LinkedInInstagramXTikTok

The Digital Omnibus on AI: what Regulation (EU) 2026/1744 changed in the EU AI Act

Why the Digital Omnibus matters

For two years, European businesses have planned their artificial intelligence compliance around a single date: 2 August 2026. That was when the bulk of the EU AI Act’s obligations for high-risk AI systems were due to bite. Budgets were built around it, vendors were pressed on it, and board papers cited it.

That date has now moved. On 8 July 2026 the European Parliament and the Council adopted Regulation (EU) 2026/1744, known as the Digital Omnibus on AI. It was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It is not a proposal, a consultation or a political statement. It is binding law, and it rewrites parts of the AI Act that many companies have already built compliance programmes around.

What the Digital Omnibus on AI actually is

The Omnibus is an amending regulation. It does not replace the AI Act; it edits it. Alongside the AI Act, it also amends the aviation safety regulation and the machinery regulation, which matters for manufacturers whose products embed AI.

Its stated purpose is simplification. The practical driver was readiness: the harmonised technical standards that high-risk providers were meant to build against were not finished, and only a handful of Member States had regulatory sandboxes running. Rather than enforce obligations against a rulebook that was not yet complete, the co-legislators bought time. The important nuance is that they bought time for some obligations only.

The deadlines that moved

Annex III high-risk systems now apply from 2 December 2027

The obligations for stand-alone high-risk AI systems listed in Annex III – recruitment and worker management tools, creditworthiness assessment, insurance risk pricing, education and access to essential services, among others – were due to apply from 2 August 2026. They now apply from 2 December 2027. This is a sixteen-month deferral, and it is unconditional. It does not depend on standards being finished by a particular date.

Annex I high-risk systems now apply from 2 August 2028

High-risk AI that sits inside a regulated product as a safety component – medical devices, machinery, lifts, vehicles and the rest of the Annex I list – was scheduled for 2 August 2027. That has moved to 2 August 2028. The Omnibus also narrowed the definition of “safety component” itself, so that a system counts only where its intended purpose relates to preventing or mitigating risks to health and safety. Tools used purely for performance optimisation, efficiency, automation, convenience or quality control fall outside it.

What did not move

This is the part that gets lost in the headlines. The Article 50 transparency obligations were not deferred. They applied from 2 August 2026 and they apply today. If your business runs a chatbot, generates synthetic images, audio, video or text, produces deepfakes, or uses emotion recognition or biometric categorisation, you owe disclosure and labelling duties right now.

There is one narrow piece of relief. For generative systems that were already on the market before 2 August 2026, the machine-readable marking requirement in Article 50(2) has a transitional period running to 2 December 2026. Systems placed on the market on or after 2 August 2026 must comply immediately.

Equally unchanged: the Article 5 prohibitions have applied since 2 February 2025, and the general-purpose AI model obligations in Chapter V have applied since 2 August 2025. Neither was touched.

Two new prohibitions from 2 December 2026

The Omnibus added to the list of banned practices in Article 5. AI systems that generate or manipulate non-consensual intimate or sexually explicit material depicting identifiable people, and systems that generate child sexual abuse material, are now prohibited. These apply from 2 December 2026.

The scope test deserves attention because it is broader than an intent test. A system is caught where this is its intended purpose or a reasonably foreseeable outcome in the absence of adequate technical safeguards. Trivial or minor edits are excluded. In practice this means providers of general image and video generation tools need to be able to show what safeguards they have built in, not merely that they never meant the tool to be used that way.

Other changes worth knowing

AI literacy became a lighter duty

Article 4 previously required providers and deployers to ensure a sufficient level of AI literacy among staff. It now requires them to take measures that support the development of that literacy. The obligation survives; the standard is softer. Companies that have already run AI training programmes have not wasted the effort, and those that have not started still owe something.

A legal basis for bias testing

A new Article 4a gives an explicit legal basis for processing special categories of personal data – ethnicity, health data, and the rest of the Article 9 GDPR list – where strictly necessary for detecting and correcting bias in AI systems, subject to safeguards. This addresses a real problem: you often cannot prove a model is not discriminating without processing the very data that reveals the characteristic. Notably, this extends beyond high-risk providers to providers and deployers of AI systems generally.

Relief for smaller companies

The Omnibus introduces the “small mid-cap” category alongside SMEs, and threads proportionality through several provisions: a simplified technical documentation form that notified bodies must accept, a quality management system proportionate to the size of the organisation, and priority sandbox access extended to small mid-caps.

