The EU AI Act's deadline moved to 2027. The work did not.
The EU AI Act's Annex III deadline moved from August 2026 to December 2027, but Article 50 and Article 26 obligations for banks and insurers did not move.

On June 29, 2026, the Council of the EU gave final approval to the Digital Omnibus. The package pushes the EU AI Act's Annex III high-risk deadline from August 2, 2026, to December 2, 2027 (Pinsent Masons, 2026). Credit scoring, insurance risk pricing, and other financial-services use cases just gained sixteen months.
The relief will not last as long as it looks. Article 50 transparency rules kept their original date. Article 26's human oversight and logging obligations describe infrastructure work that a moved deadline does not build for anyone.
What the Digital Omnibus actually delayed
The European Parliament and Council spent 2026 finalizing the Digital Omnibus on AI, a package the Commission proposed to simplify the EU AI Act's rollout. Parliament voted to adopt it on June 16, 2026, and the Council followed with final approval on June 29 (Sidley Data Matters, 2026).

The change that matters most for financial services: standalone high-risk obligations under Annex III move from August 2, 2026, to December 2, 2027. That covers creditworthiness assessment and life and health insurance risk pricing. High-risk systems embedded in regulated products get until August 2, 2028 (Pinsent Masons, 2026).
The penalty tier for getting this wrong does not change either. Non-compliance with the Act's core obligations, Article 50 included, still carries fines up to €15 million or 3% of global annual turnover, whichever is higher (Cloud Security Alliance, 2026).
Article 50 transparency did not move
Article 50's transparency duties, disclosing AI interaction and labeling AI-generated content, took effect on schedule on August 2, 2026, independent of the Annex III delay (Cloud Security Alliance, 2026). A narrow grace period runs to December 2, 2026, only for the machine-readable watermarking duty under Article 50(2), and only for systems already on the market before August 2, 2026.
KYC chatbots, claims-intake assistants, and any customer-facing agent built on generative AI fall inside this rule today. It does not matter whether the underlying decision system counts as high-risk under Annex III.

Why banks and insurers are still exposed
In 2025, Deloitte surveyed senior financial-services leaders on AI governance maturity and found only 13% of institutions ready to implement trustworthy AI (Deloitte, "AI at a crossroads," 2025). The other 87% reported gaps in oversight, documentation, or accountability structures.
Source: Deloitte, "AI at a crossroads," 2025
A later deadline does not close that gap on its own. Article 26 still requires deployers to assign human oversight to a person with the authority to override a system's output. It also requires the AI system's own logs be retained for at least six months. Credit and insurance use cases carry a fundamental rights impact assessment on top of that, under Article 27 (EU AI Act Service Desk, European Commission, 2026).
Financial institutions already subject to EU financial-services governance rules can treat Article 26's monitoring duty as met through those existing arrangements. Human oversight assignment, log retention, and the impact assessment still stand on their own.
KYC and claims automation are not waiting for enforcement dates
Financial firms did not wait for regulatory clarity to automate. Fenergo surveyed 600 senior decision-makers across banks, asset managers, and fund administrators in 2025. Reported use of advanced AI tools in KYC and AML work surged from 42% to 82% in a single year (Fenergo, 2025).
Source: Fenergo, "Global Fincrime Operations Trends in 2025," survey of 600 senior decision-makers, 2025
Even so, automation of periodic KYC reviews still averages roughly a third across respondents, and 70% of firms lost a client to slow onboarding in the past year, up from 48% in 2023. The gap sits between piloting AI and running it with the oversight a regulator will eventually ask to see.
What operational readiness actually requires
On-premise deployment puts the pieces Article 26 asks for inside the institution's own perimeter instead of a vendor's. LLM inference, workflow execution, and the logs each agent generates all run inside infrastructure the compliance team already controls.
Lunnoa records execution history and a dedicated audit trail for every agent action, so a compliance review does not depend on a vendor's retention policy or a SaaS platform's data export limits. Role-based access control assigns the human-oversight authority Article 26 requires to a named reviewer, not a shared account.
None of this waits for December 2027 to matter. The data sovereignty questions a KYC or claims automation vendor gets asked today sit close to the operational questions an AI Act audit will ask tomorrow.
The bottom line
The Digital Omnibus bought financial institutions more runway before Annex III penalties apply, not less work to do before then. Article 50 already applies. Article 26's oversight and logging expectations describe infrastructure, not paperwork, and infrastructure takes longer to build than a deadline takes to move.
Share this article
The EU AI Act's deadline moved to 2027. The work did not.. The EU AI Act's Annex III deadline moved from August 2026 to December 2027, but Article 50 and Article 26 obligations for banks and insurers did not move.Frequently asked questions
No. The delay only moved the Annex III high-risk deadline from August 2026 to December 2027; Article 50 transparency duties already applied from August 2, 2026. Lunnoa's on-premise architecture lets compliance teams build the required audit trail now, instead of waiting for the new deadline to force the work.
Article 50's transparency rules, disclosing AI interaction and labeling AI-generated content, took effect on schedule on August 2, 2026, regardless of the Annex III delay. Lunnoa's execution logs and audit trail give compliance teams the documentation these disclosures require, without adding a separate reporting layer on top of the platform.
Yes. Article 26 requires deployers to retain AI system logs for at least six months and assign oversight to a named reviewer with override authority. Lunnoa keeps execution history and audit trails inside the institution's own environment, so that record never depends on an external vendor's retention policy.
Fenergo found AI use in KYC and AML work jumped from 42% to 82% of firms in a year, well ahead of Annex III's new 2027 date. Lunnoa lets institutions that are already automating build the oversight and logging trail alongside deployment, instead of retrofitting it under deadline pressure later.
Sources
- Pinsent Masons, "Law delaying EU's 'high-risk' AI rules finalised," 2026.
- Sidley Data Matters, "EU Lawmakers Reach Provisional Agreement to Delay Key EU AI Act Obligations," June 22, 2026.
- Cloud Security Alliance, "EU AI Act Article 50: Transparency Obligations Take Effect," 2026.
- EU AI Act Service Desk, European Commission, "Article 26: Obligations of deployers of high-risk AI systems," 2026.
- Deloitte, "AI at a crossroads," 2025.
- Fenergo, "Global Fincrime Operations Trends in 2025," 2025.
Related posts
More on the same topics.
Governance6 min readThe data sovereignty checklist for enterprise AI vendorsIn 2026, 51% of companies rate data sovereignty as very important (BARC). Five architecture questions show whether an AI vendor truly keeps data in-house.
Governance8 min readWhat Is an AI Governance Platform? A 2026 GuideOnly 5% of banks running AI have a scaled, governed program, per Grant Thornton. Learn what an AI governance platform is and how to evaluate one for your firm.
Governance5 min readShadow AI is a governance problem, not a ban listShadow AI use jumped from 15% to 45% of employees in a year, outpacing IT approval. See how Lunnoa lets IT govern agent building instead of banning it.
