EU AI ActDigital OmnibusDeadlinesHigh-risk

The Digital Omnibus on AI: what actually changed, and what did not

Published June 6, 2026 · Updated on August 18, 2026 · 16 min read

Correction notice. An earlier version of this article, written before adoption, described the Digital Omnibus as a provisional political agreement. It is no longer one. Regulation (EU) 2026/1744 was adopted on 8 July 2026, published in the Official Journal on 24 July 2026, and has been in force since 27 July 2026. [1] It is binding law. This version has been rewritten against the OJ text rather than against press reporting, and every date, article number and quotation below comes from that text or from the consolidated AI Act as amended. Where we could not verify something, we say so.

The short version

Three things happened, and most coverage only reports the first.

  1. The high-risk deadlines moved. Annex III stand-alone high-risk systems go from 2 August 2026 to 2 December 2027. High-risk AI embedded in regulated products under Annex I goes from 2 August 2027 to 2 August 2028.
  2. The dates are fixed, not conditional. The Commission's original proposal tied the new timeline to the readiness of harmonised standards. That mechanism was removed before adoption. What survives is a recital, and recitals do not create obligations.
  3. Obligations were added, not only postponed. Two new prohibited practices enter Article 5 with effect from 2 December 2026, and a set of genuine simplifications for SMEs enter Articles 11, 17 and 63 — including a simplified Annex IV form that notified bodies are required to accept.

If you run a chatbot, a generative feature, or any AI-facing product, the postponement probably does not help you at all. Read section 5 before you relax.

The timeline, before and after

ObligationOriginal dateDate nowStatus
Prohibited practices (Art. 5) — original list2 Feb 20252 Feb 2025Unchanged, in force
Prohibited practices (Art. 5) — two new points2 Dec 2026New obligation
AI literacy (Art. 4)2 Feb 20252 Feb 2025Date unchanged, wording relaxed
GPAI model obligations (Chapter V)2 Aug 20252 Aug 2025Unchanged, in force
Penalties (Chapter XII, except Art. 101)2 Aug 20252 Aug 2025Unchanged, in force
Fines for GPAI providers (Art. 101)2 Aug 20262 Aug 2026Unchanged, in force
Transparency (Art. 50)2 Aug 20262 Aug 2026Unchanged, in force
Machine-readable marking (Art. 50(2)) — systems on the market before 2 Aug 20262 Aug 20262 Dec 2026Four-month transition
Governance, notified bodies, market surveillance2 Aug 20262 Aug 2026Unchanged, in force
High-risk — Art. 6(2) / Annex III2 Aug 20262 Dec 2027Postponed 16 months
High-risk — Art. 6(1) / Annex I2 Aug 20272 Aug 2028Postponed 12 months
Legacy high-risk systems already on the market2 Aug 20302 Aug 2030Unchanged

The amending provision is Article 1, point (40) of Regulation (EU) 2026/1744, which replaces point (c) of the third paragraph of Article 113. Its exact wording is worth reading, because it is broader than "Article 6 was delayed":

"Chapter III, Sections 1, 2, and 3, with the exception of Article 6(5), shall apply from: (i) 2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III; and (ii) 2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I". [1]

Two precision points that most summaries miss:

  • What is deferred is Chapter III Sections 1, 2 and 3 in their entirety — classification rules, the requirements themselves, and the obligations of providers and deployers. Not merely the applicability of Article 6.
  • Article 6(5) is expressly carved out and therefore still runs on the original timeline. Article 6(5) is the provision requiring the Commission to issue practical guidelines on high-risk classification. The guidance obligation was not postponed along with the substance.

