If you run AI agents on ServiceNow and you read the headline, you probably think the EU AI Act moved to December 2027 and there is nothing to do until then.
That is true of one part of it. It is not...
If you run AI agents on ServiceNow and you read the headline, you probably think the EU AI Act moved to December 2027 and there is nothing to do until then.
That is true of one part of it. It is not true of the part that starts applying today.
What moved and what did not
The Digital Omnibus pushed the heavy regime — the obligations for stand-alone high-risk systems under Annex III — from 2 August 2026 to 2 December 2027. High-risk AI built into regulated products under Annex I moved to 2 August 2028. Parliament backed the package on 16 June 2026 by 423 votes to 57, and the Council confirmed it on 29 June.
So yes, sixteen extra months on the documentation-heavy part. But that is an extension on one part of the Act, not on the Act.
ObligationApplies fromChanged by the Omnibus?
Article 4 — AI literacy2 February 2025Softened in wording, not deferred
Article 50 — transparency2 August 2026Essentially unchanged
Annex III — high-risk2 December 2027Deferred from 2 Aug 2026
Annex I — high-risk in products2 August 2028Deferred
Article 4 has been in force since February 2025. The Omnibus softened the wording — you now have to support AI literacy among your staff rather than guarantee some level of it — but it never went away. It has applied for eighteen months.
Article 50 is the one that catches agent deployments
Article 50 is about disclosure, and it is cheap to satisfy. That is exactly why it is worth ten minutes of checking rather than assuming you are fine.
Roughly, it requires that people are told when they are talking to an AI system rather than a person, and that synthetic content is marked in a machine-readable way.
On a ServiceNow estate that lands on the things teams are deploying fastest right now. Virtual agents in the employee portal. Agentic workflows replying to tickets. Anything drafting text that a human will send on.
The question is not whether your agent is sophisticated. It is whether the person on the other side knows what they are talking to.
One detail worth knowing: generative systems already on the market before the date have until 2 December 2026 to meet the machine-readable marking requirement in Article 50(2). New deployments do not get that grace.
Sixteen extra months are not free time
This is the part people miss, and it is the reason I would not wait.
The Annex III obligations are evidentiary. Risk classification, technical documentation, logging, human oversight you can demonstrate. These are not documents you write in the final quarter. They are claims you have to evidence, and the evidence comes from systems that were already running and already logging.
If you want to show in late 2027 that an agent has been monitored, that its outputs were reviewed, that incidents were caught and handled — you need the logging switched on well before then. Start in mid-2027 and you produce a folder of assertions. Start now and you produce a record. An auditor can tell the difference.
There is a second reason. The harmonised standards, the technical specifications that turn the Act's requirements into something you can actually test against, are running late. The practical work arrives before the guidance explaining how to do it. Firms that wait for certainty will end up doing it under time pressure and without that certainty anyway.
What this looks like on ServiceNow
The platform is moving fast here, and most of what you need already exists on it.
An agent inventory. Classification starts with knowing what you have. In practice most organisations underestimate this badly. Agents get built in AI Agent Studio by teams who do not think of themselves as deploying an AI system at all.
AI Control Tower. Which services an agent may touch, and a trail of what it did. This is the closest thing you have to the evidence base the Act will expect.
MCP Registry. Which MCP servers are trusted and what each is allowed to do. Every tool an agent can call is part of its risk surface, and a registry is where that stops being folklore and becomes something you can review.
Human oversight that is real. "A person approves it" is only oversight if that person can see what the agent did and can genuinely refuse. An approval step nobody has ever rejected is a rubber stamp. It will read as one.
A word about compliance panic
The date has already moved once. It could move again — the Omnibus itself shows that timelines bend when the infrastructure behind them is not ready. Any vendor selling you urgency tied to a specific date is selling something with a short shelf life.
So I would put it differently. Almost everything on the Annex III list is work worth doing because an agent with unexamined reach into your instance is a real operational risk, not because a regulation says so. Knowing what an agent can read, whether it can be talked out of its instructions, and what it gives away through its tool calls has value on an ordinary Tuesday with no regulator in sight.
The Act just puts a deadline on work that was already worth doing.
Where to start
Inventory. Every AI agent and assistant running against your instances, who owns it, what it can reach.
Check Article 50 now. It applies from today. Disclosure is cheap to fix and awkward to explain if you missed it.
Classify honestly. Most agents are not Annex III high-risk. Some are. Anything touching employment, access to essential services, or evaluation of people deserves a careful look rather than an optimistic one.
Turn the logging on. Whatever you will need to evidence in 2027, start generating it now.
Get it tested by someone who did not build it. The platform that ships your agents cannot also be the party certifying them safe, and an auditor will read a vendor's self-assessment exactly that way.
We audit AI agents on ServiceNow: what they can reach, what they leak through tool calls, and whether they hold up against someone hostile. If you want a second pair of eyes before the documentation starts to matter, tell us what you are running.
This is a practical summary, not legal advice. Dates reflect the Digital Omnibus agreement as confirmed by the Council on 29 June 2026; the amended regulation takes effect on publication in the Official Journal. Check your own obligations with counsel.
