TechReaderDaily.com
TechReaderDaily
Live
Policy · EU Tech Regulation

EU AI Act Deadline Reset to December 2027 After Council Adopts Omnibus

With the 2 August 2026 high-risk AI deadline just weeks away, the Council's adoption of the Digital Omnibus resets the enforcement clock, though compliance obligations stay the same and the implementing-act process is now ramping up.

On 29 June 2026, the Council of the European Union formally adopted the targeted package of amendments to the EU AI Act known as the Digital Omnibus on AI, closing a legislative sprint that, just two months earlier, had looked dangerously close to collapse. The vote was the final institutional step needed before the amending regulation can be published in the Official Journal and enter into force, and it arrives with the original 2 August 2026 deadline for high-risk AI compliance sitting on the calendar like an unexploded ordnance. For the hundreds of companies building AI systems for hiring, healthcare, education, and critical infrastructure, the Council's decision means the compliance clock has been reset to December 2027, purchasing sixteen additional months that the European Commission itself concedes the market was not going to meet on the original schedule.

The amendments are the first formal revisions to Regulation (EU) 2024/1689 since its adoption in June 2024, and their path to the Council's table was notably unsteady. After two failed trilogue sessions in March and April, the Parliament and Council finally landed a compromise in the early hours of 7 May 2026, as The Next Web reported. The deal pushes the compliance deadline for high-risk AI systems classified under Annex III of the Act from August 2026 to December 2027, writes an explicit ban on AI-powered nudification applications into the regulation, and lightens documentation and conformity-assessment paperwork for small and medium-sized enterprises. The substantive risk-classification framework and the core obligations for high-risk systems were left untouched, a point the Commission has underlined repeatedly in its public statements.

The 16-month extension is concentrated on a specific subset of high-risk use cases: AI systems used in employment, worker management, access to self-employment, education and vocational training, and access to essential private and public services, including healthcare and insurance. These are the categories most European enterprises were struggling to operationalise against a 2026 deadline, Tech Times noted in its detailed breakdown of the new timeline. The delay was framed by the Commission's competitiveness agenda, championed by Executive Vice-President Henna Virkkunen, as a necessary recalibration: the regulation's ambition would be undercut if enforcement began before the market had the standards, notified bodies, and internal compliance infrastructure to absorb it.

The other headline change is the nudification ban, which received remarkably little opposition once it survived the trilogue negotiations. The provision outlaws the placing on the market, putting into service, or use of AI systems designed to create non-consensual intimate or nude imagery, carrying a compliance deadline of December 2026. Parliament negotiators, led by rapporteurs who had pushed for the ban as a standalone amendment, secured language that does not require the Commission to conduct a separate risk assessment before enforcement begins. This makes the nudification prohibition one of the earliest fully enforceable obligations under the amended Act, predating even the extended high-risk deadline by a full year.

The legislative road to the 7 May deal exposed fault lines that have become familiar to anyone tracking EU tech files. The 29 April trilogue, which ran for twelve hours and ended without agreement, collapsed primarily over a single question: whether AI systems embedded in consumer products should be exempted from the high-risk classification when the AI component is not the product's primary function. Member states, particularly those with large manufacturing sectors, had pressed for a broad product exemption. The Parliament's IMCO and LIBE committee negotiators resisted, arguing that an exemption written too broadly would create a loophole large enough to drive a factory-automation line through. The compromise that emerged on 7 May narrowed the exemption and tied it to a requirement that the AI component not pose a significant risk to health, safety, or fundamental rights when assessed independently.

For the avoidance of doubt, the omnibus does not touch the Act's prohibitions on unacceptable-risk AI practices, which took effect in February 2025, nor does it alter the obligations for general-purpose AI models, which have been enforceable since August 2025. The transparency requirements for AI systems that interact directly with natural persons remain in force, and the GPAI codes of practice, being drafted under the auspices of the European AI Office, continue on their separate track. The amendments also preserve the existing governance architecture: the AI Board, the scientific panel, and the national market surveillance authorities retain their respective roles. What changes is only the date on which the heaviest compliance lift becomes mandatory for the largest number of deployers.

This is where the implementing-act calendar comes into focus. The AI Act is not a self-executing instrument; large swathes of its operational detail are delegated to the Commission, which must adopt implementing and delegated acts specifying everything from the technical documentation template for high-risk systems to the criteria for classifying GPAI models as presenting systemic risk. The AI Office, established within the Commission's Directorate-General for Communications Networks, Content and Technology (DG CNECT), has been staffing up throughout 2025 and early 2026. Its work programme, published in quarterly tranches, sets out a rolling schedule of draft implementing acts for public consultation, followed by inter-service consultation within the Commission and eventual adoption through the comitology procedure, where member-state representatives on the relevant committee must deliver a qualified-majority opinion.

The most closely watched implementing act concerns the methodology for classifying GPAI models as posing systemic risk, a determination that triggers the Act's most demanding obligations: model evaluation, adversarial testing, serious-incident reporting, and cybersecurity requirements. The AI Office circulated a preliminary draft in March 2026 for feedback from the AI Board, and a public consultation is expected before the end of the third quarter. The draft sets thresholds based on cumulative compute used in training, measured in floating-point operations, and supplements the quantitative trigger with a qualitative assessment framework that the Office can invoke when a model falls below the compute threshold but exhibits capabilities that warrant escalation. Several member states, including France and Germany, have pushed back on the qualitative prong, arguing it introduces regulatory discretion that undermines legal certainty for developers.

