The line the Omnibus moved quietly
Almost every summary of Regulation (EU) 2026/1744 leads with the same fact: the high-risk obligations in Chapter III now apply from 2 December 2027 rather than 2 August 2026. Fewer noticed that the Omnibus also rewrote Article 111(2) of Regulation (EU) 2024/1689, replacing its fixed cut-off date with a reference to the date Chapter III applies. The grandfathering line moved with the deadline, and for a business already running AI that is the more valuable of the two changes.
What does Article 111(2) say now?
As amended, the Regulation applies to operators of high-risk AI systems placed on the market or put into service before the date of application of Chapter III only if, from that date, those systems are subject to significant changes in their designs. A system already on the market before 2 December 2027, or 2 August 2028 for AI inside regulated products, therefore sits outside the high-risk regime for as long as its design stays where it is.
There is one hard backstop. Providers and deployers of high-risk systems intended to be used by public authorities must comply by 2 August 2030 whatever else happens.
Which systems does it not save?
The exemption is narrower than it first looks. Article 111(2) opens with a carve-out for Article 5, so the prohibitions bind a legacy system exactly as they bind a new one. The Article 50 transparency duties attach to what a system does rather than to its risk class, so a chatbot built in 2024 owes disclosure today. The Omnibus added a new Article 111(4) for the sharpest edge of that: providers of systems generating synthetic audio, image, video or text placed on the market before 2 August 2026 have until 2 December 2026 to meet the marking duty in Article 50(2).
Two other timetables sit outside the general rule. AI inside the large-scale IT systems listed in Annex X has until 31 December 2030, and general-purpose AI models placed on the market before 2 August 2025 until 2 August 2027.
What counts as a significant change in design?
The phrase is not separately defined, but recital 177 says it should be understood as equivalent in substance to a substantial modification. Article 3(23) defines that as a change not foreseen in the initial conformity assessment which either affects compliance with the Chapter III requirements or modifies the intended purpose. That is the test to work with, and it is close to the trigger in Article 25(1)(b) that turns a deployer into a provider.
One wrinkle deserves attention. The Omnibus removed the words “or intended purpose” from Article 111(2) itself, so the operative text now speaks only of design while recital 177 still speaks of both. Our reading is that little turns on it, because Article 3(23) folds intended purpose into the modification test anyway. On that basis, retraining on materially different data or giving a system a new intended purpose is significant; a security patch or a version number is not. Recital 39 of the Omnibus adds that the grace period runs at the level of a type and model rather than each unit, so further units of a model lawfully placed on the market before the cut-off can continue to be supplied while the design is unchanged.
Praktiskt exempel
A Malmö software company has sold a workforce scheduling tool since 2024. One feature ranks staff for shift allocation, which points to Annex III, point 4(b), on allocating tasks based on individual behaviour or personal traits. Under the original timetable the company faced conformity assessment, technical documentation and registration by 2 August 2026, and it had budgeted for exactly that.
After the Omnibus, the version on the market before 2 December 2027 falls outside Chapter III entirely. The catch is the roadmap. A planned 2028 release retrains the ranking model on three years of new data and adds absence prediction, which modifies the intended purpose. On the Article 3(23) test that recital 177 imports, that is a significant change, and it drags the product into the full high-risk regime on the day it ships, with no runway left.
Vanliga misstag som företag gör
The first is reading Article 111 as a permanent exemption. It lasts precisely as long as the design does, and product teams change designs continuously.
The second is assuming it covers the whole Regulation. Article 5, Article 50 and the AI literacy duty in Article 4 all sit outside it, and so does the GDPR, which never stopped applying.
The third is having no record of when a system was placed on the market or put into service. Article 111 is an evidential argument before it is a legal one, and a company that cannot date its own deployments cannot run it.
The fourth is letting the exemption become a reason to leave a system alone. A model that must not be retrained in order to stay exempt is a model quietly getting worse, and that is a commercial and a discrimination problem long before it is an AI Act problem.
Rekommenderade åtgärder
Start by dating every AI system you run, with evidence of when it was placed on the market or put into service, because that date is what the whole argument rests on. Record the design as it stands now in enough detail that you could later show what did and did not change, including the training data, the intended purpose and the model version.
Put a gate in your change control that asks, before any material release, whether the change is significant in design, and have that question answered by someone who can say no. If you supply the public sector, plan against 2 August 2030 rather than the general rule. And if you generate synthetic content with anything that was on the market before 2 August 2026, get the machine-readable marking done before 2 December 2026.
Vanliga frågor
Does Article 111 mean we never have to comply?
No. It suspends the Chapter III obligations for a system whose design does not significantly change after the applicable date. The moment you make a significant design change, the full high-risk regime applies to that system immediately, without any transitional runway.
Does selling more units of the same product restart the clock?
No. Recital 39 of the Omnibus confirms the grace period operates at type and model level rather than per unit, so further units of a model lawfully placed on the market before the cut-off can continue to be supplied, provided the design remains unchanged.
We supply public authorities. Does this help us?
Only for a while. Providers and deployers of high-risk AI systems intended to be used by public authorities must comply by 2 August 2030 regardless of when the system was placed on the market and regardless of whether its design has changed.
Slutsats
The Digital Omnibus gave existing high-risk systems something more useful than a delay: a cut-off that moved with the deadline, so that anything on the market before 2 December 2027 stays outside Chapter III until its design changes. That is real relief, and it is also a trap, because the exemption ends on a date your product roadmap chooses rather than one the legislator did. At Lawgent, we help companies establish which of their systems fall inside Article 111, document the design baseline that the argument depends on, and decide when a planned release is worth the compliance it triggers. Get in touch if you are about to change something you have been relying on.