Part of 2026 May 19, 2026 ·
--- days
-- hrs
-- min
-- sec
Content Hub Build Article
Build Aug 12, 2026 · 10 min read

The Digital Omnibus on AI: What Actually Changed and What Teams Should Do Now

The Digital Omnibus on AI: What Actually Changed and What Teams Should Do Now

The EU AI Act just got its first major revision, and most compliance teams are reading it wrong.

On 27 July 2026, Regulation (EU) 2026/1744 entered into force, amending the AI Act less than two years after its original adoption. The Digital Omnibus on AI, as it's formally known, extends deadlines, narrows definitions, and adds new prohibitions. For teams that had been scrambling toward the 2 August 2026 enforcement date, the relief is real. But the relief is also partial, conditional, and easy to misread.

Here's what changed, what didn't, and what implementation teams should actually do with the extra runway.

The Timeline Shift: 16 Months for Some, 12 for Others

The headline change is the postponement of high-risk AI system obligations. According to Orrick's analysis of the political agreement, the new deadlines break down as follows:

Standalone high-risk AI systems under Annex III (covering use cases like employment, education, critical infrastructure, law enforcement, and creditworthiness assessment) now face a compliance deadline of 2 December 2027, pushed back from the original 2 August 2026.

High-risk AI systems embedded in regulated products under Annex I (medical devices, machinery, toys, radio equipment) get until 2 August 2028, a 12-month extension from the original 2 August 2027 deadline.

The rationale is straightforward: harmonised technical standards weren't ready. European standardisation bodies faced delays, with many key standards now expected toward the end of 2026. Without these tools, organisations would have faced significant uncertainty in determining how to meet compliance requirements. The Commission acknowledged this reality rather than forcing compliance against incomplete guidance.

What Didn't Move: The 2 August 2026 Deadline Still Matters

Here's where teams get it wrong: 2 August 2026 remains an active compliance date.

As Bristows' analysis notes, the Article 50 transparency obligations largely remain on the original schedule. These require businesses to:

  • Inform people when they're interacting with certain AI systems
  • Mark AI-generated or manipulated content in a machine-readable format
  • Disclose the use of deepfakes, emotion-recognition systems, biometric-categorisation systems, and AI-generated text on matters of public interest

The watermarking obligation for AI systems generating synthetic content gets a short extension to 2 December 2026, but only for systems already on the market before 2 August 2026. New systems must comply from the date they're placed on the market.

General-purpose AI (GPAI) model obligations have applied since August 2025, and from 2 August 2026, the Commission can bring its full supervisory and enforcement powers to bear. That means requiring information or model evaluations, directing providers to take mitigation measures, and imposing fines.

New Prohibitions: Nudifiers and CSAM

The Omnibus adds to the AI Act's list of prohibited practices. According to the Council of the EU, AI systems that generate non-consensual sexual and intimate content, or child sexual abuse material (CSAM), are now banned. This covers so-called nudifier applications that generate nude images of real people or edit clothes out of existing photos.

The prohibition takes effect 2 December 2026. Violations can trigger fines of up to €35 million or 7% of annual worldwide turnover, whichever is higher.

Scope Clarifications: What Counts as High-Risk

The Omnibus narrows the definition of safety component in ways that matter for product manufacturers. Per Bristows' coverage of the political deal, AI systems that only assist users or optimise performance will not automatically face high-risk obligations if their failure or malfunction does not create health or safety risks.

The Machinery Regulation has been moved from Annex I Section A to Section B, shifting AI-enabled machinery from a dual-compliance model to one where sector-specific laws take precedence. As Covington's analysis explains, this is structurally significant: Section A products required compliance with both the AI Act and sectoral rules, while Section B products follow sector-specific laws as paramount.

The Commission can also issue implementing acts to resolve situations where sectoral law contains AI-specific requirements equivalent to those of the AI Act, limiting the latter's application in those specific cases.

SME Relief Extended to Small Mid-Caps

The Omnibus extends several AI Act measures intended to simplify compliance for SMEs (small and medium-sized enterprises) to a newly defined category of small mid-cap enterprises. According to Orrick, this includes:

  • Simplified technical documentation templates that notified bodies must accept
  • More proportionate quality-management expectations
  • Priority access to regulatory sandboxes
  • More tailored penalty caps

Small mid-cap enterprises are defined as enterprises that are not SMEs but have fewer than 500 employees and annual turnover not exceeding €100 million.

AI Literacy: Softened but Not Removed

The obligation around AI literacy has been adjusted. As Akin Gump notes, providers and deployers must now take measures to support the development of AI literacy rather than, as previously required, ensure, to their best extent, a sufficient level of AI literacy.

