AI Governance, Risk & Red Teaming
Aware · M15 · lesson 15 of 18 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
Omnibus VII Transitional Planning - What's Still Due Dec 2, 2026 vs. What Moved to Dec 2, 2027
📖
now learning

Omnibus VII Transitional Planning - What's Still Due Dec 2, 2026 vs. What Moved to Dec 2, 2027

15 min

If the previous lesson is "what the dates are," this lesson is "what you do about them." The Omnibus VII deal of May 7, 2026 did not give you a smaller compliance bill. It gave you a different one, distributed across a different two-year window, with the most painful items either unchanged or accelerated. The Responsible AI Officer who walks into the Q2 2026 Audit Committee with a re-baselined two-year roadmap, a defensible budget memo for the CFO, a portfolio-level "what slipped, what didn't, what accelerated" table, and a notified-body engagement schedule that doesn't collide with the Dec 2, 2027 capacity wall is the one who keeps their seat at the table. This lesson is how you write all four documents in an afternoon.

The Twenty-System Walk-Through - Building the Transition Memo

Start with a representative twenty-system portfolio because that's what most Fortune 1000 enterprises actually have on their roster. Each row carries a tier, an applicability anchor, a 2026 plan, a 2027 plan, and an explicit budget number. The walk-through below is the structure your transition memo follows for whatever your real portfolio looks like.

Rows 1-6: Annex III Stand-Alone Systems

Six rows for the high-risk Annex III systems that slipped from Aug 2, 2026 to Dec 2, 2027. Typical inventory:

  • Row 1, Annex III §4 employment screening tool (Workday Talent Acquisition). Original deadline Aug 2, 2026; post-Omnibus Dec 2, 2027. FY26 plan: complete the Article 27 FRIA, draft the Annex IV technical file v0.5, identify the notified body, complete the vendor Annex XII receivable review, run the bias audit (NYC LL 144 overlay). FY27 plan: finalize Annex IV file v1.0, notified-body Module H engagement Q1 2027, Article 47 declaration signed Q4 2027.
  • Row 2, Annex III §5(b) creditworthiness scoring (in-house XGBoost). FRIA capability stays on the Aug 2, 2026 track because §5(b) deployers face FRIA obligations regardless of stand-alone Annex III timing. FY26 plan: complete the FRIA, build the explanation pathway under Article 86, finalize the model card. FY27 plan: Annex IV file completion, notified-body engagement, Article 71 EU database registration.
  • Row 3, Annex III §5(c) life insurance pricing tool. Same FRIA-on-the-Aug-2026-track logic as Row 2. FY26 plan: FRIA + Article 86 explanation + ECOA / state-insurance overlay review. FY27 plan: Annex IV + notified body + Article 71.
  • Row 4, Annex III §3 education proctoring tool. Original Aug 2, 2026; post-Omnibus Dec 2, 2027. FY26 plan: scope confirmation, Article 6(3) carve-out analysis (likely doesn't apply because of profiling), FRIA preparation. FY27 plan: full conformity package.
  • Row 5, Annex III §2 critical-infrastructure AI for grid load balancing (safety component). Original Aug 2, 2026; post-Omnibus Dec 2, 2027. FY26 plan: harmonization-standard mapping, risk-management system per Article 9, hazard analysis. FY27 plan: full conformity package.
  • Row 6, Annex III §1 biometric ID system for facility access. Original Aug 2, 2026; post-Omnibus Dec 2, 2027. Notified-body required under Annex VII Module H. FY26 plan: notified-body identification and pre-engagement, GDPR Article 35 DPIA + Article 27 FRIA combined template, accuracy benchmarking. FY27 plan: Module H assessment Q2 2027, Article 47 declaration Q3 2027.

Rows 7-12: GPAI Deployer Overlay Systems

Six rows for systems built on foundation models that need GPAI exposure-map work for Aug 2, 2026 enforcement readiness, regardless of any downstream Annex III tier slip.