The Regulation's own explanation is in Recital 40: the postponement responds to "the delayed availability of standards, common specifications, and alternative guidance and the delayed establishment of national competent authorities". [1]

No stop-the-clock: why "conditional on standards" is wrong

A large amount of published commentary — including material written in late 2025 and never revised — describes the new timeline as conditional, triggered when the Commission confirms that harmonised standards and support tools are available. That was the Commission's proposal under procedure 2025/0359(COD). The European Parliament's own Legislative Train file records the intent to "link the application timeline for rules on high-risk AI systems to the availability of standards or other tools supporting the compliance with the AI Act". [4]

It did not survive into the adopted Regulation. The final text sets fixed calendar dates and nothing else. The only residue is Recital 40, which says the Commission "should ensure that measures in support of compliance ... are in place in due time". A recital is interpretive context; it does not condition the application of Article 113.

Practically: do not plan on another slip. There is no legal mechanism in the text that would produce one automatically. A further postponement would require another amending regulation, with another full legislative cycle.

This is a good test for any compliance content you read. If an article describes the deadline as conditional on standards readiness, it was written before 8 July 2026 and has not been updated.

What was added: two new prohibited practices

This is the part that gets left out of the "AI Act delayed" headlines, and it is an outright new obligation.

Article 1, point (7) of the Omnibus inserts two new points into Article 5(1). In summary — and the exact statutory language matters, so we quote it:

"(ba) the placing on the market, the putting into service or the use of an AI system that generates or manipulates realistic images, videos, audio or similar material of an identifiable natural person's intimate parts, or of an identifiable natural person engaged in sexually explicit activities, without that person's freely-given, specific, informed, unambiguous and explicit consent for that generation or manipulation" [1]

and point (bb), covering material within the meaning of Article 2, points (c) and (e) of Directive 2011/93/EU — child sexual abuse material — subject to a "without right" defence under national law.

Recital 11 identifies the targets plainly: non-consensual intimate material, "often described as 'nudification' applications", and CSAM.

Both apply from 2 December 2026, under the amended Article 113, third paragraph, point (a), which now reads: "Chapters I and II shall apply from 2 February 2025, with the exception of Article 5(1), first subparagraph, points (ba) and (bb), and Article 5(1a) and (1b) which shall apply from 2 December 2026". [1]

The scoping test in Article 5(1a) — read this if you ship a general-purpose model

A new Article 5(1a) narrows the prohibition so it does not swallow every capable image model. It bites where:

"(i) that generation or manipulation is the intended purpose of the AI system; or (ii) the system's design, training, architecture, capabilities or user-facing functionalities make that generation or manipulation a reasonably foreseeable and reproducible outcome, without requiring significant technical modification, and the system does not have reasonable and adequate technical [safeguards]". [1]

That second limb is the operative one for most builders. A general-purpose image model with meaningful guardrails is outside the prohibition. A model whose guardrails are absent or trivially bypassed, where the output is reproducible without significant technical modification, is inside it — regardless of what the marketing page says the product is for.

If you deploy or fine-tune image or video generation, this is the provision to assess against before December 2026, and it is a prohibition, which means Article 99(3) fine exposure: up to €35 million or 7% of worldwide annual turnover.

What was simplified — and this is the part that matters most for an SME

The Omnibus is titled a simplification instrument, and for smaller companies it delivers. It also introduces a new legal category: the small mid-cap enterprise (SMC), sitting between the SME definition and the general regime.

Annex IV technical documentation — a simplified form, and notified bodies must accept it. The amended Article 11(1) now provides that SMEs, including start-ups, and SMCs "may provide the elements of the technical documentation specified in Annex IV in a simplified manner", that the Commission shall establish a simplified technical documentation form, and — the operative sentence — that "Notified bodies shall accept the form for the purposes of the conformity assessment." [1]

That last clause is the one to remember. A simplified form that a notified body could refuse would be worthless. This one they must take.

Quality management system — extended from microenterprises to all SMEs. Article 63(1) previously allowed only microenterprises to comply with certain Article 17 elements in a simplified manner. As amended, it reads: "SMEs, including start-ups, may comply with certain elements of the quality management system required by Article 17 in a simplified manner, provided that they do not have partner enterprises or linked enterprises within the meaning of Recommendation 2003/361/EC." [2]

The proviso is not decoration. If you have taken venture capital, check whether your investors make you a "linked enterprise" under Recommendation 2003/361/EC before you assume you qualify.

