The Digital Omnibus on AI is now law. Regulation (EU) 2026/1744 was voted by the European Parliament on 16 June 2026, approved by the Council on 29 June, signed on 8 July, published in the Official Journal on 24 July and entered into force on 27 July 2026. It is the first amendment to the EU AI Act since the Act was adopted in June 2024. It moves the high-risk deadlines to 2 December 2027 and 2 August 2028, softens the AI literacy duty, adds two new prohibitions, and leaves 2 August 2026 exactly where it was. If you were waiting for the AI Act to go away, it did not.

By Toni Dos Santos, Co-Founder, Spicy Advisory

Key Takeaways

  • It is in force. Regulation (EU) 2026/1744 — the Digital Omnibus on AI — entered into force on 27 July 2026, three days after publication in the Official Journal. It amends the AI Act (Regulation (EU) 2024/1689) together with the Basic Aviation Regulation and the Machinery Regulation.
  • High-risk moved, twice. Stand-alone high-risk systems listed in Annex III now apply from 2 December 2027 (was 2 August 2026). High-risk AI embedded as a safety component in products covered by Annex I sectoral law applies from 2 August 2028 (was 2 August 2027).
  • 2 August 2026 did not move. The Article 50 transparency duties — telling people they are talking to a machine, labelling deepfakes, marking synthetic output — land on schedule in days, not years. The AI Office also gets its full enforcement powers over general-purpose AI model providers on that date.
  • Two new bans, one new date. AI systems that generate non-consensual intimate imagery ("nudifier" apps) and AI-generated child sexual abuse material become prohibited practices from 2 December 2026, under Article 5 — the tier that carries fines up to €35M or 7% of global turnover.
  • AI literacy survived, in weaker form. Article 4 was rewritten from a duty to ensure a sufficient level of AI literacy into a duty to take measures to support the development of it. An obligation of effort, not of result. It still applies to every deployer, and you still have to show your work.
  • It reaches UK companies. Article 2 was not narrowed. A UK provider placing an AI system on the EU market, or a UK company whose AI output is used in the EU, is in scope regardless of where its offices and servers sit.

Not sure which of these dates apply to you?

Run the free EU AI Act check →Book an AI readiness audit

5 minutes, no signup wall. Red/Amber/Green verdict plus a gap report you can hand to your board.

What the Digital Omnibus on AI actually is

The Digital Omnibus on AI is a simplification package. The European Commission proposed it in November 2025 after a year of complaints from industry and member states that the AI Act's high-risk regime was due to apply before the harmonised standards needed to comply with it existed. The formal title is a mouthful: a regulation amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 as regards the simplification of the implementation of harmonised rules on artificial intelligence. In plain terms: it changes the AI Act, civil aviation rules and machinery rules in one instrument.

It is worth being precise about the name, because two different "omnibus" files have been travelling through Brussels in parallel. The Digital Omnibus on AI is the one that became Regulation (EU) 2026/1744 and is described here. A separate, broader Digital Omnibus touching GDPR, ePrivacy and the Data Act is a different file on a different timetable. If someone tells you "the omnibus changed GDPR", they are not talking about this text.

The legislative path was fast and visibly deadline-driven:

DateStep
19 November 2025Commission publishes the Digital Omnibus on AI proposal
7 May 2026Provisional political agreement between Parliament and Council
16 June 2026European Parliament votes to adopt
29 June 2026Council gives final approval
8 July 2026Final act signed
24 July 2026Published in the Official Journal as Regulation (EU) 2026/1744
27 July 2026Enters into force, on the third day after publication

That three-day entry into force is unusual. The standard is twenty days. The legislator compressed it because the original 2 August 2026 high-risk deadline was six days away, and a delay that arrives after the deadline it is delaying is not a delay.

The new AI Act calendar, in one table

This is the single most useful output of the Omnibus: a timetable you can plan against. Dates in bold changed.

