ISTA 2026Fest Edition

Sofia Event Center

Tickets on sale

Latest InsightISTA 2026 adds Nikolay Avramov, who works on the test suites that still have to run in a year

EngineeringPattern Update

EU AI Act High-Risk Deadlines Just Shifted to December 2027: What the Omnibus Deal Means for Your Compliance Roadmap

The EU AI Act's high-risk system deadline just shifted to December 2027 after the May 7 Omnibus deal. The compliance infrastructure wasn't ready, but this isn't a reprieve - it's acknowledgment that teams need to start building now.

The EU AI Act was supposed to be the compliance headache of August 2026. Six days ago, that changed. On May 7, 2026, EU co-legislators reached a provisional agreement on the Digital Omnibus on AI, pushing the high-risk AI system deadline to December 2027 for standalone systems and August 2028 for AI embedded in regulated products. The infrastructure needed to comply (harmonised standards, notified body capacity, Article 6 classification guidance) simply was not ready. The law acknowledged reality.

In Brief

The EU AI Act (Regulation (EU) 2024/1689) is the world’s first comprehensive AI regulation, classifying AI systems by risk level and imposing obligations ranging from outright bans to transparency requirements. Prohibited AI practices have been in force since February 2025; general-purpose AI (GPAI) rules since August 2025. The May 2026 Omnibus deal delays high-risk system obligations by 16 months, giving teams until December 2027 for Annex III systems (hiring, credit scoring, critical infrastructure) and August 2028 for AI in regulated products. For Bulgarian companies building or deploying AI that touches EU users, this is the compliance framework that determines market access.

If this topic is on your radar, it is already on the agenda for ISTA 2026 this September. Speaker applications close May 31, and the organisers want practitioners with real compliance stories, not keynote tourists.

Pattern Name: EU AI Act Compliance Framework
Why This Is Important: The Omnibus deal bought time, but teams should start now. Teams that treat December 2027 as “far away” will repeat the same scramble that forced this delay. The pattern is now Adoptable: the legal text is stable, the deadlines are fixed, and the compliance architecture is clear enough to start building against.
Domain: AI / Security / Leadership
Who Should Care: DevOps/SRE, Backend, Security, Manager, PM/BA
Level: Intermediate
Evidence Type: Standard / Release

The Problem

AI systems are making decisions that affect people’s jobs, credit access, healthcare, and legal outcomes. Before the EU AI Act, no comprehensive legal framework existed to ensure these systems were safe, transparent, or accountable. Existing legislation (GDPR, product safety directives) covered adjacent concerns but left AI-specific risks unaddressed: opaque decision-making, algorithmic bias, manipulation through subliminal techniques, and the use of biometric data in ways that violate fundamental rights.

The result was a patchwork of voluntary guidelines and sector-specific rules that varied by member state. Companies operating across the EU faced uncertainty about what was permitted, what was required, and what liability they carried.

What Changed

The EU AI Act entered into force on August 1, 2024, establishing a risk-based regulatory framework that applies to anyone placing AI systems on the EU market or using AI outputs within the EU, regardless of where the company is headquartered.

The Act classifies AI systems into four risk tiers:

Unacceptable Risk (Prohibited): Banned outright since February 2, 2025. This includes social scoring by governments, AI that manipulates human behaviour through subliminal techniques, emotion recognition in workplaces and schools, untargeted scraping of facial images to build recognition databases, and real-time biometric identification in public spaces (with narrow law enforcement exceptions). Violations carry fines up to €35 million or 7% of global annual turnover.

High Risk (Strict Requirements): AI systems used in critical infrastructure, education, employment (recruitment, performance monitoring, termination decisions), credit scoring, law enforcement, migration, and administration of justice. These systems face comprehensive obligations: risk management systems, technical documentation, data governance, human oversight, accuracy and robustness requirements, and registration in an EU database.

Limited Risk (Transparency Obligations): Systems like chatbots and deepfake generators must disclose to users that they are interacting with AI or viewing AI-generated content. The deadline for providers to implement content marking (watermarks, metadata) is now December 2, 2026.

Minimal Risk: Unregulated. This covers most AI applications currently on the market: spam filters, recommendation engines, AI-enabled games.

The May 7, 2026 Omnibus agreement introduced several changes beyond the deadline shift:

  • A new prohibition on AI systems that generate non-consensual sexual content or child sexual abuse material
  • Extended SME-style compliance relief to “small mid-cap” enterprises (fewer than 500 employees, under €150 million turnover)
  • A mechanism for the Commission to disapply overlapping AI Act requirements where sectoral rules already cover the same ground
  • Reinstated obligation for providers to register AI systems in the EU database even when claiming exemption from high-risk classification

Why Now

Three factors converged to make the Omnibus necessary:

Standards were not ready. The AI Act relies on harmonised technical standards for conformity assessment. These standards were formally recorded as significantly delayed. Companies preparing for August 2026 were being asked to build compliance architecture against specifications that did not exist.

Notified body capacity was limited. The conformity assessment bodies needed to certify high-risk AI systems were not designated in sufficient numbers across member states.

The Commission missed its own deadline. Article 6 classification guidance, due in February 2026, was not delivered on time. Without clear guidance on what qualifies as high-risk, companies could not complete their risk assessments.

The delay is not a reprieve from compliance. It is an acknowledgment that the compliance infrastructure was not ready. The expectation is that implementation efforts should already be underway.

New Practice

The EU AI Act introduces a compliance model that mirrors product safety regulation. Think CE marking for AI. The core practices for organisations:

1. Inventory all AI systems. This includes internally developed systems, AI functions embedded in purchased software, and third-party platforms. Many organisations use AI without realising it: automated pricing, customer behaviour analysis, HR screening tools.