  • Row 7, Internal coding assistant on GitHub Copilot Enterprise. Article 26 deployer + Article 4 literacy on Aug 2, 2026 track. GPAI exposure map row: OpenAI signatory; Annex XII received. FY26 plan: literacy curriculum for engineering org, Article 26 monitoring runbook. FY27 plan: refresh on Copilot version upgrades.
  • Row 8, Customer-service chatbot on Anthropic Claude. Article 50(1) disclosure on Aug 2, 2026 track; Article 26 deployer obligations. FY26 plan: disclosure copy implemented, deployer monitoring runbook, agent-tool red-team coverage. FY27 plan: refresh.
  • Row 9, Marketing-content generator (mix of OpenAI + Adobe Firefly). Article 50(2) machine-readable marking on Dec 2, 2026 track (accelerated). FY26 plan: C2PA / SynthID / IPTC integration; procurement contract amendments; marking-failure incident handling. FY27 plan: refresh on tool version upgrades.
  • Row 10, Generative video for product demos (Sora / Runway). Article 50(2) + Article 50(4) deepfake disclosure on Dec 2, 2026 track. FY26 plan: marking + disclosure copy + provenance documentation. FY27 plan: refresh.
  • Row 11, Open-weight Llama 3.1-405B fine-tuned in-house for internal IT-helpdesk agent. Meta is GPAI non-signatory; Annex XI / XII receivables limited. Article 25 transfer-of-obligations on fine-tuning. FY26 plan: confirm Annex XI / XII status, complete Article 53(1)(d) public training-data summary review on Meta side and own-fine-tune side, vendor-contract amendments to fill non-signatory gap, deployer-side mitigation work. FY27 plan: refresh on Meta releases.
  • Row 12, Voice agent for customer-experience metrics (ElevenLabs synthetic voice). Article 50(2) marking on Dec 2, 2026 track; potential Article 5(1)(f) review if applied to employee calls (must avoid). FY26 plan: scope confirmation, marking integration, internal use-case restrictions. FY27 plan: refresh.

Rows 13-16: Minimal-Risk Systems with Article 4 / Article 5 Overlays

  • Row 13, Power BI Smart Insights dashboards. Minimal-risk. Article 4 literacy for power-user population. FY26 plan: literacy module for finance / operations users. FY27 plan: quarterly refresh.
  • Row 14, K-means marketing segmentation. Minimal-risk. Article 4 literacy. Article 5 negative-assurance review (especially Article 5(1)(g) re protected-attribute deduction). FY26 plan: attestation, literacy. FY27 plan: refresh on use-case expansion.
  • Row 15, Sales-call sentiment-analysis tool (CRM-bundled). Article 5(1)(f) workplace emotion-recognition review: if used on employees, prohibited; if used on customers, Article 50(3) limited. FY26 plan: scope confirmation, use-case restriction, disclosure copy if Article 50(3) triggered. FY27 plan: refresh.
  • Row 16, Email spam filter (Naive Bayes legacy). Minimal-risk. Legacy carve-out applies (placed pre-2025; no substantial modification). FY26 plan: substantial-modification gate review. FY27 plan: refresh.

Rows 17-20: Annex I Embedded-Product Systems

  • Row 17, Medical-device AI for diagnostic-image triage (CE-marked under MDR). Original Aug 2, 2027; post-Omnibus Aug 2, 2028. FY26 plan: MDR + AI Act integrated conformity-assessment scoping; risk-management system per Article 9 + ISO 14971 alignment; notified-body relationship continuation. FY27 plan: technical-file development; integrated CE-marking workflow rehearsal. FY28 plan: full Annex IV completion + integrated declaration.
  • Row 18, In-vitro diagnostic AI (IVDR). Original Aug 2, 2027; post-Omnibus Aug 2, 2028. Same MDR/IVDR integration logic.
  • Row 19, Industrial machinery AI (vibration anomaly detection on assembly-line equipment, Machinery Directive). Original Aug 2, 2027; post-Omnibus Aug 2, 2028. FY26 plan: Machinery Directive + AI Act integration scoping. FY27 plan: technical file. FY28 plan: full integrated declaration.
  • Row 20, Pressure-equipment monitoring AI (Pressure Equipment Directive). Original Aug 2, 2027; post-Omnibus Aug 2, 2028. Same integration logic.

