The European Union’s Digital Omnibus on AI has amended the AI Act, but the headline “delay” is narrower than many firms assume.
According to AscentAI, the high-risk deadline has moved from August 2026 to December 2027, while AI embedded in regulated products under Annex I, covering areas such as medical devices, machinery and vehicles, now has until August 2028 to comply.
Despite the postponements, the AI Act’s core obligations remain firmly in place. Firms still need to inventory their AI systems, classify use cases, identify which obligations apply, assign ownership and track evolving guidance. The delay eases deadline pressure in specific areas, but it does not reduce the underlying compliance workload.
AscentAI recently discussed how the EU AI is not delayed, and instead, just one provision is.
High-risk status is defined narrowly. A system qualifies if it is used as a safety component of a product, or is itself a product, covered by Union harmonisation legislation listed in Annex I, and if that product requires third-party conformity assessment.
Systems listed under Annex III are also considered high-risk, spanning eight areas including biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration and the administration of justice. Exceptions apply where a system performs a narrow procedural task, improves a completed human activity, or supports rather than replaces human decision-making.
The Act’s reach extends well beyond EU-based firms. Any business shipping an AI feature to EU end users becomes a provider placing a system on the EU market. An EU subsidiary using a US-built internal tool is a deployer located in the Union. Even without direct EU sales, output consumed in the Union pulls a firm into scope.
Two deadlines remain unmoved and demand urgent attention. From December 2, 2026, new Article 5 prohibitions take effect banning AI systems that generate non-consensual intimate imagery or CSAM. Notably, this prohibition is not limited to systems built for that purpose:
“For providers, the prohibition extends beyond systems intended for such use to any system where such generation is a reasonably foreseeable and reproducible outcome, without requiring significant technical modification, and the system lacks reasonable and adequate technical safeguards to reliably prevent it. Providers of general-purpose image- or video-generation tools must therefore actively assess foreseeable misuse risks at the design and deployment stage.”
The same date brings machine-readable watermarking requirements under Article 50(2). Other Article 50 transparency obligations, covering chatbot disclosure, emotion recognition notices and deepfake labelling, already took effect in August 2026.
With RegTech vendors, municipalities, states and countries all layering their own rules atop this framework, tracking a single change is no longer sufficient. Firms must connect evolving legislation to the specific obligations affecting each entity, jurisdiction and use case, at scale.
Read the full AscentAI post here.
Stay ahead of the regulatory curve. Subscribe to RegTech Analyst’s newsletter for the strategic intelligence and early insight decision-makers need to navigate AI regulation before it reshapes the market.
Copyright © 2026 RegTech Analyst
Copyright © 2026 RegTech Analyst





