← Back to blog
EU AI Act Omnibus extends deadlines. High-risk AI systems get more time.

SEP 20, 2026  ·  OptimusWay Team  ·  5 MIN READ

EU AI Act Omnibus extends deadlines. High-risk AI systems get more time.

EU AI Act Omnibus extends compliance deadlines for high-risk AI systems. Stand-alone systems must comply by Dec 2, 2027, embedded by Aug 2, 2028. This offers vendors more time.

Quick answer

What are the new compliance deadlines for high-risk AI systems under the EU AI Act Omnibus?

The EU AI Act Omnibus extends compliance deadlines for stand-alone high-risk AI systems to December 2, 2027, and for high-risk systems embedded in regulated products to August 2, 2028. These updates provide software vendors with additional time to meet the stringent regulatory requirements.

The European Union’s regulatory landscape for artificial intelligence continues to evolve, with recent clarifications offering a revised timeline for compliance. While the core principles of the EU AI Act remain steadfast, a series of amendments, often referred to as the “AI Act Omnibus,” have adjusted key deadlines, providing a crucial window for software vendors to adapt their high-risk AI systems. This adjustment aims to balance robust oversight with practical implementation challenges faced by the industry.

What are the new compliance deadlines for EU AI Act high-risk systems?

The EU AI Act Omnibus has officially pushed back several critical compliance dates for high-risk AI systems. Following the Council of the EU’s final approval, stand-alone high-risk AI systems, such as those used in recruitment or credit scoring, now face a compliance deadline of December 2, 2027. For high-risk AI systems embedded as safety components in regulated products like medical devices or machinery, the deadline has been extended to August 2, 2028. This provides an additional 16 months for stand-alone systems and 12 months for embedded systems compared to earlier proposals, as confirmed by legal analyses from Ogletree Deakins. The full text of the EU AI Act, Regulation (EU) 2024/1689, was published in the Official Journal of the European Union on July 12, 2024, with various provisions entering into force at different stages.

Here’s a summary of key deadlines:

System TypeNew DeadlineExtension Duration (from original proposal)Stand-alone high-risk AI (Annex III)2 Dec 202716 monthsEmbedded high-risk AI (Annex I / safety components)2 Aug 202812 monthsAI content labeling (new tools)2 Aug 2026No changeAI content labeling (existing tools)2 Dec 2026New deadline“Nudifier” & CSAM ban2 Dec 2026New prohibitionArticle 50 transparency (generative AI watermarking)2 Dec 2026Grandfathering rule for pre-existing systems

How do these deadlines impact AI tools used in employment contexts?

AI tools deployed in employment contexts, including those for recruitment, performance evaluation, worker monitoring, or decisions related to promotion and termination, are classified as Annex III stand-alone high-risk systems. Consequently, these systems are subject to the extended compliance deadline of December 2, 2027. While some transparency obligations, such as labeling under Article 50, may apply earlier for new tools (August 2, 2026), the comprehensive high-risk compliance requirements for employment AI align with the later December 2027 date. This clarification is crucial for HR tech providers and enterprises utilizing such solutions, ensuring they focus their full compliance efforts on the correct timeline.

What are the financial and compliance implications for software vendors?

The extended deadlines offer a significant reprieve for many software vendors, delaying immediate compliance costs and allowing more time for strategic planning. According to a 2026 Modulos AI industry survey, approximately 63% of EU software vendors selling stand-alone AI systems reported they were not yet compliant with high-risk obligations as of Q2 2026, citing the complexity of conformity assessments and lack of Quality Management System (QMS) frameworks. The European Commission’s impact assessment from 2026 estimates that the Omnibus amendment will delay compliance costs by an estimated €1.2, €1.8 billion across the EU software sector. This reduction in immediate financial pressure benefits around 4,500 AI providers, though it also extends the period of regulatory uncertainty as companies continue to navigate the evolving requirements.

What is the “grandfathering rule” and how does it apply to existing AI systems?

The EU AI Act includes a “grandfathering rule” that provides clarity for systems already on the market. AI systems placed on the EU market before the new compliance deadlines are generally not subject to the full high-risk requirements of the Act. This exemption applies unless these systems undergo a “substantial modification” after their respective deadlines. A substantial modification typically refers to changes that alter the system’s performance, purpose, or risk profile. This provision is designed to prevent retroactive application of the most stringent rules to legacy systems, while still ensuring that significant updates or new deployments meet the latest regulatory standards.

What other key provisions were introduced or clarified by the Omnibus?

Beyond the high-risk system deadlines, the AI Act Omnibus introduced or clarified several other important provisions. These include specific timelines for AI content labeling: new tools must comply by August 2, 2026, while existing tools have until December 2, 2026. A new prohibition on “nudifier” applications and the generation of Child Sexual Abuse Material (CSAM) also takes effect on December 2, 2026. Furthermore, Article 50 transparency obligations, which include requirements for generative AI watermarking, will apply from December 2, 2026, for pre-existing systems, under a grandfathering rule. These provisions underscore the EU’s commitment to addressing ethical concerns and ensuring transparency across various AI applications.

For founders and tech leads, the extended deadlines are not an invitation to delay, but rather an opportunity to strategically prepare.

  1. Conduct a thorough AI system audit: Identify all AI systems currently in use or under development that fall under the “high-risk” classification (Annex III for stand-alone, Annex I for embedded) and assess their current compliance readiness against the December 2, 2027, and August 2, 2028, deadlines.

  2. Prioritize transparency obligations: Ensure that all AI content labeling and generative AI watermarking capabilities (Article 50) are on track for compliance by December 2, 2026, especially for pre-existing systems.

  3. Develop a robust QMS framework: Leverage the additional time to establish or refine a Quality Management System (QMS) that can support the ongoing conformity assessments and documentation required for high-risk AI systems, mitigating the risk of non-compliance.

Following this in Poland specifically

Poland is moving in parallel with its own national AI law, transposing the EU Regulation into domestic legislation with a dedicated supervisory authority. For teams building or deploying AI systems in the Polish market, that national layer, and its own enforcement timeline, matters as much as the EU-level Omnibus changes. See how the Polish AI bill moved through the Senate and on to the President's desk for the legislative detail.

The Omnibus package also sits inside a broader EU push on digital sovereignty, including the new Cloud and AI Development Act aimed at European cloud infrastructure. If your product runs on EU cloud infrastructure or serves public-sector clients, that's a separate compliance track worth understanding, see what the Cloud and AI Development Act means for cloud vendors and their business customers for the market angle.