Skip to content

Regulation

The EU Digital Omnibus on AI: what changed in 2026

The Digital Omnibus on AI is the package of targeted amendments to the EU AI Act adopted in 2026. Published as Regulation (EU) 2026/1744 (opens in a new tab) and in force since July 27, 2026, it delays the high-risk rules, softens the AI literacy duty, extends relief to small mid-cap companies, adds two bans and gives the Commission's AI Office direct powers over some AI systems.

By the KDS security engineering teamPublished 10 min read

Key takeaways

  • Regulation (EU) 2026/1744 was signed on July 8, 2026, published on July 24 and entered into force on July 27, 2026.
  • High-risk rules now apply from December 2, 2027 (Annex III) and August 2, 2028 (Annex I). Both are fixed dates.
  • Article 50 transparency still applied from August 2, 2026. Only marking for existing generative AI systems moved, to December 2, 2026.
  • Two Commission proposals changed before adoption: dropping registration for Article 6(3) systems and removing the AI literacy duty for companies.
  • New bans on non-consensual intimate imagery and AI-generated child sexual abuse material apply from December 2, 2026.
On this page

How the Digital Omnibus on AI became law

The Omnibus is part of the European Commission's wider plan to simplify EU digital rules. It went through the ordinary legislative procedure under reference 2025/0359(COD), from proposal to entry into force in about eight months.

Legislative path of Regulation (EU) 2026/1744
DateStep
November 19, 2025The Commission proposes the Digital Omnibus on AI, COM(2025) 836
March 13, 2026The Council agrees its negotiating position
March 2026Parliament adopts its negotiating position in plenary
May 7, 2026Parliament and Council negotiators reach a provisional agreement
May 13, 2026Member State ambassadors (Coreper) approve the agreement
June 16, 2026Parliament approves the text in plenary
June 29, 2026The Council adopts the regulation
July 8, 2026The Presidents of Parliament and Council sign it
July 24, 2026Publication in the Official Journal of the EU
July 27, 2026Entry into force, on the third day after publication
Legislative path of Regulation (EU) 2026/1744

The dates come from the European Parliament's Legislative Train (opens in a new tab) and the published regulation. The co-legislators wanted the law in force before August 2, 2026, the original start date for high-risk rules, and it entered into force 6 days before that date.

Recital 40 explains the main reason for the delay: standards, common specifications and guidance for high-risk systems were late, and national competent authorities were set up late.

Digital Omnibus changes to AI Act deadlines

This guide covers the changes that matter for companies that build or use AI. The Omnibus also amends EU aviation and machinery law and the procedures for notified bodies, which we mention only where they affect AI systems directly.

High-risk dates, now fixed

The requirements for high-risk AI systems in Chapter III, Sections 1 to 3, now apply from December 2, 2027 for systems listed in Annex III and from August 2, 2028 for AI in products covered by Annex I. The original dates were August 2, 2026 and August 2, 2027.

The Commission proposal (opens in a new tab) had a moving start: the rules would apply 6 or 12 months after a Commission decision that standards and support tools were ready, with the 2027 and 2028 dates as the latest possible start. That mechanism was dropped. Article 113 now sets fixed dates.

The grace period in Article 111(2) was also clarified. High-risk systems placed on the market before the new dates stay outside the rules until their design changes significantly. Recital 39 explains that the test is the first unit of a type and model, so later units of an unchanged model are covered too. High-risk systems used by public authorities must comply by August 2, 2030 in any case.

Transparency: one short extension

Article 50 was not delayed and has applied since August 2, 2026. The only change concerns machine-readable marking of AI-generated content under Article 50(2). Providers of generative AI systems placed on the market before August 2, 2026 have until December 2, 2026 to comply (new Article 111(4)). The Commission had proposed February 2, 2027, and the co-legislators shortened it.

