What changed on 7 May
On 7 May 2026, after roughly nine hours of negotiations, the European Parliament, the Council of the EU and the European Commission reached a political agreement at their third political trilogue on the AI Omnibus — a package also referred to as the Digital Omnibus. The agreement clears the path to postpone the most demanding part of the EU AI Act: the obligations attached to high-risk AI systems, which were originally due to apply from 2 August 2026.
The headline is simple to state and easy to misread, so it is worth being precise. The high-risk rules have not been scrapped. They have not been watered down in substance. What the Omnibus does is move the dates. Under the agreement, the obligations for stand-alone high-risk AI systems would apply from 2 December 2027, and the obligations for high-risk AI embedded in regulated products from 2 August 2028. The deadline for member states to establish AI regulatory sandboxes has likewise been pushed back, to 2 August 2027.
One thing did not move, and it is the part most likely to catch teams out: the AI Act's transparency rules still come into effect in August 2026. They are not part of the postponement. If your product talks to users, generates content, or manipulates media, you may have a live compliance obligation this year regardless of everything else in this article.
There is also a procedural caveat that genuinely matters. What was reached on 7 May is a political agreement at trilogue stage. It is the point at which negotiators from the three institutions settle the shape of the text. Formal adoption by the Parliament and the Council still has to follow before the new dates are law. In practice a trilogue agreement is a strong signal of where things land, but until adoption is complete, the prudent reading is "very likely" rather than "done".
The transparency rules are not postponed. They still take effect in August 2026. If you read "the AI Act's high-risk deadline has been delayed" and conclude there is nothing to do until 2027, you have walked into the most common trap in this story. The delay applies to high-risk obligations only. Transparency duties — disclosing AI interaction, labelling synthetic content — remain on the original 2026 timeline.
The timeline, before and after
The Omnibus does not produce one new deadline; it produces several, and they hit different kinds of system at different times. The table below sets the original dates against the revised ones so you can locate your own product on it.
| Obligation type | Original date | Revised date | Who it hits |
|---|---|---|---|
| High-risk AI — stand-alone systems | 2 August 2026 | 2 December 2027 | Teams shipping a standalone AI system that falls in a high-risk use category |
| High-risk AI — embedded in regulated products | 2 August 2026 | 2 August 2028 | AI built into products already covered by EU product-safety law |
| AI regulatory sandboxes | 2 August 2026 | 2 August 2027 | Member states establishing supervised testing environments |
| Transparency rules | August 2026 | August 2026 — UNCHANGED | Anyone whose AI interacts with users or generates or manipulates content |
Read the table as two stories running side by side. The high-risk story is one of relief: roughly sixteen extra months for stand-alone systems, and two full years for AI embedded in regulated products such as medical devices or industrial machinery. The transparency story is one of continuity: nothing changes, and the 2026 obligation stands. A product can sit in both stories at once — a high-risk system with a chatbot front end has a delayed high-risk obligation and an undelayed transparency obligation. Treating the Omnibus as a single blanket extension is precisely the mistake that produces a missed deadline.
The dual-market hook: who is actually in scope
The most frequent question we hear from builders on both sides of our readership is some version of "we are not a European company, does this even apply to us?" The honest answer is that nationality is almost beside the point.
Start with the United Kingdom. Since leaving the EU, the UK is not bound by the AI Act as domestic law, and the UK is pursuing its own, lighter-touch approach to AI regulation. So a London or Manchester team building for UK customers only is outside the AI Act. The moment that same team places an AI system on the EU market — sells it to a customer in Germany, lists it on an EU app store, signs an enterprise deal with a French buyer — it is in scope. The Act applies on the basis of the EU market, not the provider's home country. A UK builder selling into the EU is, for AI Act purposes, in exactly the same position as a Berlin start-up.
The same logic catches India-based teams. An AI product built in Bengaluru or Pune that serves EU users — or whose output is used in the EU — falls within the Act's reach. This extraterritorial design is deliberate; it is what stops the rules being sidestepped by simply incorporating elsewhere. The Omnibus changes the timing of the high-risk obligations. It does not narrow who they apply to. If your roadmap includes European users, "we are an Indian company" or "we are a UK company" is not an exemption.
For teams weighing whether to formalise this kind of accountability internally, the question of who owns AI risk at a senior level is a live one — we explored it in our piece on whether you actually need a chief AI officer.
I ship into the EU — what do I do now?
This is the question that matters, so here is a concrete sequence rather than a vague reassurance. Work through it in order.
