Regulation
The EU Digital Omnibus on AI: what changed in 2026
The Digital Omnibus on AI is the package of targeted amendments to the EU AI Act adopted in 2026. Published as Regulation (EU) 2026/1744 (opens in a new tab) and in force since July 27, 2026, it delays the high-risk rules, softens the AI literacy duty, extends relief to small mid-cap companies, adds two bans and gives the Commission's AI Office direct powers over some AI systems.
By the KDS security engineering teamPublished 10 min read
Key takeaways
- Regulation (EU) 2026/1744 was signed on July 8, 2026, published on July 24 and entered into force on July 27, 2026.
- High-risk rules now apply from December 2, 2027 (Annex III) and August 2, 2028 (Annex I). Both are fixed dates.
- Article 50 transparency still applied from August 2, 2026. Only marking for existing generative AI systems moved, to December 2, 2026.
- Two Commission proposals changed before adoption: dropping registration for Article 6(3) systems and removing the AI literacy duty for companies.
- New bans on non-consensual intimate imagery and AI-generated child sexual abuse material apply from December 2, 2026.
On this page
How the Digital Omnibus on AI became law
The Omnibus is part of the European Commission's wider plan to simplify EU digital rules. It went through the ordinary legislative procedure under reference 2025/0359(COD), from proposal to entry into force in about eight months.
| Date | Step |
|---|---|
| November 19, 2025 | The Commission proposes the Digital Omnibus on AI, COM(2025) 836 |
| March 13, 2026 | The Council agrees its negotiating position |
| March 2026 | Parliament adopts its negotiating position in plenary |
| May 7, 2026 | Parliament and Council negotiators reach a provisional agreement |
| May 13, 2026 | Member State ambassadors (Coreper) approve the agreement |
| June 16, 2026 | Parliament approves the text in plenary |
| June 29, 2026 | The Council adopts the regulation |
| July 8, 2026 | The Presidents of Parliament and Council sign it |
| July 24, 2026 | Publication in the Official Journal of the EU |
| July 27, 2026 | Entry into force, on the third day after publication |
The dates come from the European Parliament's Legislative Train (opens in a new tab) and the published regulation. The co-legislators wanted the law in force before August 2, 2026, the original start date for high-risk rules, and it entered into force 6 days before that date.
Recital 40 explains the main reason for the delay: standards, common specifications and guidance for high-risk systems were late, and national competent authorities were set up late.
Digital Omnibus changes to AI Act deadlines
This guide covers the changes that matter for companies that build or use AI. The Omnibus also amends EU aviation and machinery law and the procedures for notified bodies, which we mention only where they affect AI systems directly.
High-risk dates, now fixed
The requirements for high-risk AI systems in Chapter III, Sections 1 to 3, now apply from December 2, 2027 for systems listed in Annex III and from August 2, 2028 for AI in products covered by Annex I. The original dates were August 2, 2026 and August 2, 2027.
The Commission proposal (opens in a new tab) had a moving start: the rules would apply 6 or 12 months after a Commission decision that standards and support tools were ready, with the 2027 and 2028 dates as the latest possible start. That mechanism was dropped. Article 113 now sets fixed dates.
The grace period in Article 111(2) was also clarified. High-risk systems placed on the market before the new dates stay outside the rules until their design changes significantly. Recital 39 explains that the test is the first unit of a type and model, so later units of an unchanged model are covered too. High-risk systems used by public authorities must comply by August 2, 2030 in any case.
Transparency: one short extension
Article 50 was not delayed and has applied since August 2, 2026. The only change concerns machine-readable marking of AI-generated content under Article 50(2). Providers of generative AI systems placed on the market before August 2, 2026 have until December 2, 2026 to comply (new Article 111(4)). The Commission had proposed February 2, 2027, and the co-legislators shortened it.
Article 50(7) now says the Commission assesses whether codes of practice on marking and labeling are adequate, and can adopt common rules by implementing act if they are not. For the duties themselves, see our Article 50 guide.
AI literacy: softened, not removed
The Commission proposed to turn Article 4 into a duty for the Commission and Member States to encourage AI literacy. The adopted text keeps a duty on companies. Providers and deployers must take measures to support the AI literacy of their staff and others who operate or use AI on their behalf, and the text adds that they do not have to guarantee a specific level for any individual.