2. Classify by risk. Map each system against the Act’s risk categories. Annex III lists the high-risk use cases: biometrics, critical infrastructure, education, employment, credit scoring, law enforcement, migration, justice. If your system falls into one of these categories, deployer obligations under Article 26 apply.

3. Determine your role. The Act distinguishes between providers (developers) and deployers (users). Providers bear the heaviest burden: technical documentation, risk management systems, conformity assessment, CE marking. Deployers must use systems as intended, ensure human oversight, maintain logs, and conduct fundamental rights impact assessments for public-sector use.

4. Implement AI literacy. Since February 2025, the Act requires organisations to ensure employees working with AI have sufficient understanding of the technology. This is a legal obligation, not a recommendation.

5. Review vendor contracts. If you purchase AI from an external provider, verify that your contract guarantees compliance with the EU AI Act. Liability before regulators may be shared.

Regulatory certainty remains elusive even when the ink appears dry.

Tooling Implications

The Act does not mandate specific tools, but compliance requires capabilities that most organisations do not have in place:

  • AI system registries to track what AI is deployed, where, and for what purpose
  • Risk assessment frameworks aligned with Article 9 requirements
  • Technical documentation systems that capture development, training, and evaluation data
  • Logging infrastructure that preserves automatically generated logs for the periods specified by the provider
  • Human oversight mechanisms with named individuals, training records, and documented authority to intervene

For GPAI providers (large language models, multimodal models), additional requirements apply since August 2025: technical documentation, transparency reports, training data summaries, and copyright compliance documentation. Models with systemic risk (training compute exceeding 10²⁵ FLOPs) must also conduct adversarial testing and report serious incidents to the European AI Office.

Evidence

The penalty structure is modelled on GDPR but with steeper caps:

ViolationMaximum Fine% of Global Turnover
Prohibited AI practices€35 million7%
High-risk/GPAI obligations€15 million3%
Providing misleading information€7.5 million1%

SMEs pay the lower of the monetary amount or percentage. EU institutions face reduced caps (€1.5 million for prohibited practices, €750,000 for other failures).

The enforcement framework became operational in August 2025:

  • National Competent Authorities oversee market surveillance in each member state
  • The European AI Office coordinates enforcement for GPAI and systemic risk models
  • A Scientific Panel monitors and evaluates models for compliance risks

Failure Modes

Misclassification. Treating a high-risk system as limited-risk to avoid compliance obligations. The Act includes provisions for regulators to challenge exemption claims, and the Omnibus reinstated database registration requirements even for systems claiming exemption.

Deployer-to-provider drift. Using a general-purpose AI system for a high-risk use case can transform a deployer into a provider, triggering the full set of provider obligations. If you buy a hiring model from a vendor and run it in HR, you are the deployer. If you white-label that model and sell it under your brand, you may become a provider.

Grandfathering assumptions. The Act is not retroactive: systems placed on the market before the new deadlines do not need to comply unless significantly modified. This creates an incentive to rush systems to market before December 2027. It also means some high-risk systems may remain outside the Act indefinitely unless substantially altered.

Vendor contract gaps. Purchasing an AI system does not transfer compliance responsibility. If your vendor’s system fails to meet requirements, you share liability as the deployer.

Metrics

Track these to demonstrate compliance readiness:

  • AI system inventory coverage: percentage of AI systems identified and classified
  • High-risk system documentation completeness: percentage of required technical documentation in place
  • Human oversight assignment: percentage of high-risk systems with named oversight personnel and documented training
  • Vendor contract compliance clauses: percentage of AI vendor contracts with explicit EU AI Act compliance guarantees
  • AI literacy training completion: percentage of AI-adjacent employees who have completed required training

Do This Next Sprint

  1. Run an AI inventory. List every AI system your organisation uses, develops, or distributes. Include embedded AI in third-party software.
  2. Map to risk categories. For each system, determine whether it falls under Annex III high-risk use cases. Document your reasoning.
  3. Identify your role. For each system, determine whether you are provider, deployer, importer, or distributor. Different obligations apply.
  4. Audit vendor contracts. Check whether existing AI vendor agreements include compliance guarantees. Flag gaps for renegotiation.
  5. Assign AI literacy owners. Identify who is responsible for ensuring AI literacy training reaches all relevant employees.

What This Means for Bulgaria

Bulgaria, as an EU member state, is directly subject to the AI Act. The regulation applies without requiring transposition into national law. For Bulgarian companies:

If you build AI for EU markets: You are a provider. The full set of high-risk obligations applies if your system falls under Annex III categories. Start technical documentation now; December 2027 is 19 months away.

If you deploy AI in your operations: You are a deployer. Review every AI system you use for HR, credit decisions, or customer-facing automation. Ensure human oversight mechanisms are in place and documented.

If you work for a multinational: Ask your compliance lead about the company’s AI Act readiness. Specifically: has the AI inventory been completed? Are high-risk systems identified? Is there a timeline for conformity assessment?

If you are interviewing at EU-facing companies: Ask about their AI governance posture. Companies that have not started compliance work are either unaware of the regulation or betting on further delays. Neither is a good sign.

For outsourcing providers: Bulgarian software development firms serving EU clients should expect AI Act compliance requirements to flow into contracts. Build compliance documentation capabilities now; this will become a competitive differentiator.

The Bulgarian government has not yet publicly designated its national competent authority for AI Act enforcement. Monitor announcements from the Ministry of Transport and Communications and the Commission for Personal Data Protection for updates.

Dig Deeper

Many of the patterns covered in the Content Hub will take centre stage at ISTA Conference this September, where practitioners and tech leaders discuss them live, debate the trade-offs, and put them in the context of the latest industry shifts. Stay tuned for the programme announcement.

ISTA 2026 · 15 October 2026

One day in October. A year of engineering knowledge.