What is the Digital Omnibus on AI?
AI regulation: the EU AI Act
The Digital Omnibus on AI is an amending EU regulation that rewrites parts of the EU AI Act to make implementation more workable, mainly because standards, support tools and some national set-up work arrived late. It does not delay the whole AI Act. Instead, it mainly pushes back the main high-risk system obligations, adds two new Article 5 bans, refines Article 4 AI literacy, creates new bias-testing and enforcement tools, and simplifies several compliance steps for SMEs and value-chain actors.
What this means
The Digital Omnibus on AI is not a new AI rulebook and it is not the AI Act itself. It is a targeted amending regulation for Regulation (EU) 2024/1689, plus related changes to aviation and machinery law, designed to simplify implementation where the original timetable collided with delayed standards, delayed guidance and unfinished national conformity-assessment capacity.
As of 21 July 2026, the Omnibus had been adopted by the European Parliament, approved by the Council and signed on 8 July 2026, but no Official Journal publication was located at run time. That matters because the current AI Act dates still formally apply until publication and entry into force. So the right way to read the Omnibus is on a dual track: what the AI Act says today in force, and what the Omnibus changes once it takes legal effect.
The practical headline is simple. The EU did not postpone the AI Act across the board. The early bans and AI literacy rules stayed on schedule, GPAI and governance stayed on schedule, and Article 50 transparency still stays on its general 2 August 2026 date. What moves are mostly the core standalone and embedded high-risk system rules, plus some supporting deadlines.
Why it matters
If you build, buy, deploy or govern AI in Europe, the Omnibus changes the order in which compliance pressure arrives. It gives more time for many high-risk system obligations, but it does not give a general pass on AI governance. Organisations still need to manage what is already live, especially AI literacy, the existing Article 5 bans, GPAI duties, governance arrangements and the 2 August 2026 transparency rules.
It also matters because the Omnibus is not just a timetable exercise. It changes how to classify some product AI, how providers hand over information across the value chain, how deployers can avoid duplicate paperwork between a FRIA and a DPIA, how smaller firms can document and structure compliance, how product law and the AI Act interact, and how the AI Office can act more centrally against certain systems. For many teams, the operational question is no longer only "when do we comply?" but also "which route now applies, who owns it, and what has to be handed over to whom?"
How it works
Status at run time
Regulation (EU) 2024/1689, the AI Act, entered into force on 1 August 2024. Under the law currently in force, Chapters I and II, including AI literacy and the original Article 5 prohibitions, have applied since 2 February 2025. Chapter III Section 4 on notified bodies, Chapter V on GPAI, Chapter VII on governance, Chapter XII on penalties and Article 78 on confidentiality have applied since 2 August 2025. Most remaining provisions, including Article 50 transparency and the general high-risk system machinery of Chapters III Sections 1 to 3, are scheduled under current law for 2 August 2026.
The Omnibus procedure, 2025/0359(COD), is no longer a proposal in political limbo. Parliament adopted the final text on 16 June 2026, the Council approved it on 29 June 2026, and the final act was signed on 8 July 2026. But as of 21 July 2026, no Official Journal publication and no final regulation number were located at run time. Until that publication happens, the formal legal position remains the current AI Act timetable. Once published, the Omnibus enters into force on the third day after publication.
Why it happened
The Omnibus was driven by an implementation problem, not by a decision to abandon the AI Act's risk-based model. The adopted text says the preparation of standards was delayed, and that governance and conformity-assessment frameworks at national level were also running behind. The Commission's standardisation page now presents the Omnibus in exactly those terms: support tools, including standards, were not ready in time for the original high-risk timetable, so the law was adjusted to avoid a costly and uneven rollout.
That explanation matters because it also explains the split in the new dates. The EU did not move everything. It mainly moved the parts of the AI Act that depend most heavily on standards, conformity assessment and sectoral implementation capacity. That is why the large date changes fall on Chapter III Sections 1 to 3, not on the already-live bans, AI literacy or GPAI obligations.
What moved, and what did not
The most important correction to public commentary is this: the EU did not "delay the AI Act" as a whole. Three big parts stayed on schedule.
First, the original Article 5 prohibitions and the Article 4 literacy baseline stayed on schedule from 2 February 2025. Second, GPAI obligations, governance, notified-body rules, penalties and confidentiality stayed on schedule from 2 August 2025. Third, Article 50 transparency still has its general 2 August 2026 application date. The Commission's Article 50 guidelines, adopted on 20 July 2026, still present 2 August 2026 as the live application point.
