The EU’s “Digital Omnibus” simplification package — formally Regulation (EU) 2026/1744, amending the AI Act (Regulation (EU) 2024/1689) — was published in the Official Journal of the European Union on 24 July 2026 and entered into force on 27 July 2026. It pushes back two of the AI Act’s most consequential compliance deadlines by well over a year. For research organizations, the headline delay is real, but it is narrower than the framing “the AI Act is delayed” suggests: several obligations that matter directly to universities and research institutes — transparency duties, general-purpose-AI (GPAI) provider obligations, the AI-literacy requirement, and the prohibited-practices ban — are unaffected and remain on their original schedule.
What Changed, and When
Two deadlines moved, both tied to the AI Act’s “high-risk” system obligations (Annex III use cases and Annex I embedded products):
- Stand-alone high-risk AI systems (Annex III) — including AI used in education and employment contexts — were due to face full obligations (risk management, data governance, technical documentation, human oversight, conformity assessment, and more) from 2 August 2026. That date is now 2 December 2027, a deferral of roughly sixteen months.
- High-risk AI embedded in regulated products (Annex I — machinery, medical devices, toys, and similar categories carrying their own product-safety regimes) moves from 2 August 2027 to 2 August 2028.
- Transparency and labelling obligations for AI-generated content (Article 50(2)) gained a grace period: systems already placed on the market before 2 August 2026 now have until 2 December 2026 to implement watermarking and disclosure mechanisms, rather than the original August 2026 date.
These figures are drawn from the European Commission’s own Digital Strategy announcement of the Omnibus entering into force, cross-checked against independent legal trackers reporting on the same regulation. The legislative path ran through a provisional political agreement between Parliament and Council in early May 2026, formal Parliament approval on 16 June 2026, Council approval on 29 June 2026, and Official Journal publication on 24 July 2026 — the step that made the new dates legally binding, not merely politically agreed.
Why the EU Delayed These Deadlines
The Commission’s stated rationale is implementation readiness rather than a policy retreat: harmonized technical standards for high-risk systems, the network of national conformity-assessment (notified) bodies, and the designation of market-surveillance authorities in member states were all running behind the original schedule. Pushing the compliance date for Annex III systems is presented as giving providers and deployers time to meet obligations against standards and infrastructure that are actually in place, rather than a fixed date without the supporting apparatus to comply against or be assessed by.
The delay is not without critics. Civil-society and digital-rights groups involved in the AI Act’s original negotiation have argued that deferring high-risk obligations by more than a year — for systems already in active use in hiring, education, and other sensitive domains — leaves people subject to consequential automated decisions without the safeguards (impact assessments, human oversight, transparency) the Act was designed to guarantee, for an extended period. Both positions are part of the public record around the Omnibus process; the Commission’s implementation-readiness case and the enforcement-gap criticism are worth weighing on their own terms rather than treating the delay as an uncontested simplification win.
What Is Not Delayed
The Omnibus reset the clock on Annex III and Annex I high-risk obligations specifically. It left several other tracks untouched, and these are the ones most likely to still apply to a research organization’s day-to-day AI use right now:
- Prohibited AI practices (Article 5 — social scoring, exploitative manipulation, and similar banned uses) and the AI-literacy obligation (Article 4) have applied since 2 February 2025 and are unaffected by the Omnibus.
- GPAI provider obligations (Articles 51-56 — technical documentation, training-data summaries, copyright-compliance measures, and additional duties for models with “systemic risk”) have applied since 2 August 2025 and run on a separate track from the high-risk-system timeline. An institution’s AI research group that trains and releases its own foundation or general-purpose model onto the EU market is on this clock regardless of where the Annex III date sits.
- Transparency obligations for AI-generated content remain live from 2 August 2026 for new deployments; only the grace period for systems already on the market before that date was pushed to December 2026 (above).
The practical takeaway: “the AI Act got delayed” is an oversimplification that can lead a compliance office to stand down work that is actually still due on the original clock.
