The Digital Omnibus pushed the EU AI Act's Annex III high-risk deadline from August 2026 to December 2027 — exactly one conformity assessment cycle. Banks that treated the delay as breathing room are already behind.
Table of Contents #
The EU AI Act’s Annex III high-risk deadline was supposed to be August 2, 2026. Every bank with credit scoring models, AML transaction monitoring systems, and insurance underwriting tools was supposed to have completed conformity assessments, registered in the EU database, and posted technical documentation by that date. They didn’t — not because they were ready, but because the Digital Omnibus moved the finish line.
On June 29, 2026, the Council gave final approval to the Digital Omnibus legislative package. Standalone Annex III high-risk systems — the category that includes credit scoring, insurance pricing, and AI-driven AML monitoring — got an extension to December 2, 2027. For AI embedded inside products already regulated under Annex I product safety legislation, the date moved further still, to August 2, 2028. Most compliance teams called their legal departments, got the briefing, and filed it as a win. Quarterly AI governance reviews had one fewer red item. The pressure valve released.
That was a mistake. The deferral isn’t a reprieve. It’s exactly one conformity assessment cycle — and the banks that used the intervening months to breathe rather than build are already behind the pace needed to hit December 2027.
Regulatory & Compliance Angle #
The EU AI Act creates tiered obligations with different enforcement timelines. The prohibition on unacceptable-risk AI systems has been in force since February 2026. General-purpose AI model obligations have applied since August 2, 2026. And critically, Article 50 transparency requirements — which cover AI systems that interact with natural persons or generate synthetic content — also came into force on August 2, 2026, and the Digital Omnibus did not touch them.
This is the piece most institutions missed. Their compliance briefings focused on the Annex III high-risk deferral and largely overlooked what survived it. Article 50 requires that AI systems deployed to interact with people be clearly disclosed as AI to those people. It requires that AI-generated content — in lending decisions, insurance communications, and client-facing advice workflows — be labeled as machine-generated when the system produces output that could be mistaken for human-generated content. Banks with conversational AI in wealth management, with AI-generated mortgage rejection letters, or with chatbot-mediated customer service are subject to these requirements now, today, not in December 2027.
The distinction between what was deferred and what wasn’t matters because national supervisory authorities are already active. The EU AI Office, which handles general-purpose AI and cross-border enforcement, commenced operations in February 2026. National market surveillance authorities in member states are required to begin enforcement under the framework. A financial institution that is found to have deployed a conversational AI interface without Article 50 disclosure does not get to point to the Annex III deferral as cover — that provision doesn’t apply to the transparency violation.
On the deferred side, the Annex III conformity assessment path for standalone high-risk systems requires four substantive deliverables before a system can be registered in the EU database and deployed: a technical documentation package under Annex IV, a fundamental rights impact assessment for certain categories, registration in the EU AI public database, and either self-declaration or notified-body certification depending on whether an existing product-safety regulation requires third-party review. For credit scoring, the assessment path is self-declaration with conformity assessment evidence — but the evidence requirements are substantial: dataset documentation, performance testing for bias and discrimination, explainability documentation, and post-market monitoring plans.
What the Examiner Will Find #
National supervisory authorities conducting AI Act inspections in the financial sector are structured to look at four domains: does the institution know what AI systems it has; does it know which ones are high-risk; has it completed the required pre-deployment steps; and is it operating post-market monitoring. The first two questions are harder than they sound.
Most banks with more than 50 AI use cases in production do not have a single authoritative AI inventory that maps each system to its EU AI Act risk tier. The inventory that exists is typically owned by model risk management, and it was built against SR 11-7 or SR 26-2 criteria — which are risk-tiered by model complexity and materiality, not by use-case category under Annex III. A credit scoring model that is Tier 3 under the bank’s internal MRM framework is automatically high-risk under EU AI Act Annex III regardless of its internal tier. These two classification systems do not map to each other cleanly, and the inventory work to reconcile them hasn’t been done at most institutions.
The second gap examiners will find is in third-party AI. Annex III obligations apply to deployers as well as providers. A bank that purchases an AI-powered AML transaction monitoring platform from a vendor is a deployer under the Act. It owes documentation, monitoring, and human oversight obligations even if it didn’t build the model. Vendor contracts signed before the EU AI Act entered force typically do not include the technical documentation, fundamental rights impact assessments, or post-market monitoring data that the bank now needs to demonstrate compliance. The bank is caught between what the vendor is willing to provide and what the regulator expects to see — and the regulator doesn’t care about contract terms.
The examiner will also look for evidence of human oversight in the credit and AML decisioning pipeline. Article 14 of the EU AI Act requires that high-risk AI systems be designed and deployed to allow natural persons to effectively oversee them, including the ability to intervene, override, or halt the system. In production AML environments where transaction monitoring AI generates tens of thousands of alerts per month, “effective human oversight” is not a self-evident concept. Examiners will want to see documented escalation procedures, alert review SLAs, and evidence that the human review function has sufficient staffing and access to override decisions — not just a policy document stating that humans are in the loop.
The Governance Gap #
Here is the structural problem that neither the Digital Omnibus nor SR 26-2 resolves: banks now operate two parallel governance frameworks for the same AI systems, and they don’t cover the same ground.
