Regulation & Compliance
The EU AI Act's Digital Omnibus: What the Delay Really Changes for Banks — and What It Doesn't
The Digital Omnibus defers the AI Act's high-risk obligations to 2027 — but Article 50 applies from August 2026. What banks need to know now.
•
acceleraid Redaktion
4 min read
01
Acquire
Signale erkennen
02
Onboard
Aktivierung steuern
03
Grow
Next Best Action
04
Retain
Churn reduzieren
05
Reactivate
Potenziale zurückholen
On 29 June 2026, the Council of the European Union gave its final approval to the Digital Omnibus on AI — the first substantive amendment to the AI Act since its adoption in 2024. The headlines that followed sounded much the same everywhere: the AI Act has been delayed. For banks, that shorthand is risky, because it is only half the story. Anyone pausing their compliance programme now risks missing an obligation that still takes effect, unchanged, on 2 August 2026.
What actually moves
The Digital Omnibus primarily changes the timetable for high-risk AI systems, not their substantive requirements. The key new dates at a glance:
Obligation | Previously | Now |
|---|---|---|
Stand-alone high-risk systems (Annex III, e.g. credit scoring) | 2 August 2026 | 2 December 2027 |
High-risk AI embedded in regulated products (Annex I) | 2 August 2026 | 2 August 2028 |
Machine-readable marking for systems already on the market (Art. 50(2)) | 2 August 2026 | 2 December 2026 |
Particularly relevant for banks: creditworthiness assessment and credit scoring remain high-risk use cases under Annex III. The Omnibus did not change how systems are classified — only when the obligations bite. Documentation, risk management, data quality, human oversight and conformity assessment remain in place in substance and become binding from December 2027.
The path to adoption was short: the Commission proposed the Omnibus in November 2025, the Council and Parliament reached a trilogue agreement on 7 May 2026, Parliament voted on 16 June, and the Council followed on 29 June. The amendments enter into force on the third day after publication in the Official Journal.
What did not move
The most important exception is Article 50 — the transparency obligations. They apply, unchanged, from 2 August 2026. In practice this means:
Chatbots and voicebots must disclose that customers are interacting with an AI system, unless this is obvious from the circumstances.
AI-generated content must be identifiable as such. This includes text, images and video produced with generative tools and used in marketing or customer communications.
Deepfakes and certain AI-generated publications must be labelled.
Only one element was adjusted: the duty to mark synthetic content in a machine-readable way applies from 2 December 2026 for systems already on the market. For new systems, and for disclosure duties towards end customers, the August date stands. Breaches of Article 50 can attract fines of up to 15 million euros or 3 percent of total worldwide annual turnover.
Also unchanged: the rules for providers of general-purpose AI models have applied since August 2025. The AI literacy obligation (Article 4) was softened in the Omnibus — from "ensuring" literacy to "taking measures to support" it — but not deleted. New is a prohibition on AI systems generating non-consensual intimate content, applicable from 2 December 2026.
Why the deferral is not an all-clear
From a supervisory and compliance perspective, there are three reasons not to treat the extra 16 months as a pause:
Classification is settled. Every credit scoring model that counts as high-risk today will count as high-risk tomorrow. Letting your AI inventory, model documentation and data governance drift now means rebuilding the same mountain in 2027 — under greater time pressure.
Article 50 arrives in a few weeks. Marketing and CRM teams are directly affected: anyone using generative AI for customer letters, product copy or campaign visuals needs a labelling and disclosure process by August. That is not a task for the legal department alone, but for the operational teams that create and deliver content.
Other supervisory workstreams continue. DORA has applied since January 2025, and the European supervisory authorities are stepping up pressure on AI-enabled cyber risk. The AI Act is one building block in an increasingly dense rulebook.
What banks should do now
The additional time is valuable — if it is used. Four workstreams stand out:
Consolidate the AI inventory. Which systems are in use, which fall under Annex III, which under Article 50? Without a complete inventory there is no way to prioritise or report.
Set up Article 50 processes. Disclosure texts for chatbots, labelling rules for AI-generated content, clear responsibilities across marketing, IT and compliance — before 2 August 2026.
Strengthen data quality and traceability. The high-risk obligations from December 2027 demand robust data governance. Banks that use customer data for scoring, segmentation and personalisation benefit twice: better models today, lower compliance effort tomorrow.
Bring vendors on board. Many AI capabilities enter the bank through third-party providers. Contracts, audit rights and transparency commitments should be negotiated now, not in 2027.
Conclusion
The Digital Omnibus buys banks breathing room on the high-risk obligations — nothing more. The Article 50 transparency duties apply from 2 August 2026, credit scoring remains a high-risk use case, and supervisors are already raising the tempo elsewhere. Institutions that use the coming months for inventory work, labelling processes and data governance turn the deferral into a genuine head start. Institutions that read it as an all-clear will be catching up in 2027, under pressure, on work that is perfectly plannable today.
Weitere Insights
Regulation & Compliance
The EU AI Act's Digital Omnibus: What the Delay Really Changes for Banks — and What It Doesn't
Regulation & Compliance
The ECB's 31 October Deadline: What the Supervisory Letter on AI-Enabled Cyber Threats Requires
CLM & CVM
Credit Card CLM: Why the Lifecycle Is Where Portfolio Profitability Is Won or Lost
We use Cookies 🍪
Strictly necessary cookies (e.g. Pipedrive forms) remain active. With your consent we also use Google Analytics (analytics) and Leadfeeder (visitor identification). More in our Privacy Policy.