Parallel to the Commission's implementing acts, the European standardisation organisations CEN and CENELEC are developing harmonised standards through their Joint Technical Committee 21 (JTC 21), which was established specifically to support the AI Act. Harmonised standards carry a particular legal weight under EU product legislation: a product that conforms to a harmonised standard enjoys a presumption of conformity with the corresponding essential requirements of the regulation. For AI system providers, this means a well-drafted standard can function as a safe harbour, reducing the burden of demonstrating compliance through alternative means. JTC 21's work programme spans risk management, data quality, transparency, human oversight, and accuracy specifications, and the first batch of draft standards entered the public enquiry phase in early 2026.

The timing of the standards pipeline matters enormously for the new December 2027 deadline. A harmonised standard only becomes effective when its reference is published in the Official Journal, and the publication process itself can take six to twelve months after the standard is formally adopted by CEN-CENELEC. If the first tranche of AI standards clears the standardisation process by mid-2027, providers will have roughly six months to align their systems before the compliance deadline bites. If the standards slip into late 2027 or early 2028, the gap between the legal obligation and the availability of a presumption-of-conformity pathway becomes a live operational problem. Several in-house counsel at affected companies have pointed to this sequencing risk in public comments, noting that the Act permits conformity assessment without harmonised standards, but the cost and legal uncertainty of doing so are substantially higher.

The GPAI codes of practice occupy an intermediate space between hard law and voluntary self-regulation. The AI Office has facilitated a multi-stakeholder drafting process modelled loosely on the GDPR codes of conduct, with working groups addressing transparency, copyright compliance, risk identification, and mitigation measures. The codes are not legally binding in themselves, but compliance with a Commission-approved code creates a presumption of conformity with the corresponding GPAI obligations, effectively making the codes the de facto compliance path for frontier model developers. The current draft, in its fourth iteration as of June 2026, has drawn criticism from civil-society organisations who argue the transparency provisions are insufficiently granular on training-data provenance, and from open-source developers who contend the risk-mitigation requirements are calibrated for closed-weight models and impose disproportionate burdens on downstream deployers of open models.

The Council's formal adoption on 29 June does not end the legislative process entirely, but the remaining steps are procedural. The amending regulation must now be signed by the presidents of both the Council and the Parliament, published in the Official Journal, and will enter into force twenty days after publication. Based on the typical cadence of EU legislative finalisation, publication is expected by late July or early August 2026. The European Parliament is expected to give its formal endorsement in a plenary vote during the July session, though the outcome of the 7 May trilogue, and the Council's adoption, makes the Parliament's vote a formality rather than a genuine decision point.

The national data protection authorities who will serve as market surveillance authorities for the AI Act in most member states have been watching the calendar with a mix of relief and frustration. The extension gives them additional runway to train staff, develop enforcement procedures, and coordinate through the AI Board, but it also delays the moment when their new regulatory powers become exercisable against the largest category of AI systems. Several DPAs, including those in Ireland, the Netherlands, and Spain, have already published AI Act readiness strategies and begun recruiting technical staff with machine-learning expertise. The Irish Data Protection Commission, which will be the lead supervisory authority for many GPAI model providers with European headquarters in Dublin, has been particularly active in building internal capacity, though its public statements have been cautious about the volume of cases it expects once the GPAI obligations are fully in force.

The question of global regulatory export, which has defined the Brussels effect discourse since the GDPR, applies with equal force to the AI Act. The extension to December 2027 aligns the EU's high-risk enforcement timeline more closely with the likely implementation schedules of AI governance frameworks under development in other jurisdictions: the UK's AI regulation bill, which is expected to receive royal assent by mid-2027; Canada's Artificial Intelligence and Data Act, currently before the Senate; and the patchwork of sectoral AI rules emerging from US federal agencies. Whether the alignment is deliberate or coincidental is a matter of interpretation, but the practical effect is that non-EU firms operating across multiple regulatory regimes will now face a more compressed window in which their compliance investments must pay off simultaneously.

What the omnibus does not address is the Act's extraterritorial reach, which remains unchanged. Any AI system placed on the EU market or put into service in the EU is covered, regardless of where the provider is established, and the same applies to deployers and importers. The GPAI obligations apply to any model placed on the EU market, even if the developer has no physical presence in the Union. The extension of the high-risk compliance deadline does nothing to narrow this geographic scope, and the Commission has shown no appetite for revisiting the jurisdictional provisions, which were among the most heavily negotiated articles during the original legislative process in 2023.

For businesses that had been sprinting toward the original August 2026 deadline, the advice from law firms tracking the file has been consistent: use the extra time, but do not treat it as a pause. A JD Supra analysis published on 2 July, just days after the Council vote, captured the sentiment in its headline: "EU AI Act Reset: More Time, Same Compliance Reality." The analysis noted that the core obligations for high-risk systems, risk management, data governance, technical documentation, record-keeping, transparency, human oversight, and accuracy, remain identical to those adopted in 2024. The extension shifts only the deadline, not the density of what must be done.

The real test of the reset will arrive in the first half of 2027, when the Commission is expected to adopt the remaining implementing acts on technical documentation, conformity assessment procedures, and the detailed specifications for post-market monitoring. If those acts are adopted on schedule and the first harmonised standards are referenced in the Official Journal by mid-2027, the extended timeline will have served its stated purpose: enabling compliance by design rather than by scramble. If the implementing acts and standards slip, the extension will have simply postponed the scramble by sixteen months. The AI Board's next plenary, scheduled for 15 September 2026, is the next checkpoint on the calendar where both tracks, the legislative amendments and the implementing-act pipeline, will be assessed together. For everyone on the file, that meeting is the one to watch.

Read next

Progress 0% ≈ 11 min left
Subscribe Daily Brief

Get the Daily Brief
before your first meeting.

Five stories. Four minutes. Zero hot takes. Sent at 7:00 a.m. local time, every weekday.

No spam. Unsubscribe anytime · Privacy.