July 27, 2026 — The EU’s Digital Omnibus on AI took effect, postponing the AI Act’s high-risk system compliance deadlines while transparency obligations and the ban on real-time public facial recognition by police remained in force.
What happened
High-risk requirements for standalone systems listed in Annex III were pushed to December 2, 2027, and requirements for most product-related high-risk AI systems were pushed to August 2, 2028. Real-time facial recognition by police in public spaces remains banned, with narrow exceptions for finding missing persons, preventing terrorist attacks or pursuing serious crimes, and deployers of emotion-recognition or biometric-categorization systems must inform people exposed to them.
Why it matters
Delaying high-risk obligations by roughly two years gives vendors and deployers of AI-based access control, video analytics and biometric systems significantly more runway to prepare compliance programs, while the narrower core prohibitions on real-time public facial recognition remain a hard line regulators are not relaxing.
Security and infrastructure impact
Security-technology vendors selling AI-based video analytics or biometric systems into the EU should track the distinction between the delayed high-risk obligations and the still-active transparency and facial-recognition-ban provisions, since compliance timelines now differ significantly by system category.

Leave a Reply