On 16 June 2026, the European Parliament gave its final vote on the Digital Omnibus on AI, which redraws part of the AI Act timeline for businesses operating in Luxembourg and across the rest of the EU. The Council of the EU gave its green light on 29 June. All that remains is the signature and publication in the Official Journal, expected before the end of July, for the text to formally enter into force.
In short: the AI Act’s most demanding obligations, due in August 2026, have been pushed back. High-risk AI systems under Annex III (biometric data, critical infrastructure, the administration of justice, among others) now have until 2 December 2027. Those under Annex I have until 2 August 2028.
This delay was predictable. The harmonised standards needed for compliance (risk management, data quality, human oversight) will not be ready before late 2026 at the earliest. The European Commission chose to push back the deadlines rather than impose compliance without a technical roadmap.
But this delay should not be read as a signal to pause. Several obligations are already in force, and the adopted text even adds a new one.
Companies that wait for the next deadline before acting will find themselves exactly as far behind as before.
What’s already in force, today
The AI Act has been rolling out in stages since 1 August 2024, and part of its obligations are already binding.
Since 2 February 2025, the bans have applied. AI systems considered an “unacceptable risk” are prohibited across the European Union: social scoring, manipulative AI, real-time biometric identification in public spaces (with narrowly defined exceptions), among others.
That same date, 2 February 2025, is also when Article 4 of the Regulation started requiring deployers of AI systems to ensure their staff have the skills, training and authority needed to oversee these systems. This is the so-called “AI literacy” obligation. It applies to any organisation using AI tools in its activities, and it tends to stay off the radar of compliance teams. The Digital Omnibus has just softened its wording slightly: the duty shifts from “ensuring” a level of competence to “taking measures to support its development.”
Since 2 August 2025, the obligations for general-purpose AI models (GPAI, such as GPT, Claude or Gemini) have applied: transparency on training data, respect for copyright, and systemic risk assessment for the most powerful models.
What the delay actually means
The delay concerns obligations tied to high-risk systems as defined in Annexes I and III of the Regulation. These systems include tools used in human resources (recruitment, performance evaluation), finance, education, the justice system, and critical infrastructure.
For most Luxembourg businesses, the relevant question centres on Annex III. As soon as an AI system plays a part in a credit decision, a performance review or a creditworthiness assessment, it falls within scope, because these decisions have a real impact on people’s lives.
These systems now have until 2 December 2027, 16 months more than originally planned.
The text also introduces something that wasn’t in the original Regulation: a ban on AI systems capable of generating non-consensual intimate content, such as so-called “nudify” apps, or child sexual abuse material. This ban takes effect from 2 December 2026, ahead of the high-risk deadline itself. The labelling requirement for AI-generated content (the “watermarking” obligation under Article 50) also shifts, from 2 August to 2 December 2026, for systems already on the market.
What this delay does not change is the need to know what you have deployed. You cannot tell whether your systems are high-risk, limited-risk or minimal-risk without having done that inventory. And that’s exactly where most organisations are falling behind.
The real challenge: inventory and classification
The questions regulators ask are simple: which AI systems are you using? In what context? What level of risk do they carry?
Answering that requires an inventory: a living document listing the AI tools in production, how they are actually used, the data they process and the decisions they influence. It’s the foundation of any serious compliance effort, and it’s the first thing auditors will ask for.
In Luxembourg, this work matters even more because the financial sector is particularly exposed. The CSSF is closely following European regulatory developments on AI. For funds, banks and insurers, it’s better to plan ahead than to react.
Why act now, despite the delay
Extra time is a resource, not permission to slow down.
The Digital Omnibus was negotiated because too many businesses weren’t ready. That collective delay weighed on the decision to push back the deadlines. But it also shows the gap between how fast AI tools are being rolled out inside organisations and how slowly compliance is catching up.
The companies that come out ahead in regulatory cycles aren’t the ones racing the deadline. They’re the ones that built readable governance: an up-to-date inventory, a documented classification, supervision processes already in place.
What SerendipAI offers
SerendipAI supports Luxembourg businesses across two complementary areas.
The first is the diagnostic: we start from your actual situation. Which AI tools are deployed? In which processes? Used by whom? We build an inventory, classify the systems against the AI Act’s risk grid, and flag the priority points to watch.
The second is training. The AI literacy obligation under Article 4 is already in force. Training your teams isn’t a nice-to-have, it’s a regulatory requirement. Our “AI for Decision-Makers” and “AI for Everyone” programmes are built to address this in practical terms, backed by INFPC referencing and Fit4AI certification, which give access to Luxembourg’s public funding schemes.
To wrap up
The Digital Omnibus buys time, but it only pushes the deadline back. It doesn’t remove it.
If you haven’t started mapping your AI use yet, December 2027 will arrive in the same state as August 2026: too fast, with too little preparation. The decisions you make now about your AI tools are the ones you’ll need to justify by the end of 2027.
SerendipAI is a Luxembourg-based AI consulting, training and development firm, referenced as a training organisation by the Ministry of National Education and certified Fit4AI by LuxInnovation.
Sources:
European Parliament, plenary vote of 16 June 2026 on the Digital Omnibus on AI
Council of the EU, provisional agreement of 7 May 2026
European Commission, AI Act implementation timeline
Regulation (EU) 2024/1689 (AI Act)
WEnvision (April 2026) and Klein Blue (May 2026) analyses
Read more : Anonymisation vs pseudonymisation: a distinction that changes everything for your AI use cases








