TechLaw
30/7/26

Digital Omnibus on AI: what the final text changes before 2 August 2026

7 min read

Guillermo Passas Varo

Most English-language commentary on the Digital Omnibus on AI still describes a negotiation that has ended. The alerts published through May and June set out the provisional political agreement of 7 May 2026 and, properly, flagged their conclusions as contingent on formal adoption. That contingency is spent. Regulation (EU) 2026/1744 was published in the Official Journal on 24 July 2026 and entered into force on 27 July. The dates in it are law, and they are unconditional.

This matters this week for one reason. The Omnibus defers the high-risk regime by sixteen and twenty-four months, and it leaves the general application date of the AI Act precisely where it was, on 2 August 2026. A company that reads the deferral as a general reprieve will miss obligations that begin to apply in three days, and those obligations reach a considerably wider population of businesses than the high-risk regime ever did.

What was adopted, and when

Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026 amends three instruments: the AI Act (Regulation (EU) 2024/1689), the Basic Aviation Regulation (Regulation (EU) 2018/1139) and the Machinery Regulation (Regulation (EU) 2023/1230). It appeared in the Official Journal on 24 July 2026 and, departing from the usual twenty-day rule, entered into force on the third day following publication. Recital 46 states the reason without ornament: the general application date the Regulation amends falls on 2 August, so the amendment had to be in force before it.

Two points of hygiene before the substance. This instrument is not the broader Digital Omnibus package; a separate proposal amending the GDPR and adjacent data legislation remains in negotiation on its own timetable, and treating the two as one file is the most frequent error in current coverage. And because this is a regulation amending a regulation, it applies directly across the twenty-seven Member States, with no transposition step and no national implementing measure to wait for.

The high-risk regime moves to December 2027 and August 2028

The headline change sits in Article 113 of the AI Act. Chapter III, Sections 1, 2 and 3, which contain the classification rules, the requirements for high-risk systems and the obligations of providers and deployers, were due to apply from 2 August 2026 for Annex III systems and from 2 August 2027 for systems caught through Annex I. Recital 40 records why they moved: standards, common specifications and guidance were late, and national competent authorities and conformity assessment infrastructure were not in place.

The new dates are 2 December 2027 for systems classified as high-risk under Article 6(2) and Annex III, covering stand-alone use cases such as recruitment, credit scoring, education and biometrics, and 2 August 2028 for systems classified as high-risk under Article 6(1) and Annex I, meaning AI that is, or is a safety component of, a product already regulated under Union product safety legislation.

The structural change is what did not survive drafting. The Commission's November 2025 proposal had tied these dates to an assessment that standards and support tools were ready, which would have allowed them to move again. The adopted text abandons that mechanism for fixed calendar dates. They cannot now slip without a fresh legislative procedure, and they will arrive whether or not the harmonised standards are finished. Anyone building a programme for compliance with the high-risk AI system requirements should treat 2 December 2027 as a date to work back from rather than a date to watch.

What still applies on 2 August 2026

Recital 40 confirms in passing the point most of the commentary buries: the general date of application of the AI Act remains 2 August 2026, and nothing in the Omnibus touches it.

What lands on that date is Chapter IV, and in particular Article 50. Its obligations do not depend on risk classification at all. They apply to any system that interacts directly with natural persons, to providers of systems generating synthetic audio, image, video or text, to deployers of emotion recognition and biometric categorisation systems, and to deployers publishing deep fakes or AI-generated text on matters of public interest. That is a far broader population than Annex III ever reached, because it captures the features almost every product now ships: a chat interface, generated copy, synthetic media. Infringements sit in the penalty tier of Article 99(4), up to 15 million euros or 3% of total worldwide annual turnover, whichever is higher.

The one concession, and how narrow it is

Recital 38 introduces a transitional period of four months for providers subject to the machine-readable marking obligation in Article 50(2), and only for those who had already placed their systems on the market before 2 August 2026. Those providers have until 2 December 2026 to bring output marking into compliance.

