Tallinn: Estonian software firms that spent 2025 budgeting for AI Act compliance audits have quietly moved that line item to 2028. The law changed underneath them, and almost nobody complained.
The AI Omnibus entered into force on 27 July 2026 as Regulation (EU) 2026/1744, amending the original AI Act along with the aviation safety and machinery regulations. Its central move pushes back the application date for high-risk obligations: standalone high-risk AI systems now face compliance on 2 December 2027, and high-risk systems embedded in physical products get until 2 August 2028. The Council gave final approval on 29 June, three weeks after Parliament voted on 16 June.
Supporters call this operational realism. The harmonised technical standards that companies need in order to demonstrate conformity were never going to exist by the original date. European standardisation bodies are still drafting them. Asking a firm in Tallinn or Turin to prove conformity against a standard that does not yet exist produces paperwork, not safety.
Critics answer that the Commission created the gap and then used it as an argument. Standards work started late because the Commission issued its mandate late. Two extra years of unregulated deployment in hiring, credit scoring, education and border control is a substantial concession to win in exchange for an administrative problem Brussels caused itself.
Both readings hold. What deserves more attention is the part of the omnibus that tightens rather than loosens. The regulation inserts a new prohibition covering AI systems that generate non-consensual intimate imagery or child sexual abuse material, including tools that edit clothing out of existing photographs. That ban applies from December 2026, a full year before the delayed high-risk rules. A simplification package therefore delivers Europe’s first outright ban on a generative AI use case, and it arrives faster than anything it postponed.
Smaller developers gain elsewhere. The omnibus eases documentation requirements for firms below certain thresholds, widens access to regulatory sandboxes, and extends real-world testing windows. Estonia, Ireland and the Nordic states pushed hardest for those provisions, arguing that the original text imposed multinational compliance costs on companies with a dozen engineers.
The strategic question is whether delay buys anything. Two more years gives standardisation bodies time to finish, gives national market surveillance authorities time to hire people who understand model evaluation, and gives firms time to build compliance functions. It also gives the largest developers two more years of market position built on systems nobody has audited. Whoever holds enterprise contracts in December 2027 will be hard to displace, and switching costs in AI procurement are already high.
Estonia offers a useful test case. The country runs more public services through algorithms than most of its neighbours, and several of those systems sit squarely in the high-risk category. Officials here now have until 2027 to document decision logic that citizens already live with. Whether they use the time or simply enjoy it will be visible in the Commission’s implementation reporting long before the deadline arrives.





