EU AI Act after the Omnibus: what applies now and how to use the time until December 2027
The Digital Omnibus (Regulation (EU) 2026/1744, in force since 27 July 2026) moved the EU AI Act’s high-risk dates. Annex III high-risk systems — AI used in employment, credit scoring, education, law enforcement, biometrics or critical infrastructure — now apply from 2 December 2027. AI embedded in regulated products (Annex I) follows on 2 August 2028. The penalty ceiling of EUR 35 million or 7% of global annual revenue is unchanged (Gibson Dunn summary).
Three sets of rules already apply today: the prohibited practices and the AI literacy duty (since 2 February 2025), the general-purpose AI model obligations (since 2 August 2025), and the Article 50 transparency obligations (since 2 August 2026, with a grace period to 2 December 2026 for systems already on the market).
That gives you fifteen months to build the high-risk file without a rush. Here is how to use them, phase by phase.

gantt
title EU AI Act calendar after the Digital Omnibus
dateFormat YYYY-MM
axisFormat %b %Y
section Dates
Prohibited AI + AI literacy :done, 2025-02, 2025-02
GPAI model obligations :done, 2025-08, 2025-08
Art. 50 transparency :done, 2026-08, 2026-08
Annex III high-risk :crit, 2027-12, 2027-12
Annex I high-risk :2028-08, 2028-08
section Your Actions
Classify AI systems :active, 2026-09, 2026-12
Risk assessments :2027-01, 2027-04
Technical documentation :2027-04, 2027-08
Conformity assessment :2027-08, 2027-12
Is Your AI High-Risk? A Self-Assessment
Before anything else, you need to determine whether your AI systems fall under Annex III. Use this table to check:
| High-Risk Category | Examples | Annex III Reference |
|---|---|---|
| Employment & worker management | CV screening tools, automated interview scoring, workforce monitoring, promotion algorithms | Annex III, 4(a)-(b) |
| Credit & financial assessment | Credit scoring models, loan approval automation, insurance risk profiling | Annex III, 5(b) |
| Education & vocational training | Automated grading, student admission algorithms, learning path assignment | Annex III, 3(a)-(b) |
| Law enforcement | Predictive policing, evidence analysis, suspect profiling, recidivism risk scoring | Annex III, 6(a)-(g) |
| Biometric identification | Facial recognition for access control, emotion detection in interviews, remote biometric ID | Annex III, 1(a)-(b) |
| Critical infrastructure | AI managing energy grids, water treatment, traffic control, telecom networks | Annex III, 2(a)-(b) |
| Migration & border control | Visa application screening, border surveillance, asylum claim processing | Annex III, 7(a)-(d) |
| Justice & democratic processes | Sentencing assistance tools, AI used in elections or referendum processes | Annex III, 8(a)-(b) |
If any of your AI systems touch these categories, you are subject to the full high-risk compliance framework. If you are unsure, settle it early: a short classification memo written now saves rework in 2027.
For a deeper look at the risk classification system, read our AI Risk Classification Guide.
What Compliance Actually Requires
The EU AI Act does not just ask you to be careful. It mandates specific, documented, auditable actions:
- Risk management system — a living process to identify, evaluate, and mitigate risks throughout the AI system’s lifecycle.
- Data governance — documented data quality standards, bias testing, and training data provenance.
- Technical documentation — detailed descriptions of the system’s purpose, architecture, training methodology, performance metrics, and known limitations.
- Logging requirements (Article 12) — AI agents and automated systems must maintain traceable logs of their decision-making processes. As of the April 16, 2026 guidance update, this explicitly includes agentic AI systems that take autonomous actions.
- Transparency obligations (Article 50) — chatbots must disclose their AI nature to users. AI-generated content including deepfakes must carry watermarks or machine-readable metadata. This applies since 2 August 2026; systems already on the market before that date have until 2 December 2026 for the marking duty.
- Human oversight — mechanisms that allow a human operator to understand, monitor, and override AI decisions.
- Conformity assessment — a formal evaluation that your system meets all requirements, resulting in CE marking.
