Back to blog
July 29, 2026EU AI Act Weekly Radar

EU AI Act Weekly Radar: Digital Omnibus resets timelines, but transparency and literacy work still move now

This week’s EU AI Act shift is real but selective: the Digital Omnibus delays parts of high-risk compliance, while Article 50 transparency and practical AI literacy expectations still demand near-term action.

EU AI ActDigital Omnibus on AIHigh-risk AI systemsArticle 50 transparencyArticle 6Annex IIIAI literacySME complianceAI governanceAI Act implementation

The EU AI Act’s implementation picture changed materially this week, but not in the simple “everything is delayed” way some teams may hope.

The new baseline is Regulation (EU) 2026/1744, published in the Official Journal on EUR-Lex, together with the European Commission’s notice that the AI Omnibus entered into force on 27 July 2026. Across the week’s official and practitioner updates, the message is consistent: some high-risk obligations have moved back, support measures have widened, and parts of the regime still arrive on their original timetable.

For legal, product, and governance teams, the practical takeaway is straightforward. This is a week to re-baseline compliance planning, not to pause it.

The new legal baseline: the Digital Omnibus is now the reference point

The most important source this week is the amending regulation itself: Regulation (EU) 2026/1744 amending the AI Act (Digital Omnibus on AI) on EUR-Lex. That text is now the legal anchor for implementation planning.

The European Commission’s AI Omnibus enters into force update frames the policy direction behind the changes. According to the Commission, the Omnibus extends some high-risk AI timelines, broadens support measures to small mid-caps, expands sandbox access, adds a ban on nudification apps, and clarifies how the AI Act interacts with other EU laws and conformity assessment procedures.

That combination matters. The changes are not just about extra time. They also touch scope management, support pathways, and how organizations should think about overlap between the AI Act and sectoral frameworks.

The big timeline reset: Annex III and Annex I are no longer on the old schedule

The clearest operational shift this week concerns the timetable for high-risk AI.

Across the Commission update, the Malta IDPC notice, Lewis Silkin’s The Digital Omnibus on AI enters into force today, and Akin’s EU AI Act Amendments Defer and Clarify Obligations, the same core timing changes appear:

  • standalone high-risk systems under Annex III move to 2 December 2027;
  • product-linked high-risk systems under Annex I move to 2 August 2028.

Akin’s note is particularly useful for translating the amendment into operational consequences, while Lewis Silkin highlights the same date shifts in a more implementation-focused summary.

For companies that had been building toward earlier high-risk milestones, this is a meaningful reprieve. But it is best understood as a sequencing change, not a reduction in expected maturity. Providers and deployers should use the extra runway to improve classification, governance evidence, and internal control design rather than simply moving project plans to the right.

What did not move: Article 50 transparency remains the near-term pressure point

One of the most important signals this week is that most Article 50 transparency duties still begin on 2 August 2026.

That point is highlighted both by the Malta IDPC’s IDPC draws attention to revised EU AI Act timelines following Council approval and by Lewis Silkin’s Omnibus summary. The IDPC’s notice is especially useful because it comes from a national authority with market surveillance relevance in certain high-risk areas, underscoring that enforcement-facing bodies are already drawing attention to the distinction between delayed high-risk requirements and unchanged transparency obligations.

This matters because many organizations may have tied all AI Act readiness to the high-risk timetable. This week’s updates suggest that approach is no longer defensible. If a use case triggers Article 50 duties, the fact that some Annex III or Annex I obligations were deferred does not remove the need to prepare now.

Akin also notes a short grace period for synthetic-content marking for pre-existing systems. Even with that nuance, the broader message remains: transparency obligations are still part of the immediate compliance horizon.

Why Article 6 and Annex III classification work still matters, even with delayed dates

The Omnibus may have delayed parts of the high-risk regime, but it did not make classification less important. If anything, classification becomes more central because organizations now need to decide which workstreams can be re-sequenced and which cannot.

Lewis Silkin reports that registration is simplified for some Article 6(3) cases. That is a targeted but meaningful adjustment. For teams dealing with borderline or context-dependent high-risk assessments, changes around registration mechanics may reduce some administrative friction. But they do not eliminate the need for a disciplined Article 6 and Annex III analysis.

In practice, this means companies should revisit at least three questions:

  1. Is the system actually in scope as high-risk, and under which pathway? Delayed dates change urgency, not the need for defensible classification.
  2. Which obligations are classification-dependent, and which apply independently? Transparency and literacy may still require earlier action.
  3. What evidence will support the classification conclusion if challenged later? A longer timeline is a chance to improve governance records.

For startups and SMEs, this is especially important. A weak classification memo written in a hurry today can become a costly problem in 2027 or 2028 if the system scales, changes context, or comes under regulator scrutiny.

Sandboxes and SME support: the Omnibus is also trying to change implementation economics

This week’s updates show that the Omnibus is not only a deadline reform. It also appears designed to make compliance more usable for smaller organizations.

