The AI Omnibus is here. What this means, what it changes and what to do next
Early Thursday morning, 07.05.2026, the European Institutions reached a provisional agreement to simplify the EU AI Act. While many things manifested as expected, certain changes were surprising. How these changes affect the compliance work of companies, is the focus of this article.
What the deal simplified
The most consequential simplification is the timeline. High-risk AI obligations for Annex III systems now apply from 2 December 2027. For AI systems that are either a safety component of, or themselves constitute, a product required to undergo third-party conformity assessment under EU product safety legislation listed in Annex I, the date is 2 August 2028. These are fixed dates, agreed between Parliament and Council. The Commission's proposed mechanism of a discretionary trigger that would have made application dates dependent on a Commission decision confirming that standards and guidance were ready did not survive. What this leaves companies with is a firm deadline and an additional runway of 12 months starting from August to build properly rather than rush.
Three further measures are worth mentioning as they address practical friction points that have been flagged since the AI Act entered into force:
- Safety component definition narrowed. Products whose AI functions only assist users or optimise performance are no longer automatically classified as safety components and therefore no longer automatically as high-risk if their failure or malfunction does not create health or safety risks. This aimed at reducing over-classification for a category of AI-enabled products where the original definition seen as casting too wide a net.
- Bias detection data processing. Companies may now process special categories of personal data such as data revealing racial or ethnic origin or health data where strictly necessary to detect and correct biases, with appropriate safeguards. This applies to both high-risk and non-high-risk AI systems.
- SMC exemptions extended. Simplified procedures previously available to SMEs now also apply to small mid-cap companies. This matters for companies that have grown past the SME threshold without yet having the compliance infrastructure of a large organisation.
What hasn't changed: high-risk requirements and path to compliance
The core requirements for high-risk AI systems laid out in Article 9 through Article 15 remain untouched by the Omnibus deal. This includes for example AI risk management, data governance, technical documentation, human oversight or accuracy, robustness and cybersecurity. For companies developing or deploying high-risk AI, the goal is clear: you already know what you are building towards. What the deal equally did not change is the work of getting there.
A company starting today faces the same sequence it would have faced a year ago: a gap assessment against Articles 9–15, followed by QMS implementation, technical documentation, selection of a conformity assessment route, and for systems outside of Annex III engagement with a notified body. Each step takes time. The gap assessment alone typically surfaces findings that require months to address. Building up the QMS involves defining processes, roles, and documentation that cannot be created overnight let alone streamlined across departments. The technical documentation has to be written by people who understand both the AI system and the requirements it maps to. For Annex I systems requiring third-party assessment specifically, there is an additional question: notified bodies must be designated under the AI Act itself, not just under existing sectoral legislation. That designation process is still being established across member states. The extended timeline makes this more manageable, without resolving it.
Scope: who's in, who's out
One of the most-debated questions in the negotiations was the European Parliament's proposal to restructure how AI Act requirements apply to twelve product categories. The proposal would have made sectoral legislation the primary governance framework for AI in these categories, with the AI Act applying only in a reduced, subsidiary capacity. The practical governance of AI-specific requirements would have shifted to each sector's own regulatory framework, with the Commission empowered to transpose AI Act requirements sector by sector via delegated acts. The argument was that sector-specific regulation is better placed to govern AI risks in context. That proposal did not survive. For eleven of the twelve affected sectors, the AI Act remains the direct compliance framework.
The exception is machinery. AI embedded in machinery products is now governed by the Machinery Regulation, not by a dual compliance requirement under both the AI Act and sectoral law. How exactly AI requirements will be embedded in the machinery regulation remains to be seen. For companies manufacturing AI-enabled machinery, this is a real and meaningful change to the compliance path.
Medical devices: a separate story
For companies developing AI-based medical devices, the AI Act applies under the deal as agreed. There is no Omnibus carve-out for this sector. What does exist, however, is an ongoing revision of the Medical Devices Regulation (COM/2025/1023). That process moves on its own legislative timeline, independent of the AI Act negotiations. A similar alignment of AI Act requirements with the MDR could emerge from that review, as it did for machinery through the Omnibus. The two tracks are not in conflict: the MDR review may eventually produce a more integrated compliance path for medical devices, but it does not change what AI quality requirements as laid out in the AI Act will become more important. Companies in MedTech should therefore build with the high-risk requirements in mind now and monitor the MDR revision in parallel.
What to do now
The Omnibus negotiations created real uncertainty. The provisional agreement provides some clarity.
For Annex III companies the picture is fully stable. Deadline fixed at 2 December 2027, requirements unchanged, no scope uncertainty. Start the compliance pipeline now: gap assessment, QMS build-up, technical documentation, conformity assessment. Self-assessment is available for most Annex III systems, which makes the path more manageable albeit not shorter. The runway is only useful if you begin using it.
For Annex I companies the deadline moved to 2 August 2028 and the compliance path is typically longer. Most Annex I systems will require third-party conformity assessment, which means engaging a notified body designated specifically under the AI Act. As noted above, that designation process is still being built out across member states. The longer deadline reflects that reality but it does not mean more time to wait. It means the substantive work (requirements mapping, QMS and documentation gaps) needs to begin now, while the procedural questions around conformity routes clarify in parallel.
For machinery manufacturers, the compliance path has changed under the deal. Your AI systems are now governed by the Machinery Regulation instead of under both frameworks. What that means in practice for your certification route and documentation obligations is worth working through specifically.
How KvJ can help: The AI Act Process Landscape Workshop
Central to AI Act compliance is building effective processes that not only effectively streamline different departments involved but also create defendable evidence. To help you get started, we offer hands-on workshops that provide governance and technical teams with a clear overview of the requirements of the AI Act and explain what developing these processes involves in practice. The outcome is a translation of regulatory language into an implementation roadmap your teams can actually work with. Find out more here!
