AI & Compliance · · 11 min read

The AI Omnibus: More Time, More Power, No More Certainty

The AI Omnibus: More Time, More Power, No More Certainty

The Digital Omnibus on AI (AI Omnibus) [1] was adopted on 8 July 2026, published in the Official Journal on 24 July and entered into force on 27 July, six days before the AI Act's [2] original application date. The Commission promised extended timelines and simpler administration, and delivered both in part.

But the AI Omnibus is best read neither as simplification nor as a pause: it redistributes time and enforcement power while leaving intact the features that cause most of the uncertainty. The AI Act remains a framework whose substance depends on harmonised standards, delegated acts and implementing acts that still do not exist. The AI Omnibus moved the deadlines for complying with rules nobody has written yet.

What was postponed

| Obligation | Was | Now | | Stand-alone high-risk systems (Art 6(2), Annex III) | 2 Aug 2026 | 2 Dec 2027 | | Embedded high-risk systems (Art 6(1), Annex I) | 2 Aug 2027 | 2 Aug 2028 | | Art 50(2) marking, systems on the market before 2 Aug 2026 | 2 Aug 2026 | 2 Dec 2026 (Art 111(4)) | | New prohibitions on intimate imagery and CSAM (Art 5(1)(ba), (bb), (1a), (1b)) | N/A | 2 Dec 2026 | | National regulatory sandboxes operational (Art 57(1)) | 2 Aug 2026 | 2 Aug 2027 | | Delegated acts limiting Chapter III requirements (Art 2(13)) | N/A | by 2 Aug 2027 | | Machinery delegated acts, notified body designation (Art 43(3)) | N/A | 2 Aug 2028 / 28 Jan 2028 |

The rest of the Act was not postponed. The prohibitions, the general purpose AI obligations and the Article 50 transparency duties all apply on their original dates. The only exception is Article 111(4): providers of systems generating synthetic audio, image, video or text content that were on the market before 2 August 2026 have until 2 December 2026 to meet Article 50(2). Anything placed on the market later had to comply immediately.

Two changes that are more than deferrals

The safety component was redefined. A component now fulfils a safety function only where that is its intended purpose. Systems used solely for non safety related aspects of user assistance, performance optimisation, service efficiency, automation, convenience or quality control do not qualify (Art 6(1a)), unless their failure would endanger health and safety (Art 6(1b)). Since safety component status is one of the two ways into the high-risk category, systems that would have been classified as high-risk under the pre-Omnibus definition may now fall outside that category. A lift dispatch algorithm that shortens waiting times illustrates the shift: once its intended purpose is characterised as service efficiency, it ceases to be a safety component.

Chapter III requirements can now be switched off. New Article 2(13) allows Articles 9-15 and 17-25 to be limited for Article 6(1) systems where, and to the extent that, Annex I Section A legislation already provides equivalent or higher protection and the overall level of protection is not reduced, with the Commission to specify which systems and which requirements by delegated act by 2 August 2027. The anti-duplication principle is sound, but the consequence of this is that nobody can yet say which core requirements will apply to their product.

Simplification partially delivered

As part of the Commission's simplification agenda set out in the Competitiveness Compass, which aims, among other things, to ensure that regulatory requirements are proportionate to a company's size, small mid-cap enterprises (SMCs) [3] have been included in the less restrictive regime provided by the AI Act alongside micro, small and medium enterprises (SMEs). They can therefore use the following legislative options: simplified technical documentation on a Commission form that notified bodies must accept (Art 11(1)), proportionate quality management (Art 17(2)), priority access to the Union level sandbox that the AI Office may establish for systems under its supervision (Art 57(3a)), and a fine cap at the lower of percentage or fixed amount (Art 99(6a)).

However, not all the benefits of SMEs were granted to SMCs. The Article 63(1) quality management simplification stayed SME only and was even narrowed to SMEs with no partner or linked enterprises. AI-enabled machinery moved from Section A to Section B of Annex I, so under the amended Article 2(2) only Article 6(1), the new Article 60a and Articles 102 to 112 apply directly, with the substantive requirements to be reflected in the Machinery Regulation [4] by 2 August 2028. In practice this means that, for example, conformity assessment, the declaration of conformity or CE marking will be carried out under the Machinery Regulation alone, sparing manufacturers a second, AI Act specific layer of assessment. AI literacy softened from "ensure a sufficient level" to "take measures to support the development," with responsibility shifting partly to the Commission and Member States (Art 4).