The Commission must publish practical examples of how to comply, and the European Artificial Intelligence Board will adopt recommendations. The Commission's AI literacy Q&A (opens in a new tab) confirms that no certificate is needed.
Two new prohibited practices
Parliament and Council added two bans to Article 5 that were not in the Commission proposal. From December 2, 2026, it is prohibited to place on the market, put into service or use AI systems that generate or manipulate:
- Realistic images, video or audio of an identifiable person's intimate parts, or of that person in sexually explicit activity, without the person's explicit consent
- Child sexual abuse material as defined in Directive 2011/93/EU
For providers, the ban applies when this is the system's intended purpose, or when the system can foreseeably do it without significant modification and lacks reasonable safeguards to prevent it. For deployers, it applies when they use a system for that purpose. Providers of general image, video and audio generators should test their safeguards against this standard.
Relief for smaller companies and simpler registration
SMEs and small mid-caps
The Omnibus defines small mid-cap enterprises (SMCs) by reference to Commission Recommendation (EU) 2025/1099 and extends several measures for small and medium-sized enterprises (SMEs) to them:
- SMEs, start-ups and SMCs can provide high-risk technical documentation in a simplified form, on a Commission template that notified bodies must accept (Article 11).
- Quality management must be proportionate to the provider's size, and the text now names SMEs and SMCs (Article 17). All SMEs without partner or linked enterprises, not only microenterprises, can use the simplified option (Article 63).
- For SMCs, fines for most breaches are capped at the lower of the fixed amount and the turnover percentage, as for SMEs (Article 99(6a)).
- SMEs and SMCs get priority access to a Union-level AI regulatory sandbox that the AI Office may set up (Article 57(3a)).
Registration kept, with less information
The Commission proposed to delete the duty to register Annex III systems that a provider considers not high-risk under Article 6(3). The co-legislators kept the registration and cut its content instead. Two items in Annex VIII, Section B are deleted: the summary of the grounds for the assessment and the list of Member States where the system is available. Providers must still document the assessment and show it to authorities on request.
Bias detection and AI Office powers
Special category data for bias detection
A new Article 4a lets providers of high-risk systems process special categories of personal data, such as health or ethnic origin data, where strictly necessary to detect and correct bias. The conditions are strict: other data, including synthetic or anonymized data, must not be enough, access must be controlled and documented, the data must not be shared and it must be deleted once the bias is corrected.
Providers and deployers of other AI systems may do the same under the same safeguards, but the text creates no duty to run bias detection. The proposal used a plain necessity test, and the adopted text restored the stricter one. These conditions apply in addition to the GDPR.
Stronger powers for the AI Office
The AI Office, part of the European Commission, becomes the only supervisor for two groups of AI systems (Article 75(1)):
- AI systems built on a general-purpose AI model where the same provider, or the same group of companies, develops both the model and the system. Some areas stay with national authorities: AI in Annex I products, critical infrastructure, the administration of justice and certain uses by law enforcement, border authorities and financial institutions.
- AI systems that are, or are part of, a very large online platform or very large online search engine under the Digital Services Act.
New Articles 75a to 75d give the AI Office the powers of a market surveillance authority: information requests, remote and on-site inspections, binding commitments, fines within the Article 99 limits and periodic penalty payments of up to 5% of average daily income or turnover per day. A company that builds agents on another provider's model stays with its national authority in most cases.
Other changes to the AI Act
- Safety component is defined more narrowly. AI used only for user assistance, performance optimization, efficiency, automation, convenience or non-safety quality control is not a safety component, unless its failure would endanger health or safety (Articles 3(14) and 6(1a) to 6(1c)).
- Machinery moves from Section A to Section B of Annex I, so AI in machinery follows the Machinery Regulation instead of the AI Act's high-risk regime directly.
- Overlapping product rules can be limited for products under Annex I, Section A, where sectoral law gives equal or higher protection. The Commission must adopt the delegated acts by August 2, 2027 (Article 2(13)).
- National AI regulatory sandboxes must be running by August 2, 2027 instead of August 2, 2026 (Article 57(1)).
- Post-market monitoring loses the planned mandatory template. The Commission must publish guidance with a template by September 2, 2027 (Article 72(3)).
