Don’t do SECURITY. Do business SECURELY.

EU AI Omnibus in force: high-risk obligations deferred

Amendments to the EU AI Act defer high-risk obligations and soften the AI literacy duty.

The AI Omnibus amendments to the EU AI Act enter into force today, adjusting the timetable and some obligations.

Key changes

  • High-risk obligations for Annex III systems (such as AI used in employment, credit and education) are deferred to 2 December 2027.
  • High-risk obligations for AI in products covered by Annex I harmonisation legislation are deferred to 2 August 2028.
  • The AI literacy duty is softened to “taking measures to support” AI literacy.
  • Transparency obligations under Article 50 still apply from 2 August 2026.

The extra time is welcome, but it is not a reason to pause. Organisations that develop or deploy potentially high-risk AI should use it to put a robust AI management system in place, for example based on ISO/IEC 42001, ready for the new deadlines.

Source: Regulation (EU) 2026/1744 – Digital Omnibus on AI (EUR-Lex)

This update is general information, not legal advice. If you would like help assessing the impact on your information security or privacy programme, contact us.

More insights