DateWhat appliesStatus
2 February 2025Article 5 prohibited practices; Article 4 AI literacyAlready in force, unchanged
2 August 2025General-purpose AI model obligations (Articles 51–55); governance; most penalty provisionsAlready in force, unchanged
2 August 2026Article 50 transparency duties; general application of the Act; AI Office gains full enforcement powers over GPAI model providersUnchanged — lands this August
2 December 2026Machine-readable marking of synthetic output for generative systems already on the market before 2 August 2026; two new Article 5 prohibitions (non-consensual intimate imagery, AI-generated CSAM)New
2 August 2027National AI regulatory sandboxes operationalDeferred from 2 August 2026
2 December 2027Annex III stand-alone high-risk AI obligationsDeferred from 2 August 2026
2 August 2028Annex I embedded high-risk AI (safety components in regulated products)Deferred from 2 August 2027

Change 1: high-risk obligations move to December 2027 and August 2028

This is the headline, and it is the reason most people have heard of the Omnibus at all.

Under the original AI Act, the obligations attaching to high-risk AI systems — risk management, data governance, technical documentation, logging, human oversight, accuracy and robustness, conformity assessment — were due to apply to Annex III systems from 2 August 2026. Annex III is the list that catches most ordinary businesses: AI used in employment and worker management (CV screening, promotion and task allocation, monitoring), education, credit scoring, insurance pricing, essential services, law enforcement and migration.

If you want the plain-language walkthrough of what "high-risk" means in practice, obligation by obligation, we wrote it for company leaders in the EU AI Act explained for SMB, mid-market and enterprise leaders.

That date is now 2 December 2027. Systems embedded as safety components in products already regulated under Annex I sectoral legislation — machinery, medical devices, lifts, toys, vehicles — move from 2 August 2027 to 2 August 2028.

One detail is worth knowing because it changes how much certainty you actually have. The Commission's original proposal did not set fixed dates at all. It proposed a conditional trigger: obligations would apply six or twelve months after a Commission decision confirming that harmonised standards, common specifications and guidance were genuinely available, with backstop dates as a ceiling. Both the Parliament and the Council rejected that architecture during the negotiation and converted the backstops into fixed application dates. What you get is a hard calendar rather than a floating one, which is better for planning and worse if the standards still are not ready in 2027.

"Sixteen extra months sounds generous until you price the work. Building a defensible technical file for a recruitment or credit-scoring system — data lineage, bias testing, human oversight design, post-market monitoring — is a two-to-three quarter project in a mid-market company, and it competes with everything else on the roadmap. December 2027 is not a reprieve. It is a project start date that has already passed for most of the companies I speak to." — Toni Dos Santos, Co-Founder, Spicy Advisory

Change 2: nothing about 2 August 2026 moved

This is the part that gets lost in the headlines, and it is the part with an imminent deadline. The Omnibus deferred the high-risk regime. It did not defer Article 50, the transparency chapter, which applies from 2 August 2026 as originally scheduled.

Three duties landing in days, not years

Most companies reading this are deployers, not providers. The first two duties are yours. They are also cheap to fix: a disclosure line in your chatbot's opening message, a labelling rule in your content workflow, and a note in your brand guidelines. What is expensive is discovering in October that your marketing team has been publishing unlabelled AI-generated campaign visuals of real spokespeople since August.

The one grace period the Omnibus did add

The Commission had proposed a six-month transition for the machine-readable marking duty. The final text cut it to three. Generative AI systems already placed on the EU market before 2 August 2026 have until 2 December 2026 to comply with the marking requirement. Systems launched on or after 2 August 2026 comply from day one. That is the entire relief on the transparency side.

On the same date, the AI Office gains its full penalty enforcement powers over providers of general-purpose AI models. The supervisory scaffolding around the Act is being switched on, not switched off. If your teams are already leaking data into consumer AI accounts, the transparency deadline is the least of your problems — we covered that failure mode in the risks of shared AI conversations.

Change 3: two new prohibitions arrive on 2 December 2026

The Omnibus is a simplification package that made the AI Act stricter in one place. Article 5 — the list of outright banned practices — gains two entries:

Both become prohibited from 2 December 2026. Article 5 breaches sit in the top penalty tier: up to €35 million or 7% of total worldwide annual turnover, whichever is higher. For most legitimate businesses this changes nothing operationally. It matters if you build, host, distribute or resell image-generation capability to the public, in which case your acceptable-use enforcement is now a regulatory control rather than a trust-and-safety preference.