One: classify your system honestly. Before anything else, establish whether your product is a high-risk AI system, a system subject only to transparency rules, or outside both. High-risk status follows from the use case — areas such as recruitment, credit scoring, biometric identification, education, and AI that is a safety component of a regulated product. If you are high-risk, the Omnibus has just handed you significant extra time. If you are only in transparency scope, the Omnibus changes nothing for you and the 2026 deadline is yours to meet. Getting this classification wrong in either direction is expensive: over-classifying wastes a year of engineering on documentation you did not need, under-classifying leaves you exposed.
Two: meet the transparency obligations on the original 2026 timeline. If your AI interacts with people, disclose that they are dealing with an AI system. If it generates or meaningfully manipulates image, audio, video or text content, that content needs to be detectable as artificially generated. These are not heavy lifts compared with the full high-risk regime, but they are real, they are due in August 2026, and the Omnibus does not touch them.
Three: treat the high-risk extension as runway, not a reprieve. If you are building a high-risk system, you now have until December 2027 (stand-alone) or August 2028 (embedded in regulated products). The mistake is to bank the time and stop. The high-risk obligations — a risk management process, technical documentation, data governance, logging, human oversight, robustness and accuracy testing — are not paperwork you can produce in the final fortnight. They are properties of how the system is built. Teams that use the extra runway to bake these in steadily will be in a far better position than those that rediscover the deadline in mid-2027.
Four: keep a watching brief on formal adoption. Because this is a trilogue agreement and not yet adopted law, build your plan on the new dates but verify them before you commit to anything irreversible. Adoption is expected to confirm the agreement, but "expected" is not "enacted".
Use the extended high-risk runway to build a single, living technical-documentation pack alongside the product — data sources and governance, intended purpose, known limitations, evaluation results, the human-oversight design. Update it every sprint, not at the end. When the December 2027 deadline arrives, conformity work becomes a review of something that already exists rather than a panicked reconstruction. The same discipline also makes enterprise procurement and security reviews dramatically faster.
Why the delay happened — and how to read it
The postponement did not come from nowhere. Through late 2025 and into 2026 there was sustained pressure — from industry, from some member states, and from parts of the Commission itself — arguing that the high-risk regime was arriving before the supporting machinery was ready. Harmonised technical standards, the detailed specifications that tell a provider how to actually comply, were not finalised. The guidance was incomplete. The argument ran that asking companies to meet an August 2026 deadline against standards that did not yet exist was a recipe for inconsistent, box-ticking compliance rather than genuine safety.
Whether you find that persuasive depends partly on where you sit. For a builder, the practical reading is even-handed: the delay is real and useful, because complying against finished standards is meaningfully easier than complying against drafts, and it is also a reminder that the direction of travel has not changed. The EU has reaffirmed the substance of the high-risk regime while moving its start. This is not deregulation. It is sequencing. Teams that interpret "delay" as "the EU is backing away from AI regulation" are likely to be unpleasantly surprised in 2027.
There is a security dimension worth holding alongside the compliance one. High-risk obligations such as robustness testing and logging exist partly because AI systems fail in adversarial ways that traditional software does not — a theme we examined in our reporting on prompt injection against coding agents. The extra runway is a chance to treat that engineering as a first-class concern rather than a compliance afterthought.
Want to discuss this with other verified Builders?
Every article on AI Tech Connect is written by a Verified Builder. Browse profiles, shortlist who you want to hire or collaborate with.
Browse Builders →The bottom line for builders
Strip away the procedural detail and the situation for an Indian or UK team shipping AI into Europe comes down to three sentences. The high-risk obligations of the EU AI Act have, by political agreement, been pushed from August 2026 to December 2027 for stand-alone systems and August 2028 for AI embedded in regulated products. The transparency rules have not moved and are still due in August 2026. And the Act still applies to you whenever your system reaches the EU market, regardless of where your company is registered.
The right response is neither panic nor complacency. It is to classify your system accurately, hit the 2026 transparency deadline on time, and treat the high-risk extension as an opportunity to build governance and documentation properly rather than a reason to defer the work. The teams that look well prepared in 2027 will be the ones that started in 2026 — with a clearer runway and finished standards to build against. The clock did not stop. It was reset, and reading it correctly is now part of the job.
The political agreement was confirmed by the Council of the EU. Read the primary source at the Council of the EU press releases page, and always verify the application dates against the formally adopted text before making irreversible commitments.