Selling AI to EU customers? How much time does the Digital Omnibus actually buy you?
Three things to remember
Enterprise contracts run 3 to 5 years through 2030
Buyers in regulated industries embed AI Act obligations into 2026 RFPs. They do not want to renegotiate mid-cycle when high-risk obligations kick in.
UX wins demos. Compliance wins shortlists.
Most AI vendors compete on user experience and feature velocity. In regulated industries, compliance readiness is what decides the deal.
Hold the pen on your B2B contracts
When the customer drafts the clauses, they become deal-blocking for the vendor.
Regulation (EU) 2026/1744, known as the Digital Omnibus on AI, published in the Official Journal on 24 July 2026 and in force since 27 July 2026, sets the final calendar of the AI Act. The application of obligations for high-risk AI systems listed in Annex III of the AI Act, originally scheduled for 2 August 2026, is now postponed to 2 December 2027, a 16-month extension. For high-risk AI systems integrated into products governed by other EU harmonization legislation (machinery, toys, lifts), the application date is set at 2 August 2028.
For many CEOs selling or about to sell AI or data products to EU customers, this looks like a 16-month regulatory relief. It is a misreading of the business calendar.
The Article 5 prohibited practices regime has been binding since 2 February 2025 and is not affected by the Digital Omnibus. Beyond this regime, the existing European framework that governs AI use keeps producing multi-million-euro decisions every quarter, with regulatory as well as commercial consequences. And European procurement teams in regulated industries operate on contractual cycles that ignore regulatory grace periods.
Why are European customers not waiting for the December 2027 deadline?
This is the dynamic most underestimated by AI vendor CEOs entering or expanding in the European market.
European buyers in regulated industries (defense, pharma, banking, insurance, healthcare, energy, critical infrastructure, education, public sector, large HR functions) and enterprise clients lead market expectations on AI compliance. Vendors and AI providers selling into these accounts face direct procurement pressure regardless of whether their AI system actually qualifies as high-risk, and irrespective of the regulatory grace period.
A procurement team negotiating a SaaS contract with embedded AI typically asks, among other things, the prospective vendor for:
- Documentation of the AI models used and their AI Act risk classification
- Evidence of data governance and training data quality controls
- Contractual commitments on transparency, human oversight and audit rights
In a market where vendors compete primarily on user experience design and feature velocity, regulatory readiness becomes a real commercial differentiator. For an unprepared AI vendor, the immediate exposure is commercial rather than regulatory. Compliance gaps surfacing during due diligence lead to deprioritization in procurement, exclusion from contract shortlists, or renegotiation at unfavorable terms during contract execution.
The December 2027 postponement does not change this dynamic. European legal and procurement teams work on contract cycles of 2 to 4 years. A SaaS agreement signed in June 2026 for a three-year term will be executed under AI Act obligations. The 2026 RFPs are drafted accordingly.
Compliance gaps surface during procurement due diligence.
What does the Digital Omnibus actually change, and what does it not?
The AI Act (Regulation EU 2024/1689) entered into force on 1 August 2024 and applies in waves. The Digital Omnibus on AI was adopted on 8 July 2026 and published in the Official Journal of the European Union on 24 July 2026 as Regulation (EU) 2026/1744. It has been in force since 27 July 2026. The postponement of the Annex III high-risk obligations to 2 December 2027, and of the obligations for systems embedded in Annex I products to 2 August 2028, is now set unconditionally. It also introduces simplification measures, notably the extension of SME privileges to small mid-cap companies, broader access to regulatory sandboxes, and strengthened enforcement powers for the AI Office.
The Regulation adds a new Article 5 prohibition on AI systems generating or manipulating non-consensual intimate imagery or child sexual abuse material, applicable from 2 December 2026. The Article 50 transparency obligations apply since 2 August 2026 as planned; only the Article 50(2) machine-readable marking obligation benefits from a transition until 2 December 2026 for generative AI systems already on the EU market before 2 August 2026, a reading confirmed by the Commission's Article 50 guidelines of 20 July 2026. A voluntary Code of Practice on Transparency of AI-Generated Content, assessed as adequate in July 2026, completes the set: adherence is documented compliance evidence, exactly what procurement teams ask for. The Article 101 fines for providers of general-purpose AI models are applicable since 2 August 2026.
Three pillars of the European framework remain unchanged. The GDPR continues to apply in full, including Articles 22, 9, 6 and 27. The Digital Services Act and Digital Markets Act produce their effects on platforms. National regulations on non-discrimination, employment law and consumer protection continue to apply, and European authorities actively use them to frame AI use.
Is the existing EU framework already sanctioning AI use?
Yes. Recent enforcement decisions in France and Spain illustrate this. None relies on the AI Act. All concern biometric or algorithmic systems whose operators could, in theory, have waited until 2 December 2027 if the AI Act had been the only relevant framework.
In Spain, the Spanish Data Protection Agency (AEPD) imposed a 10.04 million euro fine on AENA, the operator of Spanish airports, for deploying facial recognition systems in several airports without a valid Data Protection Impact Assessment (DPIA) as required by Article 35 GDPR for biometric data processing. Other 2025 decisions in Spain targeted biometric recognition without a DPIA, automated processing beyond the original purpose, and integrity failings on data security. The healthcare sector saw a 278 percent year-on-year increase in sanctions (source: AEPD Memoria de actuación 2025, published 6 May 2026).
In France, the CNIL issued sanctions in January 2026 totalling 42 million euros against two major telecom operators for security failings under Articles 5, 32 and 34 GDPR. Its 2025 enforcement review records 16 organizations sanctioned for unlawful employee video surveillance, a practice increasingly combined with algorithmic behavior analysis tools.
