AI Act
AI Omnibus: The 16-Month AI Act Reprieve, and Why Your Real Deadline Just Got Closer
The AI Omnibus is law. It moved the high-risk deadline to December 2027 — and created a new one on 2 December 2026, in the €35M/7% penalty band.

The AI Omnibus is no longer a political agreement. It is Regulation (EU) 2026/1744, adopted 8 July 2026, published in the Official Journal on 24 July and in force since 27 July 2026. It delays the AI Act’s biggest deployer deadline by sixteen months: Article 26 obligations for Annex III high-risk AI systems bind on 2 December 2027, not 2 August 2026. High-risk AI embedded in regulated products moves from 2 August 2027 to 2 August 2028.
Most SMBs read that as breathing room. That is the wrong read, and it is now wrong for a sharper reason than it was in May. The same regulation that pushed the high-risk deadline out created a new one. 2 December 2026 — less than three months away — is the nearest date in the AI Act, and what falls due on it sits in the Act’s maximum penalty band.
What the Omnibus actually changed
Annex III high-risk deployer duties under Article 26 — instructions-for-use compliance, human oversight design, monitoring and log retention, suspension protocols, affected-persons rights, and the Article 27 Fundamental Rights Impact Assessment — now bind on 2 December 2027: a sixteen-month deferral from the August 2026 cliff.
The product route moved too, but from a different starting point. High-risk AI acting as a safety component of a regulated product under Annex I — machinery, medical devices, aviation, toys — was never due in August 2026. It was due 2 August 2027, and now falls on 2 August 2028. The two delays are different sizes because they were never on the same clock.
Almost nothing else was pushed back. Article 5 prohibited practices have bound since 2 February 2025. Article 50 transparency for chatbots, deepfakes and AI-generated content began applying on 2 August 2026 and was explicitly not deferred. Article 53 duties for general-purpose AI model providers have bound since 2 August 2025.
One obligation was softened rather than delayed. Article 4 now requires providers and deployers to take measures to support the development of AI literacy, where it previously required them to ensure a sufficient level of it. It still applies, and has since February 2025 — but it is now an obligation of effort, not of result. If you built a literacy programme against the old wording, you are over the bar. If you have not, the bar is lower than the one you were avoiding.
The deadline the Omnibus created: 2 December 2026
Two things fall due on 2 December 2026, and neither was in the original Act.
The first is a marking obligation. Article 50(2) requires providers of systems generating synthetic audio, image, video or text to mark their outputs in a machine-readable, detectable format. For systems placed on the market from 2 August 2026 that applied immediately. For systems already on the market before that date, the Omnibus inserted a grace period at Article 111(4) — and it expires on 2 December 2026. If you put a generative feature into a product before August, the clock on marking it runs out this year, not in 2027.
The second is a pair of new prohibitions. The Omnibus added to Article 5 a ban on AI systems that generate or manipulate child sexual abuse material, and on systems generating non-consensual intimate imagery — the so-called nudifier applications. Both apply from 2 December 2026, and because they sit in Article 5, they sit in the €35 million or 7% band, not the 3% one.
For most SMBs the second is a screening question. The first is not: any organisation that shipped a generative feature before August 2026 has a dated, unglamorous piece of engineering work due this year — the kind that gets discovered in a procurement questionnaire rather than a planning meeting.
The smaller print: SMC simplification
The Omnibus extends the SME simplifications already in the Act — lighter technical documentation, proportionate fines, sandbox access, standardised templates — to small mid-caps (SMCs). The definition comes from Commission Recommendation (EU) 2025/1099: an enterprise that is not already an SME, employs fewer than 750 people, and has either turnover of no more than €150 million or a balance sheet total of no more than €129 million. Between the two brackets, that covers virtually every organisation we work with across France, Belgium, Luxembourg, Switzerland and the broader EU.
It is genuinely good news: a lighter burden on Annex IV technical files, proportionate calibration of human-oversight design, and sandbox access for firms previously excluded by the 250-employee ceiling. It does not reduce what must be done. SMCs still need their AI estate mapped, their roles classified, their Article 5 screens run. The Omnibus simplified the paperwork, not the analysis.
What didn’t move — and what it costs to ignore
What the Omnibus left intact carries the heaviest Article 99 fines. Prohibited practices under Article 5 — now including the two new bans — reach €35 million or 7% of global turnover, whichever is higher. Breaches of the high-risk duties that bind in December 2027, and of the Article 50 duties that bind today, are capped at €15M or 3%. Misleading information to authorities, €7.5M or 1%. Article 99(6) already let SMEs pay the lower of the two figures rather than the higher, across all three bands; the Omnibus extended that mitigation to small mid-caps — but only for the 3% and 1% bands. An SMC that breaches Article 5 still faces the higher figure.