- Value chain duties are clearer. An original provider must give a new provider the technical documentation, technical access and information on known limitations and failure modes. Breaches can now be fined (Articles 25(2) and 99(4)).
- Fundamental rights impact assessments can reuse a data protection impact assessment by cross-reference, and the AI Office will provide a template questionnaire (Article 27).
- Cybersecurity: high-risk AI systems that fall under the Cyber Resilience Act and meet the conditions of its Article 12(1) are deemed to meet the AI Act's cybersecurity requirement (Article 42(3)).
AI Act dates before and after the Omnibus
| Obligation | Before the Omnibus | After the Omnibus |
|---|---|---|
| Prohibited practices (Article 5) | February 2, 2025 | February 2, 2025 (unchanged) |
| New bans on intimate imagery and child sexual abuse material | Not in the Act | December 2, 2026 |
| AI literacy (Article 4) | February 2, 2025 | February 2, 2025, with softer wording since July 27, 2026 |
| General-purpose AI model duties | August 2, 2025 | August 2, 2025 (unchanged) |
| Article 50 transparency | August 2, 2026 | August 2, 2026 (unchanged) |
| Article 50(2) marking for generative AI already on the market | August 2, 2026 | December 2, 2026 |
| National AI regulatory sandbox | August 2, 2026 | August 2, 2027 |
| Post-market monitoring template | February 2, 2026 (implementing act) | September 2, 2027 (guidance) |
| High-risk rules, Annex III | August 2, 2026 | December 2, 2027 |
| High-risk rules, Annex I products | August 2, 2027 | August 2, 2028 |
The Commission's AI Act timeline (opens in a new tab) shows the same dates. Our EU AI Act guide for businesses places them in the full set of rules.
What it means for AI agent providers and deployers
For most AI agents in support, sales, booking and back-office work, the Omnibus changes little in practice. Those agents sit in the transparency tier, and Article 50 applied on schedule.
If you provide AI agents
- Design each agent so users learn they are dealing with an AI at the first interaction.
- If your agent generates synthetic audio, images, video or text, check how its outputs are marked. The December 2, 2026 extension only covers systems on the market before August 2, 2026.
- If an agent serves an Annex III purpose, use the time until December 2, 2027 for risk management, technical documentation and conformity assessment. SMEs and SMCs can use the simplified documentation form.
- If you test for bias, Article 4a now gives a narrow legal basis for using special category data, under strict safeguards.
If you deploy AI agents
- Keep AI literacy measures and records for staff who configure, supervise or use the agents.
- Check that each vendor's agent says it is an AI. Our AI disclosure checklist covers the points to test.
- Watch the Article 25 triggers: rebranding a high-risk system or changing an agent's purpose to a high-risk use makes you the provider.
- Ask vendors for documentation now. Under the new Article 25(2), an original provider must support a company that becomes the new provider, unless it clearly excluded high-risk use.
Our AI security consulting covers AI Act readiness, and we attack-test agents' disclosures, permissions and data handling before launch. For a short version of this guide, read what still applies after the AI Act delay.
Sources
- 1.Regulation (EU) 2026/1744 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 (Digital Omnibus on AI), EUR-Lex, Publications Office of the European Union, 2026-07-24 (opens in a new tab)
- 2.Proposal for a Regulation amending Regulations (EU) 2024/1689 and (EU) 2018/1139 (Digital Omnibus on AI), COM(2025) 836, European Commission, via EUR-Lex, 2025-11-19 (opens in a new tab)
- 3.Digital Omnibus on AI, Legislative Train Schedule, European Parliament, 2026-08-01 (opens in a new tab)
- 4.AI Act: deal on simplification measures, ban on nudifier apps, European Parliament, 2026-05-07 (opens in a new tab)
- 5.Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), EUR-Lex, Publications Office of the European Union, 2024-07-12 (opens in a new tab)
- 6.Digital Omnibus on AI Regulation Proposal, European Commission, 2026-07-27 (opens in a new tab)
- 7.AI literacy: questions and answers, European Commission, 2026-07-27 (opens in a new tab)
- 8.Timeline for the implementation of the EU AI Act, European Commission, AI Act Service Desk, 2026 (opens in a new tab)