The Council of the European Union gave final approval to the Digital Omnibus package on 29 June 2026, after the European Parliament had already adopted it on 16 June. The package entered into force on 27 July 2026, three days after publication in the Official Journal on 24 July. That package holds the reason most Power Platform teams can stop treating this as an emergency. The compliance deadline for high-risk AI systems under Annex III moved from 2 August 2026 to 2 December 2027, a sixteen-month delay, according to the Council's own press release on the final approval.
Annex I moved too. Product-embedded high-risk systems, the category covering things like medical devices and lifts with AI safety components, now have until 2 August 2028 rather than 2 August 2027, a one-year delay.
Standards bodies are still finishing the harmonised technical standards that providers will need before they can prove compliance, and most of those standards aren't expected until the end of 2026. That gap is the stated reason for pushing both dates back.
Not everything shifted. The prohibitions in Article 5, the outright bans on practices like social scoring, took effect on 2 February 2025 and are still in force. The rules governing general-purpose AI model providers under Articles 53 and 55 took effect on 2 August 2025. And Article 50, the transparency obligation, took effect on 2 August 2026. That one has been live for nearly two months as of this post, which makes it the deadline most tenants have already missed without noticing rather than the one still ahead.
The categories a Power Platform build could hit
Annex III lists eight categories of high-risk system. Most of what gets built in Copilot Studio or added to Dynamics 365 never goes near any of them. A document summarisation agent, an IT helpdesk bot, an expense report reader, and a meeting notes generator all sit outside biometric identification, critical infrastructure, education, law enforcement, migration, and the administration of justice. Two categories are worth checking your own build list against.
Employment is one. Annex III covers systems used for recruitment filtering, candidate evaluation, worker performance evaluation, and behavioural monitoring of workers. A Copilot Studio agent that screens CVs against a job description, or a Dynamics 365 workflow that scores call centre agents on handle time and sentiment and feeds that score into a review, is doing what the category describes.
Essential services is the other. It covers systems evaluating creditworthiness and loan eligibility, insurance eligibility and pricing, and eligibility for public benefits. A lending workflow built on Power Platform that scores an applicant, or a public sector portal deciding who qualifies for a benefit, lands here.
There's a third trigger that catches things neither list names directly. Any system that automatically processes personal data to assess, predict, or infer aspects of a person's life, their work performance, economic situation, reliability, behaviour, or location, is classified as high risk through profiling, regardless of which category it sits in. That definition is broad. An agent built to flag which employees are likely to leave, or which customers are likely to default, can still qualify even if nobody ever called it an HR tool or a credit tool.
The earlier examples are exempt because none of them touch employment, credit, or the other listed categories, not because they stay inside the company. The Act doesn't carve out an internal-use exemption at all, so an HR agent used only by your own recruiters is still in scope if it screens candidates or monitors performance. Most tenants will find zero agents in this territory. Some will find one sitting in a solution nobody has opened since it shipped. The only way to know which is which is to check.
Provider or deployer, and why nobody has a clean answer
The Act splits obligations between providers and deployers, and which one you are changes everything you owe. Article 3 of the Act defines a provider as whoever develops a system, or has one developed, and puts it into service under their own name. It defines a deployer as whoever uses a system under their own authority. Providers face the fuller set of obligations. Deployers face a narrower one under Article 26, which requires appropriate technical and organisational measures so the system is used strictly in line with the provider's instructions.
An enterprise that takes a third-party model and customises it with its own data, without altering the underlying architecture or pre-training, stays a deployer. An enterprise that builds something in-house and puts it into service under its own name becomes the provider for that system, with the provider's obligations attached.
Copilot Studio does not fit cleanly into either description, and nobody has published a clean answer for where it falls. Your team writes the topics, the prompts, and the data connections, and decides what the agent is for. Microsoft built the underlying model and the platform it runs on. Microsoft's EU AI Act trust centre page describes working groups combining AI governance, engineering, legal, and public policy staff, a Restricted Use Policy employees must consult, and Responsible AI resources for customers. None of it states whether an organisation that builds a Copilot Studio agent is the provider of that agent or a deployer of Microsoft's underlying system.
That answer likely depends on the specific agent, how much of its behaviour comes from your configuration versus the base model, and how it gets put into service. Nothing here is legal advice. The provider-or-deployer call for any agent that lands inside Annex III needs a lawyer who has read the specific build.
Transparency duties apply at every risk tier
Article 50 doesn't care whether your agent is high risk, limited risk, or nowhere near either list. It applies to any AI system used in four specific situations, and it has applied since 2 August 2026, according to the European Commission's guidelines on AI transparency obligations.
The core duty is simple to state and easy to skip in practice. People need to know they're talking to an AI system, unless that's obvious from context, and they need to know before or at the moment of first interaction. A Copilot Studio agent embedded in a Teams channel or a customer-facing web chat has to disclose that somewhere in the first exchange, in language a person will notice, not placed only inside a terms link nobody opens.
Three more duties apply alongside it. Systems generating synthetic audio, images, video, or text have to mark that output as AI-generated in a machine-readable format. Deployers using emotion recognition or biometric categorisation have to tell the people being assessed and stay inside GDPR. AI-generated content presented as news or public-interest material needs the same disclosure unless a human editor reviewed it first.
The practical check for most tenants isn't complicated. Open every customer-facing or employee-facing agent that shipped before this was a legal requirement rather than a courtesy, and read the first message it sends. If it doesn't say what it is, that's a gap that predates the deadline and has been a live obligation for close to two months already.
What an admin can check this week
None of this requires new tooling to start looking. Microsoft Agent 365 reached general availability on 1 May 2026, and the agent registry in the Microsoft 365 admin center already gives a consolidated view of every Microsoft-built, partner-built, and custom agent in the tenant. Registry sync extends that view to agents running outside Microsoft platforms. That inventory is the starting point, because nobody can classify an agent against Annex III without first knowing it exists.
After May 2026, Copilot Studio automatically creates a Microsoft Entra Agent ID for every new agent, which centralises audit logging, lifecycle management, and Conditional Access in Entra ID. Older agents don't get this for free. Microsoft began a gradual self-service migration rollout on 24 August 2026, and there's no automated conversion path. Admins have to build a new agent with Agent ID integration, reconfigure it by hand, and decommission the old one. The Power Platform admin center, under Actions and Entra ID Governance, shows which agents are eligible for that migration.
Purview Audit Logs already record who published, deployed, removed, or updated a Copilot Studio agent, along with prompts submitted and resources accessed, retained for 180 days on standard licensing or 365 days under Microsoft 365 E5. That log is where you'd go looking if a regulator or an internal auditor asked when a specific agent's behaviour last changed.
The actual work is smaller than the deadline makes it sound. Pull the registry, sort for anything touching HR, recruitment, lending, benefits, or customer scoring data, and check the first message each one sends a user. For the handful that land inside Annex III, get legal involved well ahead of December 2027 rather than in the month before it.