Skip to content

The Big Delay in the EU AI Act: Digital Omnibus Pushes High-Risk Obligations to 2027-2028

With the Digital Omnibus, the EU AI Act's high-risk obligations were delayed to 2027-2028. Is this a cancellation or a reprieve? A practical roadmap for Turkish exporters.

SYK
Şükrü Yusuf KAYA
AI Expert · Enterprise AI Consultant

TL;DR — On 7 May 2026, EU institutions reached a provisional political agreement on the "Digital Omnibus on AI," which significantly delayed the most feared part of the EU AI Act: the obligations for high-risk systems. The deadline for standalone Annex III systems moved to 2 December 2027, and for AI embedded in regulated products to 2 August 2028. But let me be clear: this is not a cancellation, it is a reprieve. Prohibited practices remain banned, GPAI transparency rules are still in force, and fines of up to 35 million euros are still on the table. Every Turkish company that sells or provides services to the EU must layer this framework on top of KVKK (Turkey's data protection law). In this article I share why the delay happened, how to use the time you gained, and a concrete roadmap especially for Turkish SMEs and exporters.

First, Let's Stay Calm: What Was Delayed and What Wasn't?

In recent weeks, at the companies I advise, I have seen the same two extreme reactions. One group said "phew, we're saved, we can relax until 2028" and put the file back in the drawer. The other group panicked: "the law changed, all our preparation is wasted." Both are wrong. The truth, as always, is in the middle.

Let's first lay out a timeline so we can see clearly what stands where. The EU AI Act is not a monolithic law that entered into force on a single date; it is an architecture that comes online in stages. The delay affected only one layer of this architecture.

Obligation layerStatusDate
Prohibited practices (unacceptable risk)In force, bannedSince February 2025
GPAI (general-purpose AI) transparency obligationsIn forceSince August 2025
High-risk — standalone Annex III systemsDelayed2 December 2027
High-risk — AI embedded in Annex I productsDelayed2 August 2028
Maximum administrative fineUnchanged35 million € or 7% of global turnover

The first two rows of the table are critical. Unacceptable-risk practices such as social scoring, emotion recognition in the workplace and school, and biometric categorization to infer sensitive data have been banned since February 2025, and this ban was not delayed. So if a Turkish software firm sells an emotion-analysis hiring tool to the EU market, that tool is unlawful today and will remain unlawful tomorrow.

The second row is just as important. For providers developing large language models such as GPT, Claude, and Gemini, the general-purpose AI (GPAI) transparency obligations have been in force since August 2025. These include publishing a summary of training data, maintaining a copyright compliance policy, and keeping technical documentation. This layer also stayed outside the delay.

"

The only thing delayed is the compliance obligations for high-risk systems. And this delay means "do it a bit later," not "don't do it."

You need to internalize this distinction from the very start, because it is exactly the source of the confusion I see in the field. When a company tells me "we got the delay, now we can use AI however we want," I first take a breath and read this table with them. Often, some of the systems the company uses are already in the limited-risk category, and the transparency obligations for that category are not affected by the delay at all. In other words, the word "delay" may actually change nothing for the vast majority of your systems.

Why Did the Delay Happen? A Reading from the Field

Now let's get to the part people are most curious about: why did the European Commission step back? Why couldn't the institutions that drafted the regulation keep to the original dates? From what I have observed in the field, there are three main reasons.

First, the technical standards weren't ready. It is not enough for a law to say "high-risk systems must meet these conditions"; you need harmonised standards that define how those conditions will be measured. These are prepared by European standardization bodies such as CEN and CENELEC. As the 2 August 2026 deadline approached, most of these standards were still in draft. Telling a company to "be compliant" without standards is like asking a student for a passing grade without giving them the exam questions. Companies didn't know what to comply against.

Second, companies weren't ready. Especially for SMEs, high-risk system obligations are a serious burden: establishing a risk management system, building data governance processes, producing technical documentation, designing human oversight mechanisms, and passing a conformity assessment. Feedback from European industry was clear: "We can't make it at this pace." Competitiveness concerns, namely the fear that EU firms would be crushed under regulatory burden against the US and China, added to this pressure.

