On 24 July 2026, the Digital Omnibus on AI (Regulation (EU) 2026/1744) was published in the Official Journal of the European Union, entering into force on the third day following publication, i.e. 27 July 2026. The Omnibus makes targeted amendments to the EU Artificial Intelligence Act (AI Act) (Regulation (EU) 2024/1689), introducing deadline extensions for high-risk AI system obligations, new prohibited practices and a range of scope clarifications and simplification measures. This post provides an overview of the key changes.

Background: Why the Omnibus

The AI Act entered into force on 1 August 2024, and has been rolling out obligations on a staggered basis ever since. The AI Act applies globally to providers, deployers, importers and distributors of AI systems that place AI on the EU market or whose AI outputs are used within the European Union. The prohibition on unacceptable-risk AI practices and AI literacy requirements took effect on 2 February 2025. Obligations for general-purpose AI (GPAI) models followed on 2 August 2025. The next major milestone, namely full compliance obligations for “high-risk” AI systems, was scheduled for 2 August 2026.

However, industry stakeholders and member states raised serious concerns about the pace of implementation. Key harmonized technical standards needed for compliance assessments were not yet available, creating genuine legal uncertainty about how companies could demonstrate conformity. In response, the European Commission published its proposal for the Digital Omnibus on AI on 19 November 2025, describing it as “targeted simplification measures to ensure timely, smooth, and proportionate implementation” of the AI Act’s provisions. After extensive trilogue negotiations between the Commission, Parliament and Council, final text was adopted on 29 June 2026.

Key changes: Why the Omnibus

The Omnibus is targeted in scope; it does not overhaul the AI Act’s overall structure or risk-based approach. It focuses on four main areas:

  1. Deadline extensions for high-risk AI system obligations.
  2. New prohibitions on certain AI practices.
  3. Technical and scope clarifications.
  4. Procedural and institutional changes.

1. Extended deadlines for high-risk AI systems

The most significant change is a significant delay to the compliance timeline for “high-risk” AI systems, which include systems used in employment decisions, education, law enforcement, credit and insurance, biometrics and critical infrastructure.

ObligationOriginal deadlineNew deadline
High-risk AI (Annex III stand-alone systems – e.g. employment, education, law enforcement)2 August 20262 December 2027 (16-month deferral)
High-risk AI (Annex I AI embedded as safety components in regulated products – e.g. toys, medical devices, machinery)2 August 20272 August 2028
(12-month deferral)
AI regulatory sandboxes (obligation on member states to have at least one operational)2 August 20262 August 2027
AI-generated content watermarking/machine-readable labelling for systems already on the market before 2 August 2026 (Article 50(2))2 August 20262 December 2026 (grace period)
High-risk AI systems intended to be used by public authorities2 August 20262 August 2030

The primary rationale for deferring the Annex III deadline is the delayed availability of harmonized standards. Under the original timetable, organizations would have had to demonstrate compliance without finalized benchmarks. The 16-month deferral is intended to allow standards to be completed and for businesses to build meaningful compliance programs around them.

Importantly, the deferral of Annex III obligations does not affect all 2 August 2026 obligations. Article 50 transparency obligations (including chatbot disclosure and deepfake labelling obligations for systems launched from 2 August 2026), GPAI model requirements (already in force since August 2025), the EU AI Office’s enforcement powers, and governance body obligations all remain on the 2 August 2026 schedule.

2. New prohibitions: Banning nudifier apps and AI-generated CSAM

While the Omnibus relaxes timelines in some areas, it simultaneously tightens the law in one important respect. A new prohibition is added to Article 5 of the AI Act, banning:

  • AI systems that generate or manipulate realistic images, videos, audio or similar material depicting an identifiable person’s intimate parts, or of an identifiable person engaged in sexually explicit activities, without that person’s freely given, specific, informed, unambiguous and explicit consent, also referred to as nonconsensual intimate content (NCIC), or so-called nudifier apps.
  • AI systems that generate child sexual abuse material (CSAM).

The prohibition operates differently for providers and deployers.

For providers, the ban on placing a system on the EU market applies in two cases:

  1. Where generating or manipulating such material is the intended purpose of the system.
  2. Where such generation is a reasonably foreseeable and reproducible outcome of the system’s design, training, architecture, capabilities or user-facing functionalities, without requiring significant technical modification, and the system lacks reasonable and adequate technical safety measures and other safeguards to reliably prevent that generation or manipulation, taking into account reasonably foreseeable misuse, and to correct observed or reported misuse.

For deployers, the standard is narrower: The prohibition applies only where the deployer uses the system for the purpose of generating or manipulating such material. Both prohibitions take effect on 2 December 2026.

