A record of 28 April 2026. Since this issue went out, the Digital Omnibus reached political agreement on 7 May 2026 and entered into force on 27 July 2026 as Regulation (EU) 2026/1744. Annex III now applies from 2 December 2027 and Annex I from 2 August 2028. The Omnibus tracker holds the current position.
Corrected 1 October 2026. The descriptions of the HSB, Armilla and Testudo products and of Italy's AI law have been brought into line with the issuers' own publications. A paragraph naming supervisory designations in four Member States, and a story on two US court decisions, rested on details we could not confirm at source and are withdrawn. The corrections log sets out each change.
- The Digital Omnibus proposed moving Annex III high-risk obligations to 2 December 2027. It had not been adopted, and the 2 August 2026 date remained binding until it was.
- Article 5 prohibitions, Article 50 transparency and the GPAI obligations under Articles 53 and 55 sat outside the deferral.
- HSB, Armilla with Chaucer, and Testudo all moved on AI liability cover in the first quarter of 2026. Underwriting was not following the regulatory calendar.
- Member States were implementing on their own schedules. Italy's AI law had been in force since 10 October 2025, and Germany's KI-MIG was still a draft.
The Digital Omnibus delay, precisely stated
The Commission's Digital Omnibus package was in the final stage of negotiation between Council and Parliament. Its central AI Act amendment proposed extending the application date for the Annex III high-risk operator obligations from 2 August 2026 to 2 December 2027, a sixteen month extension for deployers who had not yet completed their operator file.
Council and Parliament had converged on the 2 December 2027 date. That convergence was a strong signal of adoption. It was not adoption. Until the amending regulation was published in the Official Journal, the original application dates in Regulation (EU) 2024/1689 remained in full legal force.
A deployer who treated the convergence as an extension and halted compliance work was taking a legal risk that nothing in the Omnibus would compensate. The practical course was direct: keep building the operator file at the pace the original date required. If the extension arrived first, the file would already be complete, which is the right posture whatever the deadline.
What to do. Track the Omnibus closely. Do not pause compliance work. Build the operator file to the August 2026 standard, and treat an adopted extension as time gained, never as a reason to stop.
Source: European Commission, Digital Omnibus on AI, COM(2025) 836. Regulation (EU) 2024/1689, Article 113. The 100 day operator checklist.
What stayed mandatory on 2 August 2026
Three categories of obligation sat outside the Omnibus deferral, and a fourth instrument outside the AI Act altogether. Knowing what was not being delayed mattered as much as knowing what was.
Article 5 of Regulation (EU) 2024/1689 prohibits certain AI practices outright, among them biometric categorisation that infers protected characteristics, social scoring by public authorities, real-time remote biometric identification in publicly accessible spaces for law enforcement outside narrow exceptions, and systems that exploit vulnerabilities to distort behaviour. These prohibitions have applied since 2 February 2025. Deployers running systems near these categories were already inside the enforcement window.
Article 50 sets transparency obligations for AI systems that interact with natural persons or generate synthetic content, applying from 2 August 2026. Systems that interact with users through chat, voice or generated content without the Article 50 disclosures would be in breach from that date, whatever happened to Annex III.
Articles 53 and 55 set obligations for providers of general purpose AI models: technical documentation, cooperation with the AI Office and, for models with systemic risk, adversarial testing and serious incident reporting. They had applied since 2 August 2025, nine months before this issue.
The revised Product Liability Directive, Directive (EU) 2024/2853, is a separate instrument with a transposition deadline of 9 December 2026. It applies to AI software as a product, extends liability across the supply chain, and gives claimants a disclosure mechanism for technical documentation held by manufacturers. The Omnibus did not touch it.
What to do. Build the operator file regardless of the Annex III debate. Audit Article 50 disclosures in every AI facing product. Confirm GPAI compliance where a foundation model is deployed or embedded. Have counsel map the transposition of the Directive in every Member State of operation.
Source: Regulation (EU) 2024/1689, Articles 5, 50, 53, 55 and 113. Directive (EU) 2024/2853, Article 22(1). EUR-Lex: Regulation 2024/1689.