The Clearview AI cases illustrate the specific exposure of non-EU vendors. This US facial recognition company has received a 20 million euro fine from the CNIL of France in 2022 (CNIL decision) for unlawful processing under Articles 6 and 31 GDPR, with a further 5.2 million euro fine in 2023 for non-compliance. The Italian Garante imposed a separate 20 million euro fine on 10 February 2022 (EDPB press release) covering multiple GDPR breaches including failure to designate an EU representative under Article 27.
The message is direct. An AI vendor processing European personal data is already exposed to multiple applicable texts. The AI Act will add specific obligations from end-2027 for high-risk systems. It does not replace the existing framework, which keeps producing concrete decisions.
How long does building EU AI compliance actually take?
With 16 additional months, the natural assumption is a comfortable margin. In practice, building a defensible European governance for an AI vendor that has not previously structured its EU compliance typically requires three to six months of effective work.
The constraint is not the AI Act deadline. It is the procurement questionnaire that lands on your sales team's desk next quarter.
The constraint is not the AI Act deadline. The constraint is the procurement questionnaire that lands on the sales team's desk next quarter. Data and AI system mapping, designation of representatives, review of vendor contracts (including LLM provider agreements), impact assessments, technical documentation, training: these workstreams interlock and feed each other.
Starting in October 2027 to be ready for 2 December 2027 means being late on the RFPs of 2026 and 2027, and being late on the regulatory deadline itself.
Wondering if your EU compliance posture would survive a 2026 enterprise procurement audit? 30-minute confidential scoping call.
Request a first callWhich three obligations should AI vendors prioritize today?
1. Designate EU representatives (GDPR Article 27 and AI Act Article 22)
Two distinct regimes apply cumulatively to many AI vendors selling to EU customers.
Article 27 GDPR requires non-EU controllers and processors that handle data of EU residents to designate an EU representative in writing. The obligation applies whenever the company offers goods or services to individuals in Europe or monitors their behavior. It has been applicable since 25 May 2018.
Article 22 AI Act introduces a distinct obligation for non-EU providers of high-risk AI systems: an authorized representative must be designated before any Annex III system is placed on the EU market on or after 2 December 2027. While formal appointment is required at the placing-on-the-market stage, the selection, due diligence and mandate negotiation typically take 2 to 4 months and should be initiated well in advance to be operational on D-day.
Article 27 GDPR
EU representative
Article 22 AI Act
Authorized representative
These obligations are independent. Conflating them, or designating only one, leaves a structural gap that a customer's legal team will detect during due diligence.
2. Prepare anticipated AI Act documentation
If the AI system falls within Annex III, provider and deployer obligations become binding on 2 December 2027. Annex III categories include recruitment and personnel selection, employee evaluation, access to essential services, education and vocational training, and management of critical infrastructure.
The immediate exposure is not the public sanction in 2028 or 2029. It is the inability to respond to European customer requirements during procurement phases in 2026 and 2027. Technical documentation, risk management, training data quality controls, logging, transparency, human oversight, and (for certain public deployers) Fundamental Rights Impact Assessment: these workstreams require 6 to 12 months of implementation.
3. Build a defensible B2B contractual framework
B2B agreements with European customers should integrate clauses that demonstrate, in the event of an audit or customer due diligence, alignment with the European framework. A robust Data Processing Agreement under GDPR, international transfer clauses, transparency commitments, and AI Act-ready clauses that can be activated on 2 December 2027.
When European customers hold the pen on these clauses, they tend to draft them heavily protective for the buyer, sometimes to the point of being deal-blocking for the vendor. Indemnities are broad, audit rights are intrusive, termination grounds are expansive. Initiating the conversation with the vendor's own clean clause set positions the company as a credible counterpart, sets the reference template for negotiation, and preserves commercial leverage. Letting the customer introduce these requirements unilaterally, or addressing them only at the third renegotiation, introduces retroactive risks to the contract at stake and complicates the client relationship.
Does the postponement change anything for AI vendors?
Three months of inaction today equals six months of contractual lag in 2027. The AI vendors that will win European RFPs in regulated industries in 2026 and 2027 are not those waiting until December 2027 to structure their compliance. They are those who can respond today to a due diligence questionnaire with documented and defensible commitments.
The Digital Omnibus is welcome news for legal certainty and for the quality of European technical standards.
Handling it as an authorization to wait is a risky move.
FAQ
Does the AI Act apply to a US, UK, Canadian, Australian or Israeli company selling AI to EU customers?
Yes. Article 2(1)(c) of the AI Act extends its scope to providers and deployers of AI systems located outside the EU when the output produced by the system is used in the EU. Selling an AI product or a SaaS with embedded AI to an EU customer triggers the AI Act regardless of where the vendor is established.
When do AI Act high-risk obligations apply now?
Regulation (EU) 2026/1744 (Digital Omnibus on AI), published in the Official Journal on 24 July 2026 and in force since 27 July 2026, sets the application of the obligations for high-risk AI systems listed in Annex III at 2 December 2027, and at 2 August 2028 for systems integrated into products governed by other EU harmonisation legislation.
Does the Digital Omnibus delay GDPR obligations?
No. The Digital Omnibus AI only affects the AI Act calendar. The GDPR continues to apply in full, including Article 22 on automated decision-making, Article 9 on sensitive data, and Article 27 on the designation of an EU representative for non-EU controllers and processors.
Does a non-EU AI company need a GDPR Article 27 representative?
In most cases, yes. Article 27 GDPR applies to any non-EU controller or processor that offers goods or services to individuals in the EU or monitors their behavior. The obligation has been in force since 25 May 2018, independently of the AI Act.
How long does it take to build EU AI compliance?
Three to six months of effective work for an AI vendor that has not previously structured its European framework. The workstreams interlock: data and AI system mapping, designation of representatives, vendor contract review, technical documentation, transparency notices, training.