3. Scope and technical clarifications

  • Machinery products. One of the more technically complex issues resolved by the Omnibus concerns AI-enabled machinery products. Under the original AI Act, AI systems embedded in machinery that qualify as “safety components” could face dual compliance obligations both under the AI Act’s high-risk regime and under the EU Machinery Regulation (Regulation (EU) 2023/1230). The Omnibus resolves this overlap by moving the Machinery Regulation from Section A to Section B of Annex I to the AI Act, so that most of the AI Act’s high-risk provisions no longer apply directly to these products, and clarifying that they need only comply with the sectoral approach under the Machinery Regulation. The Commission is required to adopt delegated acts amending Annex III of the Machinery Regulation to include relevant health and safety requirements.
  • Clarified “safety component” definition. The Omnibus refines what qualifies as a “safety component” for AI Act purposes. Products with AI functions that only assist users or optimize performance will not automatically face high-risk obligations if their failure or malfunction does not pose health or safety risks. This is intended to prevent overclassification of AI-enabled products as high-risk.
  • Registration obligations for Article 6(3) self-assessed systems. The Commission’s original Omnibus proposal sought to remove the obligation to register AI systems in the EU database where a provider self-assessed that the system fell outside the high-risk classification by virtue of the Article 6(3) exemption (e.g. systems designed to perform a narrow procedural task). The co-legislators rejected this proposal. As a result, providers relying on an Article 6(3) exemption will still be required to register the relevant AI system in the EU database, although they may do so through a simplified registration procedure.
  • Bias detection and personal data. The co-legislators reinstated the “strict necessity” threshold (reverting from a broader proposal in the original Omnibus) for processing special categories of personal data for the purposes of detecting and correcting bias in AI systems. This applies to both high-risk and non-high-risk AI systems, with appropriate safeguards.
  • AI literacy. The AI literacy obligation, applicable to providers and deployers since 2 February 2025, has been reworded. The duty shifts from requiring providers and deployers to “ensure” a level of AI competence among staff to one where the Commission and member states “support and facilitate” providers and deployers in developing AI literacy. In practice, the evidentiary burden on individual organizations is reduced, though the substance of the underlying obligation remains.

4. SME relief, regulatory sandboxes and AI Office powers

  • The Omnibus extends existing small and medium-sized enterprise (SME) exemptions from certain administrative requirements to small mid-cap enterprises (SMCs): Companies that exceed SME thresholds but qualify as SMCs under Commission Recommendation (EU) 2025/1099. SMCs will benefit from streamlined documentation requirements and additional flexibility in post-market monitoring.
  • A new EU-level AI regulatory sandbox operated by the EU AI Office is created, with priority access for SMEs, startups and small mid-caps. This supplements the national-level sandboxes that member states are now required to have operational by 2 August 2027 (instead of 2 August 2026).
  • The Omnibus reinforces the enforcement and supervisory powers of the EU AI Office. Specifically, the AI Office will have exclusive competence to supervise AI systems built on GPAI models where the system and the underlying GPAI model are developed by the same provider (or by providers that form part of the same undertaking), meaning corporate group structures are captured, not just single-entity developers. National competent authorities, however, retain primary competence in specific sectors (including law enforcement, border management, judicial authorities and financial institutions), where sectoral rules and specialized supervisors remain the primary enforcement mechanism.

What has not changed

The following obligations remain on their original schedule and are unaffected by the Omnibus:

  • Prohibited practices (Article 5) and AI literacy obligations: in force since 2 February 2025.
  • GPAI model obligations (Articles 51-56): in force since 2 August 2025.
  • Article 50 transparency obligations for new AI systems (including chatbot disclosure and deepfake disclosure to users): applying from 2 August 2026.
  • EU AI Office enforcement powers and AI governance body operationality: applying from 2 August 2026.

Practical takeaways

Organizations deploying or developing AI systems in or into the EU should note the following:

  • Do not stand down on compliance planning. The extended deadlines create additional runway, but enforcement bodies are already operational, and several obligations (including GPAI rules and prohibited-practice restrictions) are already in force. The Omnibus is targeted relief, not a general reset.
  • If you develop or deploy generative AI tools: Article 50 transparency obligations for new systems still apply from 2 August 2026. If you had systems on the market before that date, the Omnibus gives you a four-month transitional period, until 2 December 2026, to implement machine-readable watermarking for AI-generated content.
  • If your products or services involve employment decisions, education, law enforcement, credit or biometrics: Your full high-risk compliance obligations are deferred to 2 December 2027, but standards and guidance are expected to continue developing during this period, and early preparation remains advisable.
  • If you develop or supply high-risk AI systems intended for use by public authorities: A special extended deadline of 2 August 2030 applies to your compliance obligations under Chapter III. This longer runway reflects the particular challenges of public sector procurement and deployment cycles, but identifying which systems qualify and planning ahead remains important.
  • If you have high-risk AI systems already on the market: The grace period under Article 111(2) operates at the type and model level. If at least one unit of a given type and model was lawfully placed on the market before the applicable compliance date, other units of the same type and model may continue to be placed on the market without additional obligations, provided the design remains materially unchanged. A significant design change after the compliance date triggers full compliance obligations for the changed system.
  • If you operate in the machinery sector: The Omnibus resolves the dual compliance overlap with the Machinery Regulation. Monitor the Commission’s delegated acts amending the Machinery Regulation’s Annex III for the specific requirements that will apply.
  • Review any nudification or synthetic intimate content tools immediately: The new prohibition under Article 5 takes effect 2 December 2026, with no exemption for systems already on the market.
Authors

Patrick Van Eecke, Partner

Bartholomäus Regenhardt, Associate

Posted by Cooley