Co-Founder and VP Product Strategy & Customer Experience
Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on July 27, 2026, days before the original 2 August 2026 deadline for high-risk AI systems. The headline change is a delay: obligations for stand-alone high-risk systems listed in Annex III, such as AI used in employment decisions, now apply from December 2nd, 2027. Systems embedded in products covered by sector legislation follow on August 2nd, 2028.
What did not change is just as important. The Article 50 transparency obligations, which require disclosure when people interact with an AI system and labeling of AI-generated content, applied on schedule from August 2026. Watermarking duties for systems already on the market follow on December 2nd, 2026, alongside new prohibited practices. Obligations for general-purpose AI models have applied since August 2025.
The delay was tied to the availability of harmonized standards and national supervisory structures, not to a view that organizations need less preparation. A significant part of preparing for high-risk compliance depends on understanding and governing the data AI systems rely on - and that work takes time:
Building the inventory may be the most straightforward task. The other three become considerably more challenging for unstructured content: the contracts, reports, emails and archives that assistants increasingly draw on.
Treat the delay as a chance to build a durable governance foundation rather than a last-minute compliance project. Three steps pay off whatever the final standards look like:
This work is also reusable. Inventories, lineage and access controls serve GDPR, NIS2 and internal risk programs as much as the AI Act.
The Omnibus moved a date, not the destination. The organizations that will meet December 2027 comfortably are the ones that start on their data foundations in 2026.
Want to assess your AI data inventory and lineage readiness? Talk to our specialists.
Sources