Regulation & Compliance

The EU AI Act's Digital Omnibus: What the Delay Really Changes for Banks — and What It Doesn't

The Digital Omnibus defers the AI Act's high-risk obligations to 2027 — but Article 50 applies from August 2026. What banks need to know now.

acceleraid Redaktion

4 min read

Customer Lifecycle Management

Customer Lifecycle Management

Customer Lifecycle Management

01

Acquire

Signale erkennen

02

Onboard

Aktivierung steuern

03

Grow

Next Best Action

04

Retain

Churn reduzieren

05

Reactivate

Potenziale zurückholen

Daten → KI-Score → Trigger → Kanal → Feedback

Daten → KI-Score → Trigger → Kanal → Feedback

On 29 June 2026, the Council of the European Union gave its final approval to the Digital Omnibus on AI — the first substantive amendment to the AI Act since its adoption in 2024. The headlines that followed sounded much the same everywhere: the AI Act has been delayed. For banks, that shorthand is risky, because it is only half the story. Anyone pausing their compliance programme now risks missing an obligation that still takes effect, unchanged, on 2 August 2026.

What actually moves

The Digital Omnibus primarily changes the timetable for high-risk AI systems, not their substantive requirements. The key new dates at a glance:

Obligation

Previously

Now

Stand-alone high-risk systems (Annex III, e.g. credit scoring)

2 August 2026

2 December 2027

High-risk AI embedded in regulated products (Annex I)

2 August 2026

2 August 2028

Machine-readable marking for systems already on the market (Art. 50(2))

2 August 2026

2 December 2026

Particularly relevant for banks: creditworthiness assessment and credit scoring remain high-risk use cases under Annex III. The Omnibus did not change how systems are classified — only when the obligations bite. Documentation, risk management, data quality, human oversight and conformity assessment remain in place in substance and become binding from December 2027.

The path to adoption was short: the Commission proposed the Omnibus in November 2025, the Council and Parliament reached a trilogue agreement on 7 May 2026, Parliament voted on 16 June, and the Council followed on 29 June. The amendments enter into force on the third day after publication in the Official Journal.

What did not move

The most important exception is Article 50 — the transparency obligations. They apply, unchanged, from 2 August 2026. In practice this means:

  • Chatbots and voicebots must disclose that customers are interacting with an AI system, unless this is obvious from the circumstances.

  • AI-generated content must be identifiable as such. This includes text, images and video produced with generative tools and used in marketing or customer communications.

  • Deepfakes and certain AI-generated publications must be labelled.

Only one element was adjusted: the duty to mark synthetic content in a machine-readable way applies from 2 December 2026 for systems already on the market. For new systems, and for disclosure duties towards end customers, the August date stands. Breaches of Article 50 can attract fines of up to 15 million euros or 3 percent of total worldwide annual turnover.

Also unchanged: the rules for providers of general-purpose AI models have applied since August 2025. The AI literacy obligation (Article 4) was softened in the Omnibus — from "ensuring" literacy to "taking measures to support" it — but not deleted. New is a prohibition on AI systems generating non-consensual intimate content, applicable from 2 December 2026.

Why the deferral is not an all-clear

From a supervisory and compliance perspective, there are three reasons not to treat the extra 16 months as a pause:

  • Classification is settled. Every credit scoring model that counts as high-risk today will count as high-risk tomorrow. Letting your AI inventory, model documentation and data governance drift now means rebuilding the same mountain in 2027 — under greater time pressure.

  • Article 50 arrives in a few weeks. Marketing and CRM teams are directly affected: anyone using generative AI for customer letters, product copy or campaign visuals needs a labelling and disclosure process by August. That is not a task for the legal department alone, but for the operational teams that create and deliver content.

  • Other supervisory workstreams continue. DORA has applied since January 2025, and the European supervisory authorities are stepping up pressure on AI-enabled cyber risk. The AI Act is one building block in an increasingly dense rulebook.

What banks should do now

The additional time is valuable — if it is used. Four workstreams stand out:

  1. Consolidate the AI inventory. Which systems are in use, which fall under Annex III, which under Article 50? Without a complete inventory there is no way to prioritise or report.

  2. Set up Article 50 processes. Disclosure texts for chatbots, labelling rules for AI-generated content, clear responsibilities across marketing, IT and compliance — before 2 August 2026.

  3. Strengthen data quality and traceability. The high-risk obligations from December 2027 demand robust data governance. Banks that use customer data for scoring, segmentation and personalisation benefit twice: better models today, lower compliance effort tomorrow.

  4. Bring vendors on board. Many AI capabilities enter the bank through third-party providers. Contracts, audit rights and transparency commitments should be negotiated now, not in 2027.

Conclusion

The Digital Omnibus buys banks breathing room on the high-risk obligations — nothing more. The Article 50 transparency duties apply from 2 August 2026, credit scoring remains a high-risk use case, and supervisors are already raising the tempo elsewhere. Institutions that use the coming months for inventory work, labelling processes and data governance turn the deferral into a genuine head start. Institutions that read it as an all-clear will be catching up in 2027, under pressure, on work that is perfectly plannable today.

We use Cookies 🍪

Strictly necessary cookies (e.g. Pipedrive forms) remain active. With your consent we also use Google Analytics (analytics) and Leadfeeder (visitor identification). More in our Privacy Policy.

Decline

Decline

Accept all

Accept all