The EU AI Act’s high-risk deadline has moved. Here is what tier 1 banks need to know
Tier 1 banks planned toward one date: August 2, 2026. That was when high-risk obligations were due to apply to KYC risk scoring, beneficial ownership mapping, and AML flagging. That date has now changed.
On July 24, 2026, the EU published Regulation (EU) 2026/1744, the Digital Omnibus on AI. It entered into force on July 27, six days before the original deadline. It defers the highest-friction obligations, but it does not reopen the Act’s risk framework. For banks already building AI governance programs, this is a reprieve on timing, not a change in destination.
At Encompass, we work with global banks on the KYC and due diligence processes this update affects directly. Here is what changed, what did not, and what to do next.
What is the EU AI Act Digital Omnibus
The Digital Omnibus amends the EU AI Act. The Commission proposed it in November 2025, after standards bodies and conformity-assessment infrastructure fell behind schedule. Parliament and Council agreed the text in May 2026. It became law in July 2026.
The core change delays when high-risk obligations start to apply. It does not remove the requirements. It is not a signal to pause preparation.
Are KYC and AML systems still high-risk under the AI Act
Yes. KYC risk scoring, ownership mapping, adverse media screening, and AML flagging remain high-risk categories. What moved is the date full obligations apply: conformity assessments, documentation, human oversight, data governance, and incident reporting.
The new compliance timetable
- August 2, 2026 – Transparency obligations apply to new systems, including AI-interaction disclosure and content labeling.
- December 2, 2027 – High-risk obligations apply to stand-alone Annex III systems. This covers most KYC and AML automation.
The AI Office also gained expanded supervisory powers. Oversight is increasing even as some deadlines move back.
Why the extra runway is not an invitation to slow down
Eighteen months sounds long. But banks still need conformity assessments across every live KYC and AML system. They need documented human oversight and data governance standards. None of this is a technology project alone. It needs alignment across compliance, legal, risk, and operations.
Legacy exposure matters more, not less, during the delay. Years of KYC records still need review. EC Review batches, verifies, and resolves client profiles against authoritative sources at scale. Gaps surface before regulators find them.
The vendor relationship still needs to change
Many tier 1 banks deploy AI built by third parties. The Act does not let deployers off the hook. Banks must still confirm vendor conformity assessments, documentation, and incident-reporting contracts. Standard agreements written before the Act will likely fall short. The deferral is a good moment to fix that.
How Encompass helps banks meet these obligations
Encompass is built around what the Act requires: transparency, auditability, and human-led decisions.
EC360, our corporate digital identity platform, delivers ready-to-use digital risk profiles. It combines real-time public data with private client information. Profiles are clean, normalized, and data-lineage tracked, which is exactly what auditable AI outputs require. EC360 connects directly into existing tech stacks through API and MCP.
EC Public Automation collects and integrates public KYC data automatically. It resolves inconsistencies, unwraps ownership structures, and identifies UBOs. This creates the documented, repeatable process regulators expect.
EC Private Outreach lets banks and clients share sensitive documents through a secure digital vault. Every interaction stays structured, traceable, and auditable, meeting the Act’s transparency requirements.
EC Review tackles legacy risk at scale, even with the deadline deferred. It compares existing client records against authoritative sources and flags gaps and remediation. All without introducing automated judgment. Additionally, it builds the auditable, human-overseen workflow the Act demands.
A note for UK-headquartered banks
Brexit does not exempt tier 1 banks from the Act. Any institution with EU operations or EU clients remains in scope. The FCA and PRA are moving in the same direction. Frameworks built for EU compliance will likely serve UK expectations too.
Three things to do now
- Inventory your AI. Map every AI or machine learning system across KYC, due diligence, and AML, including vendor-embedded tools. EC Public Automation and EC360 already give you a documented, auditable base to map from.
- Confirm your 2026 obligations. Transparency rules are not deferred. Check new systems meet Article 50 now. Plan for legacy marking obligations landing December 2026.
- Audit your legacy data now. Use the extra runway before deadline pressure returns. EC Review builds the compliant baseline the 2027 deadline will require.
Good KYC has always demanded transparency, accuracy, and human oversight. The deadline moved. The expectation did not. Banks that use this window well will not just satisfy regulators in 2027. They will onboard faster, cut false positives, and run compliance programs that hold up to scrutiny.
The question is still whether to treat the Act as a deadline or a foundation. It just became a longer runway to get the answer right.
FAQ’s
Yes. The Digital Omnibus defers high-risk obligations for most KYC and AML systems to December 2, 2027. AI embedded in Annex I products moves to August 2, 2028.
Yes, for new systems. Legacy system marking obligations move to December 2, 2026, alongside new prohibited-use rules.
No. Regulators want standards and infrastructure to mature. The underlying duty to build oversight and documentation has not changed.
Discover corporate digital identity from Encompass
what financial institutions need to know now