Change 4: AI literacy became an obligation of effort

Article 4 has applied since 2 February 2025 and requires providers and deployers to see to the AI literacy of their staff and of anyone operating AI systems on their behalf. The Commission originally proposed removing the binding obligation and demoting it to a recital. That is not what happened, but the duty did get lighter.

The Omnibus rewrites Article 4 from a duty to ensure a sufficient level of AI literacy into a duty to take measures to support the development of AI literacy. In legal terms it moves from an obligation of result to an obligation of effort: you are no longer on the hook for a guaranteed, measurable competence level in each individual, but you are still on the hook for having done something proportionate and being able to prove it.

Three practical consequences:

  1. The obligation still covers every deployer. If your staff use ChatGPT, Copilot, Claude or Gemini at work in the EU, Article 4 applies to you regardless of size or sector.
  2. Evidence still matters more than certificates. No certification has ever been mandatory. What a supervisory authority will ask for is an inventory of AI use, role-appropriate training records, an internal policy and dated proof that the two are connected.
  3. Supervision is arriving. The Commission has indicated national market surveillance authorities begin supervising and enforcing Article 4 from 3 August 2026. Softer wording, live supervision.

We wrote the department-by-department version of this before the Omnibus vote, and it holds up: the EU AI Act Article 4 obligation your company already has.

Can you evidence your Article 4 measures today?

Take the free AI literacy compliance check →

Answer 5 minutes of questions, get a Red/Amber/Green verdict, a gap report and a downloadable PDF for your file.

Change 5: registration survived the negotiation

Article 6(3) lets a provider self-assess a system that sits in an Annex III category as not high-risk, where it does not pose a significant risk of harm to health, safety or fundamental rights. The Commission proposed to remove the requirement to register those self-assessments in the EU database, on burden-reduction grounds.

Parliament and Council both refused. Registration stays, with a streamlined set of information to provide. The reasoning is straightforward: an opt-out that nobody can see is not supervisable. If you intend to rely on the Article 6(3) filter, plan for a documented, reasoned assessment that goes into a public database and can be challenged — not an internal memo.

Change 6: real relief for SMEs and small mid-caps

The most underrated part of the Omnibus is that it writes SME and small mid-cap (SMC) definitions into the AI Act and attaches concrete accommodations to them:

If you are a 60-person company that sells software with an AI feature into the EU, this is the provision that decides whether compliance is a quarter of legal spend or a rounding error. It is worth reading with your counsel before you assume the high-risk regime is unaffordable. Our practical framing for smaller organisations sits in the mid-market AI governance framework.

Change 7: national sandboxes slip to August 2027

Member states were required to have at least one national AI regulatory sandbox operational by 2 August 2026. Almost none were on track. The Omnibus defers that obligation to 2 August 2027. Sandboxes matter more than they sound: inside one, a provider following the competent authority's guidance is shielded from administrative fines for infringements committed during the supervised testing, though liability to third parties for damage remains. Fewer sandboxes in 2026 means fewer safe places to test a borderline high-risk product.

What the Omnibus did not touch

Anyone treating this as deregulation should read the negative space:

If you are a UK company, this still applies to you

Brexit did not put UK companies outside the AI Act. Article 2 gives the Regulation deliberate extraterritorial reach, and the Omnibus left it alone. A UK-registered business with UK offices, UK staff and UK servers is in scope if any of the following is true:

  1. You place an AI system or a general-purpose AI model on the EU market, or put one into service in the EU — including as a feature inside a SaaS product sold to EU customers. Article 2(1)(a) applies to providers "irrespective of whether those providers are established or located within the Union or in a third country".
  2. Your group has an EU entity that deploys AI systems. A French or German subsidiary using an AI recruitment tool is a deployer established in the EU, and the obligations follow the subsidiary.
  3. The output produced by your AI system is used in the EU. This is the catch that surprises people. A London agency running an AI screening model over candidates for a client's Paris office, or a UK lender scoring applicants in Ireland, is in scope because the output lands in the Union — even if the model never leaves a UK data centre.