What the Omnibus changes, once it enters into force, is mainly this. New Article 5 bans on systems used for non-consensual intimate imagery and child sexual abuse material start on 2 December 2026. The main standalone high-risk rules for systems classified under Article 6(2) and Annex III move to 2 December 2027 as the latest date. Product-embedded high-risk rules for systems classified under Article 6(1) and Annex I move to 2 August 2028. Providers of synthetic-content systems already placed on the market before 2 August 2026 get until 2 December 2026 to comply with Article 50(2). National AI regulatory sandboxes must be operational by 2 August 2027, not by 2 August 2026. Articles 102 to 110, the sectoral amendment articles, are pulled forward so they apply from the Omnibus entry into force itself.
The Commission now also frames the new high-risk dates as outer limits. Its standardisation page says 2 December 2027 and 2 August 2028 are the latest dates, and that earlier application remains possible if support tools, including standards, are ready sooner. In practical terms, that means the Omnibus gives breathing room, but it keeps pressure on the Commission and standardisers to finish the compliance stack.
New substantive changes to prohibitions, literacy and bias testing
The Omnibus is not only about delay. It adds two new Article 5 prohibitions. The first covers AI systems that generate or manipulate realistic sexual material of an identifiable person without that person's explicit consent. The second covers AI systems that generate or manipulate child sexual abuse material or performances, subject to the Directive 2011/93/EU "without right" carve-out where national law recognises it.
The final text is more precise than the headlines suggest. The market ban for these systems is limited to systems whose intended purpose is prohibited generation or manipulation, or where that outcome is a reasonably foreseeable and reproducible result of the system's design and the system lacks reasonable safeguards to prevent and correct misuse. The use ban is linked to the deployer's prohibited purpose. The text also clarifies that not every benign edit is caught. Manipulation that does not increase the exposure of intimate parts or alter the nature of depicted sexual activity is not treated as prohibited manipulation for the non-consensual intimate imagery rule.
Article 4 is also rewritten. The current law in force tells providers and deployers to ensure, to their best extent, a sufficient level of AI literacy. The Omnibus reframes this into a duty to take measures to support the development of AI literacy. It adds an explicit statement that the rule does not require anyone to guarantee a specific literacy level for any individual, requires the Commission to publish practical examples on the single information platform, and asks the AI Board to adopt recommendations with common objectives. This is a real shift in tone: from a vaguely output-based requirement to a support-and-process model.
The new Article 4a is another substantive addition. It creates a tightly bounded legal basis for processing special categories of personal data for bias detection and correction. The conditions are strict: strict necessity, no adequate alternative such as synthetic or anonymised data, privacy-preserving safeguards, no onward transmission, deletion once the bias work is done, and records explaining why the use of sensitive data was necessary. Because this new rule sits in the early-applying part of the AI Act and is expressly motivated by the need to let providers prepare for later high-risk compliance, it is designed to become usable as soon as the Omnibus itself takes legal effect.
High-risk classification, product overlap and the machinery move
A large part of the Omnibus is about stopping the AI Act from overreaching where sectoral product law already does some of the work. The first change is definitional. The Omnibus tightens the meaning of "safety component" by tying it to an intended safety function. It then adds Article 6(1a) to (1c), which says that systems used only for non-safety aspects such as user assistance, performance optimisation, convenience, service efficiency, automation or quality control are not safety components. The fail-safe is Article 6(1b): if the failure or malfunction would endanger health and safety, the system still counts as a safety component. Article 6(1c) adds that a third-party conformity assessment triggered only by non-safety risks, such as radio spectrum or electromagnetic interference issues that do not affect health and safety, does not satisfy the condition for AI Act high-risk classification under Article 6(1).
The second change is complementarity. New Article 2(13) allows the Commission to limit specific AI Act requirements for Article 6(1) product AI where Annex I sectoral law already lays down equivalent or higher protection and the overall level of protection is not reduced. This is important because it is the formal anti-duplication valve for overlaps between the AI Act and product law.
