EU AI Act Compliance Checklist: What the Omnibus Delay Means for Your August Sprint
Thirty-seven days until the original August 2026 deadline, and the Omnibus delay isn't law yet. Here's what still applies and what your team should tackle this sprint.
Thirty-seven days remain until the original August 2, 2026 deadline for high-risk AI system obligations under the EU AI Act. The Digital Omnibus agreement reached on May 7, 2026 pushes that date to December 2, 2027 for standalone Annex III systems, but the legislation has not yet been formally adopted. Teams that pause compliance work now are making a bet on a legislative outcome they cannot control.
In Brief
The EU AI Act’s high-risk obligations face a likely 16-month delay under the Digital Omnibus agreement, but formal adoption remains pending. Article 50 transparency requirements still apply from August 2, 2026. Over half of EU member states lack designated market surveillance authorities, and harmonized technical standards arrived eight months late. Bulgarian teams should treat the original deadline as operative until the Official Journal publishes the amendment.
The compliance timeline chaos and practical engineering responses are exactly the kind of operational reality that will be dissected at ISTA 2026 this September, where early bird tickets are still available.
Pattern Name: EU AI Act High-Risk Compliance Readiness
Why This Is Important: Adoptable, because the Omnibus delay is not yet law, and Article 50 transparency obligations remain on the original August 2026 schedule regardless.
Domain: Security / AI
Who Should Care: DevOps/SRE, Backend, Manager, PM/BA
Level: Intermediate
Evidence Type: Standard / Case Study
The Omnibus Gamble
The Digital Omnibus agreement reached between the Council and European Parliament on May 7, 2026 proposes to defer Annex III high-risk obligations to December 2, 2027 and Annex I product-embedded systems to August 2, 2028. The European Parliament formally endorsed the provisional agreement on June 16, 2026. Council adoption and Official Journal publication are expected in July 2026.
The catch: until that publication happens, the original August 2, 2026 deadline remains the legal default. Organizations that halt compliance programs based on anticipated relief are accepting regulatory risk without a safety net.
The Cloud Security Alliance’s research note puts the situation bluntly: over half of organizations lack systematic AI inventories, and harmonized technical standards arrived eight months late. The delay, if enacted, provides breathing room. It does not eliminate the underlying compliance burden.
What Still Applies on August 2, 2026
Even with the Omnibus delay, several obligations remain on the original schedule:
Article 50 transparency requirements for AI systems that interact with humans, generate synthetic content, or perform emotion recognition apply from August 2, 2026. Watermarking requirements for systems already on the market get a four-month extension to December 2, 2026 under the Omnibus, but new systems must comply at market placement.
AI literacy obligations under Article 4 have been mandatory since February 2, 2025. Every organization deploying AI systems must ensure staff have sufficient understanding of AI technology, its capabilities, and its limitations.
Prohibited practices under Article 5 remain in force. The Omnibus adds a new prohibition on AI systems generating non-consensual intimate imagery, effective December 2, 2026.
The High-Risk Classification Problem
Article 6 defines two routes into high-risk classification. The first covers AI systems that are safety components of products, or are themselves products, covered by Annex I harmonization legislation (medical devices, machinery, toys, radio equipment). The second covers systems listed in Annex III: biometric identification, critical infrastructure, education, employment, credit scoring, law enforcement, and migration.
The European Commission’s draft guidelines published on May 19, 2026 clarify a critical point: general-purpose AI systems may fall into high-risk classification if their documentation does not consistently exclude high-risk use cases. A chatbot marketed without explicit limitations could be treated as high-risk if deployers use it for employment screening or credit decisions.
The self-assessment escape route under Article 6(3) allows organizations to determine that their Annex III system does not actually pose significant risk. This flexibility comes with accountability: the organization must document the assessment and notify the market surveillance authority before placing the system on the market.
Deployer Obligations: The FRIA Requirement
Article 27 introduces the Fundamental Rights Impact Assessment (FRIA), a pre-deployment review required for specific deployers of high-risk AI systems. The obligation applies to:
- Public bodies deploying Annex III high-risk systems (except critical infrastructure management)
- Private entities providing public services (healthcare, education, social welfare, housing)
- Any deployer using AI for creditworthiness evaluation or life/health insurance pricing
The FRIA differs from a Data Protection Impact Assessment (DPIA). Where a DPIA focuses on data processing lawfulness, a FRIA examines whether the system treats people fairly, creates systemic disadvantage, and provides meaningful paths to challenge automated decisions. Archer IRM’s analysis notes that most compliance teams assume their existing DPIA covers the territory. It covers part of it.

