EU AI Omnibus Enters into Force, Resetting Key Compliance
The European Union’s Digital Omnibus on AI entered into force on July 27, 2026, changing key compliance dates and requirements for companies that develop, deploy, or sell AI-enabled products in Europe.
July 28th, 2026
Last updated: July 28
Key takeaways
- Annex III high-risk AI rules will apply from December 2, 2027.
- Product-embedded high-risk AI rules will apply from August 2, 2028.
- The Omnibus extends selected support measures to small mid-cap companies.
- Companies should update their EU compliance calendars, safeguards, vendor records, and regulatory-role assessments.
Data highlight
2revised application dates
Fixed deadlines introduced for major high-risk AI categories
2027–2028
The European Commission identifies December 2, 2027 for Annex III high-risk systems and August 2, 2028 for high-risk systems embedded in regulated products. These are legal application dates, not forecasts.
The most visible change is timing. Rules for high-risk AI systems listed in Annex III will apply from December 2, 2027. Rules for high-risk AI systems embedded in regulated physical products will apply from August 2, 2028.
The additional time matters, but it should not be treated as a general pause on EU AI compliance. The Omnibus also changes support measures, oversight, database registration, AI literacy obligations, bias testing, and prohibited uses. Companies serving European customers need to update their compliance plans rather than put them aside.

The EU has reset two high-risk AI deadlines
The original AI Act used a staggered implementation schedule. The Omnibus introduces fixed later dates for two important high-risk categories.
Annex III covers certain standalone uses of AI where decisions may materially affect people, including employment, education, access to essential services, law enforcement, and migration. These rules will now apply from December 2, 2027.
High-risk AI embedded in products covered by specified EU product-safety laws will have until August 2, 2028.
For AI companies, the practical effect is a longer period to complete classification, risk management, technical documentation, data governance, human oversight, monitoring, and conformity work where those obligations apply.
The extension does not mean every AI feature can wait. Other AI Act provisions, contractual duties, data-protection rules, consumer law, sector regulation, and existing prohibitions may apply on different schedules.
Compliance support now reaches more growing companies
The Omnibus extends some measures previously reserved for small and medium-sized enterprises to small mid-cap companies.
It also expands access to regulatory sandboxes and introduces an EU-level sandbox. These mechanisms are intended to give eligible companies a supervised environment in which to test AI systems and clarify regulatory questions before wider deployment.
This is relevant to Chinese and other non-EU companies entering Europe through a local subsidiary, distributor, enterprise customer, or direct online service. Eligibility and responsibility depend on the legal structure and the role each entity performs. A commercial label such as “SaaS vendor” does not, by itself, determine whether a company is a provider, deployer, importer, or distributor under EU law.
Several obligations changed, not disappeared
The European Commission says the Omnibus reduces administrative burden and provides greater legal clarity. The changes include a simplified approach to AI literacy, adjustments to registration of systems considered exempt from high-risk classification, and broader access to process certain sensitive data where strictly necessary for bias detection and correction.
AI literacy has been reframed and simplified; it has not become irrelevant. Companies still need people operating AI systems to understand the risks, limits, and controls relevant to their work.
The regulation also strengthens the AI Office’s oversight of certain systems, including some built on general-purpose AI models and embedded in large online platforms or search engines.
For companies using third-party models, this makes vendor governance more important. A product team should know which model powers each feature, what data is sent to it, what safeguards are provided by the model supplier, and which controls remain the product company’s responsibility.
New prohibited-use rules require product safeguards
The Omnibus adds an explicit prohibition targeting AI systems used to generate or manipulate non-consensual intimate material or child sexual abuse material.
The legal text distinguishes between intended misuse, reasonably foreseeable and reproducible outcomes, available safeguards, and accidental generation. It also identifies measures such as refusal training, output controls, runtime guardrails, content classification, abuse detection, reporting, and corrective action.
This is directly relevant to image, video, avatar, short-drama, social, dating, and creator tools. A general terms-of-service clause is unlikely to be enough on its own. Product controls, abuse monitoring, evidence of testing, user reporting, and an escalation process should be part of the operating design.
What AI companies serving Europe should do now
The first step is to rebuild the regulatory inventory.
List every AI-enabled feature offered to EU users and record its intended purpose, model supplier, input and output data, user group, decision impact, and current safeguards. Then identify the company’s legal role and make a preliminary risk classification.
Next, separate the work into three schedules:
- Obligations already applicable or governed by other EU laws.
- Work required before December 2, 2027.
- Product-embedded high-risk work required before August 2, 2028.
Companies should also review product safeguards, update supplier contracts, assign evidence owners, and decide how compliance records will be maintained as models or features change.
The payment impact is indirect but real. A delayed European launch, restricted feature, customer suspension, or forced product redesign can affect conversion, subscription revenue, refunds, and support costs. Compliance planning therefore belongs in the commercial launch plan, not only in the legal review.
The key takeaway
The EU AI Omnibus gives many companies more implementation time and more structured support. It does not remove the risk-based AI regime.
The useful response is to replace the old calendar, verify the classification of each EU-facing feature, and use the additional time to build durable controls and evidence.
Disclosure: This article provides general industry information and is not legal advice. Whether a product or company falls within a specific AI Act category depends on its facts, intended purpose, market role, and use in the EU.
How to cite
HaiPay News, "EU AI Omnibus Enters into Force, Resetting Key Compliance", https://www.haipay.net/news/eu-ai-omnibus-enters-into-force-2026, July 28th, 2026
About the author
Wesley Wang
Content Editor
Wesley is a Content Editor at HaiPay, focusing on cross-border payments, local acquiring, and payment compliance. He turns complex payment topics into practical guides for merchants, platforms, and businesses expanding internationally.
Reviewed by WeiJun TangEditorial policy





