What Changed on 7 May 2026, Direct Answer
In the early hours of Thursday 7 May 2026, Council and Parliament negotiators reached a provisional political agreement on the Digital Omnibus on AI. The headline change: Annex III standalone high-risk obligations move from 2 August 2026 to 2 December 2027. The deal remains provisional until both institutions formally adopt the consolidated text and the Official Journal publishes it ahead of 2 August 2026, but both institutions have stated intent to complete adoption in time.
Full Phased Enforcement Timeline
Who Is Affected by Annex III (2 December 2027)?
The 2 December 2027 Annex III deadline applies to providers and deployers of AI systems in the eight Annex III high-risk domains:
- Biometric identification and categorisation systems, including post-prohibition biometric systems and emotion recognition
- Critical infrastructure AI, safety components for utilities, transport, and digital infrastructure
- Education AI, systems determining access, assessing students, or monitoring examination integrity
- Employment AI, recruitment, selection, performance monitoring, task allocation, and termination tools
- Essential services AI, credit scoring, insurance risk, public benefit eligibility, emergency dispatch
- Law enforcement AI, risk assessment, profiling, evidence reliability, predictive policing
- Migration and border AI, risk assessment, document verification, asylum processing
- Justice and democratic process AI, judicial assistance, electoral influence, political advertising
The deadline applies equally to EU-based and non-EU organisations providing or deploying these systems for EU users or in EU-affecting contexts.
What Must Be in Place by 2 December 2027?
Art. 9, Risk Management System
Continuous, documented risk identification, evaluation, mitigation, and residual risk assessment. Must cover the entire AI system lifecycle.
Art. 10, Data Governance
Training, validation and testing datasets must be relevant, representative, and error-free. Documented governance practices required.
Art. 11 + Annex IV, Technical Documentation
Complete Annex IV documentation: system description, design specs, training methodology, datasets, testing results, performance metrics, post-market monitoring plan.
Art. 12, Automatic Logging
Built-in automatic logging enabling traceability. Minimum 6-month log retention.
Art. 13, Transparency to Deployers
Instructions for use covering capabilities, limitations, accuracy, oversight requirements, and output interpretation.
Art. 14, Human Oversight
Designed-in mechanisms for humans to monitor, interpret, override, and interrupt the system. Cannot be purely procedural.
Art. 27, Fundamental Rights Impact Assessment
Mandatory before deployment for public-sector and essential-service high-risk AI deployers.
Art. 43, Conformity Assessment
Internal self-assessment for most Annex III systems; notified body assessment for biometric identification systems.
EU AI Database Registration (Art. 49)
Registration of all high-risk AI systems in the EU AI public database before deployment. Article 6(3) self-assessed non-high-risk determinations must also be registered (reinstated under the Omnibus deal).
Arts. 72, 73, Post-Market Monitoring + Incident Reporting
Tiered serious-incident reporting (2-day / 10-day / 15-day). Post-market monitoring plan.
Compliance Action Plan, Runway to 2 December 2027
From May 2026 to 2 December 2027 is approximately 18 months. CEN/CENELEC harmonised standards are still being drafted (expected end-2026 at earliest). Realistic working time after standards land is roughly 12 months. That is enough time to build a defensible compliance programme, but it is not abundant time.
- Now, Generative AI providers focus on 2 December 2026: Watermarking technical architecture (Article 50(2)) and new Article 5 CSAM/NCII safety-filter documentation. Seven months out.
- Now, All organisations focus on what still hits 2 August 2026: Article 50 transparency (chatbot/deepfake/emotional-recognition disclosure), Article 49 registration readiness.
- Q3 2026, AI Inventory: Catalogue all AI systems including shadow AI. Apply Annex III criteria systematically. Document Article 6(3) classification decisions.
- Q4 2026 – Q1 2027, Risk Management + Policy Foundation: Build the Article 9 risk management system. Draft AI Risk Management Policy. Designate AI Risk Officer.
- Q1 – Q2 2027, Gap Analysis + Documentation: Assess against Articles 9–15, 17, 27 using structured checklist. Begin Annex IV technical documentation builds.
- Q2 – Q3 2027, Conformity Assessment Preparation: Internal conformity assessment for most Annex III systems; notified body engagement for biometric systems.
- By 2 December 2027, Registration and Launch: Register in EU AI database. Deploy with compliant systems, human oversight, and post-market monitoring in place.
Common Mistakes to Avoid
- Assuming the Omnibus deferred everything to 2 December 2027. It didn't. Article 50 transparency, Article 49 registration, and GPAI enforcement still apply 2 August 2026. New Article 5 CSAM/NCII prohibition and Article 50(2) watermarking hit 2 December 2026.
- Pausing work because the Annex III deadline moved. The runway after CEN/CENELEC standards publish is roughly 12 months. That is realistic time but not abundant time.
- Treating compliance as a documentation exercise rather than a technical and governance programme
- Confusing provider and deployer obligations, both have distinct requirements
- Ignoring third-party AI in your supply chain, deployers must verify vendor compliance
- Treating classification as final, risk tier must be reassessed when the system's purpose or context changes
Frequently Asked Questions
Yes, in part. On 7 May 2026, Council and Parliament reached a provisional political agreement on the Digital Omnibus on AI. Annex III high-risk obligations move from 2 August 2026 to 2 December 2027. Annex I embedded high-risk obligations move from 2 August 2027 to 2 August 2028. Article 50(2) watermarking moves from 2 August 2026 to 2 December 2026. However, Article 50 transparency obligations (most parts), Article 49 EU database registration, GPAI enforcement, Article 5 prohibitions, and Article 4 AI literacy continue to apply on their original dates. The Omnibus remains provisional until formally adopted by both institutions.
Article 50 transparency obligations (chatbot disclosure, deepfake disclosure to users, emotional-recognition disclosure), Article 49 EU database registration, and national market surveillance authority enforcement powers all apply from 2 August 2026 as originally enacted. Article 5 prohibitions remain in force from February 2025. GPAI obligations remain in force from August 2025. Article 4 AI literacy remains applicable.
Pre-existing high-risk AI systems must still comply by 2 December 2027 under the Omnibus deal, unless they qualify for the Article 111 public sector legacy exception. There is no general grandfathering for existing commercial systems. Compliance programme efforts will be considered in any penalty assessment.