Compliance Library Blog Product Sign In

Three clocks where there used to be one

Obligation setPosition before JulyPosition now
Annex I embedded high-risk (incl. MDR/IVDR-route devices) 2 August 2026 2 August 2028 — Reg (EU) 2026/1744, Recital (40)
Annex III standalone high-risk 2 August 2026 2 December 2027 — Reg (EU) 2026/1744, Recital (40)
Article 50 transparency (chatbots, generated content, deepfake labelling) 2 August 2026 In force since 2 August 2026 — unchanged, and widely skipped past

The omnibus also narrowed Article 6 classification, rewired parts of conformity assessment (including the 28 January 2028 notified-body deadline), largely moved machinery-embedded AI out of scope, and left Commission GPAI enforcement powers live. For a boutique advising on AiMD, the double burden didn't get lighter — it got re-dated, unevenly. A roadmap drawn in June points at the wrong dates in three directions at once.

The same thing happened in the US, worse

Colorado repealed SB 24-205 before a single obligation ever bound anyone, and reenacted a different statute at the same section numbers — SB 26-189, effective 1 January 2027. The successor contains no reasonable-care duty, no impact-assessment requirement, and no NIST safe harbour. Old 6-1-17xx citations still resolve — to text that says something else. Any control mapping citing the old sections is now pointing at the wrong provisions, and nothing about it announces itself as broken.

In our database, the predecessor's 24 obligations are flagged superseded — with the dated, sourced reason — and the successor's 53 obligations sit alongside them. Superseded obligations are never deleted, because the difference between the two statutes is the useful part.

What ReguLume does with this

ReguLume maintains 2,993 current obligations across 16 AI and data regulations — including all 334 from the EU AI Act as amended — decomposed to individual, enforceable obligation points from the legal text. Every obligation carries the verbatim source excerpt, the source link, and its article reference. When law moves, obligations are flagged superseded, never deleted. Cross-regulation references connect the frameworks — the layer that answers what an MDR-conformity position covers, and doesn't cover, under the AI Act.

We track this continuously as a subscription. How we decompose, verify, and keep it current — including the limits of our pipeline — is published openly on our methodology page.

Get your delta readout — free

We're running a research study on how boutique medical-device regulatory teams track post-omnibus regulatory change. Twenty minutes of your experience; in return you get the aggregate findings and a personalized delta readout — what changed across the regulations you advise on, at obligation level, with the amending text linked for every entry.

Request the readout Browse the obligation library

ReguLume provides regulatory intelligence, not legal advice. Verify against the cited primary sources — Reg (EU) 2026/1744 (EUR-Lex) and Colorado Session Law ch. 131 — before relying on any date or obligation on this page.

Start your compliance assessment

Map obligations to your AI systems, identify gaps, and generate board-ready reports. Plans start at $149/mo.

Get Started