The limits deserve attention. The concession covers Article 50(2) alone, not the disclosure and labelling duties in the rest of the article, and it covers systems already on the market, not systems placed on the market from 2 August onwards, which must comply on placement. The practical consequence is administrative: a provider needs to be able to show which of its systems were on the Union market before 2 August 2026, and when. That record is now the difference between two compliance dates, and it is worth fixing before the date passes. Any AI Act compliance work deferred pending the Omnibus should be reopened on this point first.

Two new prohibited practices

Article 1(7) of the Omnibus inserts two points into the list of prohibited practices in Article 5(1) of the AI Act. Point (ba) covers placing on the market, putting into service or using an AI system that generates or manipulates realistic images, video, audio or similar material depicting an identifiable person's intimate parts, or that person engaged in sexually explicit activity, without their freely given, specific, informed, unambiguous and explicit consent. Point (bb) covers systems generating or manipulating material within the meaning of Article 2, points (c) and (e), of Directive 2011/93/EU, subject to a ‘without right’ defence where national law provides one.

A new Article 5(1a) confines the scope of both. For providers, the prohibition bites where that generation is the intended purpose of the system, or where the system's design, training, architecture, capabilities or user-facing functionality make it a reasonably foreseeable and reproducible outcome without significant technical modification, and the system lacks reasonable and adequate technical safety measures and safeguards to prevent that outcome and to correct observed or reported misuse. For deployers, the prohibition applies only where the system is used for that purpose.

The second limb is what takes the provision beyond purpose-built applications. A general-purpose image or video model with thin or trivially circumvented safeguards is within scope on the text as drafted. The recitals set out what the legislature expects: training data cleaning, refusal training, prompt guardrails, content classification and filtering, usage restrictions, abuse detection, and notice and action mechanisms, calibrated to the state of the art and to the system's release and distribution strategy. Providers of generative image, audio and video systems should read Article 5(1a) alongside their general obligations as providers of AI systems rather than as a separate content policy question.

Article 113 as amended sets the application date for both prohibitions at 2 December 2026. Breaches of Article 5 sit in the top penalty tier under Article 99(3), up to 35 million euros or 7% of total worldwide annual turnover.

The calendar as it now stands

Nine dates, in order, each with the provision it rests on.

  • 2 February 2025. The original prohibited practices in Article 5(1), points (a) to (h). Article 113(a) AI Act.
  • 2 August 2026. General application of the AI Act, including the Article 50 transparency obligations. Article 113 AI Act, unchanged by Regulation (EU) 2026/1744.
  • 2 December 2026. Article 50(2) marking for generative systems already placed on the market before 2 August 2026. Regulation (EU) 2026/1744, recital 38 and the amendments to Article 113.
  • 2 December 2026. The new prohibitions in Article 5(1), points (ba) and (bb). Article 5(1) AI Act as amended by Regulation (EU) 2026/1744, Article 1(7).
  • 2 August 2027. National AI regulatory sandboxes to be operational. Article 57(1) AI Act as amended, Article 1(22)(a).
  • 2 August 2027. Deadline for the Commission delegated acts on sectoral equivalence. Article 2(13) AI Act as inserted, Article 1(3).
  • 2 December 2027. High-risk obligations for stand-alone Annex III systems under Article 6(2). Chapter III, Sections 1 to 3, Article 113 as amended; recital 40.
  • 28 January 2028. Deadline for notified bodies under Section A of Annex I to apply for designation. Article 43(3) AI Act as amended, Article 1(19).
  • 2 August 2028. High-risk obligations for embedded Annex I systems under Article 6(1). Chapter III, Sections 1 to 3, Article 113 as amended; recital 40.

Simplification, and who it actually reaches

The Omnibus inserts definitions of SME and small mid-cap enterprise at Article 3, points (14a) and (14b), by reference to Recommendation 2003/361/EC and Recommendation (EU) 2025/1099, and extends a series of existing accommodations to both categories.

