Follow us
Breaking
Tech News

The Digital Omnibus shifts the EU AI Act compliance focus

Regulation (EU) 2026/1744 resets timelines for high-risk Annex III systems to 2 December 2027. This update provides a reprieve for businesses regarding recruitment and credit scoring AI while maintaining strict transparency rules for chatbots.

Share

The Digital Omnibus for AI, which was formally adopted as Regulation (EU) 2026/1744 and entered into force on 27 July 2026, clarifies that high-risk obligations for stand-alone Annex III systems apply from 2 December 2027. This legislative update resets the timeline for many high-risk AI categories. High-risk systems in Annex III, which cover recruitment, credit scoring, and education, follow this new December 2027 date. High-risk AI embedded in products under Annex I, such as toys or medical devices, follow the 2 August 2028 deadline. The original August 2, 2026, deadline for these high-risk systems no longer applies.

The rules for transparency under Article 50 remain in effect as of 2 August 2026. This includes requirements to disclose when humans interact with chatbots. Generative AI systems already on the market before August 2, 2026, follow a four-month grace period for watermarking requirements. This allows compliance for these systems until 2 December 2026.

I see these changes as a reprieve for businesses.

Prohibited AI practices, such as social scoring and manipulative AI, became effective in February 2025. The prohibition on AI systems that generate non-consensual intimate content or child sexual abuse material comes into effect in December 2026. The AI Office holds enforcement powers over GPAI models and can request technical documentation or issue fines.

Evaluating compliance software options

I recommend selecting a system of record before you evaluate a runtime control plane. You need to decide on your system of record first, then decide whether your highest-risk workflows need a runtime control plane.

Category Primary Job Examples Strongest EU AI Act Fit
GRC automation Program management Vanta, Drata, Secureframe Cross-framework evidence
Enterprise AI governance Discovery and impact assessments OneTrust, Credo AI, Holistic AI, IBM Articles 9 and 11
LLM / agent observability Developer logging LangSmith, Langfuse, Arize, W&B Article 12
Runtime control plane Enforce policy at execution KLA Article 14 and 12

Centralizes controls, automates evidence, and supports continuous compliance. It tracks AI systems and flags gaps.

Credo AI and Holistic AI work for model documentation and compliance. IBM watsonx.governance helps with observability. KLA acts as the runtime layer for high-stakes execution. I find KLA lacks the multi-framework orchestration found in Vanta.

Compliance depends on your role. Providers develop systems. Deployers use the systems in professional settings. Non-EU providers must appoint an authorized representative within the EU to handle compliance. Deployers of high-risk systems must use the system according to provider instructions, assign human oversight, and retain logs for six months.

High-risk obligations and penalties

The EU AI Act imposes significant financial penalties for non-compliance. Fines scale based on the severity and type of violation.

Violation Type Max Fine (€) Max % of Global Annual Turnover
Prohibited AI practices €35 million 7%
Non-compliance with duties €15 million 3%
Misleading information €7.5 million 1%
GPAI model violations €15 million 3%

Prohibited practices face the highest fines. These include social scoring and manipulative AI. Failing to meet high-risk obligations results in fines of up to €15 million or 3% of global turnover. Providing incorrect or misleading information can trigger fines of up to €7.5 million or 1% of turnover.

The AI Office enforces rules. National authorities oversee other AI systems.

The Commission also manages the AI Office, which holds enforcement powers over GPAI models. It can request technical documentation, evaluate models, and issue fines. High-risk AI systems must meet requirements for risk management, data quality, and human oversight. The definition of a safety component clarifies that an AI system only qualifies as a safety component if its intended purpose is to prevent or mitigate risks to health or safety. Systems designed for user assistance or performance optimization do not qualify.

Regulators consider duration, intent, and financial benefit when determining penalties. They also evaluate cooperation and previous violations. For small and mid-cap enterprises (SMCs), the law offers simplified technical documentation and reduced fines.

Does the delay for high-risk systems mean companies should stop preparing for the August 2026 transparency deadline?

Share

Technewsdaily

Senior tech writer covering AI, gadgets and cybersecurity. Breaking down the news that matters, every day.