EU AI Act Deadline Shift: What the Digital Omnibus Means for Your 2026 Compliance Roadmap
The Digital Omnibus just reshuffled your EU AI Act timeline, high-risk obligations pushed to December 2027, but Article 50 disclosure hits in nine days. Here's what actually matters right now.

The Council of the EU Gave Final Approval to the Digital Omnibus on 29 June 2026
The Council of the EU gave final approval to the Digital Omnibus on 29 June 2026, and compliance teams across Europe are now recalculating their timelines. The package defers the Annex III high-risk AI obligations from 2 August 2026 to 2 December 2027, a 16-month reprieve that sounds generous until you realize Article 50 disclosure duties remain locked at 2 August 2026. That deadline is nine days away.
In Brief
The Digital Omnibus resets the EU AI Act compliance calendar, pushing high-risk system requirements to December 2027 while keeping transparency obligations on the original August 2026 schedule. Organizations that built their roadmaps around pre-Omnibus guidance are now working with outdated timelines. For Bulgarian engineering teams, this creates both breathing room and immediate pressure: the controls that matter most in the next two weeks are not the ones most compliance checklists emphasize.
If the regulatory whiplash feels familiar, ISTA 2026 this September is where practitioners who actually ship software in Bulgaria will stress-test these patterns in person.
The Timeline Split Nobody Planned For
Most EU AI Act compliance guides published before June 2026 treat as a single deadline for everything. That was never quite accurate, but the Digital Omnibus makes the split explicit. Here is what actually applies when:
Still Due 2 August 2026:
- Article 50 disclosure obligations (informing users when they interact with AI systems)
- Prohibited practices enforcement (already live since February 2025)
- General-purpose AI (GPAI) transparency requirements (live since August 2025)
Deferred to 2 December 2027:
- Annex III high-risk system requirements (risk management, technical documentation, conformity assessments)
- Annex I embedded product requirements (pushed further to August 2028)
New Provision with Transitional Period:
- Article 5 ban on intimate imagery generation (“nudifiers”) and CSAM-related AI, transitional period until
The AI Act Readiness Index published in May 2026 found that only 8 of 27 EU member states have officially notified a national single point of contact to the Commission. The enforcement infrastructure is still being built while the first deadlines arrive.
Control Prioritization for the Next Nine Days
With Article 50 disclosure duties hitting in just over a week, the immediate priority is transparency, not the full high-risk compliance apparatus. The practical controls that matter right now:
AI Interaction Disclosure
Any system that interacts directly with users must inform them they are communicating with AI. Chatbots, recommendation engines, automated customer service: all need clear labeling. The KOBIL Group’s compliance analysis notes this applies to “limited risk” systems that many organizations have not inventoried.
Watermarking for Pre-August Systems
Systems placed on the market before have a grace period until for Article 50(2) watermarking requirements. This is not a free pass; it is a documented extension that requires tracking which systems qualify.
Prohibited Practices Audit
The eight prohibited AI practices have been enforceable since February 2025. If your organization has not screened for social scoring, manipulative systems, or emotion recognition in workplaces, the €35 million or 7% of global turnover fine tier applies now, not in 2027.
The High-Risk Deferral Is Not a Vacation
The 16-month extension for Annex III high-risk obligations creates a dangerous temptation to deprioritize compliance work. McKenna Consultants’ technical readiness guide makes the counterargument clearly:
“Technical documentation, quality management systems, data governance frameworks, and human oversight mechanisms are engineering investments that improve your AI systems independently of their regulatory function.”
The controls that take longest to implement are exactly the ones that got deferred:
Risk Management Systems (Article 9)
Continuous, iterative processes for identifying and mitigating risks throughout the AI system lifecycle. This is not a document you write once; it is an operational capability.
Technical Documentation (Article 11)
Detailed records of system design, development methodology, training data, and testing procedures. Retrofitting documentation onto existing systems is significantly harder than building it in from the start.
Data Governance (Article 10)
Quality checks, bias detection, and lineage tracking for training datasets. Sombra’s architectural guidance emphasizes that “full data lineage tracking” is now a regulatory requirement, not a best practice.
Human Oversight (Article 14)
Mechanisms for human intervention, including the ability to override or shut down AI systems. This requires architectural decisions that cannot be bolted on later.

Organizations that pause compliance work until late 2027 will find themselves attempting 16 months of engineering in 16 weeks.
What This Means for Bulgaria
Bulgarian engineering teams face a specific set of considerations that generic EU compliance guides do not address:
Regulatory Sandbox Status
Bulgaria is not among the five EU member states (Spain, Denmark, Lithuania, Finland, Italy) with operational AI regulatory sandboxes. The Article 57 requirement for at least one sandbox per member state by means Bulgarian authorities are working against the same deadline as the organizations they will regulate.
National Authority Designation
Bulgaria has not yet appeared on the Commission’s public list of notified national single points of contact. For teams seeking regulatory guidance, this creates uncertainty about which authority to engage.
Practical Actions:
- Ask your compliance lead whether your organization has mapped AI systems against the Annex III high-risk categories (biometric identification, critical infrastructure, education, employment, credit scoring)
- Check if your cloud providers have data residency options that satisfy potential future Bulgarian or EU data governance requirements
- For engineers interviewing at EU-facing companies, ask specifically about AI inventory processes and Article 50 disclosure implementation status
Vendor Due Diligence
The Tredence compliance guide notes that the EU AI Act applies to “AI functions embedded in purchased software or third-party platforms.” Bulgarian teams using AI-powered SaaS tools need to verify their vendors’ compliance status, particularly for Article 50 disclosure.
The Ten-Control Framework, Reprioritized
The standard ten-control compliance framework remains valid, but the Digital Omnibus changes the sequencing. Here is the adjusted priority order:
Immediate (by 2 August 2026):
- AI System Inventory: You cannot disclose what you have not catalogued
- Prohibited Practices Screen: The highest fine tier applies now
- Transparency and Disclosure: Article 50 is not deferred
Near-term (by 2 December 2026):
- Watermarking for legacy systems
- AI Literacy Training: Article 4 requires staff competency
Medium-term (by 2 December 2027):
- Risk Classification for every system
- Risk Management Process for high-risk AI
- Data Governance and Quality Checks
- Technical Documentation and Logging
- Human Oversight mechanisms
Ongoing:
- Third-party and Vendor AI Governance
- Incident Response and Serious-Incident Reporting
The Holistic AI readiness assessment framework emphasizes that these controls function as “one governance system, not ten isolated tasks.” The inventory feeds the risk classification, which determines documentation requirements, which inform human oversight design. Treating them as a checklist to complete sequentially misses the interdependencies.
Dig Deeper
- EU AI Act official regulatory framework: Primary source for risk categories and prohibited practices
- AI Act Readiness Index: Member state enforcement preparedness tracking
- McKenna Consultants technical readiness guide: Engineering-focused implementation requirements
This Week’s Take
The Digital Omnibus is a gift that compliance teams should not unwrap too eagerly. The 16-month deferral for high-risk obligations creates space for better implementation, but only if organizations use that time to build genuine capabilities rather than delay uncomfortable decisions. The Article 50 deadline in nine days is the real test: organizations that cannot disclose their AI interactions by are already behind, regardless of what happens with high-risk systems. The Omnibus changed the calendar. It did not change the work.


