Compliance Library Blog Product Sign In

What the Digital Omnibus Actually Changed in the EU AI Act

August 1, 2026 | 11 min read | ReguLume
eu-ai-act digital-omnibus regulatory-change delta-report

Most coverage of the Digital Omnibus reported one fact: the high-risk deadline moved. That is true, and it is the least useful thing you can know about it.

The instrument changed classification rules, added a prohibition that is in force now, restructured conformity assessment for product-embedded systems, moved machinery into a different annex section, and quietly removed several of the Commission’s powers to issue binding implementing acts. Some of those changes create work. Some remove it. A programme built on “we have until December 2027” will miss both.

This is the article-level record.


The instrument

Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026, amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 as regards the simplification of the implementation of harmonised rules on artificial intelligence — the Digital Omnibus on AI.

Published in the Official Journal on 24 July 2026. Full text on EUR-Lex.

Note that it amends three regulations, not one. If your scope work only tracked 2024/1689, you have two more instruments to read: the civil aviation regulation (2018/1139) and the machinery regulation (2023/1230).


The dates that moved

Recital (40) sets the split, and it is a split — not a single postponement:

“2 December 2027 for AI systems classified as high-risk pursuant to Article 6(2) and Annex III, and to 2 August 2028 for AI systems classified as high-risk pursuant to Article 6(1) and Annex I.”

Two things follow that are easy to get wrong.

Annex III is not “the biometrics annex.” Article 6(2) and Annex III cover the full standalone high-risk list — recruitment and worker management, credit scoring and access to essential services, education, law enforcement, migration and border control, administration of justice, as well as biometrics. Several early summaries described the December 2027 date as applying to biometric systems. It applies to all of them.

The two dates can both apply to one organisation. A manufacturer whose product embeds AI under Annex I, and who also runs an Annex III recruitment tool internally, has a December 2027 obligation and an August 2028 obligation, with different conformity routes. One programme, two clocks.

What moved is Chapter III Sections 1–3 — classification, requirements for high-risk systems, and provider obligations. That is the bulk of the engineering and documentation work.


What did not move

This is the part that gets lost.

Article 5 prohibitions are in force. They have been since 2 February 2025. Nothing in the Omnibus defers them.

Article 50 transparency obligations are in force. Since 2 August 2026. Chatbot disclosure, synthetic content marking, deepfake labelling. If you deploy a customer-facing conversational system in the EU, your obligation is live now, and it was never part of the postponement.

General-purpose AI model obligations and the Commission’s enforcement powers over them are in force. Also since 2 August 2026.

An organisation that read “the AI Act was delayed” and stood down its Article 50 work made an error the Omnibus does not protect them from.


The new prohibition

The Omnibus inserts two new points into Article 5:

  • (ba) prohibits placing on the market, putting into service, or using an AI system that generates or manipulates realistic images, video, audio or similar material of an identifiable person’s intimate parts, or of an identifiable person engaged in sexually explicit activities, without that person’s freely given, specific, informed, unambiguous and explicit consent.
  • (bb) prohibits generation or manipulation of child sexual abuse material within the meaning of Article 2, points (c) and (e), of Directive 2011/93/EU.

Scope is bounded: the prohibition bites where this is the system’s intended purpose, or where it is a reasonably foreseeable outcome absent adequate technical safeguards. For deployers, it applies where the deployer uses the system for that purpose.

Why this matters even if you are nowhere near this use case. The bounded-scope wording — “reasonably foreseeable outcome without adequate technical safeguards” — puts general-purpose image and video generation squarely in scope of a prohibition, not a high-risk requirement. Prohibitions carry the top penalty tier and do not wait for December 2027. Any organisation offering or deploying general image or video synthesis should be able to evidence what its safeguards are.


Article 50: a grace period, and a power removed

Recital (38) provides a four-month transitional period for providers who had already placed their systems on the market before 2 August 2026, to adapt marking practices without market disruption. On the face of the recital that runs to early December 2026.

Separately, the Commission’s empowerment to adopt implementing acts specifying harmonised conditions for synthetic-content marking codes of practice was removed. The Commission now encourages codes of practice and assesses their adequacy; a binding implementing act is a fallback, not the default path.

The practical effect is that the marking standard you comply with is more likely to be an industry code than a Commission act. That is a different evidence posture — you will be demonstrating adherence to a code, not conformity to a regulation-specified condition.

The same pattern repeats at Article 56 (codes of practice assessment) and Article 72 (post-market monitoring templates): binding implementing acts out, guidance and voluntary templates in.


Classification: what counts as a safety component

Article 6 gains new paragraphs that narrow high-risk classification:

  • Systems handling non-safety-related aspects — user assistance, performance optimisation, service efficiency, automation, convenience — do not qualify as safety components.
  • Systems whose failure endangers health or safety do qualify.
  • Products that fail third-party assessment only for non-health/safety reasons do not thereby trigger high-risk classification.

If you classified conservatively in 2024 and 2025 — and most organisations did, because the guidance was thin — this is the clause that lets you reclassify. It is also the clause that requires you to document why you reclassified. A narrowed scope you cannot evidence is worse than a broad one you can.


Simplification, mostly for smaller organisations

New Article 3 definitions add SME (per Recommendation 2003/361/EC) and SMC (small mid-cap, per Recommendation (EU) 2025/1099).

  • Article 11 — SMEs, start-ups and SMCs may provide Annex IV technical documentation in simplified form. The Commission must establish the simplified form by 2 August 2027.
  • Article 17 — quality management system implementation must be proportionate to organisation size.
  • Article 63 — simplified quality-management compliance extends from microenterprises to SMEs including start-ups.
  • Article 4 — the AI literacy obligation softens from ensuring literacy to taking measures to support its development.