The practical consequence for UK businesses is a two-regime reality. Domestically you answer to UK GDPR, the ICO's guidance and the Data (Use and Access) Act — we mapped that in the Data (Use and Access) Act and AI and in AI governance for UK companies. For anything touching the EU, you answer to the AI Act calendar above as well. Running two governance frameworks is wasteful; running one framework calibrated to the stricter of the two is not. That comparison is the whole subject of UK vs EU AI regulation.

"The UK companies that get caught out are never the ones with an EU subsidiary — those have lawyers watching. It is the London agency, the recruitment firm, the fintech with a handful of Dublin clients. Nobody in the building has ever read Article 2, and the output test is doing quiet work in the background the entire time." — Toni Dos Santos, Co-Founder, Spicy Advisory

What to do in the next 90 days

The readiness data is not flattering. A 2026 EU AI Act readiness analysis by Vision Compliance, drawing on assessments across eight industries, found 78% of organisations had taken no meaningful steps toward AI Act compliance, 74% had no designated internal owner for it, and 61% had no process for producing the technical documentation high-risk systems require. The Omnibus gives sixteen extra months to the companies that will use them and sixteen extra months of drift to everyone else.

WindowActionWhy now
Before 2 August 2026Add AI disclosure to every customer-facing chatbot, voice agent and automated call flowArticle 50 applies in days; the fix is a sentence
Before 2 August 2026Write a labelling rule for AI-generated marketing content into your brand and publishing guidelinesDeepfake and synthetic-content disclosure is a deployer duty
Next 30 daysInventory every AI system in use, by department, including shadow tools on personal accountsYou cannot classify what you cannot see — see shadow AI governance
Next 30 daysName one accountable owner for AI compliance and put it in writing74% of organisations have not; it is the cheapest gap to close
Next 60 daysMap your inventory against Annex III. Flag anything in recruitment, performance management, credit, insurance or access to essential servicesThese are the systems with a December 2027 conformity deadline
Next 60 daysRun and evidence role-based AI literacy training; keep dated recordsArticle 4 supervision starts 3 August 2026
Next 90 daysDecide, per high-risk candidate, whether you will conform, rely on the Article 6(3) filter, or retire the systemEach path has a different lead time; the filter now needs a registered, defensible assessment
Next 90 daysIf you are an SME or small mid-cap, check which simplified documentation and QMS routes you qualify forNew in the Omnibus; materially changes the cost of compliance

Turn the new calendar into a plan

We help SMBs, mid-market companies and enterprises across France, the UK and Europe convert AI regulation into working practice: AI inventories, Annex III mapping, role-based literacy training and a governance framework your teams will actually use. 1,500+ professionals trained across 50+ companies including L'Oréal, EssilorLuxottica and IGN, rated 4.98/5.

Start with the free EU AI Act check

The honest read

The Omnibus is being sold as simplification and criticised as dilution. Both are partly right. Digital rights organisations, including the Center for Democracy and Technology, argue the final text weakens fundamental rights protections — the softened Article 4, the extra sixteen months of unregulated deployment in hiring and credit, the pressure that was applied to the Article 6(3) filter. Industry argues, with equal justification, that applying a conformity regime before its harmonised standards exist is not regulation, it is a lottery.

For an operator the debate is beside the point. The Act still classifies your recruitment tool as high-risk. Your customers, your works council and your enterprise buyers will ask about it long before a regulator does. The deadline moved; the questions did not. What the Omnibus bought you is time to answer them properly rather than in a panic — which is worth something, but only if you spend it.

Frequently asked questions

What is the Digital Omnibus on AI?

The Digital Omnibus on AI is Regulation (EU) 2026/1744, a simplification package amending the EU AI Act (Regulation (EU) 2024/1689) along with the Basic Aviation Regulation and the Machinery Regulation. The European Parliament voted to adopt it on 16 June 2026, the Council approved it on 29 June, and it was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It is the first set of amendments to the AI Act since the Act was adopted in June 2024.

When do EU AI Act high-risk obligations now apply?

