The European Commission published the Digital Omnibus Package in late 2025, with proposals designed to simplify and harmonise parts of the EU’s digital legislative framework, proposing amendments to GDPR, NIS 2 and more.
While the wider digital omnibus remains under negotiation, the separate Digital Omnibus on AI (AI Omnibus) was fast-tracked because it proposed amended deadlines for high-risk AI system obligations under the EU AI Act. These proposed amendments needed to enter into force before the first high risk AI obligations under the EU AI Act were due to apply on the 2nd August 2026.
On 7th May 2026, the European Parliament and Council negotiators reached a provisional agreement on the AI Omnibus, which delayed compliance deadlines for high-risk AI systems to 2027 and 2028. The final regulation entered into force on 27th July 2026.
So, what has changed? In this blog, we’ll explore some of the key amendments the AI Omnibus makes to the EU AI Act and what they mean for organisations.
Revised Compliance Deadlines for High-Risk AI Systems
Under the AI Omnibus, providers and deployers of high-risk AI systems have an extended timeline in which to ensure compliance.
From 2nd December 2027, AI systems classified as high-risk under Article 6(2) and Annex III, in so far as their use is permitted under relevant EU or national law, will need to be able to demonstrate compliance.
This covers AI systems used in areas including:
- Biometrics
- Critical infrastructure
- Education and vocational training
- Employment, workers’ management and access to self-employment
- Access to and enjoyment of essential private services and essential public services and benefits
- Law enforcement
- Migration, asylum, and border control management
- Administration of justice and democratic processes.
Being listed in Annex III does not automatically mean that every AI system used in one of these areas will qualify as high-risk. The classification rules and exemptions in Article 6 must also be considered.
And from 2nd August 2028, high-risk obligations will apply to Article 6(1) and Annex I AI systems. This includes high-risk AI systems used as safety components of certain regulated products, or which are themselves such products, where the relevant product is subject to a third-party conformity-assessment requirement. This includes:
- Toys
- Lifts
- Medical devices
- Vehicles.
The AI Omnibus also narrows the definition of what qualifies as safety components. Products with AI functions that only assist users or optimise performance will not automatically be subject to high-risk obligations. The focus is instead on whether their failure or malfunction creates safety or health risks.
An Extended Legal Basis for Processing of Special Categories of Personal Data
The AI Omnibus extends the legal basis for the processing of sensitive data for purposes of bias detection and mitigation to deployers of high-risk AI systems and providers and deployers of other AI systems and models. Previously, this legal basis was only applicable to providers of high-risk AI.
This is not a blanket permission to process sensitive information. The processing must meet the conditions set out in the AI Act and, depending on circumstances, be necessary. Organisations must also implement safeguards including access controls, security and privacy-preserving measures and restrictions on reuse and appropriate deletion of data.
Limited Grace Period for AI-Generated Content Marking
The AI Omnibus has not generally postponed the AI Act’s transparency requirements for AI-generated content.
Article 50 transparency obligations generally apply from 2 August 2026. This includes the requirement for providers of certain AI systems that generate synthetic audio, image, video or text content to ensure that outputs are marked in a machine-readable format and are detectable as artificially generated or manipulated.
However, the AI Omnibus does introduce a limited transition period for systems already on the market. Providers of relevant systems place on the market before 2nd August 2026 have until 2nd December 2026 to comply with the machine readable marking obligations in Article 50(2).
For organisations, the important distinction is that 2nd December 2026 is a limited grace period for certain existing systems, not the general start date for the AI Acts transparency requirements.
FRIAs May Leverage DPIAs
Under the AI Omnibus, fundamental rights impact assessments (FRIAs) may now include cross references to or include the relevant sections of a data protection impact assessment (DPIA) conducted under the General Data Protection Regulation or Law Enforcement Directive.
The two assessments remain distinct, but organisations that already conduct DPIAs may be able to reuse relevant analysis rather than unnecessarily duplicating it.
