The Digital Omnibus for AI is here: what is actually changing?

A few months ago, we wrote about the compromise that the Council and Parliament had reached on the Digital Omnibus for AI. At that time, the formal publication was still pending, but substantively almost everything was already clear. In the meantime, the final step has been taken: last Friday, the Omnibus was published in the Official Journal as Regulation 2026/1744, and three days later, last Monday, it formally entered into force. With this, the AI Act has been definitively amended on several points.

In this blog, we will go through the most important substantive changes and what they concretely mean for organisations working with the AI Act. For the broader context of how we arrived at this compromise, we refer you to our earlier blog.

Postponement of High-Risk AI: Fixed Dates, No Ifs or Buts

The most eye-catching element of the Omnibus (but actually the least exciting legally) is the postponement of obligations for high-risk AI systems. The conditional mechanism that the Commission originally envisaged, whereby entry into force would be linked to a decision on the availability of compliance instruments, did not make it through. The Council and Parliament wanted fixed dates, and that is exactly what has been delivered.

Concretely, this means that Annex III applications will only become applicable from 2 December 2027, and Annex I applications from 2 August 2028. Existing high-risk AI systems that were put into use before 2 August 2026 retain their original compliance deadline of December 2030.

Important to emphasise: this postponement applies exclusively to the high-risk regime. The rules on prohibited practices and general-purpose AI are already active; and, importantly, the transparency obligations of Article 50 will still take effect on 2 August this year. On LinkedIn, we regularly see the mistaken impression arising that "everything" has been postponed. That is not the case. Chatbots must have their disclaimers in order, and generated content must be marked in a machine-readable way. Only for generative (GP)AI systems is there a brief respite: for them, the transparency obligations are pushed back a few months to 2 December 2026.

Two New Prohibited Practices: NCII and CSAM

As expected, the two prohibited practices that the Council and Parliament had jointly proposed have been incorporated one-to-one into the Omnibus. These concern AI systems that can generate realistic intimate images or videos of an identifiable person without that person's freely given, specific, informed and unambiguous consent, and AI systems that can generate child sexual abuse material within the meaning of the relevant directive.

The fact that both co-legislators had submitted word-for-word the same amendment already indicated the political urgency: this had to be included, and quickly. The trigger was the Grok controversy from late last year, which made it easy to generate such sensitive material. These prohibitions will enter into force on 2 December 2026, giving providers a few extra months to get their safeguards in order.

AI Literacy: Obligation Remains, Standard Disappears

On the point of AI literacy, a compromise has ultimately been reached that appears subtle at first glance. The primary obligation of Article 4 remains with organisations that deploy AI: they must take measures to support and develop the AI literacy of their personnel.

What has been added is an explicit softening: this obligation does not entail that a certain level of AI literacy must be guaranteed for individual persons. Translated into practice, this means that regulators may not require that employees have completed a specific training or have achieved a certain level of competence. It is in fact a shift from an obligation of result towards something more resembling an obligation of means.

For most organisations, this will change little in practice. Those who were seriously engaged with AI literacy will continue to do so. But it makes enforcement by regulators considerably more difficult, which should give organisations somewhat more room to breathe.

Processing of Special Categories of Personal Data: Expansion, But with Safeguards

One of the most substantively far-reaching changes concerns the processing of special categories of personal data for bias detection. The existing Article 10(5), which opened up this possibility exclusively for high-risk AI systems in the training phase, has been moved to a new article 4a and broadened.

The expansion consists of two elements. First, the possibility is now also opened up for AI systems other than high-risk, including general-purpose AI, provided it is strictly necessary for detecting bias that is likely to have consequences for fundamental rights. Second, deployers of high-risk AI systems also gain this possibility, so that they can test in their own context whether the system does not discriminate.

From the privacy domain, considerable criticism has been voiced on this point, and that criticism is understandable. Special categories of personal data that were once collected for a specific purpose with consent can now be used under a legal basis for model evaluation, without additional consent from the data subjects. This is an expansion that data subjects themselves may well view differently. At the same time, the legal utility is also evident: if general-purpose models can be better tested for discrimination, compliance further down the chain becomes easier and injustice can also be prevented. It is therefore always a balancing act.

Other Notable Points

Besides these main points, there are several changes worth mentioning.

For SMEs, multiple alleviations are being introduced: simplified technical documentation, a proportionate quality management system, priority access to sandboxes, and lower fines. Honestly, the heaviest compliance obligations remain substantively in place; so the question is how significant the impact of this will really be.

Regulatory sandboxes receive a hard deadline: Member States must have their sandbox operational by 2 August 2027 at the latest. This was sorely needed as a stick behind the door; after all, in the Netherlands, not even a supervisory authority has been designated yet. Additionally, the AI Office itself gains the authority to set up a Union-wide sandbox, and testing under real-world conditions is made possible for Annex I applications, which is particularly relevant for the automotive sector.

The AI Office receives exclusive supervisory authority for AI systems based on general-purpose AI models when the model and system come from the same provider. This means that the ChatGPTs, Claudes and Geminis of this world no longer go through the national supervisory authority such as in Ireland, but fall directly under European supervision. Including periodic penalty payments of up to 5% of worldwide daily turnover. Whether that supervision will also be effective with regard to non-EU providers remains a question. Whether Chinese models such as DeepSeek or Kimi K2 feel committed to the rules is highly questionable. The law is there; the enforcement possibilities are another story.

Conclusion

With this Omnibus, the AI Act has been amended on several points, but it is not a fundamental revision. The high-risk obligations themselves have not been substantively touched (except for special categories of personal data). The GPAI regime remains unchanged. The transparency obligations remain in place. What has mainly been shifted are the deadlines, which is now the most important practical takeaway for organisations.

The extra time is sorely needed, because the guidance and harmonised standards are still not finished. This immediately sets the stage for blog posts in the coming months: the draft guidance on high-risk AI published by the Commission in May, and the state of play regarding harmonized standards. Because there is plenty to say about that as well.

For now: mark 2 December 2027 and 2 August 2028 in your calendar, and use your time wisely.

In the meantime, watch the recording of our webinar from July 28 on high-risk AI systems and compliance for 2027 (Dutch audio only).

Webinar EU Omnibus AI Act update

Back to overview