The EU AI Act: The Digital Omnibus, the Current Timeline, and What to Do Now (Part II of II)

Part 1 of this series covered where EU AI Act enforcement genuinely stands today: prohibited practices enforceable since February 2025, general-purpose AI obligations running since August 2025, the Commission’s first formal investigations opened in June 2026 into hiring, credit scoring, and student monitoring AI systems, and full enforcement and fining authority active since August 2026. In Part 2, we look at what the Digital Omnibus changed, lay out the current compliance timeline across the Act’s different obligation tracks, and translate all of it into practical steps for compliance and legal teams.
What the Digital Omnibus Actually Changed
The Digital Omnibus on AI, formally EU Regulation 1744/2026, became applicable on July 27, 2026, and its purpose was explicitly to simplify implementation, reduce regulatory duplication with existing EU frameworks, and give certain obligation categories more runway before enforcement applies. It’s important to understand this as a targeted recalibration, not a broad retreat from the Act’s core structure.
The most significant change involves high-risk AI systems under Annex III, the category covering AI used in contexts like employment decisions, credit and financial access, education, and law enforcement-adjacent applications. Those obligations were originally set to apply starting August 2, 2026, alongside everything else. The Digital Omnibus pushed that deadline back sixteen months, to December 2, 2027. Separately, the obligation requiring providers of AI systems that generate or manipulate synthetic content to mark their outputs as artificially generated was deferred by four months, from August 2026 to December 2026. And the requirement that each EU member state establish at least one national regulatory sandbox was pushed back a full year, from August 2026 to August 2027.
The Digital Omnibus wasn’t purely about extending deadlines, though. It also added new prohibitions to the Act, most notably banning AI systems that generate non-consensual intimate imagery of real people or produce child sexual abuse material, including AI tools capable of digitally removing clothing from existing photos to create fabricated intimate images. That prohibition takes effect this December. The Omnibus also introduced tailored accommodations for small and mid-cap enterprises, and clarified certain aspects of the AI Office’s supervisory role across the different obligation categories.
The Current Timeline, Track by Track

Given how fragmented these deadlines have become, it’s worth laying out the current state of play by obligation category rather than treating the AI Act as a single compliance date.
Prohibited AI practices: enforceable since February 2025, with full Commission fining authority active since August 2026. This track is fully live and has been for well over a year.
General-purpose AI model obligations: transparency, copyright, and safety requirements have applied since August 2025, with the most advanced models already submitting monthly systemic risk evaluations. Full enforcement authority, including fines up to 15 million euros or 3 percent of global turnover, has been active since August 2026.
AI transparency toward end users, including chatbot and voice agent disclosure requirements and synthetic content labeling: these obligations are live now for interactive AI systems; the specific synthetic content marking obligation was deferred to December 2026 under the Digital Omnibus.
High-risk AI systems under Annex III: deferred to December 2027, a substantial extension, but one that applies only to this specific category, not to the Act as a whole.
Regulatory sandboxes at the member-state level: deferred to August 2027.
New CSAM and non-consensual intimate imagery prohibitions: take effect December 2026.
What This Means for Compliance Teams Right Now
The practical implication of this fragmented timeline is that companies need a genuinely granular understanding of which of their AI systems and use cases fall into which track, because a blanket assumption that “we have until 2027” is likely wrong for a meaningful portion of any organization’s actual AI footprint. Any AI system that could plausibly fall within the prohibited practices categories, manipulation, exploitation of vulnerabilities, problematic biometric or social scoring, individual predictive policing, needs immediate review, not a 2027 review cycle, given that this track has been enforceable for well over a year and the Commission is already investigating.

Any organization deploying customer-facing chatbots, voice agents, or other interactive AI systems to EU users needs to confirm those systems clearly disclose their AI nature at the start of every interaction, regardless of where the deploying company itself is headquartered. This obligation turns on where your end users are located, not on your own corporate domicile, which means U.S. companies with EU customers or users are squarely in scope even without any EU physical presence.
Organizations building on top of, fine-tuning, or heavily customizing general-purpose AI models need to map their specific downstream provider obligations under the GPAI transparency rules, and should be tracking whether any foundation models they rely on are among those already subject to the enhanced systemic risk evaluation requirements.
For high-risk AI systems specifically, the December 2027 deadline is real relief, but it shouldn’t translate into inaction. Conformity assessment processes, documentation, and risk management systems for high-risk AI take real time to build properly, and organizations that wait until late 2027 to start will be racing a deadline that arrives faster than it currently feels. Given how the AI Office has structured its first wave of investigations, hiring tools, credit scoring, and student monitoring systems specifically, organizations operating AI in those three categories should treat this as a strong signal about where the regulator’s early enforcement attention is concentrated, even ahead of the formal Annex III deadline.
The Bottom Line
The EU AI Act has moved decisively from a future compliance obligation to a present, actively enforced regulatory regime, even as the Digital Omnibus has given real breathing room to specific tracks like high-risk systems. Compliance officers need to resist the temptation to treat the Digital Omnibus’s deadline extensions as blanket relief. Prohibited practices, GPAI obligations, and end-user transparency requirements are enforceable today, the Commission has already opened investigations, and the fining authority behind all of this, up to 7 percent of global turnover for the most serious violations, is now fully active. Build your compliance roadmap around the actual, track-by-track timeline, not around a single AI Act deadline that no longer exists as a unified concept.











