The EU’s June 29 AI Omnibus regulation moves two high-risk AI application dates to late 2027 and 2028. It does not freeze the AI Act as a whole.
The European Union has changed the timetable for major parts of the AI Act, but it has not put the regulation on hold. On June 29, 2026, the Council of the EU gave final approval to an AI Omnibus regulation that delays the application of rules for high-risk AI systems.
The revised dates are specific. Rules for stand-alone high-risk AI systems, including systems in Annex III of the Act, will apply from **December 2, 2027**. Rules for high-risk AI embedded in regulated products covered by Annex I will apply from **August 2, 2028**. The Council said these provisions had been due to enter into force on August 2, 2026.
For organizations that build or deploy systems in high-impact areas, the delay changes planning assumptions. The European Commission lists examples of high-risk uses that include AI safety components in critical infrastructure, education, employment and worker management, access to essential services, certain biometric uses, law enforcement, migration and border management, and the administration of justice. When the high-risk rules apply, providers face obligations around risk management, dataset quality, logging, documentation, information for deployers, human oversight, robustness, cybersecurity and accuracy.
But “delayed high-risk rules” should not become “the AI Act is paused.” The Act applies progressively, and the Commission’s current policy page and the EU AI Act Service Desk timeline show several obligations and milestones remain active or imminent.
The Service Desk also lists August 2, 2026 as the point at which the majority of the Act’s rules apply and enforcement begins for applicable rules. That milestone includes Article 50 transparency rules. The Commission describes these as disclosure duties intended to let people know when they are interacting with a machine and to make AI-generated content identifiable. Certain synthetic content, including deepfakes and text published to inform the public on matters of public interest, must be clearly and visibly labelled under the framework described on the Commission page.
Another date has moved closer, not farther away. The Omnibus adds a prohibition on AI systems that generate non-consensual sexually explicit or intimate content or child sexual abuse material. The Council says systems that generate nude images of real people or edit clothing out of photographs to reveal intimate parts are to be banned from December 2026. The Service Desk places the new prohibitions and the Article 50(2) transition on December 2, 2026.
The operational takeaway is to plan by obligation, not by headline. A company assessing an Annex III high-risk system has more time before the new December 2027 application date. A company placing AI inside an Annex I regulated product has until August 2028 for that high-risk milestone. Neither date removes the need to assess obligations that already apply to GPAI, transparency, AI literacy, prohibited practices, or sector-specific rules.
The Commission calls the AI Act a risk-based framework. Different systems, actors and use cases sit on different clocks. Teams should identify their role, map the system and use case, and use the Commission and Service Desk materials to track the relevant date. The June regulation simplifies and reschedules parts of the regime. It is not a blanket pause.
Bottom Line
The EU’s June 29 AI Omnibus regulation moves two high-risk AI application dates to late 2027 and 2028. It does not freeze the AI Act as a whole.
Sources
- https://www.consilium.europa.eu/en/press/press-releases/2026/06/29/artificial-intelligence-council-gives-final-green-light-to-simplify-and-streamline-rules/
- https://www.gunder.com/en/news-insights/insights/2026-ai-laws-update-key-regulations-and-practical-guidance
- https://www.reuters.com/legal/litigation/us-urge-hands-off-ai-regulation-g-20-official-says-2026-09-01/