Third, a lack of institutional capacity. Implementing the law required establishing national competent authorities, bringing the AI Office to full capacity, and having enforcement mechanisms ready. This ecosystem was not yet mature either. Imposing an obligation to be audited when the auditing body is not ready simply doesn't work in practice.

When these three reasons combined, a simplification and delay package called the "Digital Omnibus on AI" came onto the agenda, and a provisional political agreement was reached on 7 May 2026. So the delay came not from a whim but from a genuine picture of unpreparedness. Knowing this matters, because you don't want to be inside that same picture of unpreparedness.

I especially want to underline one point: the delay did not loosen the content of the regulation. The obligations that will enter into force on 2 December 2027 are largely the same as those that would have entered into force on 2 August 2026. The only thing that changed is the calendar. So waiting in the hope that "maybe while stepping back they will also soften the rules" is a risky bet. As far as I can see, the EU's fundamental philosophy on responsible AI has not changed; only the implementation timing was made more realistic.

Why Are Companies in Turkey Still in Scope?

Here I have to correct the most common misconception. I have heard the sentence "we are in Turkey, EU law doesn't bind us" so many times. This is a dangerously wrong assumption.

The scope of the EU AI Act, just like GDPR, is drawn not by geographic borders but by the principle of effect. Any one of the following three situations brings you directly into scope:

  • If you are a provider: If you place an AI system on the EU market or put it into service in the EU, it doesn't matter where you are based. If you sell a high-risk AI product you developed in Istanbul to a customer in Germany, you are in scope as a provider.
  • If you are a deployer: If you use an AI system as a deployer established in the EU, you are in scope. This is critical for Turkey-based groups with branches or subsidiaries in the EU.
  • If the output is used in the EU: If the output produced by the system is used within the EU, you may be in scope even if you run the system in Turkey. For example, a credit model that scores customers in the EU on a server in Turkey.

So every Turkish firm that exports to the EU, sells SaaS to EU companies, or develops software for the EU market is inside this framework. The delay gave you breathing room too, but it did not grant an exemption.

There is also the other side of the coin: KVKK. If you operate in Turkey, your AI systems are already covered by the Personal Data Protection Law. KVKK brings principles such as explicit consent, the duty to inform, data minimization, and purpose limitation for automated decision-making mechanisms that process personal data. The data governance and transparency requirements of the EU AI Act largely overlap with KVKK's principles. So the preparation you do for the EU also strengthens your KVKK compliance. Rather than fighting on two fronts separately, it is far smarter to build a shared governance backbone.

To make this overlap concrete, here is a mapping table I use often. See how the two frameworks feed the same backbone:

EU AI Act requirementKVKK equivalentShared action
Data governance and qualityData accuracy and being up to dateBuild the data quality process once
Transparency and informationDuty to informUser information notice
LoggingRecord of processing activitiesCentral logging discipline
Human oversightRight to object to automated decisionsHuman intervention mechanism
Risk managementData security measuresShared risk inventory

Let's also not forget: Turkey is preparing its own AI legislation. When a national AI regulation arrives, you are very likely to encounter concepts similar to the EU framework. The governance structure you build today will also make you ready for tomorrow's national regulation. So this effort is not wasted; you are investing in three different futures (the EU, KVKK, and national AI legislation) at the same time.

The Time You Gained Is Not a Gift, It's a Test

Now we come to the heart of the matter. You should read the delay not as "relief" but as a "preparation window." There is something I constantly say in consulting: compliance is not a date, it is a maturity. You have about a year and a half ahead of you until 2 December 2027; but compliance done in panic in the last three months of that period is both expensive and fragile.

To help you use the time you gained well, I divide compliance into six fundamental building blocks. Let's take them in turn.

1. AI Inventory: You Can't Manage What You Don't Know You Have

The first step of any compliance effort is inventory, and this step is surprisingly neglected. You need to list all AI systems used in your organization: purchased off-the-shelf solutions, in-house developments, models embedded in a SaaS product, and even the "shadow AI" tools departments use without IT's knowledge.