Two dates. Stand-alone high-risk AI systems listed in Annex III — including recruitment, worker management, education, credit scoring, insurance pricing and access to essential services — apply from 2 December 2027, deferred from 2 August 2026. High-risk AI embedded as a safety component in products regulated under Annex I sectoral legislation applies from 2 August 2028, deferred from 2 August 2027. These are fixed dates: the Commission's original proposal to tie them to a decision on standards availability was rejected during negotiation.

Did the Digital Omnibus delay the 2 August 2026 deadline?

No. Article 50 transparency obligations apply from 2 August 2026 as originally scheduled: disclosing that a user is interacting with an AI system, labelling deepfakes and AI-generated content published on matters of public interest, and machine-readable marking of synthetic output. The AI Office also gains full enforcement powers over general-purpose AI model providers on that date. The only relief is a transition to 2 December 2026 for the machine-readable marking duty, and only for generative systems already on the EU market before 2 August 2026.

Does the EU AI Act apply to UK companies after the Digital Omnibus?

Yes. The Omnibus did not narrow Article 2, which gives the AI Act extraterritorial reach. A UK company is in scope if it places an AI system or general-purpose AI model on the EU market or puts one into service there, if it has an EU-established entity deploying AI systems, or if the output produced by its AI system is used in the EU. The third trigger catches UK agencies, recruiters, lenders and SaaS vendors serving EU clients even when the company, its staff and its infrastructure never leave the UK.

Is the AI literacy obligation in Article 4 still binding?

Yes, in weaker form. The Commission proposed demoting Article 4 to a recital; the final text kept it as a binding article but rewrote it from a duty to ensure a sufficient level of AI literacy into a duty to take measures to support the development of AI literacy. That is an obligation of effort rather than result. It still applies to every provider and deployer using AI in the EU, no certification is required, and the Commission has indicated national market surveillance authorities begin supervising and enforcing it from 3 August 2026. Evidence — an AI inventory, role-based training records, a policy — remains the thing to have.

What new AI practices are banned under the Digital Omnibus?

Two additions to the Article 5 list of prohibited practices, both applying from 2 December 2026: AI systems that generate or manipulate non-consensual intimate imagery of real people, commonly known as "nudifier" apps, and AI systems that generate or manipulate child sexual abuse material. Article 5 infringements carry the top penalty tier of up to €35 million or 7% of total worldwide annual turnover, whichever is higher.

Do we still have to register a system we self-assessed as not high-risk?

Yes. Under Article 6(3), a provider can self-assess a system falling within an Annex III category as not high-risk where it does not pose a significant risk of harm to health, safety or fundamental rights. The Commission proposed removing the duty to register those self-assessments in the EU database; both the Parliament and the Council rejected that and kept registration, while streamlining the information required. Plan for a documented, reasoned assessment that is publicly visible and can be challenged.

What does the Digital Omnibus change for SMEs?

It writes SME and small mid-cap definitions into the AI Act and attaches concrete accommodations: a simplified technical documentation form for high-risk systems, proportionate quality management system requirements extended across the SME category, reduced caps on administrative fines, and priority access to AI regulatory sandboxes. Separately, the deadline for member states to have a national sandbox operational moved from 2 August 2026 to 2 August 2027.

Does the Digital Omnibus change GDPR?

Not this one. Regulation (EU) 2026/1744 is the Digital Omnibus on AI and amends the AI Act, the Basic Aviation Regulation and the Machinery Regulation. A separate and broader Digital Omnibus file addressing GDPR, ePrivacy and the Data Act is on its own legislative timetable. Conflating the two is the most common error in coverage of this reform.

Sources and further reading

About Spicy Advisory

Spicy Advisory helps SMBs, mid-market companies and enterprises across France, the UK and Europe turn AI regulation into working practice — through AI inventories, Annex III mapping, role-based literacy training and hands-on adoption support. 1,500+ professionals trained across 50+ companies including L'Oréal, EssilorLuxottica and IGN, rated 4.98/5. No junior consultants, no legal jargon — a compliance position you can evidence, and teams that keep working.

Book your AI readiness audit