The third change is cybersecurity. New Article 42(3) says that where a high-risk AI system falls within the Cyber Resilience Act and satisfies Article 12(1) of that Act, it is deemed to comply with the AI Act's cybersecurity requirements in Article 15. That does not remove all AI Act obligations, but it does stop firms having to prove the same cybersecurity point twice under two horizontal laws.
The machinery change is structural. The Omnibus moves Regulation (EU) 2023/1230, the Machinery Regulation, from Section A to Section B of Annex I. In practice, that shifts AI-enabled machinery toward a more sectoral route. For those systems, the AI Act's direct application is narrowed to the provisions listed in Article 2(2), and the Machinery Regulation is required to absorb the relevant AI essential health and safety requirements by delegated act, with application by 2 August 2028. This is one of the clearest examples of the Omnibus preferring sector-specific integration over dual horizontal and sectoral compliance running in parallel.
SME, value-chain and assessment simplifications
The Omnibus gives smaller operators more practical relief, but not a lighter substantive standard. The best example is Article 11. SMEs, including start-ups, and small mid-cap enterprises, or SMCs, may provide Annex IV technical documentation in a simplified manner. The Commission must produce a simplified form targeted to their needs. That is simplification of format, not simplification of the underlying duty to show conformity.
Article 63 is also widened. Under the AI Act today, a simplified quality-management route was reserved to microenterprises. The Omnibus extends that possibility to SMEs, including start-ups, provided they do not have partner or linked enterprises within the meaning used in the EU SME definition. In other words, the relief is aimed at genuinely smaller operators, not groups that can hide scale behind a small subsidiary.
The Omnibus also rewrites Article 25 on responsibilities along the value chain. If a downstream actor becomes the new provider, the initial provider is no longer treated as the provider of that specific system, but it must closely cooperate and hand over what the downstream provider reasonably needs. The text specifically mentions technical documentation, known limitations and failure modes, and targeted technical access for testing and validation. Article 25(4) is also strengthened by requiring written agreements between the high-risk provider and suppliers of models, tools, services, components or processes used in the high-risk system. The free and open-source carve-out remains for public tools and components, other than GPAI models.
Deployers also benefit. Article 27 now expressly allows a FRIA to cross-reference a GDPR or Law Enforcement Directive DPIA where the DPIA already covers the same ground. The AI Office must also develop a questionnaire template, including through an automated tool, so deployers can complete the FRIA in a simplified way. This is one of the most practical changes in the Omnibus because many public and regulated users were facing overlapping rights and risk paperwork.
There is also lighter treatment in penalties for smaller firms. Member States must take SME and SMC interests and economic viability into account when applying penalties, and for SMCs the relevant fines become capped at the lower of the fixed amount or percentage figure. That is not a general immunity, but it is a real change in enforcement proportionality.
Notified bodies, conformity assessment and Annex XIV
The Omnibus tries to make conformity assessment work more like a single corridor instead of two parallel ones. Article 28 now says that where a conformity assessment body seeks designation both under the AI Act and under Annex I Section A product legislation, the notifying authority must give it the option of a single application and a unified assessment procedure. The purpose is to avoid unnecessary duplication while still checking both AI Act and sectoral-law requirements.
Article 43 does the same from the assessment side. For Annex I Section A high-risk systems, the provider continues to follow the relevant sectoral conformity-assessment procedure, but the AI Act Section 2 requirements become part of that assessment. A notified body already notified under the sectoral law can assess the AI Act requirements too, so long as the relevant AI Act notified-body competence requirements have been assessed through the notification procedure. Such bodies must still apply for AI Act designation within 18 months from the Omnibus entry into force.
Annex XIV is the support structure that makes this work. It adds a coding system for the scope of designation of notified bodies, covering product categories, Annex III biometric categories, technology types including generative AI systems, and even a residual category for "other emerging AI technologies", including agentic AI. The point is administrative clarity: a notifying authority can state exactly what kinds of AI systems a body is competent to assess, and the Commission can manage that through an electronic notification tool.
Sandboxes, real-world testing and centralised AI Office enforcement
The innovation chapter is also reshaped. Member States still have to establish national AI regulatory sandboxes, but the operational deadline moves to 2 August 2027. The Omnibus also allows the European Data Protection Supervisor to establish a sandbox for Union institutions, and lets the AI Office create a Union-level sandbox for systems that fall under its own supervisory remit. That Union-level sandbox must work closely with relevant authorities and has to give priority access to SMEs, start-ups and SMCs.
