The Digital Omnibus moved the full high-risk obligations to 2 December 2027, and most boards I speak to have quietly filed that under good news. It is the most expensive misreading of the year.
Here is what actually happened. The Commission tabled the Digital Omnibus in November 2025, and on 7 May 2026 the co-legislators reached a provisional agreement that replaces the original schedule for high-risk systems with fixed dates. Standalone Annex III high-risk systems, which were due to become subject to the full obligations on 2 August 2026, now have until 2 December 2027. High-risk systems embedded in regulated products under Annex I move from 2 August 2027 to 2 August 2028. Note that the agreement is provisional pending formal adoption, so the final published dates should be checked against the adopted text, but the direction is settled: roughly sixteen months of extra runway for the Annex III cohort.
The trap is treating that runway as delay. A deferral you spend is preparation. A deferral you bank is complacency with a due date. And the specific obligations that were pushed back are precisely the ones that take longer to build than the deferral bought.
Free · 4 minutes
Do you know where AI is already being used in your business — and what it can see?
Fourteen questions on shadow AI, data exposure, oversight, and governance debt — the gap between how fast AI is arriving and how much control you have over it. Banded finding on screen, full sheet by email.
The arithmetic the reprieve does not change
Count backwards from 2 December 2027. If you are the provider of an Annex III system, on that date you need a conformity assessment completed, technical documentation to Annex IV standard, a functioning quality management system under Article 17, and a data-governance regime under Article 10 that you can evidence, not merely assert. Those are not documents you write in the final quarter. They are systems that have to have been operating long enough to produce a record.
A quality management system that was stood up eight weeks before the deadline is not a quality management system. It is a folder. The whole point of Article 17 is that quality management is a continuous process with a history: version control on models, documented change decisions, logged deviations, corrective actions closed out. A supervisor asking to see it in 2028 will look for the trail, and a trail that starts in October 2027 tells its own story. The obligation is not to possess the system on the day; it is to have been running it.
The same logic governs the Article 9 risk management system, which the Act describes as a continuous, iterative process run across the entire lifecycle. Iterative processes need iterations. You cannot compress a lifecycle discipline into a sprint and call it evidence.
Data governance is the genuinely long-lead item
If one obligation defines whether you make the deadline, it is Article 10. It asks whether your training, validation and testing data were subject to appropriate governance: relevant, sufficiently representative, examined for bias, and appropriate to the intended purpose. For most firms this is not a compliance task. It is a data-engineering project with a compliance output, and it is the item that consistently gets under-scoped.
The reason it takes so long is that the answers are usually not knowable from where you stand today. Where did this dataset come from? What is its provenance and its licensing basis? Who labelled it, against what definition, and how was label quality checked? Has it been assessed for the biases relevant to the people the system will affect? For a model already in use, reconstructing that lineage after the fact is slow, and sometimes the honest answer is that the record does not exist and the data has to be regathered or the model retrained on a defensible basis. That is a multi-quarter piece of work, and it overlaps directly with the data-provenance duties you already carry under other instruments, which is why the AI Act and GDPR pull on the same evidence and are best worked together rather than as two projects.
Start the data-governance work in 2027 and you are not building a governance regime. You are writing a description of whatever you happened to have, and hoping it holds.
What the deferral did not touch
One point that gets lost in the relief. The Digital Omnibus moved the high-risk obligations; it did not move everything. The Article 50 transparency duties — telling people they are interacting with an AI system, labelling synthetic content — remain on their existing footing, with 2 August 2026 as the operative date. The prohibited-practice bans and the general-purpose AI model obligations already applied in 2025. If your relief about 2027 has caused you to relax about the whole Act, you have misread the scope of what changed. The Digital Omnibus deferrals are surgical, not general.
What to start in 2026, and in what order
The sequencing matters as much as the start date, because the long-lead items feed the short-lead ones.
- Classify first, honestly. You cannot plan the build until you know which of your systems are Annex III high-risk. That is a scoping exercise against Article 6 and Annex III, and it is worth having a system inventory mapped to the risk tiers before you argue about deadlines. The wrong answer here invalidates everything downstream.
- Audit data lineage next. For each high-risk system, establish what you can actually evidence about the data today. This surfaces the regather-or-retrain decisions early, while there is still time to make them calmly.
- Stand up the quality management and risk processes so they accrue a record. Article 17 and Article 9 both need operating history. Begin them in 2026 and the 2027 documentation writes itself from real logs rather than from memory.
- Leave technical documentation and conformity assessment last, deliberately. Annex IV documentation is a rendering of the systems above. It is the fastest of the four to produce once the others exist, and close to impossible to produce well if they do not.
The order is the argument. The item that looks like the deliverable — the documentation pack — is the one you build last, because it is downstream of everything the deferral was supposed to give you time for.
The internal conversation to have now
When someone in your organisation says the deadline moved to 2027 so there is no rush, the reply is a single question: how many months of operating evidence does an Article 17 quality management system need before a supervisor will accept it, and when do we therefore have to start. Work that backwards and 2027 stops looking like a reprieve and starts looking like a delivery date with the slack already spent.
The Omnibus did not buy you time to wait. It bought you time to build, and only just enough of it. Spend it in 2026 or hand your 2028 supervisor a documentation pack with no history behind it and find out what a thin evidence base is worth.
Most technology problems are not technology problems. They are control problems.
The systems exist. The investment has been made. The question is whether leadership can understand, direct, evidence, and sustain what those systems produce. Find out where control exists — and where it only appears to.
Full Governance by Sixteen Pillars
Govern your business. Prove your compliance.
A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.
See what's coming