In June 2026 the EU adopted the Digital Omnibus, the most consequential amendment to the AI Act since it was passed. Coverage compressed it into one word — delayed — and a great many teams filed the whole regulation under "2027 problem". That reading is expensive, because the obligations that were not deferred are precisely the ones that apply to ordinary software companies.
What moved
| Obligation set | Was | Now |
|---|---|---|
| Chapter III high-risk duties for Annex III systems | 2 August 2026 | 2 December 2027 |
| Annex I — AI as a safety component in regulated products | August 2027 | August 2028 |
What did not move
| Obligation | Status | Who it hits |
|---|---|---|
| Article 5 prohibited practices | Enforceable now | Everyone |
| Article 4 AI literacy | Enforceable now | Any organisation whose staff operate AI systems |
| Article 50 transparency | Enforceable now | Chatbots, generative features, synthetic media |
| Article 53 GPAI duties | Enforceable now | Model providers, and anyone who became one by retraining |
If your product is a SaaS tool with an AI feature or a chatbot, the Omnibus gave you nothing. Your obligations were live before it and are live after it. The deferral was written for the companies facing conformity assessment, not for you.
The fine clarification everyone skipped
The Omnibus also confirmed the Article 99(6) position for SMEs and start-ups: the applicable fine is the lower of the fixed amount and the percentage of worldwide turnover — not the higher, which is the rule for large undertakings. Published guidance still routinely states this backwards. The full fine structure.
Why 16 extra months is less than it sounds
Conformity assessment for a genuinely high-risk system — risk management, data governance, technical file, logging, human oversight design, quality management, then assessment and registration — realistically takes 12 to 18 months. December 2027 minus 18 months is mid-2026. For teams that are actually in Annex III, the deferral converted an impossible deadline into a tight one, not a distant one.
The practical sequence has not changed:
- Establish whether you are in scope at all, and whether you are a provider or a deployer. Most misclassifications happen here.
- Check whether anything you ship is genuinely Annex III, and whether Article 6(3) takes it back out.
- Close the live obligations — Articles 4, 5, 50 — this quarter, because they carry enforcement powers today.
- If and only if something is high-risk, start the Chapter III programme now rather than in 2027.
The Omnibus is one amendment, not the last. Annex III is amendable by delegated act and further guidance is expected. Every change that affects how systems classify is recorded in our changelog, and material changes trigger a free re-issue for anyone holding a Reglynn report.
Did the Omnibus change anything for you?
For most SaaS and chatbot products the answer is no. The free check confirms which of your duties are live today.
Start the free scanNo card, no account. Full gap report from €59. See a real report first.
Self-assessment, not legal advice. This page and the Reglynn report are a structured self-assessment based on the EU AI Act (Regulation 2024/1689, as amended by the June 2026 Omnibus). They indicate where you likely stand and what to verify with a qualified advisor. Reglynn is not a notified body and issues no certification.
How this was made. Reglynn reports are generated by an AI system and reviewed before delivery. Reglynn is a Limited Risk AI system under Article 50; we disclose AI involvement wherever it occurs, including in our chat assistant. Our own self-assessment.