EU Digital Omnibus pushes high-risk AI compliance dates to 2027 and 2028
The EU's AI Omnibus regulation has updated the compliance timeline for the AI Act, setting transparency obligations for generative AI to August 2026. Deadlines for high-risk AI system compliance have been extended to December 2027 for standalone systems and August 2028 for embedded products.
Key Takeaways
- Transparency rules for generative AI providers and deployers remain set for August 2, 2026.
- Deadlines for high-risk standalone AI systems moved to December 2, 2027.
- Embedded high-risk products, such as those in machinery or safety components, must comply by August 2, 2028.
- A grace period for content-marking machine-readability lasts until December 2, 2026, for existing systems.
- AI literacy obligations for staff training are currently applicable for all providers and deployers.
Why It Matters
The delay provides a critical window for streaming platforms and tech vendors to refine AI-driven recommendation engines, automated moderation, and customer service bots before high-risk enforcement begins. By decoupling transparency from high-risk technical standards, the EU allows its standardisation committees more time to finalize criteria that will define 'presumption of conformity.' For the streaming ecosystem, this means immediate focus must stay on watermarking and chatbot disclosure while backend high-risk assessments can be phased in through 2028. Watch for the publication of final EU harmonised standards by JTC 21 as the next major compliance benchmark.
Additional Context
The transition period has been marked by significant activity from the EU AI Office, which recently finalized its Code of Practice for General-Purpose AI (GPAI) on July 10, 2025. This voluntary framework provides an interim compliance path for providers like OpenAI and Google to meet transparency and copyright obligations before formal harmonized standards are adopted. Per Deloitte (July 2025), the Code is effectively the go-to rulebook for responsible GenAI deployment during this transition, addressing critical areas such as training data summaries and copyright compliance policies. Simultaneously, the technical underpinnings of the AI Act are being developed by the CEN-CENELEC Joint Technical Committee 21. According to a JTC 21 update (January 2026), over 1,000 experts are currently drafting standards for data quality, cybersecurity, and risk management. While basic terminology standards (ISO/IEC 22989) are already operational, the more complex technical specifications required for high-risk systems are expected to undergo public consultation through summer 2025. This specialized work is the primary reason the Omnibus pushed back enforcement dates, as companies cannot assess 'conformity' without these finalized technical metrics. On the enforcement front, member states are struggling to meet deadlines for establishing national market surveillance authorities. Per artificialintelligenceact.eu (June 2026), only nine member states had fully designated their authorities by mid-2026, with many still in the legislative process. Despite these delays, the European Data Protection Supervisor (EDPS) has already been designated as the supervisor for AI systems used by EU institutions, signaling that regulatory scrutiny is already beginning at the administrative level even as member states lag in broader implementation.
Read full article at dataprotectionreport.com
Get this in your inbox → Subscribe
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source