Get In Touch
katarzyna.szczudlik@gmail.com
Tel: ‪+48 663 696 999‬
Work Inquiries
Schoenherr Attorneys at Law Plac Małachowskiego 1 Warsaw, Poland
ka.szczudlik@schoenherr.eu
Back

AI Omnibus and the EU AI Act: What Changed on 27 July 2026

5 key takeaways

  • The AI Omnibus entered into force on 27 July 2026, amending the EU AI Act and extending several key deadlines
  • The most significant change: the high-risk AI compliance deadline under Article 6(2) + Annex III moves from 2 August 2026 to 2 December 2027
  • The deadline for Article 6(1) high-risk systems (safety components of regulated products) moves to 2 August 2028 – unchanged from the original Act
  • GPAI model obligations, governance provisions and the prohibited AI systems ban remain in force – these were not deferred
  • For organisations that have already begun compliance programmes, the Omnibus provides breathing room – but does not remove the obligation to comply

This post explains what changed, what did not change, and what it means in practice for organisations operating in Poland.

For context on the underlying high-risk classification rules – which remain in force but with extended deadlines – see my earlier post on High-Risk AI Classification Under the EU AI Act.


AI Omnibus AI Act Poland 2027: What the Omnibus Actually Changes

The key deadline changes

The most significant change is the deferral of the AI Act’s high-risk obligations under Article 6(2) + Annex III from 2 August 2026 to 2 December 2027. This covers the broad category of high-risk AI systems based on specific use cases – including credit scoring, biometrics, employment AI, law enforcement AI, and critical infrastructure AI.

ObligationOriginal deadlineNew deadline (AI Omnibus)
Prohibited AI systems ban2 February 2025Unchanged
GPAI model obligations2 August 2025Unchanged
Governance, penalties, confidentiality2 August 2025Unchanged
High-risk AI – Article 6(2) + Annex III2 August 20262 December 2027
High-risk AI – Article 6(1) (safety components)2 August 20262 August 2028
AI regulatory sandboxes (Member State obligation)2 August 20262 August 2027
Non-consensual intimate image AI ban2 August 20262 December 2026
AI-generated content transparency2 August 20262 December 2026

What the Omnibus also does

Beyond the deadline changes, the AI Omnibus introduces targeted simplifications. Specifically:

  • SME relief: lighter obligations for smaller providers and deployers, with proportionality principles more explicitly embedded in the compliance framework
  • Testing and experimentation: expanded opportunities for AI regulatory sandboxes and real-world testing before full compliance
  • Legal clarity: additional guidance on the boundary between general purpose AI and high-risk systems

What Did Not Change

This is as important as what did change. The following obligations remain in force and were not deferred by the AI Omnibus:

Prohibited AI systems – the ban on unacceptable risk AI (social scoring, real-time biometric mass surveillance in public spaces, manipulation of vulnerable groups) has been in force since February 2025 and was not touched by the Omnibus.

GPAI model obligations – providers of general purpose AI models, including foundation models and LLMs, have been subject to transparency documentation and copyright compliance obligations since August 2025. The Omnibus did not defer these.

Governance and penalties – the AI Act’s governance structure (national competent authorities, EU AI Office, enforcement powers) and penalty framework remain in force.

Non-consensual intimate content and CSAM bans — these were actually accelerated by the Omnibus to 2 December 2026 rather than deferred.


AI Omnibus AI Act Poland 2027: What This Means in Practice

If you have already started your AI Act compliance programme

The Omnibus gives you additional time to complete implementation – specifically until 2 December 2027 for Annex III high-risk systems. Consequently, if your gap analysis identified compliance gaps, you now have 16 additional months to close them. However, this does not mean pausing your programme – it means you have more runway to do it properly.

If you have not yet started

The Omnibus extended the deadline – but it did not remove the obligation. Consequently, organisations that have not yet classified their AI systems, assessed their governance frameworks, or begun technical documentation should start now. The 2 December 2027 deadline requires a 12-18 month implementation programme for most regulated organisations.

If you are a financial institution

Financial institutions using AI for credit scoring, fraud detection, insurance pricing or AML screening face high-risk classification under Annex III. The Omnibus deferred the compliance deadline for these systems to 2 December 2027. However, DORA obligations – which intersect with AI Act requirements for ICT risk management – remain in force and are not deferred. Consequently, financial institutions should integrate their AI Act and DORA compliance programmes rather than treating them as separate workstreams.

For more on the intersection of DORA and AI Act obligations, see the Cybersecurity, NIS2 & DORA practice area page.

If you are a GPAI provider or deployer

GPAI obligations were not deferred. If you provide or deploy a general purpose AI model – an LLM, foundation model, or AI system with broad applicability – your obligations under the AI Act have been in force since August 2025 and were not affected by the Omnibus.


Updated AI Act Compliance Timeline for Poland

WhatWhen
Prohibited AI – ban in forceSince 2 February 2025
GPAI obligations in forceSince 2 August 2025
AI-generated content transparency2 December 2026
High-risk AI – Annex III (Article 6(2))2 December 2027
High-risk AI – safety components (Article 6(1))2 August 2028

Bottom Line on the AI Omnibus

The AI Omnibus is a genuine and meaningful extension of the high-risk compliance deadline. Nevertheless, it is not a licence to delay. Organisations that use the additional time productively – to classify their AI systems properly, build governance frameworks, prepare technical documentation and align with GDPR – will be in a significantly stronger position than those that treat the Omnibus as a reason to wait.

If you have questions about AI Act compliance in Poland in light of the AI Omnibus, get in touch. For more on AI governance and the AI Act, see the AI Act practice area page.

Related posts:

Katarzyna Szczudlik is a Partner at Schoenherr in Warsaw and one of Poland’s leading lawyers advising on EU AI Act compliance. She has followed the AI Act since its earliest legislative stages. Ranked by Chambers & Partners (FinTech) and Legal 500 EMEA. Get in touch.

Katarzyna Szczudlik
Katarzyna Szczudlik
http://www.techlawyer.pl
I help international companies enter and scale in Poland - with a strong focus on fintech, financial regulation and technology-driven businesses. I am one of Poland's leading lawyers specialising in fintech regulation, MiCA and AI law.

Leave a Reply

This website stores cookies on your computer. Cookie Policy