Read together: the Omnibus reduced documentation burden for small providers and left it essentially unchanged for large ones.


Conformity assessment and notified bodies

This is the least-covered change and, for anyone shipping a regulated product, probably the most operationally significant.

  • Article 28 — notifying authorities must offer a single application and unified assessment for bodies seeking designation under both the AI Act and Annex I Section A sectoral law (MDR, IVDR and the rest).
  • Article 43 — bodies already designated under Annex I legislation may assess AI conformity provided they satisfy specified Article 31 requirements. Where sectoral law permits a harmonised-standards route without a third party, that route survives, provided the standards cover all the Article 16 Section 2 requirements. The presence of high-risk AI in a product does not by itself force third-party assessment.
  • Deadline — already-notified bodies seeking AI designation must apply by 28 January 2028.
  • Article 42 — high-risk systems meeting Cyber Resilience Act (Regulation (EU) 2024/2847) cybersecurity requirements are deemed to comply with Article 15 cybersecurity requirements.

That last one is a genuine reduction in duplicated work, and it is the kind of cross-regulation dependency that only shows up if you are reading both instruments against each other.


Sandboxes and real-world testing

  • Article 57 — each Member State must have at least one national sandbox operational by 2 August 2027. The AI Office may establish a Union-level sandbox for GPAI and systemic-risk systems, with priority access for SMEs, start-ups and SMCs.
  • Article 60 — real-world testing extends beyond Annex III to systems covered by Annex I Section A.
  • New Article 60a — Member States may permit real-world testing for high-risk systems in products under Annex I Section B, subject to notified frameworks.

Machinery moved

Regulation (EU) 2023/1230 moves from Section A to Section B of Annex I. The Commission is empowered to fold Article 6(1) high-risk requirements into the machinery regulation’s own Annex III by 2 August 2028. Until machinery-specific standards exist, manufacturers may rely on AI Act harmonised standards for presumption of conformity.

If you assessed a machinery product against Annex I Section A, that assessment now sits under a different sectoral route.


The grace period for systems already on the market

Article 111(2) is clarified: where a type and model of AI system was already placed on the market before 2 August 2027, subsequent identical units may follow without new compliance obligations, provided the design is unchanged. Significant design change triggers full Article 16 conformity.

“Unchanged design” is doing a lot of work in that sentence. For any system under continuous model updates, this is a question worth answering deliberately rather than assuming.


What this means for your programme

If you paused high-risk work: restart the classification layer, not the whole programme. Article 6’s new paragraphs may take systems out of scope, and that reclassification needs documenting while the reasoning is fresh.

If you deploy conversational or generative systems in the EU: your Article 50 obligations are live and were never postponed. If you were relying on a Commission implementing act to tell you what compliant marking looks like, that act is no longer the expected route — track the codes of practice instead.

If you ship a regulated product: the conformity assessment changes are the ones with a hard operational date. Confirm your notified body intends to seek AI designation, and note the 28 January 2028 application deadline for bodies that are already notified.

If you generate images or video: the Article 5 additions are in force and carry prohibition-tier exposure. Safeguards need to be evidenced, not asserted.

For everyone: the two-date split means a single “AI Act readiness” percentage is now misleading. Annex III and Annex I obligations have different clocks, different conformity routes and, after this instrument, partly different requirements. They need to be tracked separately.

The broader lesson is not about this instrument. Within roughly a year, the EU rescheduled its high-risk regime and Colorado repealed its AI Act before it ever took effect, replacing it with SB 26-189 effective 1 January 2027. The assumption that an enacted law will apply as written on the date originally given is no longer a safe planning assumption. What survives that volatility is work anchored to controls and frameworks rather than to section numbers.


Verification status

We publish what we have verified and mark what we have not. Every row below was checked against the Official Journal text on 1 August 2026.

Claim Source Status
Title, instrument number, date of 8 July 2026 OJ text Verified against primary source
Published in OJ 24 July 2026 OJ text Verified against primary source
Annex III → 2 Dec 2027; Annex I → 2 Aug 2028, per Art 6(2)/6(1) Recital (40), quoted verbatim above Verified against primary source
New Article 5 points (ba) and (bb) OJ text Verified against primary source
Four-month marking transitional period for systems on market before 2 Aug 2026 Recital (38) Verified against primary source
Entry into force 27 July 2026 (third day after publication) Recital (46) Derived, not read from the final article — to confirm against the consolidated text
Art 5 (ba)/(bb) transitional date Not stated in the text we retrieved. We make no claim
Art 28 / 43 notified-body deadline of 28 January 2028 Amending text Single-pass extraction — second verification pending
Art 42 CRA deemed-compliance; Art 57 sandbox date; Art 60a; Art 111(2); machinery Section A→B Amending text Single-pass extraction — second verification pending

Rows marked second verification pending were read once from the Official Journal text and have not yet had an independent confirmation pass. We would rather tell you that than let you assume otherwise. This page will be updated when they clear.


Regulatory intelligence, not legal advice. This analysis describes what an instrument says; it does not tell you what to do about it, and it is not a substitute for advice from a qualified lawyer in your jurisdiction.

ReguLume decomposes AI and data regulations to the article level and tracks what changes between versions. Superseded provisions are flagged, not deleted. How we do this.

Source: Regulation (EU) 2026/1744 — EUR-Lex

Map obligations to your AI systems

ReguLume decomposes 16 regulations to the article level and maps them to your systems. Score your compliance posture in hours, not months.

Get Started

Start your compliance assessment

Map obligations to your AI systems, identify gaps, and generate board-ready reports. Plans start at $149/mo.

Get Started