The EU AI Act Delay: What the Digital Omnibus Changes for Mid-Size Companies
On May 7, 2026, the Council of the EU and the European Parliament reached a provisional agreement on the Digital Omnibus on AI, the simplification package the Commission put forward in November 2025 to rework the AI Act's timeline before its heaviest obligations ever took effect. If you read our breakdown of the August 2026 deadline earlier this year and kicked off a compliance sprint, some of that urgency just got rescheduled. Some of it did not, and the parts that survived are the parts most mid-size companies actually touch.
I've spent the past few weeks fielding versions of the same question from operators we advise at FirmAdapt: "so we can stop now, right?" The short answer is that one track got sixteen extra months, one track kept its original August date, and a third got a new date that is only four months later than the old one. This post walks through what moved, what stayed, and how I'd spend the window. It also updates the four AI Act posts on this blog, all written before the omnibus, so you don't have to cross-reference them against the news yourself.
What the omnibus actually moved
Two deferrals matter for this audience.
First, the big one. Obligations for standalone high-risk systems under Annex III, the list covering AI in hiring, credit decisions, education, essential services and the other categories we mapped in our Annex III walkthrough, were due to apply on August 2, 2026. Gibson Dunn's alert on the agreement confirms the new date: December 2, 2027. That's sixteen extra months for the tier with the heaviest workload, the one requiring risk management, data governance, technical documentation, logging, human oversight and conformity assessment.
Second, AI embedded in products that already sit under EU safety legislation (machinery, medical devices, vehicles, the Annex I list) was due in August 2027 and now applies from August 2, 2028, per the same analysis. If you manufacture or import regulated products with AI inside, you gained a year.
One caveat before you update any board deck. This is a provisional political agreement. It becomes law when it is formally adopted and published in the Official Journal, which observers expect to happen before August 2, 2026. Until then, the old dates are technically still on the books. I wouldn't build a plan that assumes the omnibus collapses, but I also wouldn't tell customers the law has changed until it actually has.
What still lands on August 2, 2026
The transparency obligations in Article 50 kept their original date, and they're the piece with the broadest reach across ordinary companies. If you run a customer-facing chatbot, a voice agent, or an AI assistant inside your product, users must be told they're interacting with AI, clearly and at first contact. Disclosure duties for deepfakes and for emotion recognition and biometric categorisation systems arrive the same day. Everything in our Article 50 guide for B2B SaaS still applies on the original schedule, with one adjustment.
The adjustment is the machine-readable marking of AI-generated content, the requirement that generative systems label their output so software can detect it as synthetic. Gibson Dunn's alert puts the new date for that obligation at December 2, 2026. That's four months of relief rather than sixteen. If your product or your marketing operation generates synthetic media at scale, this remains a 2026 problem.
Enforcement wasn't softened either. The penalty structure we detailed in our fines breakdown, topping out at EUR 35 million or 7 percent of global revenue with transparency violations in a lower tier, survives the omnibus intact. What did change is who qualifies for proportionate treatment, which brings me to the part of the package I think mid-size companies are underweighting.
The small mid-cap regime is the sleeper change
The AI Act always had lighter-touch provisions for SMEs. The omnibus extends them to a category the EU calls small mid-cap enterprises. Orrick's briefing on the package puts the thresholds at up to 750 employees with annual turnover up to EUR 150 million, or a balance sheet total up to EUR 129 million. That covers a very large slice of the mid-market, including plenty of companies that had assumed they would be treated like enterprises under the Act.
Qualifying gets you concrete things: simplified technical documentation templates that notified bodies must accept, more proportionate quality management expectations, priority access to regulatory sandboxes, and penalty caps scaled to company size. What it does not get you is an exemption or a different deadline. A 400-person logistics firm running an AI shift-scheduling tool that strays into worker-management territory has the same December 2027 date as a multinational. It just carries a lighter documentation and penalty profile on the way there.
The practical move is to establish this week whether you qualify, and to write the determination down with the supporting numbers. It changes what you should buy. I've seen mid-size firms scope AI Act programs off enterprise checklists and price themselves into paralysis, when the standard they will actually be held to is the simplified template.
Updating our earlier posts, one by one
Four posts on this blog covered the Act as it stood before May. Consider this the errata for all four.
- The August 2026 deadline overview: the high-risk portions of that timeline moved to December 2, 2027. The transparency portions did not. Wherever that post says August 2026, read it as still correct for Article 50 duties and sixteen months later for Annex III ones.
- The Annex III walkthrough: intact on substance. The categories, the classification logic and the exemption analysis are untouched by the omnibus, so any system inventory you built from it remains valid. Only the date moved.
- The Article 50 transparency guide: still lands August 2, 2026 for chatbot, deepfake and biometric disclosure. The content-marking element inside it now points at December 2, 2026.
- The fines breakdown: caps unchanged. If you newly qualify as a small mid-cap, your realistic exposure is lower than that post implied, and your documentation burden shrinks with it.
Why I'd keep the program running
I've watched three mid-market compliance efforts stall the same way, and none of the failures had anything to do with the regulation itself. A deadline moves. The steering committee reallocates budget to something revenue-facing. The two people who understood the system inventory rotate off. Fourteen months later the new deadline is a quarter away, the inventory is stale, the vendor contracts renewed without the clauses you needed, and you're paying rush rates for help that would have cost half as much spread across two years.
The Annex III workload punishes restarts more than most projects do. Data governance and logging have to be designed into systems, which means catching development cycles as they happen rather than retrofitting after the fact. Human oversight only counts if the humans are trained and the escalation paths are drilled. Vendor documentation requires contract leverage, and you mostly get that at renewal time. None of it compresses well into a final quarter.
There's also a sequencing benefit hiding inside the delay. Part of the Commission's stated rationale for the deferral was that the harmonized standards and support tools companies need were not ready. Over the next year or so, the standards bodies and the Commission are expected to publish the templates and guidance that turn compliance from interpretation into paperwork. So the sensible plan does the slow structural work now (inventory, data governance, contracts, oversight design) and deliberately defers the template-shaped work until the templates exist. Grinding through documentation this year, in formats you may have to redo, is the one genuinely wasteful use of the window.
A concrete plan for the sixteen months
Here's what I'd put on the calendar, roughly in order.
- Reconfirm the exposure map this month. One page per AI system: what it does, whose data it touches, whether it plausibly hits an Annex III category or an Article 50 duty, and who owns it. If you built this in early 2026, refresh it, because tools multiply between audits.
- Ship the August items now. Chatbot and assistant disclosure at first contact, deepfake labeling where relevant. For most companies this is disclosure copy, a UI pattern, and a review of every place where AI talks to a human. Days of work, and the deadline is weeks away.
- Sort content marking before December 2, 2026. If you generate synthetic media, pick and test your watermarking or provenance approach. If you build on vendor models, get written confirmation of how their marking works and which obligations still fall on you as the deployer.
- Document small mid-cap eligibility. Headcount, turnover, balance sheet, one memo. Then scope everything downstream against the simplified regime instead of an enterprise checklist.
- Plan Annex III backward from December 2, 2027. A workable shape: gap analysis against your inventory in 2026, data governance and oversight design through mid-2027, documentation and conformity preparation in the final stretch. Put dated checkpoints in front of leadership so the program can't quietly dissolve.
- Fix vendor paper at every renewal. Any AI-adjacent contract signed this year will still be live in December 2027. Add documentation duties, incident notification, and cooperation-with-assessment clauses while you have leverage, which is at signature, not two months before your deadline.
- Watch for publication in the Official Journal. Until formal adoption, keep one line in every plan noting that the new dates are agreed but not yet law. It costs nothing and avoids an awkward retraction later.
The dates worth writing down
- August 2, 2026: Article 50 transparency duties apply, including chatbot and deepfake disclosure. Formal adoption of the omnibus is expected around the same time.
- December 2, 2026: machine-readable marking of AI-generated content applies.
- December 2, 2027: Annex III high-risk obligations apply.
- August 2, 2028: obligations for AI embedded in regulated products apply.
My read on the omnibus, after a year of working with the Act in client settings, is fairly mundane. Brussels concluded that the support infrastructure was not ready and bought time for everyone, itself included. Take the time, and take it with a dated plan attached, because the first deadline on that list is now weeks away and it covers the chatbot sitting on your homepage.