The "What Accelerates, What Slips, What Stays" Roll-Up

After the row-by-row walk-through, the CFO-facing roll-up is a single page. It has three columns and is the entire reason the transition memo exists:

What Accelerates Under Omnibus VII (FY26 SPEND UP vs. Original Plan)

  • Article 50(2) machine-readable marking, Grace period cut. Now Dec 2, 2026 instead of mid-2027. Procurement contract amendments for every generative-content vendor (Adobe Firefly, Midjourney, DALL-E, Sora, Runway, Pika, ElevenLabs, Suno) need C2PA / SynthID / IPTC marking commitments locked in by end of Q3 2026. Technical-integration work in Q3-Q4 2026.
  • Article 50(4) deepfake disclosure, Same Dec 2, 2026 date alongside Article 50(2). Customer-facing disclosure copy for any generative-image/audio/video output of natural persons.
  • GPAI enforcement readiness, Aug 2, 2026 unchanged. The Annex XI / XII receivable closure with non-signatory vendors (Meta, DeepSeek, Alibaba, Baidu) becomes more urgent because the enforcement track is shorter than the program had absorbed.

What Stays on the Aug 2, 2026 Track (FY26 SPEND UNCHANGED vs. Original Plan)

  • Article 73 serious-incident reporting infrastructure: Reporting machinery, 10/2/15-day clock runbook, market-surveillance-authority contact, incident-classification decision tree, legal-counsel routing, retention discipline.
  • Article 27 FRIA capability for public-body deployers, private operators providing public services, and Annex III §5(b) creditworthiness / §5(c) life/health insurance deployers.
  • National competent authority designation, Member State completion expected by Aug 2, 2026.
  • Notified-body designation regime under Article 31, Notified-body capacity ramp targeting Aug 2, 2026.
  • Article 5 negative-assurance review, Already overdue in May 2026 if not yet performed.
  • Article 4 AI literacy, Already operational. Refresh cadence continues.
  • Article 53 GPAI obligations on every foundation-model provider: Operational from Aug 2, 2025; enforcement Aug 2, 2026.

What Slips to 2027-2028 (FY26 SPEND DOWN, FY27 SPEND UP)

  • Stand-alone Annex III high-risk obligations moved from Aug 2, 2026 to Dec 2, 2027 - Articles 9 (RMS), 10 (data governance), 11 + Annex IV (technical file), 13 (transparency to deployers), 14 (human oversight), 15 (robustness/cybersecurity), 16 (provider), 17 (QMS), 26 (deployer), 43 (conformity assessment), 47 (declaration), 71 (EU database registration), 72 (post-market monitoring).
  • Annex I embedded-product obligations moved from Aug 2, 2027 to Aug 2, 2028, same obligation set integrated with the harmonized-product CE-marking workflow.
  • Notified-body engagement scheduling shifts to align with the Dec 2, 2027 (Annex III) and Aug 2, 2028 (Annex I) demand peaks. Early engagement still wins slots; deferral risks the late-2027 capacity wall.

The CFO Budget Memo - Two Pages, Three Asks

The CFO asks two questions when the AI Officer walks in with a re-baselined roadmap: "How much do I save in FY26?" and "How much will FY27 cost me that I didn't expect?" The defensible answer:

FY26 (calendar year 2026), no net reduction. The Aug 2, 2026 obligations are unchanged and consume the original FY26 budget. The Dec 2, 2026 Article 50(2)/50(4) acceleration adds procurement and integration costs. The Dec 2, 2027 Annex III runway begins now to avoid the late-2027 capacity wall. Net: FY26 budget unchanged or marginally up. Cutting FY26 means missing Aug 2, 2026 readiness on GPAI / Article 73 / FRIA, missing Dec 2, 2026 acceleration on Article 50(2), and arriving at Q4 2027 unprepared for the notified-body capacity squeeze.

FY27 (calendar year 2027), runway-shaped spend. Q1-Q2 2027: technical-file completion across the Annex III portfolio (rows 1, 4, 5, 6 in the walk-through); notified-body engagement scheduling. Q3 2027 - Module H assessments, Annex IV file v1.0 finalization, Article 47 declarations. Q4 2027 - Article 71 EU database registration, CE marking, deployer-side Article 26 readiness, customer notifications. Annex I work (rows 17-20) sequences into 2027-2028 alongside MDR / IVDR / Machinery Directive integration.

FY28 (calendar year 2028), integrated CE-marking workflow. Q1-Q3 2028, completion of Annex I embedded-product conformity work for rows 17-20. Q3 2028 - Annex I applicability date. Q4 2028, post-market monitoring at scale across both Annex III and Annex I portfolios.

