now holds full investigatory and enforcement powers over general-purpose AI models and systems under its supervision—including requesting information, conducting model evaluations, requiring mitigations, and restricting or withdrawing models from the EU market. Enforcement machinery for the prohibited AI practices (banned since February 2025) is now in place, with fines up to €35 million or 7% of worldwide annual turnover.
AI Office centralized supervision
The Omnibus broadens the AI Office's exclusive competence: systems built on general-purpose AI models—developed not only by the same provider but by providers within the same undertaking—fall under direct AI Office supervision rather than national regulators. Direct consequences for AI labs and large platforms.
Complaints and whistleblowing
Any individual or organization may submit a complaint to a market-surveillance authority over an alleged AI Act breach, and reports of suspected infringements fall within the EU Whistleblowing Directive. Ensure internal reporting channels capture AI-related concerns.
2 December 2026 milestone
That is the deadline for legacy generative systems to complete machine-readable marking, and the date two new prohibitions (non-consensual intimate imagery and CSAM generation) take effect. Do not misplace the finish line for transparency work.
OOMeta's View
The Digital Omnibus is a fork in the enterprise AI compliance timeline: the heaviest high-risk obligations are pushed back, while transparency and supervision take effect immediately. For most enterprises the right mindset is not "relief" but "priority-setting." First, test your AI touchpoints against the transparency duties already in force since 2 August—chatbots, content generation, deepfakes. Then use the delayed high-risk window to build solid gap analyses and governance foundations. Regulation is not going away; it is giving you time to prepare. Use the window to advance, not to postpone governance until the last minute.
References: Goodwin, "Not Delayed, Not Deferred: EU AI Act Transparency Obligations Are Now in Force", 2026-08, https://www.goodwinlaw.com/en/insights/publications/2026/08/alerts-technology-dpc-eu-ai-act-transparency-obligations-now-in-force · Debevoise & Plimpton, "The Third Wave of EU AI Act Requirements Are in Force", 2026-08-03, https://www.debevoisedatablog.com/2026/08/03/the-third-wave-of-eu-ai-act-requirements-are-in-force-transparency-requirements-supervisory-powers/ · EUR-Lex, Regulation (EU) 2026/1744 (Digital Omnibus on AI), https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng
Frequently Asked Questions
What is the Digital Omnibus and when did it take effect?+
The Digital Omnibus (Regulation (EU) 2026/1744) is the EU's simplification amendment to the AI Act, adopted 8 July 2026 and in force 27 July 2026. It reschedules high-risk AI obligations and streamlines administration, without changing the substance of obligations already in force such as transparency.
When are the high-risk AI obligations delayed to?+
Annex III standalone high-risk systems (employment, education, law enforcement, critical infrastructure) move to 2 December 2027; Annex I AI systems embedded in product-safety-regulated products (medical devices, toys, lifts) move to 2 August 2028. Machinery takes a sectoral path, transposed into the machinery regulation via a delegated act due by 2 August 2028.
Are the transparency obligations in force now?+
Yes. From 2 August 2026, Article 50 transparency and information obligations apply to AI systems regardless of risk classification and are enforceable: chatbots must disclose AI identity, deepfakes must be labelled, and AI-generated content must carry machine-readable marks. The Omnibus only extends the marking deadline for legacy generative systems already on the market before 2 August 2026 to 2 December 2026.
What can market surveillance and enforcement do now?+
From 2 August 2026, the AI Act's market-surveillance and enforcement framework is operational: national authorities can investigate non-compliant systems, require access to information and documentation (and, in defined cases, data or source code), and order corrective action, restriction, withdrawal or recall. The AI Office has full investigatory and enforcement powers over systems built on general-purpose AI models, with fines up to €35 million or 7% of worldwide annual turnover.
How should enterprises respond to the delay?+
Delay is not cancellation. Transparency obligations, the ban on unacceptable AI practices, and GPAI model obligations all follow the original schedule. Enterprises should use the extended high-risk window to advance, not defer, AI governance: run gap analyses, update internal policies, engage emerging technical standards, and build internal processes for investigations and enforcement.
Related Articles
UK ICO Draws the Data-Protection Line for Agentic AI: Is Your Agent Compliant?
The UK ICO set an early data-protection baseline for agentic AI with an action framework for agent compliance.
The Second Wave of AI Sensitive Data: 39.7% of Interactions Touch Enterprise Data
39.7% of AI interactions touch enterprise sensitive data—the second wave is widening the corporate data-exposure surface.
Okta Survey: Shadow AI Outruns Governance—A Wide Gap Between Confidence and Reality
Okta's survey shows shadow AI outrunning governance, with a wide gap between executive confidence and reality.
NIST Launches AI Agent Security Standards—A Three-Pillar Strategy Reshapes the Landscape
NIST's AI agent security standards initiative and three-pillar strategy provide technical grounding for compliance.