Analysis · 3 min read

The Compliance Calendar: What the EU AI Omnibus Changes for High-Risk Deployments

Regulation (EU) 2026/1744 entered force July 27, 2026, delaying standalone high-risk AI obligations to December 2, 2027 and embedded product AI to August 2, 2028 while adding nudifier bans and expanded AI Office oversight.

By Classy AI News · July 28, 2026

The Compliance Calendar: What the EU AI Omnibus Changes for High-Risk Deployments

European AI compliance teams woke up Monday to a new statute book. Regulation (EU) 2026/1744—the Digital Omnibus on AI—entered into force on July 27, 2026, rewriting key deadlines and obligations under the EU AI Act without replacing its core safety architecture.

For enterprises that built 2026 compliance programs around the original August deadlines, the Omnibus is less a repeal than a calendar reset with sharper bans and broader AI Office powers.

Modern technology and innovation backdrop

What changed on day one

The European Commission confirmed the Omnibus entered into force across the EU on July 27, three days after publication in the Official Journal on July 24. From that date, amendments become part of the AI Act text—though not every amended provision is immediately enforceable.

The most consequential timeline shifts:

CategoryNew application date
Standalone high-risk AI (Annex III)2 December 2027
High-risk AI embedded in regulated products (Annex I)2 August 2028

Stand-alone systems—including many enterprise classifiers, HR tools, and credit models—gain roughly 16 additional months beyond the original 2 August 2026 high-risk deadline. Embedded systems in machinery, medical devices, toys, and lifts gain even longer.

Transparency obligations for general-purpose and generative systems still apply from 2 August 2026, with a grace period until 2 December 2026 for machine-readable marking on generative systems already on the market.

What did not wait

The Omnibus is not a deregulation package. New prohibitions took effect with the instrument, including bans on AI systems that generate non-consensual intimate imagery and child sexual abuse material—the "nudifier app" ban referenced in parliamentary debate.

Other July 27 changes include:

  • Extended simplified obligations from SMEs to small mid-cap companies
  • Expanded regulatory sandboxes, including an EU-level sandbox for supervised testing
  • Explicit permission to process special-category personal data for bias detection and correction under safeguards
  • Extended AI Office oversight over general-purpose-model-based systems on large online platforms

Freshfields, in a July analysis, advised enterprises to confirm whether AI-embedded products fall under Annex I sectoral legislation—a classification that now determines whether compliance lands in 2027 or 2028.

Futuristic virtual reality and digital interface concept

Why robotics and industrial AI should read closely

Annex I covers AI embedded in machinery and other regulated physical products. Humanoid robot makers deploying AI on factory floors in Europe may face a longer conformity-assessment runway—but only if their systems qualify as embedded product safety components rather than standalone Annex III deployments.

That distinction is product-specific. A warehouse scheduling model may be Annex III in 2027; an AI stack inside a CE-marked industrial robot may be Annex I in 2028. Legal teams cannot assume one timeline for an entire robotics portfolio.

The strategic read

Brussels framed the Omnibus as "targeted simplification" preserving "strong safeguards for people's safety and fundamental rights." In practice, it buys implementers time while tightening certain prohibitions and centralizing oversight through the AI Office.

U.S. frontier labs, meanwhile, spent the same week negotiating government vetting for cybersecurity-capable model releases—a different regulatory grammar entirely. Multinational AI vendors now operate across at least two clocks: Washington's pre-release review for frontier models and Brussels' phased AI Act with freshly adjusted dates.

Compliance leaders should rebuild program timelines around 2 December 2027 and 2 August 2028, not retire them. The Omnibus extended deadlines. It did not eliminate obligations.

Programmer and designer collaborating on software development

### Sources

Newsletter

Get the dispatch

One field. One email when we publish. Privacy.