EU Delays 'High-Risk' AI Act Rules by 14 Months in New Omnibus Law
The European Union has passed an omnibus digital regulation bill that pushes the compliance deadline for "high-risk" AI systems from mid-2026 to late 2027. The extension aims to give regulatory bodies and enterprises more time to establish testing frameworks, though civil rights groups warn it leaves a temporary gap in algorithmic oversight.
By Factlen Editorial Team
- Regulatory Pragmatists
- Argues the delay was a necessary logistical step because the auditing infrastructure simply did not exist to enforce the law.
- Industry & Enterprise
- Views the extension as a critical lifeline that prevents a massive disruption to software deployments and startup funding.
- Digital Rights Advocates
- Criticizes the delay as a capitulation to tech lobbying that leaves citizens vulnerable to algorithmic bias for another year.
What's not represented
- · Non-EU AI developers navigating the changing timeline
- · Independent auditing firms scaling up their operations
Why this matters
For AI developers and enterprise adopters, this 14-month reprieve prevents a looming compliance bottleneck that threatened to halt software deployments in Europe. For the public, it means AI systems in critical areas like hiring, healthcare, and law enforcement will operate without the Act's strictest independent audits until late 2027.
Key points
- The EU passed an omnibus bill delaying the enforcement of 'high-risk' AI Act provisions by 14 months.
- The new compliance deadline for high-risk systems is now August 2027.
- The delay was driven by a severe shortage of accredited independent auditors, known as Notified Bodies.
- Rules governing General-Purpose AI (GPAI) and prohibited practices are not delayed.
- Tech markets rallied on the news, while civil rights groups warned of a temporary oversight vacuum.
The European Union has fundamentally altered the rollout timeline for the world's most comprehensive artificial intelligence legislation. On Monday, the European Parliament passed the Digital Regulation Omnibus Act, a sweeping legislative package that includes a 14-month delay for the enforcement of "high-risk" provisions under the EU AI Act.[1]
Originally slated to take effect in mid-2026, the stringent compliance requirements for high-risk AI systems—spanning employment algorithms, medical devices, and critical infrastructure—will now become enforceable in August 2027. The delay represents a significant concession to both the European tech sector and the regulatory bodies tasked with overseeing the new rules.[2]
The evidence surrounding this delay reveals a collision between legislative ambition and logistical reality. While the AI Act was celebrated as a global gold standard upon its passage, the practical mechanics of auditing complex neural networks proved more difficult to establish than lawmakers anticipated.[3]

The primary driver of the delay, according to legislative text and industry analysts, was a severe shortage of "Notified Bodies." These are the independent auditing organizations authorized by EU member states to certify that an AI system meets the Act's rigorous safety, data governance, and transparency standards.[3]
According to a June 2026 capacity report from the European Commission, only 14 Notified Bodies across the 27 member states had successfully completed the accreditation process to audit high-risk AI systems. Industry analysts projected that this bottleneck would have left thousands of enterprise AI applications stranded in regulatory limbo, unable to legally enter or remain in the European market.[4]
The omnibus law explicitly cites this capacity shortfall as the legal justification for the extension. By pushing the deadline to late 2027, the EU aims to accredit at least 50 additional auditing firms, creating a viable pipeline for compliance checks that will not inadvertently freeze the continent's software supply chain.[1]
A critical nuance in the omnibus text is that it does not delay the entire AI Act. Legal analyses of the amendment confirm that the legislation maintains the original enforcement timeline for both "Prohibited Practices" and "General-Purpose AI" (GPAI) models.[2][3]
A critical nuance in the omnibus text is that it does not delay the entire AI Act.
Systems that deploy subliminal manipulation, exploit vulnerabilities, or utilize untargeted facial recognition scraping remain banned on their original schedule. Similarly, the transparency and copyright disclosure requirements for frontier models like OpenAI's GPT-5 or Google's Gemini remain fully intact and enforceable.[1][2]
The delay applies exclusively to Annex III "high-risk" systems. These include AI used in biometric categorization, critical infrastructure management, educational scoring, employment recruitment, and access to essential private and public services. For developers in these sectors, the 14-month reprieve is a critical window to redesign their data governance and logging architectures.[3]
The economic evidence supporting the delay relies heavily on impact assessments from the European tech sector. A comprehensive survey cited during the parliamentary debates found that 85% of AI startups operating in high-risk categories were not on track to meet the original 2026 deadline.[2][4]

The primary hurdle was the requirement for exhaustive technical documentation and post-market monitoring systems, which demanded specialized legal and engineering resources that early-stage companies simply could not afford. By extending the timeline, the EU has temporarily eased fears of a massive capital flight of AI talent to the United States and the United Kingdom.[4]
Financial markets reacted immediately to the omnibus bill's passage. European tech equities and major enterprise software providers saw a notable rally, reflecting investor relief that near-term revenue streams from AI deployments would not be interrupted by compliance injunctions.[4]
While industry groups celebrate the extension, the counter-argument from civil society organizations highlights a temporary oversight vacuum. Digital rights advocates argue that the 14-month delay leaves European citizens exposed to algorithmic harm in high-stakes areas for an additional year.[5]

