5 key takeaways
- The AI Omnibus entered into force on 27 July 2026, amending the EU AI Act and extending several key deadlines
- The most significant change: the high-risk AI compliance deadline under Article 6(2) + Annex III moves from 2 August 2026 to 2 December 2027
- The deadline for Article 6(1) high-risk systems (safety components of regulated products) moves to 2 August 2028 – unchanged from the original Act
- GPAI model obligations, governance provisions and the prohibited AI systems ban remain in force – these were not deferred
- For organisations that have already begun compliance programmes, the Omnibus provides breathing room – but does not remove the obligation to comply
This post explains what changed, what did not change, and what it means in practice for organisations operating in Poland.
For context on the underlying high-risk classification rules – which remain in force but with extended deadlines – see my earlier post on High-Risk AI Classification Under the EU AI Act.
AI Omnibus AI Act Poland 2027: What the Omnibus Actually Changes
The key deadline changes
The most significant change is the deferral of the AI Act’s high-risk obligations under Article 6(2) + Annex III from 2 August 2026 to 2 December 2027. This covers the broad category of high-risk AI systems based on specific use cases – including credit scoring, biometrics, employment AI, law enforcement AI, and critical infrastructure AI.
| Obligation | Original deadline | New deadline (AI Omnibus) |
|---|---|---|
| Prohibited AI systems ban | 2 February 2025 | Unchanged |
| GPAI model obligations | 2 August 2025 | Unchanged |
| Governance, penalties, confidentiality | 2 August 2025 | Unchanged |
| High-risk AI – Article 6(2) + Annex III | 2 August 2026 | 2 December 2027 |
| High-risk AI – Article 6(1) (safety components) | 2 August 2026 | 2 August 2028 |
| AI regulatory sandboxes (Member State obligation) | 2 August 2026 | 2 August 2027 |
| Non-consensual intimate image AI ban | 2 August 2026 | 2 December 2026 |
| AI-generated content transparency | 2 August 2026 | 2 December 2026 |
What the Omnibus also does
Beyond the deadline changes, the AI Omnibus introduces targeted simplifications. Specifically:
- SME relief: lighter obligations for smaller providers and deployers, with proportionality principles more explicitly embedded in the compliance framework
- Testing and experimentation: expanded opportunities for AI regulatory sandboxes and real-world testing before full compliance
- Legal clarity: additional guidance on the boundary between general purpose AI and high-risk systems
What Did Not Change
This is as important as what did change. The following obligations remain in force and were not deferred by the AI Omnibus:
Prohibited AI systems – the ban on unacceptable risk AI (social scoring, real-time biometric mass surveillance in public spaces, manipulation of vulnerable groups) has been in force since February 2025 and was not touched by the Omnibus.
GPAI model obligations – providers of general purpose AI models, including foundation models and LLMs, have been subject to transparency documentation and copyright compliance obligations since August 2025. The Omnibus did not defer these.
Governance and penalties – the AI Act’s governance structure (national competent authorities, EU AI Office, enforcement powers) and penalty framework remain in force.
Non-consensual intimate content and CSAM bans — these were actually accelerated by the Omnibus to 2 December 2026 rather than deferred.
AI Omnibus AI Act Poland 2027: What This Means in Practice
If you have already started your AI Act compliance programme
The Omnibus gives you additional time to complete implementation – specifically until 2 December 2027 for Annex III high-risk systems. Consequently, if your gap analysis identified compliance gaps, you now have 16 additional months to close them. However, this does not mean pausing your programme – it means you have more runway to do it properly.
If you have not yet started
The Omnibus extended the deadline – but it did not remove the obligation. Consequently, organisations that have not yet classified their AI systems, assessed their governance frameworks, or begun technical documentation should start now. The 2 December 2027 deadline requires a 12-18 month implementation programme for most regulated organisations.
If you are a financial institution
Financial institutions using AI for credit scoring, fraud detection, insurance pricing or AML screening face high-risk classification under Annex III. The Omnibus deferred the compliance deadline for these systems to 2 December 2027. However, DORA obligations – which intersect with AI Act requirements for ICT risk management – remain in force and are not deferred. Consequently, financial institutions should integrate their AI Act and DORA compliance programmes rather than treating them as separate workstreams.
For more on the intersection of DORA and AI Act obligations, see the Cybersecurity, NIS2 & DORA practice area page.
If you are a GPAI provider or deployer
GPAI obligations were not deferred. If you provide or deploy a general purpose AI model – an LLM, foundation model, or AI system with broad applicability – your obligations under the AI Act have been in force since August 2025 and were not affected by the Omnibus.
Updated AI Act Compliance Timeline for Poland
| What | When |
|---|---|
| Prohibited AI – ban in force | Since 2 February 2025 |
| GPAI obligations in force | Since 2 August 2025 |
| AI-generated content transparency | 2 December 2026 |
| High-risk AI – Annex III (Article 6(2)) | 2 December 2027 |
| High-risk AI – safety components (Article 6(1)) | 2 August 2028 |
Bottom Line on the AI Omnibus
The AI Omnibus is a genuine and meaningful extension of the high-risk compliance deadline. Nevertheless, it is not a licence to delay. Organisations that use the additional time productively – to classify their AI systems properly, build governance frameworks, prepare technical documentation and align with GDPR – will be in a significantly stronger position than those that treat the Omnibus as a reason to wait.
If you have questions about AI Act compliance in Poland in light of the AI Omnibus, get in touch. For more on AI governance and the AI Act, see the AI Act practice area page.
Related posts:
- High-Risk AI Classification Under the EU AI Act
- Fintech, AI Act and NIS2 Lawyer in Poland
- US AI Companies Entering the EU: What the AI Act Means for Your Product
Katarzyna Szczudlik is a Partner at Schoenherr in Warsaw and one of Poland’s leading lawyers advising on EU AI Act compliance. She has followed the AI Act since its earliest legislative stages. Ranked by Chambers & Partners (FinTech) and Legal 500 EMEA. Get in touch.