What did the omnibus actually change?
Timing and paperwork, not the architecture. The EU AI Act’s risk classes, prohibitions and the transparency duties that applied in August 2026 all stand. What moved are the high-risk compliance dates, set as fixed calendar dates rather than the standards-conditional timeline the Commission first proposed: 2 December 2027 and 2 August 2028. Smaller companies got the practical relief: simplified technical documentation, lighter registration, and explicit permission to process special-category data for bias detection under safeguards.
How do you know whether your AI counts as high risk?
By what the system decides, not by how clever it is. The Act’s high-risk list covers systems that make or shape decisions about people and safety: hiring and worker management, credit and insurance decisions, education, access to essential services, and AI acting as a safety component in regulated products. A tool that drafts, summarizes or executes a narrow procedural step usually falls outside it, and a provider can self-assess that its Annex III system is exempt. The omnibus kept the public register for self-assessed systems, in lighter form, so the judgment call still leaves a trace. Start with an honest risk classification, not with the answer you would prefer.
What does the omnibus mean for AI you buy rather than build?
Most mid-sized companies will meet the AI Act as deployers of purchased systems, and the omnibus left that role’s basics alone: use the system as the vendor instructs, keep human oversight where the rules require it, and know which of your suppliers’ products sit in the high-risk categories. What changed is the calendar your vendors are working to, since they now have until the 2027 and 2028 dates to ship compliant versions. Put those dates into contracts and renewal talks now, as part of AI vendor assessment, rather than learning in 2028 that a critical tool was never going to make it.
What should a company do with the extra time?
Not wait. The deferral rewards firms that use it to build the boring machinery: an inventory of AI systems, risk classification, and evidence trails inside a working AI governance program. The omnibus moved deadlines, not accountability, and customers keep asking for proof regardless of Brussels timetables, which is why certifiable structures such as ISO 42001 keep gaining ground. Treat the new dates as a project plan, not a pause, and fold them into the same AI compliance file an auditor will eventually open.