On 24 July 2026 the Digital Omnibus was published in the EU Official Journal, entering into force on 27 July 2026. The direct consequence: the compliance deadline for high-risk AI systems, previously 2 August 2026, moves to 2 December 2027 — a delay of roughly 16 months.
For Vietnamese companies selling into Europe this is worth noting, and easy to misread.
What exactly was delayed
According to DLA Piper's analysis, updated 10 August 2026, obligations for Annex III high-risk systems move from 2 August 2026 to 2 December 2027. That group covers biometric identification, critical infrastructure, recruitment, credit scoring and several other areas.
Travers Smith, writing at the earlier political-agreement stage, notes two further dates: Annex I systems — where AI is a safety component of a product already covered by EU product safety rules — move to 2 August 2028, while transparency requirements for AI-generated content move to 2 December 2026.
Annex I is the group Vietnamese manufacturers should read closely. If a company sells machinery, equipment or components into the EU and the product contains an AI component performing a safety function, the obligations land there.
What is easy to misread
A delay is not a repeal. The requirements are unchanged: a documented risk management system, data governance, technical documentation, automatic logging, human oversight, and assurances on accuracy, robustness and cybersecurity.
A second point is easily missed: when a high-risk AI system is integrated into a product sold under the manufacturer's own name, the manufacturer can inherit provider-level obligations — even where a third party built the AI. Buying a partner's AI module does not automatically transfer responsibility to them.
For enterprises in Vietnam
Sixteen months sounds like plenty. But most compliance work is not paperwork; it is whether the system can produce anything worth writing on the paperwork.
Automatic logging is the clearest example. The requirement is that the system records its activity across its lifecycle. If the current software does not log, or logs without being traceable to individual decisions, there is no way to bolt that on at the last minute — it has to be fixed in the architecture. That takes months, not weeks.
The same applies to human oversight. The requirement is not that someone sits somewhere, but that the process has real stopping points where a person can intervene and the intervention is recorded. If the system was designed to run fully automatically, adding those points means redesigning the flow.
A sensible way to use the time: check whether your product or service falls into either group, then test the two hardest things first — does the system log in enough detail, and does the process leave room for a person to decide. Those two answers determine how much work remains.
And for companies not selling into the EU: these requirements are becoming a common reference for AI in regulated environments. Building for traceability and human approval is worth doing whatever the market.
Sources
DLA Piper — The Digital AI Omnibus: Proposed deferral of high risk AI obligations under the AI Act (updated 10 August 2026): https://knowledge.dlapiper.com/dlapiperknowledge/globalemploymentlatestdevelopments/2026/The-Digital-AI-Omnibus-Proposed-deferral-of-high-risk-AI-obligations-under-the-AI-Act
Travers Smith — EU agrees to delay key AI Act compliance deadlines: https://www.traverssmith.com/knowledge/knowledge-container/eu-agrees-to-delay-key-ai-act-compliance-deadlines/