For each system, record the following: the system's purpose, the types of data it uses, its role in the decision-making process, the people it affects, and whether you are a provider or a deployer. Without this inventory, you cannot do risk classification. At one of my clients, when we drew up this inventory, a candidate-assessment tool the marketing team was using without asking HR came to light; no one was even aware that it fell into the high-risk category. That is exactly why inventory saves lives.

2. Risk Classification: Not Every System Goes in the Same Basket

The EU AI Act defines four risk levels: unacceptable (banned), high, limited, and minimal. Position each system in your inventory on this pyramid.

  • Unacceptable: Practices such as social scoring, manipulative techniques, and emotion recognition in the workplace. These are already banned; if you have any in your inventory, stop immediately.
  • High-risk: Areas listed in Annex III; hiring, credit scoring, education assessment, critical infrastructure, biometric identification, and so on. The delayed obligations are for these.
  • Limited risk: Chatbots and systems that generate deepfakes. There is a basic transparency obligation for these (informing the user that they are interacting with AI).
  • Minimal risk: Most applications such as spam filters and recommendation engines. There is no strict obligation for systems here.

My practical observation: companies often assume their systems are higher-risk than they are and panic needlessly, or the opposite, they belittle a high-risk hiring tool as "just software." Correct classification lets you direct your resources to the right place.

3. Data Governance: Is the Model's Fuel Clean?

For high-risk systems, data governance is the heart of the heart. You need to document the quality, representativeness, and bias status of your training, validation, and test datasets. Where did the data come from, how was it labeled, which population does it represent, which groups might be underrepresented?

The intersection with KVKK is right here: if you use personal data, your legal basis (explicit consent or legitimate interest) must be clear, you must comply with the data minimization principle, and you must define retention periods. Once you build a proper data governance framework, you strengthen both the EU and KVKK fronts at the same time.

4. Human Oversight: The Machine Decides, the Human Is Responsible

The EU AI Act requires meaningful human oversight for high-risk systems. This doesn't mean "have someone sit in front of a screen"; it means designing a mechanism that can understand the decision, stop it when necessary, and intervene.

In practice, ask these questions: Can a human override the system's decision? Is there a safeguard against automation bias (the human blindly trusting the machine)? Was the person doing the oversight trained for it? Making these design decisions now is far cheaper than patching them onto the system later.

5. Documentation and Transparency: If It's Not Written, It Doesn't Count

This is the area companies struggle with most in audits. High-risk systems require technical documentation, logging, instructions for use, and a declaration of conformity. The golden rule here is: if you didn't write down what you did, you are legally deemed not to have done it.

Establish a documentation discipline now. Let there be a traceable record of every model decision, every data choice, and every risk assessment. This is the one thing that will save you when an audit arrives.

6. Governance and Accountability: Who Is Responsible?

Finally, build an AI governance structure. Designate a person responsible (an AI compliance officer or committee), put your policies in writing, train your staff, and create regular review cycles. Compliance should not be one person's side job; it should be a process embedded in the organization.

Sector by Sector: How Does the Delay Affect You?

The general framework is nice, but everyone's situation is different. Let me make it concrete through the four sectors I encounter most in consulting.

Finance and insurance. Applications such as credit scoring, insurance risk assessment, and fraud detection typically fall into the high-risk category. For banks and fintechs, the delay is a valuable preparation period; but this sector is already tightly supervised under banking regulators and KVKK, so your data governance infrastructure is probably partly ready. My recommendation here: map your existing model risk management framework to the EU AI Act requirements, don't start from scratch.

Healthcare. Diagnostic support systems and clinical decision tools can fall under both Annex III and medical device legislation (Annex I); that is why the deadline for some healthcare AI products extends to 2 August 2028. But since the cost of error in healthcare is high, don't let the delay lull you into complacency; start early on clinical validation and human oversight design.

