Friday, September 11, 2026

News

AI Act Gets New Timeline Under Omnibus VII Package

PolicyPatryk Raba

The newly effective Digital Omnibus on AI regulation pushes back requirements for high-risk AI systems by more than a year, while accelerating obligations to label AI-generated content and banning so-called nudify apps.

Contents
  1. Changes for high-risk systems
  2. What got moved up
  3. Legislative process
  4. Regulatory sandboxes and practice
  5. Implications for Polish companies

Companies developing or deploying high-risk artificial intelligence systems have been given more time to comply with EU rules. Regulation (EU) 2026/1744 of the European Parliament and of the Council, known as the Digital Omnibus on AI, entered into force on July 27, 2026, and changes the timeline for applying some of the most demanding obligations under the AI Act.

Changes for high-risk systems

The original AI Act timeline called for some provisions covering high-risk systems to take effect as early as August 2, 2026, with requirements for systems tied to sector-regulated products following from August 2, 2027. The new regulation pushes back both deadlines. Requirements for systems that can directly affect individuals' rights, safety, or access to essential services and opportunities will now apply from December 2, 2027.

This category includes systems used in biometrics, critical infrastructure, education and employment, among others. For AI systems that are safety components covered by separate EU sector-specific legislation on product safety and market surveillance, the deadline was moved from August 2, 2027 to August 2, 2028.

What got moved up

Not every deadline was extended. Two issues were deemed urgent enough to warrant an accelerated timeline. The first involves obligations to label AI-generated content in a way that allows it to be detected and traced, which will apply from December 2, 2026.

The second is the ban on AI systems that generate material depicting child sexual abuse or the intimate body parts of an identifiable person without their consent, known as nudify apps. The ban covers both offering and placing such tools on the market without adequate safeguards, as well as their actual use.

Legislative process

EU institutions reached a preliminary agreement on the Omnibus VII package, intended to simplify digital rules, on May 7, 2026. The European Parliament formally approved the agreed text on June 16, 2026. After publication in the Official Journal of the European Union, Regulation 2026/1744 entered into force on July 27, 2026, just days before the original August 2 deadline that was to apply to high-risk systems.

The revised timeline does not mean every AI Act obligation has been deferred, though. Article 50 of the regulation, covering transparency toward users about the use of artificial intelligence, including labeling chatbots and deepfake content, remains unchanged and has been in force since August 2, 2026.

Regulatory sandboxes and practice

The regulation also postpones until August 2, 2027 the obligation to set up national regulatory sandboxes for AI, meaning controlled testing environments for new solutions. At the same time, plans are underway to create sandboxes at the European level, intended to standardize AI testing conditions across member states.

Experts commenting on the changes note that the extra time to prepare for high-risk system requirements should be used to actually put compliance processes in order, not to shelve the issue for later. Companies that only start preparations closer to the new deadlines may not have enough time to fully implement the required documentation and risk-assessment procedures.

Implications for Polish companies

For Polish businesses deploying AI systems in areas such as recruitment, education, or critical infrastructure protection, the new timeline means extra time to prepare compliance documentation, but also the need to track two parallel tracks. Obligations around transparency and labeling of AI-generated content must be met sooner than originally planned, while full requirements for high-risk systems now have more time to be implemented.

Companies that have already begun auditing recruitment and HR algorithms against earlier AI Act requirements should check which planned deadlines have shifted and which, such as transparency toward users, remain unchanged since August 2026.

Share: