GRC & Compliance

The high-risk AI deadline may move. Plan as if it won't.

Published
Read time3 min read
GRC & Compliance

Under the Commission's proposed Digital Omnibus on AI, the obligations for Annex III high-risk AI systems would move from 2 August 2026 to no later than 2 December 2027, and Annex I product-embedded systems from 2 August 2027 to 2 August 2028. The EDPB and EDPS have said plainly that they are concerned. For anyone building a compliance plan, a moving deadline is the least useful thing to build it around.

What is on the table

The Digital Omnibus on AI is a simplification package. Two elements matter most for planning purposes.

Timing. The implementation of Annex III high-risk obligations would be delayed from 2 August 2026 to no later than 2 December 2027, and Annex I high-risk systems from 2 August 2027 to 2 August 2028.

Special category data. Under the AI Act as it stands, special category data may be used for bias detection and correction in high-risk systems only where strictly necessary. The proposal would extend that permission to all AI systems and models, and lower the threshold from "strictly necessary" to "necessary" or "necessary and proportionate".

In their joint opinion, the EDPB and EDPS supported the objective of simplification and competitiveness while warning that the changes could adversely affect the level of protection individuals enjoy, create legal uncertainty and make data protection law harder to apply. On timing specifically, they expressed concern that delay may harm fundamental rights and undermine legal certainty in a fast-moving field.

Key points
Proposed delay
Annex III to no later than 2 December 2027; Annex I to 2 August 2028.
Also proposed
Wider permission to use special category data for bias testing, at a lower threshold.
Unchanged
Article 50 transparency duties, which have applied since 2 August 2026.

Why a delay is a bad reason to slow down

There is an obvious temptation to reallocate the budget and revisit this in 2027. Three reasons not to.

The obligations that already apply are not delayed. Article 50 transparency duties have applied since 2 August 2026, the prohibited-practice provisions land on 2 December 2026, and the Commission has already begun using its enforcement powers. A delay to Annex III does not pause any of that.

Other regimes ask the same questions regardless. If an AI system makes or materially influences a decision about a person, the GDPR already requires a lawful basis, a DPIA in most cases, meaningful information to the individual and — under Article 22 — safeguards around solely automated decisions with legal or similarly significant effects. Sector regulators in financial services and healthcare are asking too. None of that waits for the AI Act.

The work is slow and mostly unglamorous. The delivery bottleneck for AI compliance is almost never the legal analysis. It is finding out which systems exist, who owns them, what they were trained on, what the vendor will actually tell you, and who has authority to overturn a decision. That takes quarters, not weeks, and none of it is wasted if a deadline moves.

The special category data change deserves scrutiny

The proposal to allow special category data for bias testing more widely is not obviously wrong — you genuinely cannot test a model for racial or gender bias without data about race or gender, and privacy law has long sat awkwardly with fairness testing.

But the practical risk is that "necessary for bias testing" becomes a durable justification for collecting sensitive attributes that are then available for other purposes. If you intend to rely on it, the controls that make it defensible are the familiar ones: collect the minimum, separate it from operational data, restrict access to the testing function, set a retention period and enforce it, and document the necessity argument at the time rather than reconstructing it later.

A reasonable planning posture

  • Treat the inventory as due now. It is the input to every version of this regulation and to the GDPR obligations that already apply.
  • Plan to the earlier date, and accept the slack gratefully. A programme that lands early is a good outcome. A programme that assumed 2027 and then discovers the delay was trimmed is not.
  • Watch the final text, not the proposal. "No later than 2 December 2027" is a ceiling in a proposal that is still being negotiated.
  • Separate what is AI-specific from what is not. Much of the work — DPIAs, lawful basis, transparency, human oversight, vendor documentation — is owed under existing law whatever happens to the AI Act's timetable.

Turn AI compliance into a live inventory and evidence trail, not a 2027 project.

Explore GRC Automation

Common questions

Not yet. The delay to no later than 2 December 2027 for Annex III systems is part of the Commission's proposed Digital Omnibus on AI, which is still in negotiation. Plan against the current law and treat any delay as slack rather than as a new baseline.

Article 50 transparency duties have applied since 2 August 2026, and the prohibited-practice provisions take effect on 2 December 2026. Enforcement powers over general-purpose AI model providers became applicable on 2 August 2026 and the Commission has already used its investigatory powers.

Under the AI Act as it stands, only where strictly necessary and for high-risk systems. The Digital Omnibus proposes widening this and lowering the threshold. Either way, the defensible approach is to collect the minimum, isolate it from operational use, restrict access, set and enforce retention, and document the necessity argument at the time.

Sources

  1. Digital Omnibus: EDPB and EDPS support simplification and competitiveness while raising key concerns — European Data Protection Board, 1 February 2026
  2. EDPB-EDPS Joint Opinion 1/2026 on the Digital Omnibus on AI — European Data Protection Board, 1 January 2026
  3. EU: EDPB and EDPS publish joint opinion on the European Commission's Proposal for the Digital Omnibus on AI — DLA Piper Privacy Matters, 1 February 2026