Real-world testing becomes broader. Article 60 is opened up so high-risk systems covered by Annex I Section A product legislation can also be tested in real-world conditions outside sandboxes. New Article 60a then creates a separate route for systems in Annex I Section B. Member States may allow such testing, but only through frameworks they adopt or co-adopt, and they must notify those frameworks to the Commission before implementation. Those frameworks must include a mandatory real-world testing plan and cooperation arrangements between the relevant authorities and infrastructure managers.
Finally, the Omnibus centralises more enforcement in the AI Office. Article 75 is rewritten so the AI Office has exclusive competence over certain AI systems based on GPAI models where the model and system are developed by the same provider, or providers within the same undertaking, plus AI systems that constitute or are integrated into a very large online platform or very large online search engine under the Digital Services Act. Certain sectoral and public-sector exceptions remain.
New Articles 75a to 75d then give the AI Office a fuller enforcement toolkit. It gains the powers of a market surveillance authority for those systems, can open investigations, issue formal information requests, carry out remote and on-site inspections, use external experts and auditors, accept binding commitments, adopt non-compliance decisions, impose fines and periodic penalty payments, publish key decisions, and operate under explicit procedural safeguards such as rights of defence and negotiated disclosure. For organisations affected by AI Office supervision, this is not a cosmetic change. It creates a more recognisably central EU enforcement route.
Examples
A provider of a stand-alone Annex III recruitment-screening system is the cleanest timeline example. Under the AI Act as currently in force, the provider is still looking at the 2 August 2026 phase-in for the main high-risk system obligations. If the Omnibus is published and enters into force before then, that latest application date changes to 2 December 2027. The provider does not get to ignore current work, though. It still has to track already-live duties that may apply elsewhere in its stack, and once the later high-risk date arrives it will be able to use the new FRIA and DPIA cross-reference logic where relevant.
A provider of a synthetic-image generator placed on the market before 2 August 2026 is a good Article 50 example. The general transparency rules under Article 50 still remain set for 2 August 2026. What the Omnibus adds is a specific transitional rule in Article 111(4): providers of systems already on the market before that date get until 2 December 2026 to comply with Article 50(2), the machine-readable marking duty for synthetic content. This is why saying "the Omnibus delayed Article 50" is wrong. It did not. It created a narrow transition for one category of already marketed systems.
An AI-enabled machinery manufacturer faces the product-law version of the change. The Omnibus moves machinery into the Annex I Section B route, narrows direct AI Act application for those systems, and requires the Machinery Regulation to absorb the relevant AI requirements by delegated act, to apply by 2 August 2028. That means the compliance lead has to treat machinery less like a stand-alone AI Act file and more like a coordinated sectoral file, with AI requirements increasingly carried through the machinery safety route, plus the new Article 60a real-world testing option where Member States choose to open that framework.
Common misunderstandings
"EU delayed the AI Act."
No. What moved are mainly the Chapter III Sections 1 to 3 high-risk system rules and some supporting deadlines. The original Article 5 bans and AI literacy stayed on schedule from 2 February 2025. GPAI, governance, notified bodies, penalties and confidentiality stayed on schedule from 2 August 2025. Article 50 transparency still keeps its general 2 August 2026 date.
"The Omnibus only changes dates."
Wrong. It also adds new prohibited practices, rewrites Article 4 AI literacy, creates Article 4a on bias-testing data, narrows safety-component classification, changes value-chain handover duties, simplifies FRIA and DPIA overlap, introduces notified-body single-application logic, creates a CRA deeming rule, expands sandbox and testing routes, and centralises some AI Office enforcement.
"Article 50 transparency was pushed back across the board."
Not true. The broad Article 50 timetable was not moved. What changes is a transitional rule for providers of synthetic-content systems already placed on the market before 2 August 2026, which gives them until 2 December 2026 to meet Article 50(2).
"The new Article 5 bans catch every general-purpose image or video model."
Not exactly. The final text narrows the market ban to systems whose intended purpose is prohibited generation or where prohibited output is a reasonably foreseeable and reproducible outcome without adequate safeguards. It also links the use ban to the deployer's prohibited purpose.
"The Omnibus weakens regulation of AI in products and machinery."
That overstates it. The Omnibus tries to reduce duplication and clarify sectoral routes. Product AI still remains regulated. In machinery, the route changes, but the goal is to carry AI safety requirements into the Machinery Regulation rather than drop them.
