Digital Omnibus: high-risk slips to 2027, what stays live in August 2026
The Digital Omnibus defers Annex III to 2027. But in August 2026 transparency (art. 50), literacy (art. 4) and the bans stay live. What SMEs must do now.
The June 2026 Digital Omnibus did one simple thing and one thing that got misread.
The simple thing: it proposed deferring the high-risk obligations under Annex III to end of 2027. The misread thing: half the AI consulting newsletters read it as “the AI Act is postponed, you can relax until 2027”.
Not true. In August 2026, obligations that touch far more SMEs than the high-risk tier stay live. Here is the honest map of what slips and what does not.
Key takeaways:
- The Digital Omnibus defers the Annex III (high-risk) obligations to end of 2027, not the whole AI Act.
- Still mandatory in August 2026: the bans (unacceptable risk), the art. 50 transparency duty (tell users they are talking to an AI) and art. 4 AI literacy (train the team).
- If you run a chatbot or a client-facing agent, the art. 50 fix has to happen anyway: a matter of hours, not months.
- The high-risk deferral is no excuse to postpone the audit log: building it now is cheap, adding it later is expensive.
- For 90% of SMEs the real work stays small: a policy, basic training, a transparency notice.
What actually slips: Annex III
Annex III lists the high-risk systems: automated recruitment, credit scoring, critical infrastructure management, educational assessment, some healthcare uses.
For these, the Digital Omnibus proposal pushes back (to end of 2027 per the text under discussion) the heavy obligations: formal risk assessment, structured logging, technical documentation, EU database registration.
If you use AI to decide or significantly influence hiring or evaluations, you fall here. The deferral buys you breathing room, not absolution.
What does NOT slip: the three pieces live in August 2026
1. The bans (unacceptable risk)
Social scoring, subliminal manipulation, exploitation of vulnerabilities, certain biometric recognition uses. Banned and staying banned. For the average SME this is not a concern, but it bears saying: no postponement here.
2. Transparency, art. 50
This touches many SMEs. If you have a chatbot, a voice assistant or an agent that talks to external customers, users must clearly know they are interacting with an AI system, not a person.
AI-generated or manipulated content (images, audio, client-facing text) must also be labelled where appropriate.
The practical fix is small: an explicit line in the chatbot, a route to a human, a label on generated content. Hours of work, not weeks.
3. AI literacy, art. 4
Anyone who develops or uses AI systems must ensure staff operating them have an adequate level of competence. This is not deferred by the Digital Omnibus and already applies.
For an SME that means: a 1-page internal policy (what is allowed, what is not, how to report issues) and basic training for whoever uses the tools. Nothing heroic, but it has to be documented.
The trap: using the deferral as an excuse
The most concrete risk we see in calls is not the fine. It is the mental deferral: “high-risk slips to 2027, so we will add the audit log later”.
That is an economic mistake, not just a compliance one. Bolting immutable logging, decision tracking and human oversight onto an agent already in production costs far more than designing them in from day one.
In our sprints these are default, not because we are heroic, but because without them we cannot work on regulated sectors:
- immutable audit log on every agent decision
- human always in the loop on critical cases (for recruitment: always on the final offer)
- DPA art. 28 GDPR included in the contract
- no LLM training on your data
Build it now and the deferral becomes a safety margin. Postpone it and 2027 arrives sooner than you think.
What to do now, in order
- Map your AI systems by risk tier. Client-facing chatbot = limited (art. 50). Automated recruitment = high (Annex III, deferred). Internal invoice automation = minimal.
- Fix art. 50 on everything that talks to the outside. Hours of work.
- Write the policy and train the team (art. 4). Already due, not deferred.
- Do not postpone the audit log even if high-risk slips.
For the tier-by-tier map, we have a guide on the AI Act for companies. For training and the internal policy, the AI Adoption track. If the topic is a client-facing chatbot to bring into compliance, we start from customer support.
If you want to understand which tier your systems fall into and what really needs doing, let’s talk, 20 minutes, no pitch.
Frequently asked questions
What people usually ask us.
Does the Digital Omnibus cancel my AI Act obligations?
My SME uses a website chatbot: what do I need to do in August 2026?
What is art. 4 AI literacy and when does it apply?
If my agent screens CVs, does the Annex III deferral save me?
Keep reading
Transizione 5.0 and AI Software: AI Act Compliance
From 2026, AI software funded under Italy's Transizione 5.0 risks losing the credit if the system isn't AI Act compliant. What a CFO must check first.
Agentic commerce for SMBs: selling to AI agents
Agentic commerce for SMBs: when the buyer is your customer's AI agent, are your product data, prices and checkout ready? A practical guide for sales leads.
Next step
Where are you on the AI journey?
The check-up gives you an AI readiness score (0–100) + 3 concrete next steps. 3 minutes, no email.