Proportionality written into Article 17. New Article 17(2): implementation "shall be proportionate to the size of the provider's organisation, in particular, if the provider is an SME, including a start-up, or an SMC." [1]

Penalties. Article 99(1) now requires Member States to "take into account the interests of SMEs, including start-ups, and SMCs, and their economic viability when imposing penalties." [1]

Guidance. A new Article 96(1)(g) requires Commission guidelines on complementarity and proportionality, "published by 1 August 2027", drawn up with particular attention to the needs of SMEs, start-ups and SMCs. [1]

A drafting asymmetry worth knowing which side of you are on

Article 99(6), unchanged, caps fines for SMEs and start-ups at the percentage or the fixed amount, "whichever thereof is lower" — where for everyone else it is whichever is *higher*. [3]

The Omnibus adds Article 99(6a) extending a similar cap to SMCs — but only for paragraphs 4 and 5:

"In the case of SMCs, each fine referred to in paragraphs 4 and 5 shall be up to the percentages or amount referred therein, whichever is lower." [1]

Paragraph 3 — the prohibited-practices tier, €35 million or 7% — is not in the SMC list. An SME gets the lower-of cap across paragraphs 3, 4 and 5. An SMC does not get it for Article 5 breaches. If you are near the SME/SMC boundary, that distinction is worth several million euros.

What did not move, and why the delay may not help you

Article 50 transparency has applied since 2 August 2026. It sits in Chapter IV, which was not carved out of Article 113's general application date. If you operate a chatbot, generate synthetic content, or run emotion recognition or biometric categorisation, you are in scope now.

The only element with a transition is Article 50(2) — provider-side machine-readable marking of synthetic output — and the new Article 111(4), inserted by Article 1, point (39)(b), defines it narrowly:

"Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, that have been placed on the market before 2 August 2026 shall take the necessary steps in order to comply with Article 50(2) by 2 December 2026." [1]

Recital 38 confirms the purpose: "a transitional period of four months for providers who have already placed their systems on the market before the 2 August 2026". [1]

*Three things follow, and they are commonly got wrong:*

  1. The trigger is the system, not the content. Nothing turns on when a given piece of output was generated. What matters is whether the system was on the market before 2 August 2026. A system launched in September 2026 has no transition — Article 50(2) applies to it from day one.
  2. It covers Article 50(2) only. Article 50(1) interaction disclosure, Article 50(3) emotion recognition and biometric categorisation, and Article 50(4) deployer disclosure of deep fakes all bite in full since 2 August 2026, with no grace period.
  3. It binds providers, not deployers. If you deploy someone else's generative system, Article 111(4) is not your transition.

Also unchanged: prohibited practices from the original list (2 February 2025), AI literacy (2 February 2025), GPAI model obligations (2 August 2025), penalties (2 August 2025, except Article 101 from 2 August 2026), and the governance and market-surveillance machinery (2 August 2026).

Article 4 AI literacy: relaxed, not removed

Article 1, point (5) replaces Article 4 entirely. The duty moved from "ensure a sufficient level of AI literacy" to:

"Providers and deployers of AI systems shall take measures to support the development of AI literacy of their staff ... This obligation does not require providers or deployers to guarantee any specific level of AI literacy of any individual." [1]

Recital 8 confirms the change was deliberate: a solution imposing stringent obligations to "ensure a sufficient level of AI literacy" was judged unsuitable for all types of providers and deployers.

New Article 4(2) obliges the Commission to publish practical compliance examples on the single information platform under Article 62(3)(b), and Article 4(3) tasks the Board with recommendations informed by European competence frameworks.

Read this correctly in both directions. The obligation still exists and has applied since 2 February 2025. What was removed is any implication that you must test your staff and certify a level. A vendor selling you a mandatory certification-and-examination programme as the route to Article 4 compliance is selling more than the Article requires.

