EU AI Omnibus Takes Effect and Moves High-Risk AI Deadlines to 2027 and 2028

The EU AI Omnibus entered into force on July 27, extending high-risk AI timelines and expanding sandboxes while adding a ban on non-consensual intimate-image systems and broader AI Office oversight.

What changed

The European Union's AI Omnibus entered into force on July 27, 2026. Proposed with the Digital Omnibus in November 2025, it adjusts administrative obligations and implementation dates while adding safeguards for safety and fundamental rights.

Timelines and support

  • Rules for Annex III high-risk systems apply from December 2, 2027.
  • Rules for Annex I high-risk AI embedded in machinery, toys, lifts, and other regulated products apply from August 2, 2028.
  • Some simplified SME obligations extend to small mid-cap companies.
  • Access to national sandboxes expands and an EU-level regulatory sandbox is introduced.

Safety and oversight

The measure bans AI systems that generate non-consensual sexually explicit or intimate content and child sexual abuse material. It permits specified processing of sensitive personal data to detect and correct bias, and extends some AI Office oversight, including certain general-purpose models embedded in large online platforms and search engines.

What organizations should verify

Later dates do not remove the obligations. Organizations should map each product and role—provider, deployer, or importer—to the legislative text and check separate transparency duties applying from August 2. This article is not legal advice; national enforcement and transitional rules also require review.

Official source