If you've been tracking the EU AI Act's August 2026 deadline, the ground shifted under it this month. Here's what the Digital Omnibus on AI actually changed, what it didn't, and what that means if your business touches EU customers, EU data, or EU-facing AI systems.
## What just happened
The European Parliament formally endorsed the Digital Omnibus on AI on 16 June 2026, the Council of the EU gave its final sign-off on 29 June, and the regulation is now formally adopted. It enters into force three days after publication in the EU's Official Journal, which is expected in the second half of July 2026 — comfortably ahead of the original 2 August 2026 deadline it amends.
This is the first substantive set of amendments to the EU AI Act (Regulation (EU) 2024/1689) since it entered into force in August 2024. It followed a failed trilogue in April 2026 and a political agreement reached on 7 May 2026, after the co-legislators accepted that the technical standards and conformity assessment infrastructure needed to make the high-risk rules workable were not going to be ready in time.
## What actually moved
Standalone high-risk AI systems (Annex III) — covering employment decisions, credit scoring, biometrics, critical infrastructure, education, migration and law enforcement — now have until 2 December 2027 to comply, deferred from 2 August 2026. That's a 16-month extension.
AI embedded in regulated products (Annex I) — medical devices, machinery, toys and similar — moves to 2 August 2028, deferred from 2 August 2027.
Watermarking and synthetic content labelling (Article 50(2)) gets a shorter runway: systems already on the market before 2 August 2026 have until 2 December 2026 to comply, a four-month grace period rather than the full delay.
National AI regulatory sandboxes, which Member States were due to establish by 2 August 2026, now have until 2 August 2027.
## What didn't move
This is the part worth sitting with, because it's easy to read "16-month delay" as "problem solved for two years."
Transparency obligations (the rest of Article 50) — informing people they're interacting with an AI system, disclosing emotion-recognition or biometric categorisation use — still apply from 2 August 2026, unchanged. If your AI-driven customer service, HR screening, or content tools interact with people, this is a live deadline in weeks, not years.
General-purpose AI model obligations (Articles 51–55) have applied since 2 August 2025 and the Omnibus doesn't touch them. If your business builds on foundation models, those provider-level duties are already in force.
The core architecture is intact. Risk classification, the four-tier system, conformity assessment requirements, EU database registration, and penalty tiers (up to €35 million or 7% of global turnover for prohibited practices, €15 million or 3% for high-risk non-compliance) are unchanged — only the calendar moved.
The Omnibus also adds a new prohibited practice: AI systems used to generate non-consensual intimate imagery or child sexual abuse material are now explicitly banned under Article 5, with a transitional period to 2 December 2026.
## What this means if you're a UK business
The EU AI Act has extraterritorial reach in the same way GDPR does — it applies based on where an AI system's outputs land, not where the business is registered. A UK company whose AI-powered product is used by EU customers, or whose AI output is consumed in the EU, remains in scope regardless of the Omnibus.
The practical risk isn't the delay itself. It's what businesses do with it. Sixteen months is genuinely useful time to build a governance framework properly rather than rushing one together in July 2026. It is not sixteen months to do nothing and hope the next Omnibus moves the date again.
The classification work — identifying every AI system in use, working out which Annex III category (if any) it falls into, documenting human oversight and data governance — doesn't get easier with time. It gets harder to reconstruct from scratch under pressure once notified bodies have queues and the December 2027 date is close.
## Where ISO 42001 fits
ISO 42001 isn't mandated by the EU AI Act, but it was built to answer the same underlying questions: what AI are you running, who's accountable for it, how are risks assessed and treated, and what evidence exists that oversight is real rather than a policy document nobody reads. That framework doesn't change when an EU application date moves. Businesses that build an AI management system now arrive at December 2027 — or August 2028, or whatever the next Omnibus lands on — with the substance already in place, rather than a compliance sprint against a hard deadline.
It's also the same framework UK sector regulators are increasingly pointing to when they ask about AI governance, which isn't affected by EU timeline changes at all.
If you're not sure whether the Omnibus changes anything for your business specifically, get in touch — that's a five-minute conversation, not a project.
Frequently asked questions
Has the EU AI Act's August 2026 deadline been cancelled?
No. The Digital Omnibus on AI defers specific obligations — it does not repeal the Act. Standalone high-risk AI systems under Annex III (recruitment, credit scoring, biometrics, critical infrastructure, education, law enforcement) now have until 2 December 2027 to comply, moved from 2 August 2026. AI embedded in regulated products under Annex I (medical devices, machinery, toys) moves to 2 August 2028.
What EU AI Act obligations still apply from 2 August 2026?
Article 50 transparency obligations remain on schedule from 2 August 2026 — informing people when they are interacting with an AI system, chatbots disclosing their nature, and similar disclosure duties. General-purpose AI model obligations under Articles 51 to 55 have applied since 2 August 2025 and are unaffected by the Omnibus. Watermarking of AI-generated content (Article 50(2)) gets a shorter, four-month grace period to 2 December 2026 for systems already on the market.
Does the Digital Omnibus mean UK businesses can stop preparing for the EU AI Act?
No. The deferral gives more time to prepare properly, not a reason to stop. The risk-based classification system, the conformity assessment regime, and the underlying obligations are unchanged — only the application dates moved. UK businesses whose AI systems or outputs reach EU customers are still in scope, and the practical work of identifying, classifying and governing AI systems takes months regardless of which deadline applies.
How does ISO 42001 relate to the EU AI Act Omnibus changes?
ISO 42001 is not legally required by the EU AI Act, but its framework — risk assessment, human oversight, data governance, documented accountability — maps closely to what the Act asks for regardless of the exact date. Building an AI management system now means the December 2027 and August 2028 deadlines become a formality rather than a scramble, and the same system also satisfies UK sector regulator expectations, which are not affected by EU timeline changes.
Ready to talk about your business?
Book a free, no-obligation call. We will tell you exactly what certification would involve for your size, sector, and starting point.