The insurance market did not wait for the Omnibus
Three named developments in the first quarter of 2026 showed the market for AI liability cover moving on its own clock. Each matters both to operators looking for cover and to brokers advising on placement.
On 18 March 2026, HSB introduced AI Liability Insurance for small and mid-sized businesses. It covers bodily injury, property damage, and personal and advertising injury arising from the insured's use of AI, with standard limits of USD 25,000 or USD 50,000, a USD 500 deductible and higher limits available. It is added to partner carriers' business policies rather than sold direct, and is subject to insurance regulatory approval.
On 10 February 2026, Armilla and Chaucer launched Vanguard AI, a coordinated cyber, technology and AI liability structure backed by Lloyd's of London. Armilla Insurance Services is a Coverholder at Lloyd's, and its Standalone AI Liability Policy carries limits of up to USD 25 million per organisation. Its cover extends to AI regulatory violations, including defence costs and insurable fines under the EU AI Act.
Testudo, a Lloyd's coverholder for US enterprises, launched on 21 January 2026 with limits of USD 1 million to 10 million. On 26 February 2026 Atrium and QBE joined Apollo on its capacity, which reached USD 9.25 million per insured.
The pattern across all three was consistent: underwriters were developing products and deploying capacity faster than the regulatory calendar moved. For brokers, it meant clients seeking AI specific cover in the second half of 2026 would meet underwriters already asking how the AI is governed, and treating missing documentation as an adverse factor.
What to do. Go into renewal with a documented compliance position, not a summary of intentions. Brokers advising technology clients should check whether current placements include AI specific terms, or rely on general liability wordings that may restrict AI claims through exclusion endorsements.
Source: HSB press release, 18 March 2026. Chaucer, Vanguard AI, 10 February 2026. Armilla, AI liability insurance. Testudo and Atrium, 21 January and 26 February 2026. AI policy exclusions.
Member State implementation on its own schedule
The Omnibus debate ran against a background of national implementation moving independently. Operators watching only the Regulation's dates were missing a layer of procedure that was already taking shape.
Italy's Legge 23 settembre 2025, n. 132 was published in the Gazzetta Ufficiale, Serie Generale n. 223 of 25 September 2025, and has been in force since 10 October 2025. It designates AgID as the notifying authority and ACN as the market surveillance authority and single point of contact, and keeps Banca d'Italia, CONSOB and IVASS as market surveillance authorities for the financial sector. Article 3(5) states that the law creates no obligations beyond those of Regulation (EU) 2024/1689.
Germany had published a draft of its KI-MIG, the Gesetz zur Marktueberwachung und Innovationsfoerderung von kuenstlicher Intelligenz, naming the Bundesnetzagentur as the market surveillance authority. It was not yet enacted when this issue went out. It has been in force since 29 July 2026.
For cross border deployers, the relevance is procedural. Enforcement is national, and each Member State's procedure shapes how investigations open, how documentation is requested and how penalties are set. A deployer compliant with the Regulation still needs to know which authority will knock, and under which national rules.
What to do. Map the designated authorities and the state of implementing legislation in every Member State where high-risk systems are deployed. Instruct local counsel where national acts are in force or close to it.
Source: Legge 23 settembre 2025, n. 132, Articles 3 and 20, at normattiva.it. Bundesnetzagentur. Member State implementation tracker.
Closing note
The Digital Omnibus, once adopted, would give much of the European operator market more time. A programme that produced a complete operator file by July 2026 would still stand stronger with underwriters, national supervisors and clients than one that treated a proposed extension as a reason to pause. The developments in this issue shared one thread: the legal and insurance environment around AI liability was moving on its own momentum, and the regulatory calendar was one input among several.
Related reading
- The Digital Omnibus in force: what changed for deployers
- Article 27 FRIA: the deployer guide
- AI policy exclusions: what your coverage excludes
- Member State implementation tracker
- Article 50 transparency: the deployer guide
- EIOPA's AI governance Opinion and the AI Act
- The liability framework
- The Act, read in plain sequence
The briefing is editorially independent. Future Proof Intelligence receives no payment from carriers, vendors or regulators for coverage. Carrier and product references rest on the issuers' own public announcements. Nothing here is legal, financial or regulatory advice. Editorial standards are at agentliability.eu/editorial-standards.