Sandboxes and enforcement

The deadline for Member States to have at least one operational AI regulatory sandbox moved from 2 August 2026 to 2 August 2027, and the AI Office gained the ability to run a sandbox at Union level. At the same time, the AI Office’s supervisory, investigatory and enforcement powers over general-purpose AI were significantly expanded, applying from 2 August 2026. Deferral in one direction, sharper teeth in the other.

Praktiskt exempel

A Swedish software company sells an applicant-ranking tool to employers across the Nordics. Under the original timetable it faced a conformity assessment, CE marking, technical documentation and registration in the EU database by 2 August 2026. Its compliance programme was scoped and budgeted accordingly.

After the Omnibus, that package is due by 2 December 2027 instead. But the company also operates a customer-facing chatbot and generates AI-written candidate summaries. Those fall under Article 50, which did not move – so the disclosure and marking duties applied from 2 August 2026 and are enforceable today. The correct response was not to pause the programme but to re-sequence it: transparency work pulled forward, conformity assessment work rescheduled with the extra runway used for data governance and documentation quality rather than dropped.

Vanliga misstag som företag gör

The first is reading “delay” as “cancellation” and standing down the project. The obligations did not change; only the date did. Sixteen months disappears quickly when it includes building a data governance regime, a quality management system and a full technical file.

The second is assuming the deferral covers everything. It covers Chapter III obligations for high-risk systems. It does not cover transparency, prohibited practices, general-purpose AI model duties, or the GDPR, which continues to apply in full to every AI system that processes personal data regardless of what the AI Act says.

The third is relying on outdated guidance. A great deal of published material, including some official pages that carry an explicit “not yet updated” disclaimer, still shows the pre-Omnibus dates. Check the date on anything you rely on.

The fourth is confusing this instrument with the separate Digital Omnibus proposal on data protection, which would amend the GDPR and related legislation. That is still a proposal working its way through the legislative process. Nothing in it is law.

Rekommenderade åtgärder

Re-baseline your AI compliance plan against the new dates rather than abandoning it, and separate the workstreams that moved from those that did not. Confirm today whether anything you operate falls under Article 50, because that is the live exposure. Check whether any system already on the market before 2 August 2026 needs machine-readable marking by 2 December 2026.

Review your AI inventory against the narrowed “safety component” definition, since some products may no longer be high-risk. Review published content, vendor commitments and customer-facing compliance statements that cite 2 August 2026 as a live deadline, and correct them. Finally, use the additional time deliberately: the deferral is most valuable to companies that spend it on data quality, documentation and human oversight, and worth nothing to those that spend it waiting.

Vanliga frågor

Does the delay mean we can stop our AI Act work?

No. The substance of the obligations is unchanged and the deferral is a sequencing change, not a reprieve. Several obligations – transparency, prohibited practices, general-purpose AI model duties – are enforceable now. And the technical work required for high-risk compliance typically takes longer than the time now available.

Do the Article 50 transparency rules really apply already?

Yes. They applied from 2 August 2026 and were expressly not deferred. If you deploy a chatbot, publish AI-generated content, or use emotion recognition, the disclosure duties are live. The only relief is a transitional period to 2 December 2026 for machine-readable marking of generative systems placed on the market before 2 August 2026.

Does the Digital Omnibus on AI change the GDPR?

Only marginally, and only through the AI Act. The new Article 4a creates a basis for processing special category data for bias detection and correction, and a fundamental rights impact assessment may now cross-refer to a data protection impact assessment. The broader package of proposed GDPR amendments sits in a separate instrument that has not been adopted.

Slutsats

Regulation (EU) 2026/1744 gave European businesses more time on the hardest part of the AI Act and no time at all on the parts that are easiest to overlook. High-risk obligations for Annex III systems now apply from 2 December 2027 and for Annex I systems from 2 August 2028. Transparency, prohibitions and general-purpose AI rules are live today. The companies that come out of this well will be the ones that read the change precisely rather than generally. Lawgent helps businesses re-baseline their AI Act programmes against the new timetable, identify which obligations are already enforceable, and build compliance that holds up when the deferred deadlines arrive.

Lämna ett svar

Din e-postadress kommer inte publiceras. Obligatoriska fält är märkta *


0Varukorg0,00 

Inga produkter i varukorgen.

Gå tillbaka till butiken