AcademyMikeVisionLegal OpsContainersSkillsPortalPricingBlog
← Back to Blog
Estratégia

What the Omnibus changed in AI regulation — and what it didn't

In July 2026 the European Union published the Digital Omnibus and postponed most of the AI Act's obligations for high-risk artificial intelligence systems. Over the coming weeks, plenty of people will keep selling the fear of the old deadline — because fear with a date on it sells. I'd rather tell you what actually happened.

What changed: dates

Obligations for high-risk systems under Annex III — the category that includes AI used in the administration of justice and in decisions affecting rights — moved from August 2026 to December 2027. Those for AI embedded in regulated products (Annex I) moved to August 2028.

That's it. Dates.

What didn't change: everything else

No obligation was removed. Conformity assessment, technical documentation, data governance, human oversight — all of it remains exactly as written. Only the calendar moved.

Transparency obligations were not postponed: they have applied since 2 August 2026. People interacting with AI must know they are; generated content must be identifiable as such. There was a grace period for one specific case — content marking in systems already on the market — and it is short.

Prohibited practices have been prohibited since February 2025. Rules for general-purpose models have applied since August 2025.

And enforcement got stronger, not weaker: the AI Office gained direct supervisory powers over certain classes of systems, with investigation, inspection and fines.

What this means for a law firm

If you have clients or operations in Europe, the new deadline isn't relief — it's planning. Sixteen months is the time to implement AI governance calmly, test it, correct it and document it. It is not time to wait. Whoever waits will arrive in December 2027 exactly where they are today, with less time.

If you have nothing in Europe, two things remain true.

First: your own data-protection law didn't change. Case files are, almost always, personal data — and often sensitive. The question "where does the data go when someone here uses AI" doesn't depend on Brussels. It has been yours all along.

Second: the regulatory direction is set, and it is the same everywhere this is legislated — transparency, data governance, human oversight. The Omnibus changed the when, not the what. And the corporate client who already asks how your firm uses AI won't stop asking because a European deadline moved.

One last note

I'm not writing this to sell urgency. I'm writing because most of the messages you'll receive on the subject will do exactly that, and they'll be wrong about the date.

The deadline changed. What you need to do didn't.

Marcus Camargo has practiced law for thirty years and worked in legal technology for more than twenty.

AutoJus

Evaluate with a real case

No generic demos. Submit your own case, validate the quality yourself, then decide.
Start Free Evaluation