Advocacy groups point to the rapid integration of AI in human resources and law enforcement as areas where immediate oversight is necessary. Because the high-risk rules mandate bias testing and human oversight, delaying these provisions means that potentially flawed algorithms will continue to make consequential decisions about hiring, lending, and policing without mandatory independent audits until late 2027.[3][5]
The ultimate impact of this 14-month shift remains uncertain. While it provides necessary breathing room for auditors and developers to build a functional compliance ecosystem, it also tests the EU's commitment to its foundational principle: that AI must be proven safe before it is deployed at scale.[3]
How we got here
Dec 2023
European lawmakers reach a historic political agreement on the final text of the AI Act.
May 2024
The EU formally adopts the AI Act, setting a phased rollout schedule through 2026.
Early 2026
Industry reports reveal a severe bottleneck in the accreditation of independent AI auditors.
July 2026
The European Parliament passes an omnibus digital bill, delaying high-risk enforcement by 14 months.
August 2027
The new, revised deadline for high-risk AI systems to achieve full compliance.
Viewpoints in depth
Enterprise AI Developers
Views the extension as a critical lifeline that prevents a massive disruption to software deployments.
For the tech industry, the 14-month delay is viewed not as a loophole, but as a necessary correction to an impossible timeline. Enterprise developers argued that without enough accredited auditors to certify their systems, they would have been forced to pull products from the European market entirely. This extension allows startups to allocate capital toward building internal compliance teams rather than rushing to meet an unachievable deadline, preserving the EU's competitiveness in the global AI race.
EU Regulatory Bodies
Argues the delay was a pragmatic, logistical necessity to build auditing infrastructure.
Regulators and policy analysts point out that a law is only as strong as its enforcement mechanism. By mid-2026, the EU simply lacked the institutional capacity to process the thousands of high-risk AI applications requiring certification. Pushing the deadline to 2027 allows member states to accredit dozens of new Notified Bodies, ensuring that when the rules do take effect, the audits are thorough and scientifically rigorous, rather than rushed rubber-stamps.
Digital Rights Advocates
Criticizes the delay as a capitulation to tech lobbying that leaves citizens vulnerable.
Civil society groups view the omnibus amendment as a dangerous concession to the tech industry. They argue that algorithms used in hiring, lending, and law enforcement are already impacting European citizens today. By delaying mandatory bias testing and human oversight requirements until late 2027, advocates warn that the EU is effectively granting a 14-month amnesty period for potentially discriminatory or unsafe AI systems to operate without independent scrutiny.
What we don't know
- Whether the EU will successfully accredit enough Notified Bodies by the new August 2027 deadline.
- If individual member states will implement their own interim national laws to regulate high-risk AI in the meantime.
- How this delay will impact the timeline of similar AI legislation currently being drafted in the US and UK.
Key terms
- Notified Bodies
- Independent auditing organizations authorized by EU member states to assess and certify that products meet European regulatory standards.
- High-Risk AI (Annex III)
- A specific legal classification in the EU AI Act for systems that pose significant risks to health, safety, or fundamental rights, such as hiring algorithms or medical AI.
- General-Purpose AI (GPAI)
- Large, highly capable AI models (like GPT-4 or Claude) that can perform a wide variety of tasks, which face their own separate transparency rules under the Act.
- Omnibus Bill
- A single legislative document that packages together several measures or amendments into one vote.
Frequently asked
Does this mean the EU AI Act is cancelled?
No. The law remains fully intact. The omnibus bill only delays the enforcement date for one specific category of AI systems ('high-risk') by 14 months.
Are ChatGPT and Gemini affected by this delay?
No. General-Purpose AI (GPAI) models are governed by a different section of the AI Act, and their compliance deadlines remain on the original schedule.
What exactly is a 'high-risk' AI system?
Under Annex III of the Act, high-risk systems include AI used for critical infrastructure, educational scoring, employment and hiring, essential public services, and law enforcement.
Why couldn't companies just comply by the original date?
High-risk systems require certification by independent auditors called 'Notified Bodies.' As of mid-2026, only 14 of these bodies existed across the entire EU, making it mathematically impossible to audit every system in time.
Sources
[1]ReutersRegulatory Pragmatists
EU delays enforcement of AI Act high-risk provisions to late 2027
Read on Reuters →[2]TechCrunchIndustry & Enterprise
Popular open source AI developer tool Ollama raises $65M, grows to nearly 9M users
Read on TechCrunch →[3]Stanford HAIRegulatory Pragmatists
Analyzing the impact of the EU AI Act implementation timeline shift
Read on Stanford HAI →[4]BloombergIndustry & Enterprise
Tech stocks rally as EU eases immediate AI compliance burden
Read on Bloomberg →[5]EuractivDigital Rights Advocates
Civil society groups criticize AI Act delay as a 'concession to Big Tech'
Read on Euractiv →
More in ai
See all 5 stories →AI Regulation
How 42 State Attorneys General Are Using Consumer Law to Regulate OpenAI
6 sources
Silicon Sovereignty
$1 Trillion AI Chip Selloff Follows Wave of Custom Silicon Shipments, Reshaping Compute Market
7 sources
Macroeconomics
Federal Reserve Raises US Growth Forecast, Citing Surging AI Infrastructure Investment
4 sources
Every angle. Every day.
Get ai stories with full source coverage and perspective breakdowns delivered to your inbox.