The European Commission says support measures now extend to small mid-caps, while Lewis Silkin similarly notes that SME support broadens beyond the narrower original framing. The Commission also says sandbox access expands, and the Malta IDPC flags 2 August 2027 as the date relevant to national sandboxes in its timeline summary.

That combination is strategically important.

For growth-stage companies, one of the hardest parts of AI Act compliance has been the mismatch between regulatory expectations and internal compliance capacity. Expanded support eligibility and sandbox access could help bridge that gap, especially for teams that need structured testing or regulator-adjacent validation before full market rollout.

The signal from this week is that smaller players should not assume the AI Act is only a burden story. The architecture is increasingly also about implementation support, controlled experimentation, and more gradual onboarding into the regime.

AI literacy remains live, and it is not a box-ticking exercise

Alongside the Omnibus changes, the European Commission published AI Literacy - Questions & Answers, which is one of the most practical governance updates of the week.

According to the Commission’s Q&A:

  • Article 4 does not impose one fixed training format;
  • organizations can draw on the AI literacy practices repository;
  • deployers of high-risk systems still need staff sufficiently trained to carry out human oversight in practice.

This is a useful corrective to two common misconceptions: first, that literacy requires a single prescribed curriculum; second, that literacy is separate from operational controls.

The Commission’s framing suggests the opposite. AI literacy is flexible in form, but it must be real enough to support role-based responsibilities, especially where human oversight is expected. In other words, governance teams should think less about “did everyone complete a module?” and more about “can the relevant people perform their oversight responsibilities credibly?”

That is particularly relevant for deployers. Even where high-risk timing has moved, organizations using AI in sensitive workflows should expect questions about who was trained, what they were trained on, and whether training aligns with actual system risks and human decision points.

Standards are starting to fill the implementation gap

Another notable development this week is BSI’s announcement that EN 18286 provides a framework for AI quality management under the EU AI Act.

BSI describes EN 18286 as a European standard that can support AI quality management relevant to AI Act readiness. While this week’s source does not establish the full legal status or detailed content of the standard, the significance is still clear: standards are increasingly becoming the bridge between broad statutory duties and day-to-day implementation evidence.

That matters most for high-risk providers, but the wider lesson applies beyond them. As the formal obligations continue to be clarified and phased in, organizations need practical operating models for documentation, quality controls, testing, and lifecycle governance. Standards can become the scaffolding for that work.

The timing is also notable. A delayed compliance deadline does not reduce the value of building a repeatable quality-management backbone now. It may increase it, because teams have more time to institutionalize processes rather than relying on one-off remediation.

Enforcement significance: authorities are already signaling selective urgency

This week’s national and Commission communications point toward an important enforcement theme: regulators are likely to distinguish sharply between obligations that moved and obligations that did not.

The Malta IDPC’s public reminder on revised timelines is a good example. Its emphasis that Article 50 transparency duties still start on 2 August 2026 suggests authorities do not want the Omnibus to be read as a general relaxation.

Akin also notes strengthened AI Office powers in its analysis of the amendment’s operational impact. Even without going beyond the supplied source summary, that is a meaningful governance signal. If central oversight capacity is being reinforced while timelines are being recalibrated, organizations should expect the extra time to come with continued scrutiny over preparedness, documentation, and implementation discipline.

The broader compliance implication is that delay should not be confused with deregulation. The regime is being staged, clarified, and operationalized, not withdrawn.

What this week means for providers and deployers

For providers, this week supports a reset in sequencing:

  • re-check high-risk classification under Article 6 and Annex III;
  • separate delayed high-risk workstreams from unchanged transparency obligations;
  • use the extended runway to strengthen documentation, quality management, and conformity-readiness foundations;
  • assess whether support measures or sandbox routes are now more accessible.

For deployers, the picture is more immediate:

  • verify whether any current use cases trigger Article 50 obligations on the original timetable;
  • review staff enablement and human oversight readiness in light of the Commission’s AI literacy Q&A;
  • preserve governance records showing how operational controls match actual use of the system.

For SMEs and startups, the message is mixed but constructive. Yes, some of the hardest high-risk obligations are later than previously expected. But this is also the moment to build a lean, evidence-based compliance model before product and customer complexity make that harder.

The lextrace view

This week’s AI Act developments are best read as a shift from countdown mode to prioritization mode.

The Digital Omnibus has changed the implementation calendar in important ways. Standalone Annex III high-risk systems and Annex I product-linked systems now have more time. Support measures appear broader. Sandbox access is expanding. Some administrative friction points, including certain Article 6(3) registration scenarios, are being simplified.

But the near-term compliance story did not disappear. Article 50 transparency remains close. AI literacy remains live. Authorities are already emphasizing the revised but selective timetable. And the appearance of implementation-oriented standards like EN 18286 shows that the market is moving from abstract legal reading toward operational proof.

For most organizations, the right response is neither panic nor complacency. It is a careful re-baselining of obligations, dates, and evidence needs against the amended legal framework now in force.

That is the real lesson from this week’s radar: the EU AI Act has become more staged, not less serious.