Human resources. Hiring, candidate ranking, and performance evaluation tools are high-risk. This is critical for firms that employ remote workers from Turkey into the EU or sell HR technology to EU companies. Candidate bias tests and transparency notices for candidates are matters you need to solve now.

E-commerce and marketing. The good news: most applications such as recommendation engines, search ranking, and personalization are in the minimal or limited risk category. So for the vast majority of e-commerce firms, the EU AI Act burden is lighter than assumed. But if you have a customer service chatbot, watch out for the limited-risk transparency obligation requiring you to clearly inform the user that they are talking to an AI; this was not delayed.

GPAI Obligations: Don't Forget They Weren't Delayed

I need to open one more parenthesis, because this point is constantly overlooked. If you integrate large language models into a product (which nearly everyone does today), the providers of the foundation models you use are under GPAI obligations. This concerns you indirectly too.

Questioning whether your model's provider supplies a training data summary, a copyright policy, and technical documentation is part of your own supply chain responsibility. Request compliance documents for these obligations from providers such as Cohere, OpenAI, Anthropic, and Google. In an audit, be ready for the question "do you know which model you use and whether that model is compliant?" This layer was not affected by the delay at all and has been in force since August 2025.

Do the Fines Stay on Paper? The Reality of Enforcement

I hear the question "the fine is big, but will it be enforced?" a lot. What we learned from the GDPR experience is this: enforcement starts slowly at first, then accelerates with serious fines. In the EU AI Act, the maximum administrative fine is 35 million euros or 7% of global turnover; this is even higher than GDPR's upper limit. The heaviest tier applies to prohibited practices.

The real risk I see is not just the fine. An EU customer now asks for a compliance document when signing a contract with you; if you are non-compliant, you get eliminated from the tender. So the real sanction is loss of market access. The delay does not delay this commercial pressure; large buyers have already started asking their suppliers for evidence of preparation. Commercial reality, even before fear of fines, should get you moving.

Frequently Asked Questions and Common Mistakes

Let me briefly answer the questions I encounter most in the field.

"We only use open-source models, are we exempt?" No. What matters is how you use the model and which risk category the purpose it serves falls into, not whether its source is open or closed.

"Is the delay finalized?" A provisional political agreement was reached on 7 May 2026; you should follow developments until the official publication of the final text, but the direction is clear: high-risk obligations moved to 2027-2028.

"Isn't being KVKK-compliant enough?" No. KVKK is personal-data-focused; the EU AI Act focuses on the risk and safety of the system. They overlap, but one does not replace the other.

"We're a small SME, they won't come after us." This was also the thinking during the GDPR era, and then fines came to SMEs too. Size does not put you outside scope; it only brings proportionality in some obligations.

A Concrete Roadmap for the Turkish SME and Exporter

Now let's set theory aside and turn it into a plan that is applicable in the field. If you are a mid-sized Turkish company doing business with the EU, I recommend splitting the next 18 months as follows.

First 3 months — Visibility. Draw up your AI inventory. Make sure you use nothing unacceptable-risk; if you do, stop immediately. For each system, clarify whether you are a provider or a deployer. This phase is low-cost but high-return, because most companies don't even know what they have.

Months 3-6 — Classification and gap analysis. Classify each system in your inventory by risk level. For the high-risk ones, produce a gap analysis between your current state and the target. Which documentation is missing, which data governance process doesn't exist, how should human oversight be designed?

Months 6-12 — Build. Close the gaps in order of priority. Build the data governance framework, create documentation templates, integrate human oversight mechanisms into the system. Align these with your KVKK compliance so you don't do the work twice.

Months 12-18 — Test and mature. Conduct an internal audit, run your processes end to end once, train your staff. Approach the end of 2027 not in panic but ready.

In this roadmap I recommend being realistic about budget. Minimal investment is enough for non-high-risk systems; focus your energy and money on the one or two systems that are genuinely high-risk. Everyone trying to do everything at once is the most common resource waste I see.