- EU database registration — high-risk AI systems must be registered in the EU’s public database before deployment.
For a complete compliance walkthrough, see our EU AI Act Compliance Guide.
Your Phased Plan to December 2027
Phase 1 (now to December 2026) — Audit, classify, and meet what already applies
- Inventory all AI systems in your organization, including third-party tools and embedded AI features in SaaS products
- Classify each system against the Annex III categories above
- Identify your role for each system — are you a provider (developer) or deployer (user)?
- Assign a compliance lead — someone must own this process internally
- Review prohibited practices — confirm none of your systems fall under the 8 banned categories (these have been enforceable since February 2025)
- Check Article 50 transparency — chatbot disclosure and marking of AI-generated content apply since 2 August 2026; systems on the market before that date have until 2 December 2026
- Cover AI literacy (Article 4) — people who operate AI need training on what the system can and cannot do; this has applied since February 2025
Phase 2 (January to April 2027) — Document and assess
- Draft technical documentation for every high-risk system — architecture, training data, performance benchmarks, known limitations
- Conduct bias and fairness testing on training datasets and model outputs
- Implement logging that meets Article 12 requirements — traceable, timestamped, tamper-resistant
- Map your data governance — where does training data come from? How is it validated? How is it stored?
- Begin conformity assessment preparation — self-assessment for most categories, third-party audit for biometric systems
Phase 3 (May to August 2027) — Implement and test
- Set up post-market monitoring — how you will collect incidents and performance drift once the system is live
- Build human oversight controls — manual override capabilities, monitoring dashboards, escalation procedures
- Run the conformity assessment — complete the formal evaluation process
- Prepare CE marking documentation
- Train your staff — operators of high-risk AI must understand the system’s capabilities, limitations, and override procedures
Phase 4 (September to November 2027) — Register and verify
- Register high-risk systems in the EU database
- Conduct a final compliance review — walk through every requirement against your documentation
- Test incident reporting procedures — you must be able to report serious incidents to national authorities
- Verify third-party compliance — if you use AI tools from vendors, confirm they have completed their provider obligations
- Document everything — if it is not written down, it did not happen
Who Enforces This?
The European AI Office oversees general-purpose AI models and coordinates cross-border enforcement. National competent authorities in each EU member state handle high-risk AI system supervision. In Spain, the designated supervisory authority operates under the Agencia Espanola de Supervision de Inteligencia Artificial (AESIA).
Enforcement will be real. The penalty structure — up to EUR 35M or 7% of global revenue — is deliberately modeled after GDPR to ensure it cannot be dismissed as a cost of doing business.
Why Start Now When the Date Is December 2027
If you have not started, the most useful thing you can do this quarter is know what you are dealing with. Classify your systems. Understand your obligations. Then build a plan.
Starting early pays in four ways. You do the inventory once, at your own pace, instead of in a rush. You can choose or replace tools while contracts come up for renewal. Your documentation matures alongside the harmonised standards and AESIA guidance still being published. And the transparency and AI literacy duties already apply, so Phase 1 is useful today whatever happens to the high-risk date.
For detailed guidance, start with our comprehensive EU AI Act resource page.
Sources: Gibson Dunn — EU AI Act Omnibus: postponed high-risk deadlines, European Commission — AI Omnibus enters into force, artificialintelligenceact.eu, legalnodes.com, secureprivacy.ai
Related reading
- EU AI Act timeline and key dates
- AESIA: What Spain’s AI Watchdog Means for Your Business
- EU AI Act Compliance Guide 2026: What Spanish SMEs Must Do Now
- GDPR and AI Convergence in 2026: Why Local Deployment Is the Only Clean Answer
- Grab the template: Prohibited practices checklist (Article 5).
- Grab the template: AI transparency notice template.
Need Help Getting Compliant?
VORLUX AI offers a free compliance assessment consultation for EU-based companies. We will review your AI systems, classify your risk level, and give you a clear action plan — no strings attached.
Book your free assessment or email us at hello@vorluxai.com. You have until December 2027. Use the time well.