Skip to content
New: ask the Rexfin Analyst Agent about your model. Every figure comes back cited.
· 9 min read

The Digital Omnibus Moved Your AI Deadline. It Did Not Move the Work

The EU pushed high-risk AI duties to December 2027, but GPAI enforcement and the AI literacy rule land in August 2026. Why CFOs who wait still lose.

The EU pushed high-risk AI duties to December 2027, but GPAI enforcement and the AI literacy rule land in August 2026. Why CFOs who wait still lose.

By The Rexfin team

The headline most finance leaders read in late 2025 was simple: the EU is delaying the AI Act. The number that stuck was 2027. And in a lot of boardrooms, that single number quietly became permission to stop.

That reading is wrong in a way that will cost money.

The Digital Omnibus, the simplification package EU legislators agreed on in May 2026, does push the application date for stand-alone high-risk systems under Annex III to 2 December 2027, with AI embedded in regulated products under Annex I sliding to 2 August 2028. Those are real extensions. But the package leaves a second timeline almost untouched, and that second timeline is the one that actually reaches your accounting close. Two dates matter far more than December 2027 if you run a finance function: the general-purpose AI rules already enforceable from 2 August 2025, and the supervision-and-enforcement layer that national market surveillance authorities begin applying around 2 August 2026.

So the deadline that moved is not the deadline that binds you first.

What actually got delayed, and what did not

Let me separate the two piles cleanly, because the press coverage blurred them.

Delayed. High-risk obligations for Annex III systems, the conformity assessments, the formal risk-management documentation, the registration steps. If you build or operate a system the Act classifies as high-risk, the compliance machinery around it has roughly an extra year. The Council and Parliament confirmed this in their May 2026 agreement.

Not delayed. The prohibited-practices rules have applied since 2 February 2025. The GPAI model obligations under Articles 51 to 55 have applied since 2 August 2025, and the Omnibus does not touch them. The AI literacy obligation, Article 4, entered application on 2 February 2025 and remains in force; the Omnibus proposes to reshape how it is promoted, not to switch it off. And the enforcement apparatus, the national authorities with the power to ask questions and impose penalties, comes online around 2 August 2026.

That last point is the one CFOs keep missing. A duty without enforcement feels theoretical. A duty with a supervising authority and a penalty regime is a board-level risk. The Omnibus did not delay the arrival of the people who can knock on the door.

Here is the uncomfortable detail. Almost every finance AI tool a mid-market company actually uses, the assistant that drafts a variance commentary, the chatbot over your management accounts, the copilot in your planning suite, sits on top of a general-purpose model. Those are precisely the obligations that did not slip. You may not operate a high-risk system at all. You almost certainly touch GPAI every week.

Why the extension is a trap if you treat it as a pause

Say you accept all of that and still decide to wait until 2027. The problem is not legal. The problem is that the binding constraint on trustworthy finance AI was never the compliance paperwork. It was the data.

An auditor under IDW PS 861 does not reject an AI-assisted figure because you missed a 2027 filing. They reject it because they cannot trace the number back to a ledger entry and reproduce it. The German GoBD framework does not care about the Omnibus calendar; it cares whether your records, including AI-produced results, are complete, accurate, and machine-evaluable. Article 14 of the Act asks for meaningful human oversight, which is impossible if the human cannot see what the machine actually did.

None of that gets easier in December 2027. Every one of those requirements assumes something most finance stacks do not yet have: a single, reconciled financial model that ties out to the books, and a record of exactly which figure the AI used and how it computed the answer.

That foundation takes months to build properly. Reconciling a chart of accounts across QuickBooks, Xero, NetSuite, Sage, and a warehouse, then proving the consolidated model agrees with each underlying ledger, is not a thing you stand up in the quarter before an audit. If you spend 2026 waiting, you arrive at the real deadline with the same broken inputs and less runway. The extension does not buy you preparation time unless you actually use it to prepare.

The mechanism that survives every version of the timeline

Strip away the regulatory specifics and the underlying demand from every authority is the same: show the number, show where it came from, show how it was derived, and let a human check it. Build for that, and the precise enforcement date stops being existential.

This is where the architecture matters more than the calendar. The common failure is letting the language model itself produce the figures, where it pattern-matches a plausible-looking number with no link to the ledger and no reproducible math. That is the exact thing GoBD, PS 861, and Article 14 are built to catch.

The alternative is to separate retrieval and computation from generation. Rexfin connects your accounting platforms or uploaded statements and builds one reconciled financial model, a single source of truth that ties out to the ledger. The AI retrieves figures from that model rather than recalling them. Calculations run through a deterministic engine, not the model, so the same question yields the same answer every time and every result traces to its source. That is what makes human oversight real instead of ceremonial: the reviewer sees the source figure, the calculation path, and the output side by side.

We will not pretend this resolves your entire Act exposure. Classification, registration, the governance documentation for any genuinely high-risk system, those remain your obligations and your counsel’s call. What a traceable model layer removes is the part most likely to fail an audit and the part that takes longest to fix: the absence of a defensible, reproducible number underneath the AI.

What to do in 2026, concretely

Stop reading 2027 as a finish line. Use the months the Omnibus gave you for the work that has no shortcut.

First, find out whether any tool you run is actually high-risk, or whether your real exposure is GPAI and Article 4, the two timelines that did not move. Most finance teams discover it is the latter. Second, address the AI literacy obligation now; it is in force, it is cheap to satisfy, and it is exactly the kind of low-effort gap an early enforcement action will flag. Third, and this is the long pole, build the reconciled, audit-ready data foundation that every framework assumes you already have. That is the difference between an extension that helps you and one that just delays the moment you get caught short.

The Digital Omnibus moved a deadline. It did not move the audit, the auditor, or the math. If you want to see what a number that survives all three looks like, book a demo and bring your hardest reconciliation.

Part of AI in Finance, Audit-Proof: GoBD- and AI-Act-Defensible Models With Traceable Numbers

Keep reading

Book a demo

See your numbers tie out.

Book a 30-minute demo. Bring a question you can never answer fast enough, and we will model it live against real financial data.