The Research Exemption’s Real Limits
Article 2(6) of the AI Act excludes AI systems and models “specifically developed and put into service for the sole purpose of scientific research and development.” The Omnibus did not amend this provision — it is unchanged by the deadline shift. But the exemption’s boundary is where research organizations most often misjudge their own exposure, and that boundary has nothing to do with the delayed dates above.
The exemption is purpose-based, not institution-based: it covers an AI system for as long as it stays inside a research project as the object or instrument of that research, with no operational deployment beyond it. The moment an institution moves a model past that — spinning it out as a commercial product, releasing it publicly as a general-purpose model, or deploying it operationally in a non-research function such as admissions, proctoring, or grading — the exemption stops applying to that use, and ordinary provider or deployer obligations attach. A GPAI model built by a university research group and placed on the EU market is on the GPAI provider timeline (already in force since August 2025) regardless of its academic origin. This is the edge the Digital Omnibus does not move.
Educational Assessment as High-Risk AI: Why 2027 Is a Planning Horizon, Not a Reprieve
Annex III’s education and vocational-training category is one of the two Annex III areas most likely to touch a university directly (the other is employment/HR use, e.g. AI-assisted recruitment screening). It covers AI systems used to determine access or admission to an educational institution, to evaluate learning outcomes, to assess the appropriate level of education for a person, and to monitor or detect prohibited behaviour during tests — squarely covering AI-assisted admissions scoring, automated or AI-assisted grading, and AI proctoring tools.
The deferral to 2 December 2027 changes when full obligations bite, not whether they will. For an institution using or evaluating AI in admissions, assessment, or proctoring, the additional runway is best used as compliance lead time — building the risk-management system, technical documentation, and human-oversight procedures Annex III requires — rather than as a reason to defer starting that work. Vendor procurement, system selection, and internal governance decisions made now will still need to satisfy the same substantive requirements in 2027; starting the classification and documentation work early is materially cheaper than doing it under deadline pressure.
What Research Organizations Should Do Now
- Build or update an AI system inventory. Catalogue every AI system in institutional use — research tools, administrative systems, vendor platforms — with enough detail to classify each one.
- Classify by risk tier and by the Article 2(6) test. For each system, determine: is this within the sole-purpose-of-research exemption, or does it fall under Annex III/Annex I, limited-risk transparency duties, or none of the above?
- Determine provider vs. deployer status separately for each system. An institution that builds and releases its own model is a provider for that model; the same institution using a vendor’s AI tool in an HR or admissions workflow is a deployer for that tool. The obligations differ substantially.
- Keep documentation and logging current for anything approaching Annex III use, even while the compliance date sits in 2027 — the paper trail is easier to build contemporaneously than to reconstruct later.
- Confirm AI-literacy training is actually in place. Article 4 has applied since February 2025; this is not part of the delayed timeline.
- Add AI Act clauses to vendor and procurement contracts — provider/deployer role allocation, documentation-delivery commitments, and audit rights — for any AI system procured or renewed now.
What Remains Uncertain
The dates above are now backed by a published, in-force regulation rather than a political agreement awaiting formal adoption, which is a meaningfully firmer footing than reporting on the Omnibus carried through much of mid-2026. What is still open: implementing and delegated acts, harmonized standards, and Commission guidance that flesh out how the amended Annex III timeline interacts with specific sector rules are still being developed, and the precise boundary of the Article 2(6)/2(8) research exemption — particularly for dual-use research tools and university spin-outs — has not been the subject of dedicated Commission guidance as of this writing. Institutions relying on any date or classification here in a compliance filing should confirm current status directly against the official AI Act Service Desk timeline or the regulation’s EUR-Lex text before treating it as settled for institutional purposes.
For the fuller picture of how Article 2(6) and 2(8) apply to research organizations — including the harder edge cases around “sole purpose” — see CASRAI’s guide, EU AI Act: Obligations and Exemptions for Research Organizations. For the broader compliance picture beyond this deadline shift, see Making sense of the EU AI Act for research administration. On the transparency/labelling obligations for AI outputs specifically, see the CASRAI dictionary entry on AI-generated content.







