Blog

The AI Act after the Digital Omnibus: postponement for high-risk, firm obligations from August 2026

The Digital Omnibus shifts high-risk deadlines to 2027-2028, but transparency obligations under article 50 already apply from 2 August 2026 for organisations.

· Victor Angelier

On 24 July 2026 Regulation (EU) 2026/1744, the so-called Digital Omnibus on AI, appeared in the Official Journal. The regulation has been in force since 27 July 2026. It formally amends the EU AI Act — including Regulation (EU) 2024/1689 — and recalibrates the timeline. For organisations the essence is simple: this is not a general postponement of the AI Act, but a precise rescheduling in which some obligations are pushed back while others in fact come into force firmly in the short term.

This explanation is aimed at professionals who work with sensitive or high-trust information. The aim is sober: what changes legally, what already applies now, and how can you use the coming months to map out your AI landscape?

What the Digital Omnibus does legally

The regulation's official title shows its nature: it concerns the simplification of the implementation of harmonised AI rules. According to an analysis by Licentium, the Digital Omnibus among other things shifts the application of article 6 (high-risk classification) of the AI Act: the use cases from Annex III move to 2 December 2027 and the product-based categories from Annex I to 2 August 2028.

What is important is what does not shift. The postponement mainly concerns the heaviest high-risk layer. The transparency obligations under article 50 remain in place and take effect earlier. So anyone who reads the Digital Omnibus as "we can postpone our AI homework until 2027" is reading the regulation incorrectly. The core structure of the AI Act remains intact; only some deadlines have been rescheduled.

Transparency under article 50 already applies from 2 August 2026

On 20 July 2026 the European Commission adopted final guidelines on transparency obligations, with a start date of 2 August 2026. According to the Commission, providers must design generative and interactive AI systems in such a way that users are explicitly informed when they interact with AI, and outputs must contain machine-readable markings. Deployers, for their part, have transparency obligations concerning, among other things, emotion recognition, biometric categorisation and deepfakes.

Law firm Bird & Bird summarises the guidelines and points to four transparency obligations under article 50 that apply from 2 August 2026. The firm notes that a breach can lead to fines of up to 15 million euros or 3% of worldwide annual turnover, that providers outside the EU may also fall under the rules when their outputs are used in the EU, and that deployers — as persons under whose authority a system is used — have specific labelling obligations for deepfakes and certain AI texts.

For organisations this means a concrete inventory task. You need to know where in your landscape generative, interactive and classifying AI systems run, which role you fulfil for each system (provider or deployer), and which transparency chains — information texts, markings, policy and logging — must be operational within a few months.

The breathing space for high-risk is meant for classification

The Commission is also working on guidelines for high-risk systems under article 6. The set-up is threefold: general principles, an annex for product safety (article 6(1) plus Annex I) and an annex for use cases (article 6(2) plus Annex III). The associated consultation ran until 23 July 2026 and the final guidelines are expected by the end of 2026 — well before the application dates of 2 December 2027 and 2 August 2028 moved by the Digital Omnibus.

That sequence is no coincidence. The postponed deadlines give organisations time to classify their AI inventory along the Annex I and Annex III categories, the impact on fundamental rights and sectoral usage scenarios. For high-trust workflows in healthcare, law, finance and government that classification is not a paper exercise, but the starting point of governance: recording per workflow whether you are provider or deployer, which transparency and labelling obligations apply, which use cases are growing towards high-risk and which logging, human oversight and impact assessments go with them.

Making visible which obligation applies when

The practical challenge is that these two layers — direct transparency obligations and postponed high-risk obligations — differ per workflow. Here a verification layer such as IamVera.ai can provide support. Vera is not a chatbot and not its own language model, but a layer that can route a task through selected independent AI models and in doing so makes verification steps, corrections, mutual differences and sources visible for inspection. That gives more insight into what happens in a workflow; it supports checking rather than replacing your own judgement, and does not remove the need to review model output for errors.

For sensitive documents the Semantic Privacy Shield is relevant: pre-processing and anonymisation take place on EU infrastructure, after which the workflow is designed to send only anonymised content to the selected models. The workflow is fail-closed: if the privacy check fails, the document is not forwarded. That is an architectural choice, not a legal guarantee and not full GDPR compliance.

Where the new EU obligations call for demonstrability, such visible logging can help to show per workflow which AI Act role you fall under, which systems already fall under article 50 now and which point towards the high-risk deadlines of 2027-2028. The professional final judgement — which classification is correct and which measures suffice — remains with you.

← All articles