Bans on Harmful AI Systems
The Omnibus introduces a ban applying to AI systems that generate non-consensual intimate material or child sexual abuse material (CSAM) from 2nd December 2026.
The prohibition applies to placing AI systems on the EU market with the purpose of creating or manipulating this material. It can also apply where this is a reasonably foreseeable and reproducible outcome of the system and the system does not have reasonable and adequate technical safety measures to prevent such use.
For deployers, the prohibition applies where they use an AI system for the purposes of generating or manipulating the prohibited material.
SME Flexibilities Extended to Small Mid-Caps
The AI Omnibus introduces a new category of small mid-cap enterprises (SMCs) and extends several regulatory flexibilities previously available to SMEs to these businesses.
These include:
- The ability to use simplified technical documentation for high-risk AI systems
- Proportionate implementation of certain quality management system requirements
- Reduced maximum fine level, with relevant fines for SMCs capped at the lower of the applicable percentage or fixed monetary amount
These changes do not mean that every SME exemption automatically applies to SMCs. Rather, the AI Omnibus extends specific simplification and proportionality measures to this new category of business.
Other Considerations
Changes for regulators: The AI Omnibus expands and clarifies the EU AI Office’s exclusive supervisory and enforcement role. It has exclusive competence for certain AI systems built on general-purpose AI models where the model and system are developed by the same provider or within the same undertaking, subject to specified exceptions.
It’s exclusive competence also covers AI systems constituting or integrated into very large online platforms or search engines regulated under the Digital Services Act (DSA). This is narrower than applying to ever AI system that falls within the scope of the DSA.
AI literacy: The AI Omnibus also revises the AI Act’s AI literacy requirement. Providers and deployers must take measures to support the development or AI literacy among staff and others operating or using AI systems on their behalf. The revised provision makes clear that organisations do not have to guarantee a particular level of AI literacy for each individual.
Extended deadline for regulatory sandboxes: The deadline for member states to ensure that their competent authorities have at least one national AI regulatory sandbox in operation is extended from 2nd August 2026 to 2nd August 2027. The AI office may also establish a regulatory sandbox at EU level for AI systems for failing within its competence.
What This Means for Organisations
The AI Omnibus’ amendments to the EU AI Act largely streamline or clarify existing requirements. Crucially it does not postpone the AI Act as a whole.
As a first step, we suggest reviewing your current AI governance programme, mapping it to the AI Omnibus’ amendments and identifying any areas that need to be revised. Ensure you have oversight of which AI systems your business uses and where they’re used.
Transparency marking is one area requiring particular attention now. Article 50 transparency requirements have generally applied since 2nd August 2026. If your organisation provides or deploys systems to generate content covered by the disclosure requirements, identify which provider or deployer obligations apply. Providers of relevant systems already on the market before 2nd August 2026 should also determine whether they fall withing the limited transition period ending on 2nd December 2026.
Organisations using AI should also review their approach to AI literacy following the amended Article 4 and ensure appropriate measures are in place to support staff who operate or use AI systems.
For organisations responsible for Annex III high-risk systems, the revised deadlines provide additional implementation time, but they do not remove the underlying requirements. Organisations may already have been working to meet the original August 2nd, 2026, deadline, while organisations responsible for Annex I systems were working towards the AI Act’s later product-related timetable.
Crucially, the revised deadlines don’t represent a reprieve from compliance requirements, and the additional time should be used to strengthen compliance programmes, confirm AI system classifications, establish governance and documentation processes, test controls and address gaps well ahead of the new 2nd December 2027 and 2nd August 2028 deadlines.
Expand Your Knowledge
Blog: What’s in the New EU AI Act Code of Practice on Transparency of AI-Generated Content?
Blog: White House AI Collaboration Scheme Should Inspire Broader AI Supply Chain Introspection
Podcast: Phishing for Trouble S2 E10: Built to Last: How Compliance Enables Business Resilience