Risks and boundaries
The first boundary is legal status. As of 21 July 2026, this article has to be read on the basis that the Omnibus was adopted and signed, but no Official Journal publication was located at run time. That means the AI Act's current dates still formally stand until the Omnibus is published and enters into force. If publication happens after this article is read, the date logic will need refreshing.
The second boundary is scope. The Omnibus is a targeted amending act, not a reset of EU AI regulation. It does not rewrite the AI Act's risk-based architecture, and it does not remove the need to classify systems, manage transparency risks, prepare value-chain evidence, or build governance. It mainly redistributes timing, removes overlap, and adds some targeted substantive changes.
The third boundary is that several implementation pieces are still moving. The Commission's Article 50 guidelines were adopted on 20 July 2026, but the high-risk classification guidelines are still in draft and the related consultation runs until 23 July 2026. Some future simplifications also depend on Commission forms, questionnaires, delegated acts and further guidance. So the Omnibus improves the legal map, but it does not yet complete the operational tooling.
Nothing here is legal advice. In live programmes, especially for Annex I products, public-sector deployments, systems connected to GDPR and sectoral regulation, or AI that may fall under AI Office exclusive supervision, legal and regulatory review is still necessary.
What to do next
Treat this as a reprioritisation exercise, not a pause button. Keep immediate effort on what is already live or still on schedule: Article 4 literacy, the existing Article 5 bans, GPAI obligations where relevant, governance arrangements, and Article 50 transparency preparation for 2 August 2026.
Then re-segment your portfolio. Separate stand-alone Annex III systems, product-embedded Annex I systems, AI-enabled machinery, GPAI-linked systems, synthetic-content systems already on the market, and systems likely to sit within AI Office exclusive supervision. The Omnibus gives each of those categories a slightly different route.
Use the extra time on high-risk systems to fix the hard parts rather than to defer them. Build supplier handover clauses around Article 25, prepare for simplified but still robust documentation, reduce duplicate FRIA and DPIA work, and decide early whether your product compliance will run through sectoral law, the AI Act, or both. If you are smaller, plan to use the simplified technical-documentation form and the broader Article 63 route when they become available.
Finally, monitor two events closely: Official Journal publication of the Omnibus, and the 2 August 2026 milestone. Those two points determine whether your organisation is still governed by the current timetable or has started the Omnibus timetable.
FAQs
Has the Digital Omnibus on AI entered into force?
At run time on 21 July 2026, no Official Journal publication was located. The Omnibus had been adopted, approved and signed, but it still had to be published before it could enter into force.
Does the Omnibus delay the whole EU AI Act?
No. It mainly delays the core high-risk system obligations in Chapter III Sections 1 to 3. It does not generally delay the original Article 5 bans, Article 4 literacy, GPAI obligations, governance, notified-body rules, penalties or the general Article 50 transparency date.
What is the biggest date change for stand-alone high-risk AI?
For AI systems classified as high-risk under Article 6(2) and Annex III, the Omnibus moves the latest application date for the main high-risk obligations to 2 December 2027, once it is in force.
What is the biggest date change for AI embedded in regulated products?
For AI systems classified as high-risk under Article 6(1) and Annex I, the Omnibus moves the latest date for the main high-risk obligations to 2 August 2028.
Did the Omnibus change Article 50 transparency?
It did not move the general Article 50 date. Transparency obligations still generally apply from 2 August 2026. What it adds is a transition for providers of synthetic-content systems already on the market before that date, giving them until 2 December 2026 to comply with Article 50(2).
What is new in Article 4 on AI literacy?
The Omnibus reframes the duty from ensuring a sufficient level of literacy to supporting the development of AI literacy. It also says no one must guarantee a particular literacy level for any individual and requires Commission examples and AI Board recommendations.
Why is Article 4a important?
It gives providers a specific, tightly limited basis for using special category personal data to detect and correct bias, subject to strict safeguards. That matters because bias testing often needs protected-characteristic data that firms were previously nervous about handling.
Does the Omnibus make life easier for SMEs only on timing?
No. It also creates simplified technical documentation for SMEs and SMCs, broadens the simplified quality-management route for SMEs, requires more useful handovers across the value chain, and lets deployers simplify FRIA work by cross-referencing existing DPIAs.
