Maurice Müller
Senior Content Manager
Maurice Müller is a journalist and content strategist with experience across print and digital media. At Formalize, he translates complex compliance and regulatory topics into clear, practical content for compliance, risk, and security professionals across Europe.
Key takeaways
High-risk AI obligations for stand-alone systems are deferred from August 2026 to December 2027. For AI embedded in regulated products, to August 2028.
GPAI models, general prohibited use cases, and general transparency obligations still apply on the original timeline. Only the Art. 50(2) watermarking requirements have been adjusted, with a grace period until 2 December 2026 for systems already on the market.
Only 5 to 15% of AI systems deployed across organisations fall within the EU AI Act's scope, but adjacent regulations like GDPR, NIS2, and DORA still apply to the rest.
The delay reflects the absence of finalised technical standards, not reduced regulatory expectations.
Inaction is not a strategy: inventory, classification, and governance work should already be underway.
What is the EU AI Act?
The EU AI Act (Regulation (EU) 2024/1689) is a product safety regulation that defines specific requirements for AI models and systems deployed across the EU. It is the first overarching regulatory framework for AI in Europe and applies directly across all member states, unlike a directive which requires national transposition.
The Act uses a risk-based approach, dividing AI systems into four tiers: unacceptable risk (prohibited), high risk, limited risk, and minimal risk. Most compliance obligations focus on the high-risk category.
One of the most common mistakes organisations make is treating the AI Act as a cybersecurity regulation. It is not. It is rooted in product safety law and includes explicit fundamental rights protections. This distinction matters for how organisations approach compliance, and which internal teams need to lead it. A cybersecurity team alone will not be enough.
What is the Digital Omnibus on AI, and what did it change?
The Digital Omnibus on AI is a set of targeted amendments to the EU AI Act, formally adopted in July 2026. It was part of a broader EU simplification effort, driven partly by concerns about regulatory complexity outlined in Mario Draghi's 2024 report on EU competitiveness.
The central reason for the amendment was practical: most of the technical standards needed to operationalise the AI Act's requirements for high-risk systems had not been finalised. Without those standards, organisations had no clear way to demonstrate compliance. The Omnibus extended the deadlines to align with when those standards are expected to be available.
Deadlines extended for high-risk AI systems
Stand-alone high-risk AI systems listed in Annex III (covering use cases such as recruitment tools, credit scoring, law enforcement, education, and border control) now need to comply by 2 December 2027, extended from 2 August 2026.
High-risk AI systems embedded in regulated products under Annex I (such as medical devices, machinery, and vehicles) move to 2 August 2028, extended from 2 August 2027.
New prohibitions added
The Omnibus introduces new prohibited AI practices covering systems that generate non-consensual intimate imagery and child sexual abuse material. These apply immediately.
Transparency obligations adjusted
Watermarking and synthetic content disclosure requirements under Article 50(2) now apply from 2 December 2026 for systems already on the market. New systems must comply from the date they are placed on the market.
What did not change
The AI Act's core architecture is unchanged. The risk-based classification framework, the four tiers, the obligations for general-purpose AI (GPAI) models, and the AI Office's oversight role all remain. The deadline extension does not apply to GPAI obligations or to the general prohibited use cases already in force.
Who does the EU AI Act apply to?
The AI Act distinguishes primarily between two roles along the AI value chain.
Providers are organisations that develop an AI system and place it on the market or put it into service under their own name or trademark. This includes organisations that develop AI systems purely for internal use: if you build a system that has never been on the market before and deploy it internally, you are considered a provider under the Act.
Deployers are organisations that use an AI system in a professional context. If you use an AI tool built by a vendor, you are the deployer. Your obligations depend on the system's risk classification and what your vendor is responsible for under contract.
One important nuance: if a deployer uses an AI system in a way the provider did not intend or explicitly prohibit in their terms of service (for example, applying a general-purpose tool to a high-risk use case), the deployer can become the provider of a high-risk system by default.
Determining your role for each system you use or build is the first step in any AI compliance programme. Formalize's EU AI Act compliance platform is built specifically for deployers, helping teams map AI systems, classify use cases, and maintain audit-ready documentation in one place.
What are the key compliance steps?