One honest caveat on the enforcement date. You will see both "2 August 2026" and "3 August 2026" quoted for when supervision of Article 4 begins — the European Commission's own AI literacy FAQ states both, on the same page. [5] Neither date appears in the Regulation. The legal hook is Article 113's general application date of 2 August 2026, when the Chapter IX market-surveillance provisions took effect. We cite 2 August 2026 and flag the discrepancy rather than pretending it is settled.

Five changes that got almost no coverage

Safety components were narrowed (Article 6(1a) and (1b)). New Article 6(1a): AI systems "solely used for non-safety related aspects of user assistance, performance optimisation, service efficiency, automation or convenience or quality control shall not qualify as safety components." Article 6(1b) restores the qualification where "failure or malfunctioning ... would endanger health and safety." [1] Recital 20 adds that Article 6(1) should not be read to require products embedding a high-risk AI system to automatically undergo third-party conformity assessment by a notified body. For anyone embedding AI in a physical product, this is the most useful paragraph in the Omnibus.

FRIA and DPIA became interoperable (Article 27(4)). The old text said a FRIA "shall complement" an existing data protection impact assessment. The new text lets the deployer "include cross-references to the relevant sections of that data protection impact assessment or include relevant parts thereof". [1] Not a merger, not a substitution — you still conduct a FRIA — but you may now populate it by reference. New Article 27(5) requires the AI Office to develop a questionnaire template, "including through an automated tool", to simplify this.

A legal basis for processing special-category data to detect bias (new Article 4a). Providers "may exceptionally process special categories of personal data" for bias detection and correction, subject to necessity, safeguards, documented justification, and deletion "once the bias has been corrected or the personal data has reached the end of its retention period, whichever comes first". [1] Article 4a(2) extends this to providers and deployers of other AI systems and models. If your fairness testing was previously blocked on GDPR Article 9, this is the provision that unblocks it — under conditions.

The AI Office gained exclusive competence over integrated GPAI systems (Article 75). Where a general-purpose model and the system built on it come from the same provider or the same undertaking, supervision moves to the AI Office rather than national market surveillance — as it does for systems integrated into a VLOP or VLOSE designated under the DSA. Serious-incident reporting follows the competence: new Article 75(1a) provides that, by way of derogation from Article 73, those providers report to the AI Office, with Article 73(2)–(9) applying *mutatis mutandis*. Article 73's own two-day and ten-day deadlines are unchanged; only the recipient changes. [1]

Machinery moved out of the AI Act's Annex I Section A. Article 1, point (41) deletes point 1 of Annex I Section A and adds Regulation (EU) 2023/1230 on machinery to Section B. Article 2 of the Omnibus requires corresponding delegated acts under the Machinery Regulation; Recital 42 states they should apply by 2 August 2028. [1] Manufacturers of AI-enabled machinery should re-check which instrument now carries their conformity route.

What to actually do between now and December 2027

The postponement bought calendar time for high-risk documentation. It bought nothing for transparency, prohibitions or literacy, and it added two obligations. A sensible sequence:

*Before 2 December 2026 — hard deadlines.*

  • If any system you provide generates synthetic content and was on the market before 2 August 2026, implement Article 50(2) machine-readable marking. This is the four-month window, and it closes.
  • If you build or fine-tune image, video or audio generation, assess against the new Article 5(1)(ba) and (bb) using the Article 5(1a) test — intended purpose, or reasonably foreseeable and reproducible output without significant technical modification, absent adequate safeguards.

*Now, and already overdue.*

  • Article 50(1), (3) and (4) disclosures. In force since 2 August 2026, no transition.
  • Article 4 measures supporting AI literacy. In force since February 2025. Measures, documented — not certificates.

*Through 2027 — use the runway rather than spending it.*

  • Maintain an inventory of the AI systems you provide and deploy, with a documented Article 6 classification for each. Note that if you rely on Article 6(3) to conclude a system is not high-risk, Article 6(4)'s duty to document that assessment before placing it on the market is unchanged, and Recital 22 restates it.
  • Start Annex IV documentation on the assumption you will use the simplified SME form, and track the Commission's publication of it.
  • Check whether Article 6(1a) takes any embedded system of yours out of the safety-component category. If it does, document why.
  • Determine whether you are an SME, an SMC, or neither. It changes your Annex IV burden, your Article 17 obligations, and your fine cap.
  • Re-verify in February 2027. The Commission owes guidance under Article 6(5) and, by 1 August 2027, under Article 96(1)(g).

