EU AI Omnibus: What the New Compliance Deadlines Mean for Your Product Roadmap
TL;DR
The EU AI Omnibus (Regulation 2026/1744) entered into force on July 27, 2026. It pushed the high-risk AI system obligations for Annex III use cases from August 2, 2026 to December 2, 2027, giving product teams an additional 16 months. Annex I (AI embedded in regulated products) moved to August 2, 2028. The prohibited practices ban and transparency obligations stayed on their original schedule and are already in force. If your Q3 2026 compliance sprint was built around the August deadline, your roadmap assumptions need revision now. Here is what changed, what stayed, and how to reprioritize.
The AI PM Minute
One tactic to make you a sharper AI PM, twice a week. 60 seconds to read. Free.
No fluff. Unsubscribe anytime.
What the Omnibus Amendment Changed
The original EU AI Act set a tiered compliance timeline. Prohibited practices and GPAI model obligations took effect August 2, 2025. High-risk AI system requirements for Annex III use cases were scheduled to hit August 2, 2026. Many product teams were mid-sprint on compliance when the Omnibus amendment passed.
Regulation 2026/1744 did not repeal the Act. It compressed its scope, extended key deadlines, and in some areas softened obligations for SMEs and startups. Here are the three changes that most affect product roadmaps.
Annex III deadline extended to December 2, 2027
Annex III covers high-risk AI systems in eight specific domains: biometric identification, critical infrastructure management, education (automated grading, monitoring), employment (CV screening, performance monitoring), essential private/public services (credit scoring, public benefit assessments), law enforcement (risk assessment, polygraph), migration and border control, and administration of justice. If your product falls into any of these categories, you now have until December 2027 to meet the full Annex III obligations (risk management, data governance, technical documentation, transparency, human oversight, robustness requirements).
PM implication: Roadmap items that were scheduled for Q3 2026 completion to hit the August deadline can be rescheduled. This is genuine runway, not a loophole. Use it to build compliance infrastructure that is sustainable rather than rushed. If you were planning a compliance sprint, convert it into a structured compliance program over the next 14 months.
Annex I deadline moved to August 2, 2028
Annex I covers AI systems embedded in products already subject to EU product safety law: machinery, medical devices, radio equipment, aircraft, vehicles, and similar. These were already subject to existing sector regulation; the AI Act layered additional AI-specific obligations on top. The 2028 date gives product teams building AI into physical products significantly more time.
PM implication: If you are building AI into a hardware product or a regulated medical/safety device, the compliance horizon just extended by two years. Coordinate this update with your regulatory affairs and hardware teams, since their roadmap timelines likely assumed the August 2026 date.
SME and startup exemptions expanded
The Omnibus added proportionality provisions for small and medium enterprises. Some technical documentation requirements are simplified, regulatory sandbox access is easier to obtain, and the conformity assessment process for lower-risk Annex III categories has reduced procedural burden. The core obligations remain, but the compliance path for smaller companies is lighter.
PM implication: If your company has fewer than 250 employees and under 50 million euros in revenue, review the specific SME provisions with your legal team. You may qualify for documentation simplifications that meaningfully reduce your compliance workload.
What Did Not Change: What Is Already in Force
The Omnibus is not a reprieve across the board. Several provisions are already in force and were not extended. Product teams that assumed everything moved have a different kind of problem.
Already in force: August 2, 2025
- Prohibited AI practices ban: social scoring, real-time remote biometric ID in public spaces (with narrow exceptions), manipulation through subliminal techniques, exploitation of vulnerabilities.
- General-Purpose AI (GPAI) model obligations for providers: technical documentation, transparency to downstream providers, copyright policy, summary of training data.
- Systemic-risk GPAI model obligations for models above 10^25 FLOPs training compute.
Already in force: February 2, 2025
- AI literacy obligations: all providers and deployers must ensure staff have sufficient AI literacy to use AI systems safely.
- GPAI Code of Practice process began.
Still on original schedule: August 2, 2026
- Transparency obligations for specific AI systems: chatbots must disclose they are AI; deepfakes must be labeled; emotion recognition and biometric categorization systems must inform users.
- These were NOT extended by the Omnibus. If your product includes a chatbot, emotion detection, or synthetic media generation for EU users, these requirements are already overdue.
Extended: December 2, 2027
- High-risk AI system requirements under Annex III (see above).
- Market surveillance and enforcement provisions for high-risk systems.
Common mistake: conflating the Annex III extension with everything
The most frequent PM error after the Omnibus announcement is assuming all EU AI Act compliance work moved to 2027. It did not. Chatbot disclosure requirements, deepfake labeling, and emotion recognition notifications were due August 2026. If you have EU users and a conversational AI feature, audit whether you have met the transparency obligations now.
Is Your Product in Scope for Annex III?
The most important roadmap question is whether your AI system is classified as "high-risk" under Annex III. The classification is specific, not a general "if AI affects people" rule. Most enterprise SaaS with AI features does not fall under Annex III. Several categories that look general actually have narrow criteria.