Article 50(7) now says the Commission assesses whether codes of practice on marking and labeling are adequate, and can adopt common rules by implementing act if they are not. For the duties themselves, see our Article 50 guide.

AI literacy: softened, not removed

The Commission proposed to turn Article 4 into a duty for the Commission and Member States to encourage AI literacy. The adopted text keeps a duty on companies. Providers and deployers must take measures to support the AI literacy of their staff and others who operate or use AI on their behalf, and the text adds that they do not have to guarantee a specific level for any individual.

The Commission must publish practical examples of how to comply, and the European Artificial Intelligence Board will adopt recommendations. The Commission's AI literacy Q&A (opens in a new tab) confirms that no certificate is needed.

Two new prohibited practices

Parliament and Council added two bans to Article 5 that were not in the Commission proposal. From December 2, 2026, it is prohibited to place on the market, put into service or use AI systems that generate or manipulate:

  • Realistic images, video or audio of an identifiable person's intimate parts, or of that person in sexually explicit activity, without the person's explicit consent
  • Child sexual abuse material as defined in Directive 2011/93/EU

For providers, the ban applies when this is the system's intended purpose, or when the system can foreseeably do it without significant modification and lacks reasonable safeguards to prevent it. For deployers, it applies when they use a system for that purpose. Providers of general image, video and audio generators should test their safeguards against this standard.

Relief for smaller companies and simpler registration

SMEs and small mid-caps

The Omnibus defines small mid-cap enterprises (SMCs) by reference to Commission Recommendation (EU) 2025/1099 and extends several measures for small and medium-sized enterprises (SMEs) to them:

  • SMEs, start-ups and SMCs can provide high-risk technical documentation in a simplified form, on a Commission template that notified bodies must accept (Article 11).
  • Quality management must be proportionate to the provider's size, and the text now names SMEs and SMCs (Article 17). All SMEs without partner or linked enterprises, not only microenterprises, can use the simplified option (Article 63).
  • For SMCs, fines for most breaches are capped at the lower of the fixed amount and the turnover percentage, as for SMEs (Article 99(6a)).
  • SMEs and SMCs get priority access to a Union-level AI regulatory sandbox that the AI Office may set up (Article 57(3a)).

Registration kept, with less information

The Commission proposed to delete the duty to register Annex III systems that a provider considers not high-risk under Article 6(3). The co-legislators kept the registration and cut its content instead. Two items in Annex VIII, Section B are deleted: the summary of the grounds for the assessment and the list of Member States where the system is available. Providers must still document the assessment and show it to authorities on request.

Bias detection and AI Office powers

Special category data for bias detection

A new Article 4a lets providers of high-risk systems process special categories of personal data, such as health or ethnic origin data, where strictly necessary to detect and correct bias. The conditions are strict: other data, including synthetic or anonymized data, must not be enough, access must be controlled and documented, the data must not be shared and it must be deleted once the bias is corrected.

Providers and deployers of other AI systems may do the same under the same safeguards, but the text creates no duty to run bias detection. The proposal used a plain necessity test, and the adopted text restored the stricter one. These conditions apply in addition to the GDPR.

Stronger powers for the AI Office

The AI Office, part of the European Commission, becomes the only supervisor for two groups of AI systems (Article 75(1)):

  • AI systems built on a general-purpose AI model where the same provider, or the same group of companies, develops both the model and the system. Some areas stay with national authorities: AI in Annex I products, critical infrastructure, the administration of justice and certain uses by law enforcement, border authorities and financial institutions.
  • AI systems that are, or are part of, a very large online platform or very large online search engine under the Digital Services Act.

New Articles 75a to 75d give the AI Office the powers of a market surveillance authority: information requests, remote and on-site inspections, binding commitments, fines within the Article 99 limits and periodic penalty payments of up to 5% of average daily income or turnover per day. A company that builds agents on another provider's model stays with its national authority in most cases.