The practical difference: the obligation shifts from a results-oriented standard to a process-oriented one. Teams still need to demonstrate they're doing something, but the bar for what counts as sufficient has lowered.

What Implementation Teams Should Do Now

The extra runway is real, but treating December 2027 as a snooze button is a mistake. Here's what the timeline actually supports:

1. Separate the compliance streams. High-risk obligations moved. Transparency obligations largely didn't. GPAI enforcement is live. Build three separate workstreams with three separate timelines.

2. Inventory AI use cases now. As Bristows' governance guidance suggests, a useful starting point is a simple inventory capturing what each tool does, who uses it, what data it processes, whether it affects customers or employees, and whether it supports business-critical or regulated activities. This doesn't need to be perfect on day one, but it should capture enough information to support meaningful review.

3. Watch for the conditional trigger. The December 2027 deadline is an outer limit, not a guarantee. The Commission can pull the deadline forward to six months after it formally concludes that the necessary standards, common specifications, or guidance are in place. If harmonised standards arrive earlier than expected, the runway shortens.

4. Don't wait for standards to start governance. The substance of the obligations hasn't changed. Article 26 still places duties on deployers for human oversight, monitoring, logging, and informing affected individuals. Article 27 still requires a Fundamental Rights Impact Assessment (FRIA) before a high-risk AI system goes into use. Start the governance work now; refine it when standards arrive.

5. Check your supply chain. The Omnibus details the original provider's obligations to cooperate with and assist new providers, and specifies fines for breach of that obligation. If you're deploying AI systems from third-party providers, understand what documentation and cooperation you're entitled to receive.

The Bigger Picture

The Digital Omnibus on AI is the first substantive amendment to the AI Act since its adoption in June 2024. It won't be the last. The broader Digital Omnibus Package also proposes amendments to the GDPR, the ePrivacy Directive, NIS2, and the Data Act, though those remain subject to ongoing negotiations and are not yet law.

The pattern is clear: the EU is willing to adjust timelines when implementation realities don't match legislative ambition. But the adjustments are targeted, not wholesale. The core architecture of the AI Act remains intact. The risk-based approach, the general obligations of providers and deployers, the prohibited practices, the transparency requirements: all of these survived the Omnibus process.

For teams doing the implementation work, the message is: use the extra time to build something durable, not to delay starting. The December 2027 deadline will arrive faster than the August 2026 deadline did.

For ongoing analysis of European AI policy, governance frameworks, and implementation realities, the Human × AI Content Hub tracks what's actually changing and what teams need to do about it.

Frequently Asked Questions

Q: When do high-risk AI system obligations under the EU AI Act now apply?

A: Standalone high-risk AI systems under Annex III must comply by 2 December 2027. High-risk AI systems embedded in regulated products under Annex I must comply by 2 August 2028. These deadlines were extended from the original 2 August 2026 and 2 August 2027 dates respectively.

Q: What AI Act obligations still apply from 2 August 2026?

A: Article 50 transparency obligations largely remain on the original schedule, requiring disclosure when people interact with AI systems and marking of AI-generated content. GPAI model enforcement powers also became fully active on 2 August 2026. Only the watermarking obligation for systems already on the market before that date was extended to 2 December 2026.

Q: What new AI practices does the Digital Omnibus prohibit?

A: The Omnibus bans AI systems that generate non-consensual sexual and intimate content (so-called nudifier applications) or child sexual abuse material. This prohibition takes effect 2 December 2026, with violations potentially triggering fines of up to €35 million or 7% of annual worldwide turnover.

Q: Can the December 2027 deadline be moved earlier?

A: Yes. The Commission can pull the deadline forward to six months after it formally concludes that the necessary harmonised standards, common specifications, or guidance are in place. December 2027 is an outer limit, not a guaranteed date.

Q: How does the Omnibus affect SMEs and smaller companies?

A: The Omnibus extends SME relief measures to a new category of small mid-cap enterprises (fewer than 500 employees, annual turnover not exceeding €100 million). Benefits include simplified technical documentation templates, more proportionate quality-management expectations, priority access to regulatory sandboxes, and tailored penalty caps.

Q: What changed regarding the AI literacy obligation?

A: The obligation shifted from requiring providers and deployers to ensure, to their best extent, a sufficient level of AI literacy to requiring them to support the development of AI literacy. This moves from a results-oriented standard to a process-oriented one, lowering the compliance bar while still requiring demonstrable effort.

Enjoyed this? Get the Daily Brief.

Curated AI insights for European leaders — straight to your inbox.

Created by People. Powered by AI. Enabled by Cities.

One day to shape
Europe's AI future

Secure your place at the most important AI convergence event in Central Europe.