Evidence explainer

Health policy, systems, and equity

The EU AI Act Digital Omnibus: Why the High-Risk Deadlines Moved

The Digital Omnibus moved the EU AI Act's high-risk deadlines. Annex III systems now comply by 2 December 2027, and AI inside regulated products, medical devices included, by 2 August 2028.

Fully reviewed by Jasaman (Jasmin) Tojjar, MD, PhD

On this page
  1. Key points
  2. The two deadlines that actually changed
  3. Why the medical-device date is the one to watch
  4. What stayed exactly where it was
  5. The reasoning: standards before penalties
  6. Planning around the new calendar

The EU AI Act's high-risk obligations no longer switch on in August 2026. Under the Digital Omnibus, on which the Council and Parliament reached political agreement on 7 May 2026, two fixed calendar dates now govern the heaviest tier of duties: stand-alone high-risk systems listed in Annex III must comply by 2 December 2027, and high-risk AI built into regulated products under Annex I, a group that includes medical devices and in-vitro diagnostics, must comply by 2 August 2028. The risk tiers did not change. The clock did.

Key points#

The two deadlines that actually changed#

Two dates carry most of the weight. The first covers Annex III, the use-case list that reaches into areas such as biometrics, critical infrastructure, education, employment, and access to essential services. Those duties were scheduled to apply from 2 August 2026 and now apply from 2 December 2027. The second covers Annex I, meaning AI that lives inside a product already governed by EU product-safety law, such as a device regulated under the Medical Device Regulation or the In Vitro Diagnostic Regulation. Those duties were set for 2 August 2027 and now apply from 2 August 2028. The Gibson Dunn analysis of the agreement sets both shifts against their original timelines.

It helps to picture the difference between the two annexes. Annex III is about what a system is used for. Annex I is about where a system sits: inside a product that already carries its own safety regime. A diagnostic algorithm sold as a standalone screening tool tends toward the Annex III side. That same algorithm embedded in a CT scanner or a lab analyzer tends toward Annex I, because the host product is already a regulated medical device.

Why the medical-device date is the one to watch#

If you build or evaluate clinical AI, 2 August 2028 is the date to circle. Software that qualifies as a medical device and also meets the AI Act's high-risk criteria falls under Annex I, and it has to satisfy both regimes at once. Until that date, such manufacturers are not yet required to layer the Act's full high-risk requirements, which cover risk management, data governance, technical documentation, human oversight, and conformity assessment, on top of the device obligations they already carry.

The word "yet" matters. A tool that is high-risk today is still high-risk in 2028. The classification logic, the documentation burden, and the conformity-assessment route are unchanged. What lengthened is the runway, not the distance.

What stayed exactly where it was#

A later start for high-risk duties is not a pause on the rest of the law, and reading it that way would be a costly mistake. Several parts of the Act remain live:

According to Covington's analysis, registration of high-risk systems in the EU database also stays in place. The architecture of the Act is intact. Only the high-risk compliance clock was reset.

The reasoning: standards before penalties#

The stated motive is sequencing, not retreat. High-risk conformity leans on harmonized technical standards and guidance that tell developers, in operational detail, how to prove a system meets the legal requirements. Those standards were not finished. Co-legislators concluded that firms should not be penalized for missing benchmarks that do not yet exist, and that standards bodies needed more time to produce documents auditors can actually apply. The European Commission's own regulatory-framework materials describe the Act as depending on harmonized standards to translate broad obligations into testable engineering practice, which is precisely the machinery that was running late.

There is a second change worth noting, one of method rather than dates. The original design carried a conditional trigger: high-risk rules would begin once the supporting standards and tools were ready. The final agreement dropped that trigger in favor of fixed dates. The trade-off is familiar from other corners of regulation, including how device transition periods are set. A conditional trigger creates uncertainty that is hard to plan around, because no quality team can schedule validation and audit work against a date that floats. A firm calendar date, even a later one, is something you can build an engineering program toward. Predictability often does more for real-world safety than an aggressive date most of the field cannot meet.

Planning around the new calendar#

The delay changes the schedule, not the destination. A few practical moves follow.

First, classify early. Whether your tool lands in Annex III, Annex I, or neither drives which deadline and which obligations apply, and that determination should not wait for the deadline to arrive.

Second, treat the interim standards work as the specification. When harmonized standards publish, they will define what adequate data governance and meaningful human oversight look like as evidence. Building toward a draft that can be revised later is cheaper than building toward nothing.

Third, keep the unchanged obligations on your calendar. Prohibited-practice and transparency rules are already live, and a device maker still answers to the MDR or IVDR no matter what the AI Act clock reads.

The Omnibus is a schedule change reached through political agreement, and its precise text becomes binding only on formal adoption and publication. The direction is clear enough to plan around: the same high-risk regime, on later fixed dates, with more room for the standards that make it enforceable.

Sources and further reading

  1. Council of the EU press release (7 May 2026)
  2. Gibson Dunn: Omnibus postponed high-risk deadlines
  3. Covington Inside Privacy: EU AI Act timeline relief
  4. European Commission: Regulatory framework for AI

Questions and answers

Did the Digital Omnibus weaken the EU AI Act?

No. It postponed when the high-risk tier of obligations starts to apply and swapped a conditional trigger for fixed dates. The obligations, the risk tiers, and the bans on prohibited practices are unchanged.

When must AI-enabled medical devices comply?

High-risk AI embedded in a product regulated under EU product-safety law, including medical devices and in-vitro diagnostics under Annex I, must meet the Act's high-risk requirements by 2 August 2028. Those products still have to satisfy the MDR or IVDR in the meantime.

What is the difference between Annex I and Annex III?

Annex III lists stand-alone high-risk use cases and now applies from 2 December 2027. Annex I covers AI built into products already governed by EU product-safety law and now applies from 2 August 2028.