SR 26-2, issued April 17, 2026, explicitly carved generative and agentic AI out of its scope. The Federal Reserve, OCC, and FDIC asked for comment on how to handle those systems but issued no binding guidance. Banks were told to apply their existing governance principles — which were built for traditional quantitative models, not LLMs. The EU AI Act, by contrast, covers any AI system that is high-risk regardless of what technology underlies it. An LLM deployed for credit decisioning is high-risk under the Act and subject to all Annex III requirements, whether or not SR 26-2 treats it as a model.
This creates a specific failure mode for banks with US and EU operations: the system that the US regulator doesn’t require you to formally validate is the system the EU regulator requires you to have a conformity assessment for. Teams running dual-jurisdiction compliance programs have to maintain two governance postures simultaneously, and they often can’t share documentation because the frameworks ask different questions. SR 26-2 wants to know how the model was developed, validated, and monitored against a performance benchmark. The EU AI Act wants to know what data the system was trained on, whether that data was representative and bias-tested, and how a human can intervene in real time. These are not the same question, and the technical documentation for one doesn’t satisfy the other.
The vendor governance gap amplifies this. A bank that deployed a third-party LLM for AML alert narrative generation — a use case that grew substantially in 2025-2026 — faces a documentation request from EU supervisors that the LLM provider may not be contractually obligated to fulfill. If the provider is not EU-established and has not registered a GPAI model with the EU AI Office, the bank is in an exposed position with no clear path to the documentation it needs.
What to Watch #
The December 2, 2027 deadline will produce a conformity assessment bottleneck in 2027. The number of notified bodies designated under the EU AI Act remains limited — the designation process is slow, and most EU member states had not completed notified body designations as of mid-2026. For standalone Annex III high-risk systems that require notified body involvement (typically those embedded in regulated products under Annex I, though some financial services use cases may require third-party review), queue times will extend. Banks that wait until Q1 2027 to begin notified body engagement risk being unable to complete conformity before the December deadline.
Watch for enforcement actions against Article 50 transparency violations in late 2026 and early 2027. These are the easiest cases for national supervisors to build: the violation is clear (AI disclosed as human, or not disclosed at all), the evidence is the deployed system, and the fine structure — up to €15 million or 3% of global turnover — is significant enough to motivate penalties. The first financial-sector AI Act enforcement action will likely be an Article 50 case, not an Annex III case.
Watch for the EU AI Office’s GPAI model regulation to create a secondary compliance burden. General-purpose AI models above the 10^25 FLOP threshold have their own obligations under the Act, and banks deploying these models via API from major providers need to understand how those obligations flow through the supply chain. If the provider doesn’t meet GPAI obligations, the bank’s deployment is at risk regardless of its own conformity status.
Finally, watch for the December 2027 deadline to slip again. The Digital Omnibus deferral was driven by industry lobbying supported by member state governments arguing that compliance infrastructure wasn’t ready. Those conditions haven’t fundamentally changed. A second deferral is politically plausible — but compliance teams that plan for a second deferral and don’t get one will have no recovery time.
The SuperML Take #
The financial services industry should have learned by now that regulatory deadline deferrals are not gifts. The SR 11-7 era taught this lesson repeatedly: institutions that used exam cycles to defer validation work didn’t eliminate the compliance requirement, they just compressed it into a shorter runway when enforcement finally arrived. The EU AI Act Digital Omnibus is structurally identical to every previous “we’ll come back to this” regulatory moment, except the stakes are higher because the Act has extraterritorial reach and its fine structure applies to global turnover.
The December 2, 2027 deadline is not far away. A bank that begins its Annex III conformity assessment program today — in October 2026 — has 14 months. Industry practitioners put the standard conformity assessment engagement at 12 to 18 months for a complex financial services AI system, accounting for notified body scheduling, technical documentation preparation, bias testing, and post-market monitoring plan development. An institution that started this work in August 2026 when the original deadline passed is running a normal timeline. An institution that hasn’t started is running a compressed one.
The model risk teams that will be in the best position at December 2027 are the ones that used the deferral to do something the compressed pre-August 2026 timeline didn’t allow: build the EU AI Act documentation as part of the model lifecycle rather than as a retroactive compliance project. That means treating Annex IV technical documentation as a model development artifact, not a regulatory submission prepared after deployment. It means wiring fundamental rights impact assessments into the pre-deployment review gate, not the compliance calendar. It means building Article 14 human oversight procedures into the system design, not adding them as a policy overlay on top of an existing automated pipeline.
The governance gap between SR 26-2 and the EU AI Act is real and will not self-resolve before December 2027. US-facing model governance and EU AI Act compliance are asking different questions about the same systems. Banks that haven’t built cross-functional working groups — MRM, legal, data science, product, and compliance together — to reconcile those frameworks are operating a governance illusion. They have two documents that each say something, and no one who can answer the question a EU supervisor will actually ask.
The Digital Omnibus was a necessary course correction for an industry that genuinely wasn’t ready for August 2026. But it did not move the destination — it moved the departure time one conformity cycle later. If you haven’t boarded yet, you’re not ahead of schedule. You’re late.
Sources #
Enterprise AI Architecture
Want more enterprise AI architecture breakdowns? #
Subscribe to SuperML.