All articles
· 6 min read · Daniel Levis

Digital Omnibus: high-risk slips to 2027, what stays live in August 2026

The Digital Omnibus defers Annex III to 2027. But in August 2026 transparency (art. 50), literacy (art. 4) and the bans stay live. What SMEs must do now.

The June 2026 Digital Omnibus did one simple thing and one thing that got misread.

The simple thing: it proposed deferring the high-risk obligations under Annex III to end of 2027. The misread thing: half the AI consulting newsletters read it as “the AI Act is postponed, you can relax until 2027”.

Not true. In August 2026, obligations that touch far more SMEs than the high-risk tier stay live. Here is the honest map of what slips and what does not.

Key takeaways:

  • The Digital Omnibus defers the Annex III (high-risk) obligations to end of 2027, not the whole AI Act.
  • Still mandatory in August 2026: the bans (unacceptable risk), the art. 50 transparency duty (tell users they are talking to an AI) and art. 4 AI literacy (train the team).
  • If you run a chatbot or a client-facing agent, the art. 50 fix has to happen anyway: a matter of hours, not months.
  • The high-risk deferral is no excuse to postpone the audit log: building it now is cheap, adding it later is expensive.
  • For 90% of SMEs the real work stays small: a policy, basic training, a transparency notice.

What actually slips: Annex III

Annex III lists the high-risk systems: automated recruitment, credit scoring, critical infrastructure management, educational assessment, some healthcare uses.

For these, the Digital Omnibus proposal pushes back (to end of 2027 per the text under discussion) the heavy obligations: formal risk assessment, structured logging, technical documentation, EU database registration.

If you use AI to decide or significantly influence hiring or evaluations, you fall here. The deferral buys you breathing room, not absolution.

What does NOT slip: the three pieces live in August 2026

1. The bans (unacceptable risk)

Social scoring, subliminal manipulation, exploitation of vulnerabilities, certain biometric recognition uses. Banned and staying banned. For the average SME this is not a concern, but it bears saying: no postponement here.

2. Transparency, art. 50

This touches many SMEs. If you have a chatbot, a voice assistant or an agent that talks to external customers, users must clearly know they are interacting with an AI system, not a person.

AI-generated or manipulated content (images, audio, client-facing text) must also be labelled where appropriate.

The practical fix is small: an explicit line in the chatbot, a route to a human, a label on generated content. Hours of work, not weeks.

3. AI literacy, art. 4

Anyone who develops or uses AI systems must ensure staff operating them have an adequate level of competence. This is not deferred by the Digital Omnibus and already applies.

For an SME that means: a 1-page internal policy (what is allowed, what is not, how to report issues) and basic training for whoever uses the tools. Nothing heroic, but it has to be documented.

The trap: using the deferral as an excuse

The most concrete risk we see in calls is not the fine. It is the mental deferral: “high-risk slips to 2027, so we will add the audit log later”.

That is an economic mistake, not just a compliance one. Bolting immutable logging, decision tracking and human oversight onto an agent already in production costs far more than designing them in from day one.

In our sprints these are default, not because we are heroic, but because without them we cannot work on regulated sectors:

  • immutable audit log on every agent decision
  • human always in the loop on critical cases (for recruitment: always on the final offer)
  • DPA art. 28 GDPR included in the contract
  • no LLM training on your data

Build it now and the deferral becomes a safety margin. Postpone it and 2027 arrives sooner than you think.

What to do now, in order

  1. Map your AI systems by risk tier. Client-facing chatbot = limited (art. 50). Automated recruitment = high (Annex III, deferred). Internal invoice automation = minimal.
  2. Fix art. 50 on everything that talks to the outside. Hours of work.
  3. Write the policy and train the team (art. 4). Already due, not deferred.
  4. Do not postpone the audit log even if high-risk slips.

For the tier-by-tier map, we have a guide on the AI Act for companies. For training and the internal policy, the AI Adoption track. If the topic is a client-facing chatbot to bring into compliance, we start from customer support.

If you want to understand which tier your systems fall into and what really needs doing, let’s talk, 20 minutes, no pitch.

Frequently asked questions

What people usually ask us.

Does the Digital Omnibus cancel my AI Act obligations?
No. It pushes back the high-risk obligations under Annex III (to end of 2027 per the proposal). Still fully in force in August 2026: the bans, the art. 50 transparency duty (telling users they are talking to an AI) and art. 4 AI literacy (training your team). Anyone running client-facing chatbots or agents must still comply.
My SME uses a website chatbot: what do I need to do in August 2026?
Art. 50 requires that users clearly know they are interacting with an AI system, not a person. A plain disclosure inside the chatbot plus a route to a human is enough. It is a matter of hours, not months. We handle it by default in our customer support work.
What is art. 4 AI literacy and when does it apply?
Art. 4 requires anyone who develops or uses AI systems to ensure adequate competence among the staff operating them. It already applies and is not deferred by the Digital Omnibus. In practice: an internal policy and basic team training. We cover it with our AI Adoption tracks.
If my agent screens CVs, does the Annex III deferral save me?
Automated recruitment is in Annex III (high-risk), so the postponement pushes back heavy duties like risk assessment and formal logging. But we advise not to wait: building an immutable audit log and keeping a human on the final offer costs little now and a lot if you bolt it on later.
ai actcompliancedigital omnibusgdprstrategy

Next step

Where are you on the AI journey?

The check-up gives you an AI readiness score (0–100) + 3 concrete next steps. 3 minutes, no email.

20 min with Daniel