
On August 2, 2026, the EU AI Act reached one of its most consequential milestones – and most companies still don’t realise how much shifted underneath them just days before.
Background of the Digital Omnibus on AI
In November 2025, the European Commission proposed the “Digital Omnibus on AI” – a package to delay parts of the AI Act because the harmonised technical standards and national supervisory bodies weren’t ready in time. It was adopted in June 2026 and published on July 24, 2026, and entered into force on July 27 – just days before the original August 2 deadline.
EU AI Act Extension for High-Risk Systems
The result: deadlines for standalone high-risk AI systems (Annex III) – the rules covering AI used in employment decisions, credit scoring, insurance risk, law enforcement, and more – were pushed back 16 months, from August 2, 2026, to December 2, 2027. High-risk AI embedded in regulated products (Annex I) – medical devices, lifts, toys – got a 12-month extension, now due August 2, 2028.
Active Obligations Under Article 4 and Article 50
But not everything moved: key transparency obligations under Article 50 remain applicable from 2 August 2026, although the Omnibus introduced limited adjustments to certain content-marking timelines: disclosing when someone is interacting with AI, labelling AI-generated or manipulated content, and flagging deepfakes. These rules are live right now.
Also unaffected: the ban on prohibited AI practices (in force since February 2025) and the AI literacy requirement under Article 4 – every provider and deployer must ensure staff working with AI systems have adequate AI literacy for their role. That one is easy to overlook, and it is already enforceable.
AI System Classification for RegTech and Finance
For companies building or using AI in regulated spaces – RegTech, AML/CFT, financial services – the real work is not waiting for 2027. It’s classification. Is your AI-assisted screening tool a supporting input to a human decision, or does it drive the outcome directly?
Human oversight is one signal, but it’s not the whole test – classification under Article 6 and Annex III also turns on the system’s intended purpose and whether it falls into one of the Act’s listed high-risk categories.
Getting that call right determines whether you’re looking at Annex III high-risk obligations or a lighter compliance path – and getting it wrong is expensive: high-risk violations carry penalties of up to €15 million or 3% of global turnover, while the most serious offences – like deploying a prohibited AI practice – run up to €35 million or 7%.
Takeaways for AI Governance
The lesson from this Omnibus episode: the AI Act’s timeline is not fixed. It moves in response to institutional readiness, and it will likely keep moving. What doesn’t move is the expectation that you can explain, today, how your AI systems are classified under the framework and why.
Authors:
Sibel Ahmed, Compliance Specialist, RabbIT Solutions
Rumen Valkov, Director Legal, Compliance & International Expansion, RabbIT Solutions