The most substantial concerns technical documentation. Article 11(1) now permits SMEs, including start-ups, and SMCs to provide the Annex IV elements in simplified form, requires the Commission to establish a simplified form for that purpose, and obliges notified bodies to accept it for conformity assessment. Article 17(2) makes implementation of the quality management system proportionate to the size of the provider's organisation, with the express rider that the required degree of rigour and level of protection must still be met. Article 63's simplified route, previously open only to microenterprises, extends to all SMEs. Where the AI Office establishes a Union-level sandbox under the new Article 57(3a), SMEs and SMCs are to have priority access.

Article 4 is rewritten. The duty to ensure a sufficient level of AI literacy becomes a duty to take measures to support its development among staff and others operating AI systems on the provider's or deployer's behalf, with an express statement that no specific level need be guaranteed for any individual. It is an obligation of effort rather than of result, and it binds every provider and deployer irrespective of risk tier.

Two classification changes matter to product companies. The definition of safety component in Article 3, point (14), is narrowed to components fulfilling a safety function, and the new Article 6(1a) to (1c) excludes systems used solely for user assistance, performance optimisation, service efficiency, automation, convenience or quality control, while confirming that systems whose failure would endanger health and safety remain safety components whatever they are called. Separately, Regulation (EU) 2023/1230 moves from Section A to Section B of Annex I, so AI-enabled machinery is handled through sectoral requirements to be added by delegated act, applying by 2 August 2028.

Planning against three different clocks

Three categories, and they should be kept apart on any compliance plan. Obligations already live or arriving on 2 August 2026: the prohibited practices in force since February 2025, the AI literacy duty as rewritten, and the Article 50 transparency regime. Obligations with fixed medium-term dates: the high-risk requirements, on 2 December 2027 and 2 August 2028. And obligations whose shape still depends on instruments the Commission has yet to finalise, including the classification guidelines, the simplified documentation form, and the delegated acts on sectoral equivalence.

The deferral changes when the high-risk requirements bite. It does not change what they require, and it does not make the prior question any easier. Whether a given system falls within Annex III, or qualifies as a safety component of an Annex I product, is the same analysis it was in May, and it is the analysis that determines how much of the additional sixteen months a company actually has. That work is best done while the deadline is still distant.

If your situation calls for it, you can book a virtual consultation here (€90, deducted from your first invoice if we take on your matter).

VIRTUAL CONSULTATION · 60 MIN

If You Think You Need Us, Tell Us.

90
60
100
%
[{"@context":"https://schema.org","@type":"Article","headline":"Digital Omnibus on AI: what the final text changes before 2 August 2026","description":"The AI Omnibus is in force. High-risk duties move to 2027 and 2028, but Article 50 transparency still applies from 2 August 2026. The dates, with sources.","url":"https://passas.io/en/blog/digital-omnibus-ai-act-final-text","inLanguage":"en","datePublished":"2026-07-30","dateModified":"2026-07-30","author":{"@type":"Person","name":"Guillermo Passas Varo","jobTitle":"Lawyer","url":"https://passas.io/en/team/guillermo-passas-varo"},"publisher":{"@type":"Organization","name":"PASSAS","url":"https://passas.io"},"mainEntityOfPage":{"@type":"WebPage","@id":"https://passas.io/en/blog/digital-omnibus-ai-act-final-text"},"about":[{"@type":"Legislation","name":"Regulation (EU) 2026/1744 (Digital Omnibus on AI)","legislationIdentifier":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"@type":"Legislation","name":"Regulation (EU) 2024/1689 (Artificial Intelligence Act)","legislationIdentifier":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"keywords":"digital omnibus ai act, ai act high-risk delay, ai act 2 august 2026, article 50 transparency obligations, regulation 2026/1744, ai act annex III postponed"}]