Biometric identification
In scope:
Systems that identify individuals from biometric data in law enforcement, border control, or public spaces. Facial recognition for building access in a private workplace is not in scope; facial recognition for police identification in public is.
Not in scope:
Biometric authentication (verifying that you are who you claim to be, such as Face ID) is explicitly excluded from the high-risk definition.
Employment
In scope:
Automated systems used in hiring (CV screening, interview analysis), managing workers, or determining access to work. If your AI product ranks job candidates or scores interviews, you are likely in scope.
Not in scope:
AI that assists HR with scheduling, drafts job descriptions, or suggests benefits packages. The Act targets AI that makes or significantly influences employment decisions, not all HR software with AI features.
Education
In scope:
AI that determines access to educational institutions, evaluates student performance for certification, or monitors students for behavioral analysis during exams.
Not in scope:
AI tutoring tools, course recommendation engines, or AI writing assistants used in education. These are not high-risk under Annex III unless they make determinations about student progression or certification.
Essential services (credit, benefits)
In scope:
AI that evaluates creditworthiness, determines eligibility for public benefits, or assesses insurance risk. A credit-scoring model that determines loan approvals is clearly in scope.
Not in scope:
AI used in customer service, fraud detection (flag for human review), or financial product recommendation without automated approval decisions.
Navigate AI Regulation in the Masterclass
The AI PM Masterclass covers regulatory frameworks and how compliance decisions translate into roadmap priorities, taught live by a Salesforce Sr. Director PM.
How to Revise Your Compliance Roadmap
A roadmap revision is not "push everything to 2027." The right response is to triage: which obligations are already live, which get additional runway, and which can be built sustainably rather than in a sprint.
Step 1: Audit current compliance state against already-in-force obligations
Start with what is already required. Chatbot disclosure, deepfake labeling, emotion recognition notices, and AI literacy training for staff are all obligations that were already due by August 2026. Run a product audit: do your EU-facing features meet these now? If not, this is priority zero before worrying about the 2027 extension.
Step 2: Reclassify your Annex III work in the roadmap
Items that were 'Q3 2026 compliance sprint' can move to 'H1 2027 compliance program.' This is not a cancellation; it is a realistic resequencing. The compliance requirements are unchanged; only the enforcement date moved. Building a sustainable compliance architecture over 14 months is better than a rushed one in 3.
Step 3: Use the runway to build compliance infrastructure, not just artifacts
The Annex III requirements include risk management systems, data governance frameworks, technical documentation, and human oversight mechanisms. These are ongoing capabilities, not one-time documents. Use the extra 14 months to integrate them into your development process (risk register in your sprint planning, documentation in your CI/CD pipeline) rather than producing documents that go stale.
Step 4: Assess whether you qualify for SME proportionality provisions
If your company is below the SME thresholds, review the Omnibus's specific simplifications with your legal team. Simplified technical documentation and lighter conformity assessment processes can meaningfully reduce compliance costs for smaller AI product teams.
Step 5: Monitor national enforcement agency guidance
Each EU member state designates a national supervisory authority for the AI Act. Enforcement interpretations will vary, and several countries (France, Germany, Netherlands) have indicated they may act before the formal December 2027 deadline on egregious cases. Track your key markets' agency announcements, not just Brussels.
The Strategic Angle: Why This Is an Opportunity
The extension creates an opportunity that first-movers can exploit. Most of your competitors are reading the Omnibus as an excuse to deprioritize compliance entirely. That is the wrong read. Companies that use the runway to build genuine compliance infrastructure will have a structural advantage in enterprise sales by mid-2027, when buyers start requiring documented AI Act compliance before signing contracts.
Enterprise sales advantage
Enterprise procurement teams, especially in financial services and healthcare, are already asking for AI Act compliance documentation before signing. Being able to hand over a risk management system and technical documentation today closes deals that competitors lose. The December 2027 deadline is when regulators enforce, not when buyers ask.
Build the trust layer once
Many of the Annex III requirements (audit trails, human override mechanisms, incident logging) overlap with what makes AI products trustworthy to users. Building them now means your product is more reliable, not just more compliant. Compliance and quality improvements are not separate work.
GPAI model obligations are already live
If you are building a foundation model or offering GPAI capabilities, the August 2025 obligations are already in force. The Omnibus extension does not apply to you. Your competitive advantage is having documentation and copyright policies that allow enterprise downstream customers to use your model without legal exposure.
Regulatory sandbox access
The Omnibus made it easier for SMEs to access regulatory sandboxes: supervised programs where you can test high-risk AI systems with real users under temporary regulatory protection. If you are building in healthcare, finance, or law enforcement, explore sandbox programs in France, Spain, or the Netherlands as a route to early-mover advantages in regulated markets.
Build AI Products That Win in Regulated Markets
The AI PM Masterclass covers how to turn regulatory requirements into product decisions and competitive advantages. Taught live by a Salesforce Sr. Director PM.
Related Articles
Before you go: get the AI PM Minute
One tactic to make you a sharper AI PM, twice a week. 60 seconds to read. Free.
No fluff. Unsubscribe anytime.