
On 29 June 2026, the Council gave final approval to the Digital Omnibus, the package that pushes the EU AI Act’s high-risk obligations from August 2026 to 2 December 2027. Most compliance teams read that as a reprieve and moved on. It is not. One deadline in the original text was never touched by the Omnibus, and it lands in about four weeks: 2 August 2026, when the Article 50 transparency duties become enforceable. Teams that spent the last month tracking the deferred date are now four weeks from a live one they stopped watching.
The Digital Omnibus is not yet published in the Official Journal. Until it is, the original AI Act text remains binding law, though the political outcome is settled enough that most legal teams are already planning against it. Here is what moved and what did not.
What moved:
What did not move:
The Act sorts AI systems into four tiers, and the question a compliance officer usually asks is which tier an email or writing-compliance tool falls into.
| Tier | What it covers | Applies from |
|---|---|---|
| Prohibited | Social scoring, manipulative or exploitative systems, workplace or school emotion recognition | February 2025 |
| High-risk | Hiring, credit, insurance, biometrics, essential services (provider and deployer duties) | December 2027 (Annex III) |
| Limited (transparency) | Chatbots, deepfakes, AI-generated content: disclose and label | August 2026 (Article 50) |
| Minimal | Most everyday tools, no dedicated obligations | AI literacy and good practice still apply |
Annex III’s employment category is the one worth reading carefully, because it does not cover every tool that touches an employment relationship. It covers AI systems used to make or materially inform decisions on recruitment, promotion, termination, or task allocation based on individual behavior, personality traits, or performance monitoring. A tool that flags a risky sentence in a draft email, before it is sent, and leaves the decision to the person writing it, is not making or materially informing an employment decision about that person. A tool that scores individual employees and feeds those scores into a promotion or termination decision is a different thing entirely, and worth checking against Annex III regardless of the December 2027 date, since building toward that use case now means designing for high-risk duties from day one.
This is a real distinction, not a technicality to route around it. Anonymized, department-level signal and individual behavioral scoring answer different questions, and the Act treats them differently for a reason.
Four things do not wait for Annex III, whatever your organization deploys:
A useful test for any AI-assisted process in your organization: does a person decide, or does the system decide? If a human reviews the flag and chooses whether to act on it, you are far more likely sitting in the minimal or limited tier. If the system’s output becomes the decision, without a person meaningfully able to override it, look at Annex III now rather than in 2027.
The GPAI rules that took effect in August 2025 apply to providers of general-purpose AI models: documentation of training data sources, copyright compliance summaries, technical information for downstream integrators. Most organizations reading this are not providers. If your writing-compliance tool, your email assistant, or your internal chatbot runs on a model from OpenAI, Anthropic, Google, or another foundation model provider, the GPAI documentation duty sits with that provider, not with you.
What does sit with you, as a deployer, is narrower but still real: knowing which models power the tools your staff rely on, keeping a record of that for when a customer or auditor asks, and reading the provider’s own transparency documentation rather than assuming it does not apply because you did not build the model. A vendor that cannot point to its own GPAI documentation, or that is vague about which model does the underlying work, is telling you something worth noting before the contract is signed, not after.
VerbaPulse is not an AI Act compliance platform. It does not classify AI systems, run conformity assessments, or replace legal obligations. What it does sit under is the human-use layer the Omnibus deferral does not touch: it supports AI literacy in the moment a person is writing, gives department-level visibility into where AI-assisted communication carries risk, and flags language before a message sends, leaving the decision to the person writing it. That last part matters for the distinction above: the person stays in the loop, which is also the design choice that keeps a pre-send check out of Annex III’s individual-decision territory rather than a way of avoiding the question.
The EU AI Act toolkit on our site has a role-based self-assessment and a checklist for what applies to you today, separate from what is coming in 2027. It is orientation, not legal advice, and the usual caveat applies: confirm specifics with counsel before you rely on any of it.
Do not wait for the Official Journal publication to act. Four weeks is short enough that Article 50 exposure needs checking this week, not planned for next quarter. Then, separately and on its own timeline, decide whether anything you are building toward touches Annex III’s individual-decision territory. Those are two different clocks, and the Omnibus only reset one of them.
VerbaPulse flags risky wording as you write in Outlook and Gmail, then offers a safer phrasing before you send. Run it against your own messages and your own rules in a 30-day pilot.
Up to 10 seats. EUR 120, credited to your plan if you continue.
See how VerbaPulse flags risk before an email is sent, right inside Gmail and Outlook.
See VerbaPulse in action →