Other changes to the AI Act

  • Safety component is defined more narrowly. AI used only for user assistance, performance optimization, efficiency, automation, convenience or non-safety quality control is not a safety component, unless its failure would endanger health or safety (Articles 3(14) and 6(1a) to 6(1c)).
  • Machinery moves from Section A to Section B of Annex I, so AI in machinery follows the Machinery Regulation instead of the AI Act's high-risk regime directly.
  • Overlapping product rules can be limited for products under Annex I, Section A, where sectoral law gives equal or higher protection. The Commission must adopt the delegated acts by August 2, 2027 (Article 2(13)).
  • National AI regulatory sandboxes must be running by August 2, 2027 instead of August 2, 2026 (Article 57(1)).
  • Post-market monitoring loses the planned mandatory template. The Commission must publish guidance with a template by September 2, 2027 (Article 72(3)).
  • Value chain duties are clearer. An original provider must give a new provider the technical documentation, technical access and information on known limitations and failure modes. Breaches can now be fined (Articles 25(2) and 99(4)).
  • Fundamental rights impact assessments can reuse a data protection impact assessment by cross-reference, and the AI Office will provide a template questionnaire (Article 27).
  • Cybersecurity: high-risk AI systems that fall under the Cyber Resilience Act and meet the conditions of its Article 12(1) are deemed to meet the AI Act's cybersecurity requirement (Article 42(3)).

AI Act dates before and after the Omnibus

AI Act application dates before and after Regulation (EU) 2026/1744
ObligationBefore the OmnibusAfter the Omnibus
Prohibited practices (Article 5)February 2, 2025February 2, 2025 (unchanged)
New bans on intimate imagery and child sexual abuse materialNot in the ActDecember 2, 2026
AI literacy (Article 4)February 2, 2025February 2, 2025, with softer wording since July 27, 2026
General-purpose AI model dutiesAugust 2, 2025August 2, 2025 (unchanged)
Article 50 transparencyAugust 2, 2026August 2, 2026 (unchanged)
Article 50(2) marking for generative AI already on the marketAugust 2, 2026December 2, 2026
National AI regulatory sandboxAugust 2, 2026August 2, 2027
Post-market monitoring templateFebruary 2, 2026 (implementing act)September 2, 2027 (guidance)
High-risk rules, Annex IIIAugust 2, 2026December 2, 2027
High-risk rules, Annex I productsAugust 2, 2027August 2, 2028
AI Act application dates before and after Regulation (EU) 2026/1744

The Commission's AI Act timeline (opens in a new tab) shows the same dates. Our EU AI Act guide for businesses places them in the full set of rules.

What it means for AI agent providers and deployers

For most AI agents in support, sales, booking and back-office work, the Omnibus changes little in practice. Those agents sit in the transparency tier, and Article 50 applied on schedule.

If you provide AI agents

  • Design each agent so users learn they are dealing with an AI at the first interaction.
  • If your agent generates synthetic audio, images, video or text, check how its outputs are marked. The December 2, 2026 extension only covers systems on the market before August 2, 2026.
  • If an agent serves an Annex III purpose, use the time until December 2, 2027 for risk management, technical documentation and conformity assessment. SMEs and SMCs can use the simplified documentation form.
  • If you test for bias, Article 4a now gives a narrow legal basis for using special category data, under strict safeguards.

If you deploy AI agents

  • Keep AI literacy measures and records for staff who configure, supervise or use the agents.
  • Check that each vendor's agent says it is an AI. Our AI disclosure checklist covers the points to test.
  • Watch the Article 25 triggers: rebranding a high-risk system or changing an agent's purpose to a high-risk use makes you the provider.
  • Ask vendors for documentation now. Under the new Article 25(2), an original provider must support a company that becomes the new provider, unless it clearly excluded high-risk use.

Our AI security consulting covers AI Act readiness, and we attack-test agents' disclosures, permissions and data handling before launch. For a short version of this guide, read what still applies after the AI Act delay.

