The EU AI Act: what the 2027 deferral means for security and conformity teams.
The Digital Omnibus, formally adopted June 2026, moved the high-risk deadlines — but not the prohibitions, not the GPAI obligations, and not the scale of what conformity requires. Seventeen months of runway is preparation time, not a reprieve.
What moved — and what didn't.
Annex III AI systems: biometrics, critical infrastructure, employment, credit, law enforcement, and other listed uses.
AI embedded in products already covered by EU product-safety regulation (Annex I).
Social scoring, manipulative techniques, untargeted facial-image scraping, and other banned uses. Maximum penalty tier applies.
Transparency, documentation, and copyright obligations for general-purpose AI model providers.
Disclosure duties for chatbots, synthetic content, emotion-recognition, and deepfakes. Attaches by function, not risk tier — untouched by the Digital Omnibus deferral. Read the full brief →
What does high-risk conformity actually require?
For providers, Articles 9–17 define the obligations: a risk management system operating across the AI lifecycle, data governance for training and testing sets, technical documentation, automatic record-keeping, transparency to deployers, human oversight design, and accuracy, robustness, and cybersecurity requirements. Article 26 adds deployer obligations — usage monitoring, input-data relevance, and human oversight assignment.
The strategic framing: 17 months of runway is preparation time. Conformity assessments for complex AI systems take quarters, not weeks. Organizations that begin now avoid the 2027 assessor capacity crunch — the same dynamic FedRAMP CSPs are living through with 3PAOs this year.
The free self-assessment scores your AI security posture against BOD 26-04 and the AI Defense Matrix's 8 asset classes — five minutes for a baseline before you tackle EU AI Act conformity work.
Take the assessment — free →