Regulation & Compliance
The Digital Omnibus on the EU AI Act: What the postponement really changes for banks — and what it doesn't
The Digital Omnibus postpones the obligations for high-risk AI to 2027 — but Article 50 applies from August 2026. What banks need to know now.
•
acceleraid Editorial Team
4 min. read
01
Acquire
Recognize signals
02
Onboard
Control activation
03
Grow
Next Best Action
04
Retain
Reduce churn
05
Reactivate
Reclaim potential

On June 29, 2026, the Council of the European Union finally approved the Digital Omnibus on AI — the first substantial amendment to the AI Act since its adoption in 2024. The headlines afterward sounded almost identical everywhere: The AI Act has been postponed. For banks, this shorthand is risky because it only tells half the story. Anyone who pauses their compliance program now risks overlooking an obligation that remains effective on August 2, 2026.
What is actually being postponed
The Digital Omnibus primarily changes the timeline for high-risk AI systems, not their content requirements. Here is an overview of the key new dates:
Obligation | Previous | Now |
|---|---|---|
Standalone high-risk systems (Annex III, e.g., credit scoring) | August 2, 2026 | December 2, 2027 |
High-risk AI in regulated products (Annex I) | August 2, 2026 | August 2, 2028 |
Machine-readable labeling for systems already on the market (Art. 50 para. 2) | August 2, 2026 | December 2, 2026 |
Particularly relevant for banks: Creditworthiness assessments and credit scoring remain high-risk use cases under Annex III. The Omnibus does not change how systems are classified — only when the obligations take effect. Documentation, risk management, data quality, human oversight, and conformity assessment remain unchanged in terms of content and will become binding from December 2027.
The path to adoption was short: The Commission presented the Omnibus in November 2025, the Council and Parliament reached a trilogue agreement on May 7, 2026, the Parliament voted on June 16, and the Council followed on June 29. The changes enter into force on the third day after publication in the Official Journal.
What is not being postponed
The most important exception is Article 50 — the transparency obligations. They apply unchanged from August 2, 2026. In practice, this means:
Chatbots and voicebots must disclose that customers are interacting with an AI system, unless this is obvious from the circumstances.
AI-generated content must be recognizable as such. This includes texts, images, and videos created with generative tools and used in marketing or customer communication.
Deepfakes and certain AI-generated publications must be labeled.
Only one element has been adjusted: The obligation for machine-readable labeling of synthetic content applies to systems already on the market from December 2, 2026. For new systems and for disclosure obligations towards end customers, the August deadline remains. Violations of Article 50 can result in fines of up to 15 million euros or 3 percent of global annual turnover.
Also unchanged: The rules for providers of general-purpose AI models have already been in force since August 2025. The obligation for AI literacy (Article 4) was weakened in the Omnibus — from "ensure" to "take measures to support" — but not deleted. New is a ban on AI systems that generate non-consensual intimate content; this applies from December 2, 2026.
Why the postponement is not a free pass
From a supervisory and compliance perspective, there are three reasons why the additional 16 months should not be seen as a break:
The classification is set. Any credit scoring model considered high-risk today will also be considered high-risk tomorrow. Anyone who lets AI inventory, model documentation, and data governance slide now will build the same mountain back up in 2027 under greater time pressure.
Article 50 is coming in a few weeks. Marketing and CRM teams are directly affected: Anyone using generative AI for customer letters, product texts, or campaign visuals needs a labeling and disclosure process by August. This is not a task for the legal department alone, but for the operational teams that create and distribute content.
Other supervisory tracks continue to run. DORA has been in force since January 2025, and European supervisory authorities are increasing pressure on AI-supported cyber risks. The AI Act is just one building block in an increasingly dense regulatory framework.
What banks should do now
The additional time is valuable — if it is used. Four workstreams stand out:
Consolidate AI inventory. Which systems are in use, which fall under Annex III, and which under Article 50? Without a complete inventory, it is impossible to set priorities or fulfill reporting obligations.
Set up Article 50 processes. Disclosure texts for chatbots, labeling rules for AI-generated content, clear responsibilities between marketing, IT, and compliance — before August 2, 2026.
Strengthen data quality and traceability. The high-risk obligations starting in December 2027 require robust data governance. Banks that use customer data for scoring, segmentation, and personalization benefit twice: better models today, less compliance effort tomorrow.
Involve providers. Many AI capabilities enter the bank through third-party providers. Contracts, audit rights, and transparency commitments should be negotiated now, not in 2027.
Conclusion
The Digital Omnibus gives banks breathing room regarding high-risk obligations — nothing more. The transparency obligations under Article 50 apply from August 2, 2026, credit scoring remains a high-risk use case, and supervisory authorities are already picking up the pace elsewhere. Institutions that use the coming months for inventorying, labeling processes, and data governance will turn the postponement into a real head start. Institutions that read it as an all-clear will find themselves catching up under pressure in 2027 on work that is highly plannable today.
Further Insights
We use cookies 🍪
Strictly necessary cookies (e.g. Pipedrive forms) remain active. With your consent, we also use Google Analytics (analytics) and Leadfeeder (visitor identification). Learn more in our Privacy Policy.