InsightsEU AI Act
Deferred, not cancelled: what the Digital Omnibus changes.
Regulation (EU) 2026/1744 has applied since 27 July 2026. The deadlines for high-risk AI move, but most of the AI Act stands. What changed, what didn’t, and what that means for your planning.
In November 2025 the European Commission proposed targeted amendments to the AI Act, as part of a broader package to simplify digital rules. A little over eight months later, that proposal is law. The key message: the requirements for high-risk AI arrive later, but they do arrive. And for most other obligations the date doesn’t change.
Why there was an omnibus
The requirements for high-risk systems were due to apply on 2 August 2026. The harmonised standards and guidance that organisations need to meet those requirements in practice were not ready by then. Businesses asked for clarity, and in many member states supervision was still being set up.
The legislative process then moved quickly. Parliament and Council reached agreement on 7 May 2026, the European Parliament approved it on 16 June and the Council on 29 June. The regulation was published in the Official Journal on 24 July and has applied since 27 July 2026.
What moves
The chart sets the original dates against the dates that now apply. Hover over a row or use the Tab key for details.
- Original date
- Date that applies
- Today
View as table
| Part | Original | Now |
|---|---|---|
| Prohibited practices (Art. 5) | 2 February 2025 | 2 February 2025 |
| AI literacy (Art. 4) | 2 February 2025 | 2 February 2025 |
| General-purpose AI models | 2 August 2025 | 2 August 2025 |
| Transparency obligations (Art. 50(1), (3) and (4)) | 2 August 2026 | 2 August 2026 |
| Marking AI-generated content, existing systems (Art. 50(2)) | 2 August 2026 | 2 December 2026 |
| New prohibitions: intimate deepfakes and CSAM | not applicable | 2 December 2026 |
| High risk, Annex III | 2 August 2026 | 2 December 2027 |
| High risk, Annex I | 2 August 2027 | 2 August 2028 |
- High risk, Annex III: use cases such as recruitment and selection, credit scoring, education and access to essential services. New date: 2 December 2027.
- High risk, Annex I: AI in products already covered by EU product legislation, such as medical devices. New date: 2 August 2028.
- Marking AI-generated content: generative systems on the market before 2 August 2026 have until 2 December 2026 to mark their output in a machine-readable way. New systems must comply immediately.
High-risk systems already on the market before the new date only fall under the requirements after a substantial modification. Systems intended for public authorities must comply by 2 August 2030 at the latest.
What doesn’t change
The prohibited practices have applied since 2 February 2025, as has the AI literacy duty. The latter was rewritten: providers and deployers must take measures to support the AI literacy of their people, taking into account knowledge, experience and context. It has become a best-efforts obligation, but one that applies.
The rules for providers of general-purpose AI models (since August 2025) and the transparency obligations of Article 50 (since August 2026) also stand. If you deploy a chatbot, users must know they are talking to AI. If you publish deepfakes, you must disclose them. Maximum fines are unchanged: up to 35 million euros or 7 per cent of worldwide annual turnover for prohibited practices.
What’s new
- Two new prohibitions, from 2 December 2026: AI that creates non-consensual intimate imagery, such as so-called nudify apps, and AI that generates child sexual abuse material.
- A narrower definition of safety component. AI that only assists users or optimises performance is no longer automatically high risk when a malfunction poses no risk to health or safety.
- Room for small mid-caps. The SME relief measures now also cover companies with up to 750 employees and turnover up to 150 million euros or a balance sheet total up to 129 million euros: simpler technical documentation, a more proportionate quality system, priority access to regulatory sandboxes and lower penalty caps.
- Special category data for bias detection. The legal basis for processing special category personal data to detect and correct bias in AI has been broadened, under strict conditions such as necessity, pseudonymisation and timely deletion.
- Machinery moves to the Machinery Regulation. AI in machinery no longer falls directly under the AI Act’s high-risk regime, but under the sectoral rules.
- More powers for the AI Office, including supervision of AI systems built on a general-purpose AI model from the same provider.
A simplified registration obligation also remains for Annex III systems that a provider itself assesses as not high risk. If you rely on that exemption, you still need to document the assessment.
Three misconceptions we hear now
“High risk has been postponed, so there’s nothing to do yet.”
AI literacy, the prohibitions and the transparency obligations already apply. And setting up risk management, data quality, logging and human oversight for a high-risk system takes months, especially when suppliers and internal teams need to move with you.
“It will probably be postponed again.”
The new dates are now in the regulation itself. Another shift would require a full new legislative procedure. Building a plan on that is a gamble.
“Our supplier takes care of it.”
As a deployer you have your own obligations, even if you build nothing yourself. That is the subject of our article on procured AI.
What this means for your planning
- Now: map all AI, determine the risk class and your role for each use case, check that you don’t engage in prohibited practices, organise AI literacy per role, and review the transparency obligations that have applied since August.
- Before December 2026: make sure generative systems mark their output, and check your use cases against the new prohibitions.
- In 2027: set up risk management, documentation, human oversight and monitoring for high-risk use cases, and carry out a fundamental rights impact assessment where required. Agree with suppliers what they will provide.
Our advice
Use the extra time to do it properly, not to wait. Organisations that start now can build governance into ongoing projects. Those who start in the second half of 2027 will have to build it around them afterwards.
Sources
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), EUR-Lex.
- Regulation (EU) 2024/1689 (AI Act), EUR-Lex.
- European Parliament, Legislative Train: Digital Omnibus on AI.
This article is for information only and is not legal advice. Current as of October 2026. Always consult the official text before making decisions.