The deadline extension does not change the compliance work. It changes when obligations become enforceable.
Build and maintain an AI inventory
Document every AI system your organisation provides or deploys. For each system, answer: does it constitute an AI system under the Act? What is your role (provider or deployer)? Can you document and defend that reasoning in front of an auditor?
Classify each system
Determine the risk classification for each AI system based on its use case and context. Classification is not a one-off exercise. If a system changes purpose or is used in a new context, its classification may change. Note that some national guidance on AI Act classification has been criticised for treating it as a cybersecurity exercise: EU-level guidance from the AI Office should be the primary reference.
Assess your obligations and agree a RACI with vendors
For each system, determine which obligations apply and who is responsible for what. If you deploy a high-risk AI system built by a vendor, your vendor should be able to explain their compliance roadmap against the December 2027 deadline.
Translate requirements into operational governance
Requirements need to become policies, processes, training programmes, and monitoring procedures. This is not documentation for its own sake. It is the foundation for audit readiness, evidence collection, and ongoing oversight.
Monitor continuously
Compliance is not a project with an end date. AI systems change, use cases evolve, and regulatory guidance develops. Build monitoring into standard operations, not just pre-deadline sprints.
A note on SMEs and small mid-caps
Given that most EU companies are SMEs, the Digital Omnibus also broadens existing simplification measures. SMEs and startups, not just microenterprises as before, may now demonstrate compliance with certain elements of the mandatory quality management system for high-risk AI systems in a simplified way. Other relief measures have been extended to the newly created Small Mid-Cap (SMC) category, defined as organisations that are not SMEs, employ fewer than 750 persons, and have an annual turnover not exceeding €150 million or an annual balance sheet total not exceeding €129 million.
What about AI systems not covered by the EU AI Act?
This is one of the most important points to understand. According to the European Commission's own impact assessment, only 5 to 15% of AI systems deployed across organisations fall within the EU AI Act's scope.
That does not mean the rest are unregulated.
GDPR applies to any AI system that processes personal data, which covers most AI tools used in day-to-day business operations. Organisations are responsible as data controllers and/or processors for what they input into AI systems. At a minimum, this requires defining or updating internal policies, data classification criteria, and instructions for use.
NIS2 and DORA apply to organisations in their respective scope, and AI systems that touch critical infrastructure, incident management, or third-party risk are likely relevant to those compliance obligations, though the interaction between sectoral rules and the AI Act can be complex and depends on context.
Sector-specific regulations such as those covering medical devices, financial services, and critical infrastructure may also impose requirements on AI systems that fall outside the EU AI Act's scope.
International standards such as ISO 42001 and the NIST AI Risk Management Framework provide useful governance structures, but they are not equivalent to EU AI Act compliance. An organisation with a mature ISO 42001 implementation will find the AI Act compliance journey easier, but the two frameworks have different objectives and cannot be substituted for each other.
How does AI governance connect to existing GRC frameworks?
For organisations already managing NIS2, DORA, ISO 27001, or GDPR, AI governance is not a separate programme. It is an extension of existing compliance infrastructure.
The core capabilities are the same: assessing risk, mapping controls, collecting evidence, and maintaining audit readiness. What changes is the subject matter. AI systems, their use cases, and how they are governed replace the regulatory frameworks compliance teams are used to working with.
Organisations that already have structured GRC workflows are better positioned to absorb AI governance requirements because the operational model is familiar. The challenge is often not understanding what needs to happen, but connecting the right teams and making sure AI systems are inventoried and classified before they are deployed, not after.
How to get started
The practical starting point is an inventory. Before any classification, obligation mapping, or vendor due diligence can happen, you need a clear picture of what AI systems your organisation provides or deploys, what they do, and who is responsible for them.
From there, the work is largely familiar to any compliance team: classify, assess obligations, assign ownership, document, and build evidence continuously rather than in a pre-deadline sprint.
Formalize supports AI governance as part of a broader GRC framework, including AI system mapping, risk assessment workflows, incident management, and pre-built configurations for both EU AI Act deployers and organisations implementing ISO 42001. For organisations already using Formalize to manage NIS2, DORA, or ISO 27001, AI governance fits into the same structure rather than running as a separate workstream.