The three CFO asks:

  1. Preserve FY26 budget at original level. The Aug 2, 2026 and Dec 2, 2026 obligations consume the original spend. Cutting it creates Article 99 exposure.
  2. Pre-commit notified-body engagement spending in 2026 for the 2027 Annex III work. Notified bodies bill on engagement, not on assessment completion. Locking in slots requires deposit in 2026.
  3. Approve modest FY27 increase, 15-25% over the originally-planned FY26 figure, to cover the runway-shaped Annex III completion work. The increase is partial offset of the FY27 cost spike that the original Aug 2, 2026 timeline would have created in late 2026.

The Audit Committee Narrative - Three Slides

For the Q2 2026 Audit Committee, the narrative is on three slides:

Slide 1 - What Changed Under Omnibus VII (What We Know)

  • Three dates moved (Annex III to Dec 2, 2027; Annex I to Aug 2, 2028; Article 50(2)/(4) accelerated to Dec 2, 2026).
  • Six dates did not move (Article 5 / Article 4 / Article 53 / Article 99 / Article 73 / FRIA capability / GPAI enforcement / national authority designation / notified-body designation).
  • Omnibus VII publication still pending; original Annex III date legally remains operative until publication; dual-timeline planning posture in place.

Slide 2 - Our Portfolio (What This Means For Us)

  • Portfolio summary: 20 systems, six Annex III high-risk (rows 1-6), six GPAI deployer overlay (rows 7-12), four minimal-risk-with-overlays (rows 13-16), four Annex I embedded products (rows 17-20).
  • Aug 2, 2026 still-applies readiness state per row: green / yellow / red status indicators on GPAI exposure-map closure, Article 73 reporting infrastructure operational state, FRIA capability for §5(b)/§5(c) and public-body deployers, Article 5 negative-assurance attestation completion, Article 4 literacy coverage.
  • Dec 2, 2026 acceleration impact: rows 9, 10, 12 affected by Article 50(2)/(4); procurement contract amendment status; technical-integration milestone state.
  • Dec 2, 2027 runway: rows 1-6 plan with FY26 / FY27 milestones named; notified-body engagement status; budget commitment posture.

Slide 3 - Article 99 Worst-Case Exposure

  • Aggregate Article 99 worst-case quantification: prohibited (Article 99(2) €35M / 7%), most provider failures (Article 99(3) €15M / 3%), specific operator/notified-body failures (Article 99(4) €15M / 3%), misleading information (Article 99(5) €7.5M / 1%).
  • For a €10B global-turnover entity: Article 5 worst-case €700M; Article 16 / 73 / 27 worst-case €300M; misleading-information worst-case €100M.
  • Per-row exposure mapping in appendix; aggregate dashboard front and center.

Three slides. Five-minute brief. The audit committee leaves with the post-Omnibus picture and the operational plan to address it. The CFO has the budget defense. The General Counsel has the regulator-readiness narrative. The Chief Information Security Officer has the synchronization between AI Act work and the existing ISO 42001 / SOC 2 / NIST AI RMF programs.

The Cross-Walk Overlay - Mapping Transition Work Onto the Full Stack

The cross-walk pattern from Lesson 004 applies to the transition memo as well. Every row in the twenty-system walk-through maps to the same five-framework citation set:

  • EU AI Act articles (the binding regulation)
  • NIST AI RMF functions and categories (U.S. consensus / customer assurance)
  • NIST AI 600-1 GenAI Profile actions (for generative components)
  • ISO/IEC 42001 Annex A controls (audit-defensible spine)
  • OWASP LLM Top 10 / Agentic Top 10 and MITRE ATLAS v5.4.0 (security coverage)

The transition memo can be presented to an ISO 42001 auditor as evidence of operating the AIMS (the "performance evaluation" clause in ISO 42001 expects management review of the AI program's regulatory environment); to a SOC 2 + AI assessor as evidence of operating the Trust Services Criteria; to an internal-audit team as evidence of risk assessment refresh; to a notified body as the rationale behind the FY26 / FY27 Annex IV development sequence. One artifact, five audiences.