Also pay attention to the contracts with your providers. If you use the product of a provider that sells a high-risk system to the EU market, check how the responsibility for compliance is distributed in the contract. Request the documentation the provider must supply to you. Compliance in the supply chain is part of your own compliance.

Conformity Assessment and the CE Mark: For High-Risk Products

If you are a provider of a high-risk AI system, there is also a technical approval dimension. Before the system is placed on the EU market, it must pass a conformity assessment and, on that basis, carry the CE mark. In other words, your AI product will go to market with a declaration of conformity, just like an electronic device.

For most Annex III systems this assessment can be done through the provider's own internal control (self-assessment); but in some cases a notified body comes into play. The catch here is this: self-assessment does not mean "we write whatever we want." Your technical documentation, your risk management records, and your data governance documents must be of a quality that supports this declaration in an audit. The delay gives you time to build this assessment infrastructure calmly. A technical file prepared in a rush in the final month becomes the first thing to crack in an audit.

Also watch out for the concept of "substantial modification." When you make a serious update to your high-risk system, you may need to renew the conformity assessment. Because AI systems are products that are continuously retrained and updated, this is not a one-time obligation but one that requires continuity. Frame it as a matter of culture.

Training and Culture: The Invisible Half of Compliance

Technical documentation and risk classification are the visible face of the job. But what I have seen in the field many times is this: even the best-prepared compliance framework stays on paper if the people who will apply it don't understand it. If the HR specialist using a hiring tool doesn't know what automation bias is, the human oversight policy you wrote is of no use.

That is why you must set aside part of the time you gained for training. Explain to managers what the obligations are, to the technical team the documentation discipline, and to end-user employees the limits of the system and the points of intervention. The EU regulation already brings an "AI literacy" obligation too; that is, your employees' understanding of the systems they use is now a legal expectation. See this not as a burden but as an investment: a team with high AI literacy makes fewer mistakes and seizes new opportunities faster.

My recommendation is to hold a short "AI governance refresher" session every six months. The regulation changes, your systems change, your team changes; your culture must breathe along with this change too. The companies that win are not the ones that start and finish compliance like a project, but the ones that turn it into a habit.

Turning It into a Competitive Advantage: Make Compliance a Marketing Weapon

I want to offer one final perspective, because this is usually overlooked. If you see compliance only as a defense, a "let's not get into trouble" activity, you miss half of its potential. The smartest companies I see in the field turn responsible AI compliance into a sales argument.

Consider this: an EU buyer will choose between two Turkish suppliers, one offering a documented compliance framework and the other saying "we're in Turkey, it won't come to us." Which one will they prefer? Compliance is now a trust signal, just like ISO certificates. Being able to put the sentence "our AI systems are compliant with the EU AI Act and KVKK" into your proposal creates a difference that sets you apart from your competitors.

My recommendation is to budget your compliance work not as a cost item but as a market positioning. Use the year and a half you gained to build this difference; because while everyone panics in the final month and tries to prepare the same documents at the same time, you will already be ready and referenced. When I recommended this approach to one of my clients, they hesitated at first; six months later they told me they used their compliance documents as the decisive advantage in a contract with a German retail chain. Compliance, when told correctly, is not a burden but a key.

The Real Lesson to Draw from This Delay

My observation is this: those who see regulation as an obstacle read every delay as an opportunity to escape, while those who see regulation as a sign of maturity use every delay as a window of advantage. The second group builds trust in the EU market, can tell its customers "we do responsible AI," and calmly continues on its way while competitors panic at the last minute.

The most valuable thing the delay gives you is not money, it is time. And time is valuable only for those who turn it into a plan. If you start drawing up your inventory today, by the end of 2027 compliance will be a routine for you, not a crisis. My recommendation is clear: don't put the file back in the drawer, take your next step this week. I have seen many times that a company advancing with small but regular steps builds a cheaper and more robust compliance than a company trying to get everything done in the final month. The decision is yours: you will turn this year and a half into either an advantage or a debt.

Consulting Pathways

Consulting pages closest to this article

For the most logical next step after this article, you can review the most relevant solution, role, and industry landing pages here.

Comments