The EU has pushed back the date on which its rules for high-risk AI systems begin to apply. For teams building AI that will be used in the EU, including teams outside it, the extra time is welcome. It is worth spending well.
What changed
The AI Omnibus entered into force on 27 July 2026. Under it, the rules for high-risk AI systems listed in Annex III now apply from 2 December 2027, and the rules for high-risk AI built into regulated products (Annex I) apply from 2 August 2028. The Omnibus also extends simplified compliance measures to small mid-cap companies, widens access to regulatory sandboxes and adds a prohibition on generating non-consensual intimate content. Obligations for general-purpose AI models, which have applied since 2 August 2025, are not changed by the delay.
Why the delay is not a pause
Delay does not mean the work goes away. High-risk obligations are about how AI systems are built and run: documented risk management, data governance, logging, human oversight, accuracy and robustness. Those are engineering properties that are far cheaper to design in than to retrofit.
Is your system in scope?
Annex III of the Act lists eight areas where AI systems are treated as high-risk: biometrics; critical infrastructure; education and vocational training; employment, workers’ management and access to self-employment; access to essential private and public services and benefits; law enforcement; migration, asylum and border control management; and the administration of justice and democratic processes. Whether a particular system falls into one of them depends on what it is intended to do, so check the text of the Act or take legal advice for your own case.
For systems that are in scope, Articles 9 to 15 set out the requirements: a risk management system, data and data governance, technical documentation, record-keeping, transparency and information for deployers, human oversight, and accuracy, robustness and cybersecurity. These are the areas the practical steps below are meant to prepare for.
Five practical steps
- Inventory your AI systems. List every model, agent and AI feature in use, who owns it, and what decisions it influences.
- Classify by risk. Work out which systems might fall under the high-risk categories, and involve legal advisers early.
- Make systems traceable. Versioned prompts and models, audit logs and monitoring give you the evidence that regulators and customers will ask for.
- Evaluate continuously. Automated tests for quality, bias and safety, run in your delivery pipeline, turn compliance from a one-off project into a routine.
- Design for human oversight. Decide where a person reviews or approves an AI-driven action, and build that step into the workflow.
Where we can help
Much of this is platform work: AI-ready landing zones, evaluation pipelines, observability and governance controls. Our AI Platform Foundations & LLMOps service builds exactly those foundations as code.
This article is general information, not legal advice. Check the final text of the regulation and take advice for your own situation.
Sources: European Commission, “AI Omnibus enters into force”; Gibson Dunn analysis of the EU AI Act Omnibus agreement. Also: EU AI Act, Annex III; EU AI Act, Chapter III Section 2 (Articles 8 to 15).