Questions we get asked

Has the EU AI Act been delayed? Only the high-risk chapter, and only for the two categories in section 1. Prohibitions, GPAI obligations, penalties, transparency and AI literacy all remain on their original dates — and two new prohibitions arrive on 2 December 2026.

Our product is a chatbot. Does the delay apply to us? No. A chatbot's obligation is Article 50(1) transparency, which has applied since 2 August 2026 and was not postponed. The high-risk deferral is irrelevant to you unless your chatbot also falls under Annex III.

We launched a generative feature in September 2026. Do we have until 2 December to mark our output? No. Article 111(4) applies to systems placed on the market before 2 August 2026. A system launched afterwards is subject to Article 50(2) immediately.

Can these dates slip again? Not automatically. The adopted text contains no conditional trigger — that was dropped from the Commission's proposal. Another postponement would require a further amending regulation.

Did the AI literacy obligation go away? No. It was reworded from "ensure a sufficient level" to "take measures to support the development of", and the new text states expressly that you need not guarantee any individual's level. The duty itself stands and has applied since 2 February 2025.

We are a deployer, not a provider. Does the deferral help us? Yes for Chapter III Section 3 deployer obligations, which move with the rest. No for Article 50(4) deep-fake disclosure, Article 4 literacy, or Article 26 obligations that fall outside the deferred sections. And note Article 25: a deployer that puts its name on a high-risk system, modifies its intended purpose, or substantially modifies it becomes a provider.

Does ISO 42001 certification make us compliant? No. ISO/IEC 42001 is a management-system standard for AI. It is a strong foundation and will likely support conformity arguments, but it does not discharge Annex III classification, Annex IV documentation, Article 27 FRIA or Article 50 transparency.

Sources

*Primary*

[1] Regulation (EU) 2026/1744 (Digital Omnibus on AI) — authentic Official Journal text: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202601744 · ELI: https://eur-lex.europa.eu/eli/reg/2026/1744/oj [2] Consolidated Regulation (EU) 2024/1689 as amended, version of 27 July 2026 — https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A02024R1689-20260727 *(EUR-Lex consolidated texts are editorial and not legally authoritative; used here to identify which provisions carry amendment markers)* [3] Regulation (EU) 2024/1689 (EU AI Act), original text — https://eur-lex.europa.eu/eli/reg/2024/1689/oj [4] European Parliament, Legislative Train — Digital Omnibus on AI, procedure 2025/0359(COD) — https://www.europarl.europa.eu/legislative-train/package-digital-package/file-digital-omnibus-on-ai [5] European Commission — AI literacy questions and answers — https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers

*Secondary, for a second reading*

[6] White & Case — EU AI Omnibus enters into force, amending the AI Act — https://www.whitecase.com/insight-alert/eu-ai-omnibus-enters-force-amending-ai-act [7] Gibson Dunn — EU AI Act Omnibus agreement: postponed high-risk deadlines and other key changes — https://www.gibsondunn.com/eu-ai-act-omnibus-agreement-postponed-high-risk-deadlines-and-other-key-changes/ [8] Council of the EU, press release of 7 May 2026 (provisional agreement stage) — https://www.consilium.europa.eu/en/press/press-releases/2026/05/07/artificial-intelligence-council-and-parliament-agree-to-simplify-and-streamline-rules/

Legislative history, for the record: EP position 16 June 2026; Council decision 29 June 2026; EDPS/EDPB joint opinion 20 January 2026; EESC opinion 18 March 2026; ECB opinion OJ C/2026/2285 of 15 April 2026. All recorded in the OJ text at [1].

This article states the law as published. It is not legal advice. If a statement here is inaccurate, tell us and we will correct it with a dated note.

Related guides