The Non-Signatory Acceleration Trap

The non-signatory GPAI providers in your stack, Meta, DeepSeek, Alibaba, Baidu, and any other Chinese-origin or non-Code-of-Practice provider, present a sharper transition risk than the Code signatories. Three reasons:

  1. Aug 2, 2026 enforcement is closer than the Annex III Dec 2, 2027 date. Non-signatory GPAI providers face Article 53 enforcement starting Aug 2, 2026. Their Annex XI / XII / copyright / public training-data summary receivables must be locked in well before then. Your deployer-side downstream evidence depends on those receivables.
  2. The Code-signatory presumption pathway is unavailable. Non-signatory providers cannot point to the Code of Practice as evidence of compliance with Articles 53 and 55. They must produce direct evidence to authorities. Your contractual flow-down language has to demand it.
  3. Annex XIII discretionary designation risk is higher for non-signatories. The Commission's first Article 51(1)(b) designation actions are expected in H2 2026. Non-signatory providers with EU business-user reach approaching the 10,000-threshold criterion are designation candidates. A designation event mid-procurement creates contract-renegotiation pressure.

The transition memo should highlight non-signatory rows in red. Procurement should treat non-signatory contracts as priority items for FY26 amendment. The audit committee should see the non-signatory exposure as a separate line item, with the FY26 deployer-side mitigation work documented.

Legacy and Substantial Modification Discipline - The Carve-Out Preservation Plan

The legacy carve-out for systems placed on the market before the applicability dates is one of the few areas where prudent transition planning saves real money. The carve-out narrows on substantial modification under Article 43(4), so preserving it requires discipline. The transition memo should include a fourth section after rows / accelerates / slips: a legacy-system change-control register. Each legacy row carries a "placement date," a "current modification status," a "scheduled changes" column (vendor model updates, retraining, scope expansion, language addition, threshold adjustment, foundation-model swap), and a "carve-out durability assessment" (green / yellow / red).

Red rows, legacy systems with scheduled substantial modifications, should be re-baselined into the post-modification timeline. The change is the trigger; the carve-out collapses with the change; the obligation set becomes the post-modification obligation set. This is not a loss of legacy treatment in a bad sense; it is a planned migration into the future obligation set with the FY27 / FY28 budget that the migration requires.

Green rows, stable legacy systems with no planned substantial modifications, preserve the carve-out and the budget savings. The discipline is to not break the carve-out accidentally with a routine vendor patch that turns out to be substantial. Procurement and operations teams need to route any vendor update through the change-control gate.

Key Takeaways

  • Transition planning is not "cutting 2026 spend." The Aug 2, 2026 obligations are unchanged; the Dec 2, 2026 obligations accelerated. The Annex III date slip is matched by a notified-body capacity squeeze in late 2027. FY26 budget stays largely at original level.
  • The twenty-system walk-through is the operational artifact. Each row with tier, applicability anchor, FY26 plan, FY27 plan, FY28 plan (where applicable), and a budget number per phase.
  • Three columns to roll up: what accelerates, what stays, what slips. Article 50(2)/(4) accelerated. Article 5 / 4 / 53 / 99 / 73 / FRIA / GPAI enforcement / national authority / notified-body designation unchanged. Annex III stand-alone slipped to Dec 2, 2027. Annex I slipped to Aug 2, 2028.
  • The CFO memo has three asks. Preserve FY26 budget, pre-commit notified-body engagement, approve modest FY27 increase. Defensible against any cost-cutting pressure.
  • The audit committee narrative is three slides. What changed under Omnibus VII; our portfolio impact; Article 99 worst-case exposure. Five-minute brief.
  • Non-signatory GPAI providers carry sharper transition risk. Aug 2, 2026 enforcement is closer than Dec 2, 2027 Annex III. Their Annex XI / XII receivables and contractual flow-down need priority. Annex XIII designation risk in H2 2026.
  • Legacy-system change-control discipline preserves real budget savings. Article 43(4) substantial modification collapses the carve-out. Plan migration into post-modification obligations rather than break the carve-out accidentally.
  • Dual-timeline planning is the prudent posture until Omnibus VII publication. Conservative-date anchor for hard-to-reverse work; post-Omnibus dates for budget planning.
  • The transition memo cross-walks the same five frameworks. EU AI Act + NIST AI RMF + NIST AI 600-1 + ISO 42001 + OWASP/ATLAS. One artifact, five audiences.
  • Notified-body capacity is the long-pole. Engage early. The Dec 2, 2027 stand-alone Annex III date concentrates demand on a small supply of designated bodies. Pre-commitment in 2026 wins slots that 2027 deferrers will not have.