Sources

  1. 1.Regulation (EU) 2026/1744 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 (Digital Omnibus on AI), EUR-Lex, Publications Office of the European Union, 2026-07-24 (opens in a new tab)
  2. 2.Proposal for a Regulation amending Regulations (EU) 2024/1689 and (EU) 2018/1139 (Digital Omnibus on AI), COM(2025) 836, European Commission, via EUR-Lex, 2025-11-19 (opens in a new tab)
  3. 3.Digital Omnibus on AI, Legislative Train Schedule, European Parliament, 2026-08-01 (opens in a new tab)
  4. 4.AI Act: deal on simplification measures, ban on nudifier apps, European Parliament, 2026-05-07 (opens in a new tab)
  5. 5.Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), EUR-Lex, Publications Office of the European Union, 2024-07-12 (opens in a new tab)
  6. 6.Digital Omnibus on AI Regulation Proposal, European Commission, 2026-07-27 (opens in a new tab)
  7. 7.AI literacy: questions and answers, European Commission, 2026-07-27 (opens in a new tab)
  8. 8.Timeline for the implementation of the EU AI Act, European Commission, AI Act Service Desk, 2026 (opens in a new tab)

Get a free 30-minute assessment

Walk us through the AI tools and agents you use or plan to launch. We'll point out the biggest risks and the first fixes, in plain words.

Frequently asked questions

What is the Digital Omnibus on AI?

It is Regulation (EU) 2026/1744, a set of targeted amendments to the EU AI Act. The European Commission proposed it in November 2025 as part of its plan to simplify EU digital rules. Parliament and Council adopted it in June 2026, and it entered into force on July 27, 2026. It delays the high-risk rules, adjusts several duties and adds two prohibited practices.

When do the high-risk AI rules apply after the Omnibus?

From December 2, 2027 for high-risk systems listed in Annex III, such as AI used in hiring, credit scoring or education, and from August 2, 2028 for AI that is a safety component of products covered by Annex I, such as medical devices. These are fixed dates. The Commission's proposal to link them to the availability of standards was not adopted.

Did the Digital Omnibus remove the AI literacy obligation?

No. The Commission proposed to move the duty to the Commission and Member States, but the adopted text keeps it for providers and deployers. They must take measures to support the AI literacy of staff and others who use AI on their behalf. The text now states that no specific level has to be guaranteed, and the Commission says no certificate is needed.

Does the Omnibus change the Article 50 transparency deadline?

Not for most duties. Article 50 has applied since August 2, 2026. The only extension covers machine-readable marking of AI-generated content: providers of generative AI systems placed on the market before August 2, 2026 have until December 2, 2026. Systems placed on the market from August 2, 2026 must comply from the start.

What does the Omnibus mean for small companies?

SMEs, start-ups and the new category of small mid-cap enterprises can use simplified technical documentation for high-risk systems and get priority access to a Union-level sandbox. Small mid-caps also get the lower fine cap that SMEs already had for most breaches. All SMEs without partner or linked enterprises can use a simplified quality management system.

Services and use cases

  • Service

    AI security and red teaming

    AI security consulting for AI agents and LLM apps: red teaming, prompt injection testing, shadow AI discovery and EU AI Act and ISO/IEC 42001 readiness.

    Explore AI security consulting

Free 30-minute assessment

Find the one workflow worth automating first.

Tell us how your team works. We'll come back with two or three AI opportunities, the risks to watch and a rough payback estimate. No obligation.

  • A senior engineer replies within one business day
  • We can sign an NDA before you share details
  • No fixed packages, every quote tailored to you
What can we help with?
About your company

Company size

When would you like to start?

How can we reach you?

Encrypted in transit · read only by our team · never sold

Free 30-minute AI assessmentGet it →

Before you go

Find out where AI can save your team time

Book a free 30-minute assessment. A senior engineer reviews one workflow with you and sends back the opportunities, the risks and a rough payback estimate.