What Is the EU AI Act Digital Omnibus?

6 min readAbleneo AI transformation team

Short answer. The Digital Omnibus on AI is a European Commission proposal from 19 November 2025 that simplifies the EU AI Act. Its headline change moves the compliance deadline for standalone high-risk AI systems from 2 August 2026 to 2 December 2027, and for high-risk AI embedded in regulated products to 2 August 2028. The obligations themselves do not change. Only the date the rules start to bite moves.

1What This Means in Practice

The Digital Omnibus on AI sits inside a wider Digital Omnibus package the Commission tabled to simplify EU digital law. The package touches the AI Act, the GDPR, the Data Act, and the EU’s cybersecurity rules. For the AI Act specifically, the change that matters most is time. The most demanding set of obligations, the ones attached to high-risk systems, now applies later.

The deadline shift is not a blanket pause. It targets defined categories.

Alongside the deadline, the proposal trims administrative load. It extends simplified technical documentation and lighter quality-management expectations to small mid-cap companies, not only to SMEs and microenterprises. It removes the duty to register certain systems in the EU database when they are judged non-high-risk because they perform narrow or procedural tasks. It also shifts AI literacy from a firm-level obligation to something the Commission and Member States are asked to encourage.

2Why This Matters for Regulated Industries

Banks and insurers own several systems the Act treats as high-risk. Annex III names creditworthiness assessment and credit scoring of individuals, and risk assessment and pricing in life and health insurance. Before the Omnibus, these systems had to meet the full high-risk regime by 2 August 2026. Now the binding date is 2 December 2027. That is 16 more months to build the documentation, the risk management, the human oversight, and the logging the Act requires.

The extra time is not a reprieve from the work. DORA has applied to financial entities since 17 January 2025, and it already demands control over the systems that run these models. The AI Act adds an accountability layer on top. A financial firm that waits until late 2027 to start will face the same volume of evidence to produce, with less runway and the same supervisor watching. The obligations did not shrink. The clock moved.

The Digital Omnibus on AI, proposed on 19 November 2025, moves the high-risk AI compliance deadline from 2 August 2026 to 2 December 2027 for standalone Annex III systems.

3What Exactly Changed for High-Risk AI Deadlines?

Before the Omnibus, all high-risk obligations were due on a single date, 2 August 2026. The proposal splits that date into two. Standalone high-risk systems under Annex III, the category that covers most banking and insurance use, now apply from 2 December 2027. High-risk AI built into products already regulated under Annex I, such as medical devices or machinery, applies from 2 August 2028.

The delay is also tied to readiness. The revised text links the start of high-risk duties to the availability of the harmonised standards and support tools that let firms comply, so the deadline does not arrive before the technical guidance does. The fines for breaching high-risk duties are unchanged at up to EUR 15 million or 3% of worldwide annual turnover, whichever is higher.

4Does the Digital Omnibus Reduce What a Bank Actually Has to Do?

For the core high-risk duties, no. Risk management, data governance, technical documentation, human oversight, logging, and post-market monitoring all remain. The Omnibus moves the date and eases the administrative packaging, not the substance. A credit-scoring model still has to be documented, tested for bias, and kept under human oversight.

What it does cut is friction at the edges. Smaller firms and small mid-caps get simplified documentation templates and lighter quality-management requirements. Systems that qualify as non-high-risk through narrow-task exemptions no longer need EU database registration. Providers and deployers of non-high-risk systems may use sensitive personal data where strictly necessary to detect and correct bias. These are targeted reductions, and the high-risk regime stands.

5How Does the Omnibus Interact With DORA?

The two regimes run in parallel and do not cancel each other. DORA has been fully in force for financial entities since 17 January 2025, covering ICT risk management, incident reporting, resilience testing, and third-party risk. The AI Act governs how AI systems are built, classified, and controlled. The Omnibus changes only the AI Act’s timeline. A bank’s DORA duties are untouched.

In practice the overlap is an advantage. The system inventory, ownership records, and control logs a firm builds for DORA are the same artefacts the AI Act’s high-risk regime expects. A financial institution that treats the extra 16 months as time to align both frameworks, rather than as time to postpone, turns two regulations into one governance model.

6What Should a Financial Institution Do Before December 2027?

Do not read the new date as permission to wait. Start with an inventory of every AI system, its purpose, its owner, and its risk classification under the Act. Most compliance gaps trace back to a system nobody had mapped. The inventory is the artefact that turns the regulation into a work list.

Then use the added time deliberately. Build the risk-management file, the human-oversight design, and the logging for each high-risk system now, while the deadline is far enough away to do it well. Firms that start in 2026 will meet 2 December 2027 with tested controls. Firms that start in 2027 will meet it with a scramble.

7The Ableneo Perspective

The Omnibus gives regulated firms more time, and the firms that gain from it are the ones that treat AI as accountable production infrastructure rather than as pilots. That is the work Ableneo does. In 2025 Ableneo shipped 34 production AI projects across financial services, insurance, and other regulated sectors, and about 80% of the projects we start reach production. We map each AI system to its risk tier, its owner, and its evidence trail before it ships, so a shifting deadline changes the schedule, not the readiness. See the Ableneo AI Transformation FAQ for related answers on EU AI Act and DORA obligations.

Key takeaways

Sources

Planning AI in a regulated business? Ableneo takes systems from classification to governed production.

Talk to Ableneo