The National Authority Gap
The AI Act requires each member state to designate market surveillance authorities by August 2, 2025. As of June 2026, only eight of 27 member states have officially notified a national single point of contact to the Commission.
The AI Act Readiness Index classifies five countries as “Ready” (Spain, Denmark, Lithuania, Finland, Italy), four as “Advanced” (Ireland, Germany, Slovenia, Netherlands), thirteen as “Emerging,” and five as “Low.” France remains the largest economy without designated national AI Act authorities.
Germany’s KI-MIG (AI Implementation Act) passed its first Bundestag reading on March 20, 2026, with the Bundesnetzagentur proposed as market surveillance authority. Until the law is passed and published, the designation remains incomplete.
Romania designated ANCOM as its national market surveillance authority on March 12, 2026, establishing a hybrid enforcement model with sector-specific authorities for medical devices, financial services, and biometric systems.
Do This Next Sprint
1. Inventory your AI systems against Annex III categories. Map each system to the eight high-risk domains: biometrics, critical infrastructure, education, employment, credit/insurance, law enforcement, migration, and democratic processes. Document the intended purpose explicitly.
2. Check your GPAI documentation. If you deploy general-purpose AI systems (chatbots, code assistants, content generators), verify that your terms of service and technical documentation explicitly exclude high-risk use cases. Vague language creates classification risk.
3. Identify FRIA obligations. Determine whether your organization qualifies as a public body, provides public services, or deploys AI for creditworthiness or insurance pricing. If yes, begin FRIA template development now.
4. Implement Article 50 transparency controls. For AI systems that interact with humans, generate synthetic content, or perform emotion recognition, ensure users are informed they are interacting with AI. This applies August 2, 2026 regardless of the Omnibus.
5. Establish log retention. Article 26 requires deployers to retain automatically generated logs for at least six months. Verify your logging infrastructure captures the required data and your retention policies comply.
6. Identify your national authority. Check the Commission’s market surveillance authority list for your member state’s designated contact. If none exists, monitor national implementation progress.
7. Document your Article 6(3) assessment. If you believe your Annex III system does not pose significant risk, document the reasoning. The assessment must be completed before market placement and notified to the relevant authority.
What This Means for Bulgaria
Bulgaria’s AI regulatory landscape remains in transition. The country has not yet designated a market surveillance authority or notifying authority for the AI Act. A draft AI Act implementation bill from the political party “Da, Bulgaria” seeks to clarify national application, but no legislation has been enacted.
Practical actions for Bulgarian teams:
- Contact the Commission for Regulation of Communications (CRC) to inquire about AI Act authority designation plans. Romania’s ANCOM designation provides a regional precedent.
- Align with the “Concept for the Development of Artificial Intelligence in Bulgaria until 2030” when documenting AI governance frameworks. National strategy alignment may ease future regulatory interactions.
- Prepare for cross-border enforcement. If your AI systems affect EU users outside Bulgaria, the market surveillance authority in those member states has jurisdiction. A system deployed to German users falls under Bundesnetzagentur oversight once Germany’s KI-MIG is enacted.
- Monitor the Bulgarian Data Protection Commission (CPDP) for guidance on FRIA requirements. The CPDP’s existing DPIA expertise positions it as a likely resource for fundamental rights assessments.
- Budget for compliance consulting. With no national authority operational, Bulgarian organizations may need to engage EU-level resources or authorities in other member states for conformity assessment guidance.
Dig Deeper
- EU AI Act Implementation Timeline (Future of Life Institute)
- Draft Commission Guidelines on High-Risk AI Classification (European Commission, May 2026)
- Digital Omnibus Agreement Analysis (Gibson Dunn, May 2026)
- AI Act Readiness Index (Ovidiu Suciu, May 2026)
- Article 27 FRIA Requirements (Archer IRM, April 2026)
- National Implementation Plans Overview (Future of Life Institute, June 2026)