This is why “wait until 2027” is the worst possible reading. A specialty lender running an AI credit-scoring tool since 2024 acquired no new liability from the Omnibus — it acquired time, and only time. Article 5 still binds. Article 50 binds now. And an undocumented high-risk AI estate is still a live problem in every due-diligence conversation with a customer, partner or insurer.
The work the delay doesn’t postpone
Phase 1 Discovery — knowing whether you are in scope at all — is unchanged. Five things need doing regardless of when the headline deadline lands:
- AI estate inventory. Every AI system in use, every AI feature embedded in a SaaS your team relies on, every internal copilot or RAG application. Shadow AI is the norm in SMBs; an inventory turns it into a managed asset.
- The 2 December 2026 marking check. Does anything in that inventory generate synthetic content, and did it ship before 2 August 2026? If both, Article 111(4) gives you until December. This is the only item here with a deadline inside the year.
- Role determination. Deployer, provider, downstream provider, GPAI integrator? The answer sets which obligations apply and what proportionality you can claim. Most SMBs sit in more than one category — and Article 25(1) is the switch most of them miss: put your name or trademark on a high-risk AI system already on the market, substantially modify one, or change a non-high-risk system’s intended purpose so that it becomes high-risk, and you are its provider. You never have to have trained anything.
- Article 5 screen. Most SMB AI use is nowhere near Article 5, but the cost of being wrong is the maximum band — and the list grew in July. One pass identifies it cheaply.
- Article 4 literacy measures. Show you have taken measures proportionate to the risk and context of use. This folds into existing training and awareness programmes at low marginal cost.
The Omnibus buys planning time, not work time.
Why December 2027 is not far
A Regulated AI Deployment engagement runs sixteen to twenty weeks from kick-off to management body sign-off, before rollout starts. Pilot deployment, remediation, an internal review cycle and a mock audit add three to four months. That is a seven- to nine-month project.
Working backwards from 2 December 2027, the latest realistic kick-off is Q1 2027. The smarter date is this quarter or next. The Commission’s Annex III classification guidelines were published in draft on 19 May 2026 and consulted on through June; as of September 2026 they remain draft, so the classification questions they will settle are still open and still cheap to explore. Starting now also means inventorying the AI estate while it is small enough to map without forensic effort — and it is the same inventory the December 2026 check needs.
This is the pattern that played out for fintech and payment firms after DORA’s first inspections — You’re Not a Bank. DORA Still Applies. The firms now scrambling read a delayed deadline as a green light. The firms in control treated regulatory runway as a planning asset.
The 42001 angle: free future-proofing
ISO/IEC 42001 — the first certifiable Artificial Intelligence Management System standard — uses the same Annex SL backbone as ISO 27001 and the same ISO 31000 / ISO 23894 risk methodology the AI Act recognises, with ISO/IEC 42005:2025 alongside it for AI system impact assessment. Every governance artefact produced during an AI Act readiness engagement maps to 42001 clauses and Annex A controls at marginal cost, turning a certification engagement eighteen months out into assembly work rather than rework.
One caveat the market regularly oversells: a 42001 certificate is not a presumption of conformity with the AI Act. That attaches only to a harmonised standard cited in the Official Journal, and as of September 2026 none has been — EN 18286, published in July 2026, is still awaiting citation. The full treatment is in ISO 42001, sized for SMBs.
Our AI Governance & Security service carries an explicit 42001 mapping appendix on every Phase 3 deliverable; the certification track itself is ISO 42001 readiness in the Compliance Hub.
The AI Act timetable after Regulation (EU) 2026/1744: what binds now, what falls due on 2 December 2026, and what was deferred to 2027 and 2028.
A 30-day deployer Discovery plan an SMB can run this quarter, starting with the 2 December 2026 check.
What an SMB can do in thirty days without committing to a full engagement: name an internal owner for AI governance, probably whoever already runs the ISMS or DPO function; circulate a one-page survey of every AI tool, copilot or AI feature in use; flag anything on it that generates synthetic content and shipped before 2 August 2026, because that is your December deadline; run a fifteen-minute Article 5 screen against the rest; note which systems might fall under Annex III once the Commission’s guidelines are final; and put an AI policy stub on the next board agenda. None of it requires regulatory expertise. All of it shortens the December 2027 work — and one item is due this year.
Take the next step
Talk to a security practitioner, not a salesperson.
Twenty-five minutes, no slide deck, no follow-up sequence. We'll talk through where you are, what's coming up next on your regulatory horizon, and whether we can help.