The AI Office grows teeth

The longest part of the Omnibus has nothing to do with simplification. Under the amended Article 75(1) the AI Office becomes exclusively competent for systems built on general purpose models by the same undertaking (subject to four carve-outs left with national authorities), and for systems integrated into very large online platforms and search engines. New Articles 75a-75d import the competition and DSA [5] playbook: investigations, information requests by decision, remote and on-site inspections, entry, copying, questioning, sealing of premises, binding commitments, fines for infringement of any provision of the Regulation, and periodic penalties of up to 5% of average daily income or worldwide annual turnover in the preceding financial year, per day. National courts will be asked to authorise inspections, verify proportionality but may not review necessity. Legality of the AI Office's decisions will be reviewable only by the Court of Justice of the EU.

This is centralisation on the DSA model: for the largest providers, supervision moves out of the Member States and into the Commission, with national courts confined to authorising inspections they may not fully review and legality tested only in Luxembourg.

Two new prohibited AI practices

From 2 December 2026, Article 5(1)(ba) and (bb) will ban AI systems that generate or manipulate realistic intimate images, video or audio of an identifiable person without that person's explicit consent, and systems that produce child sexual abuse material. The prohibition is narrower than it first appears: placing such a system on the market is prohibited only where that generation is its intended purpose, or where it is a reasonably foreseeable and reproducible outcome that the system lacks adequate safeguards to prevent, and use is prohibited only where the deployer uses the system for that purpose (Art 5(1a)). Manipulations that do not increase the exposure of intimate parts fall outside the ban (Art 5(1b)). The target of these prohibitions is the so-called "nudify" apps, which use AI systems to create nude pictures of people without their consent.

In this, the EU legislature is not acting alone. The United States adopted the TAKE IT DOWN Act [6] at federal level in 2025, and this year Minnesota went further at state level by prohibiting the provision of nudification technology itself rather than only the distribution of the resulting images [7]. The Minnesota statute took effect on 1 August 2026 and is being challenged by xAI on First Amendment grounds. The District of Minnesota denied a preliminary injunction on 4 September 2026 and the case is ongoing.

The GDPR question still unsolved

The AI Omnibus deletes Article 10(5) and inserts Article 4a, permitting the processing of special categories of personal data for bias detection subject to six cumulative conditions and extending that possibility to providers and deployers of other AI systems and models and to deployers of high-risk systems (Art 4a(2)). That is a wider gateway than the provision it replaces, and the amended Article 2(7) now says the AI Act does not affect the GDPR [8] "without prejudice to Articles 4a and 59."

The harder question sits outside the AI Act and AI Omnibus. The Digital Omnibus, which aims, among other things, to amend the GDPR, has not yet reached trilogue (the Council has no general approach and Parliament's committee vote is not expected before early 2027), and its proposed Article 9(2)(k) GDPR would permit processing special categories for the "development and operation" of AI systems, framed as a derogation for incidental and residual processing subject to safeguards in a new Article 9(5) [9]. The recitals [10] justify it as a training data problem, "operation" is undefined. EDPB-EDPS Joint Opinion 2/2026 recommended excluding data collected through user prompts after deployment. If the provision survives in anything like its proposed form, AI development in the EU will change significantly.

A missed opportunity for structural change

The changes described above show that the AI Omnibus brought no comprehensive revolution, but merely partial adjustments: postponed obligations, some simplification, and a few new rules. The AI Act remains a framework regulation establishing basic principles and institutions, intended to be specified through delegated and implementing acts, which have not been adopted yet. Rather than providing certainty for everyone, the AI Omnibus left everyone in a state of continued uncertainty [11].

Since the AI Omnibus has bought time for the EU legislator, developments must be monitored not only within the AI Act itself but also across the closely related legislation, from the GDPR and the ePrivacy Directive [12] to the Data Act [13], NIS2 [14], CRA [15] and DORA [16], which together shape what AI compliance actually requires.

Notes

  1. Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI)
  2. Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act)
  3. Art.3(14b) of the AI Act, in connection with point (2) of the Annex to Commission Recommendation (EU) 2025/1099
  4. Regulation (EU) 2023/1230 of the European Parliament and of the Council of 14 June 2023 on machinery
  5. Regulation (EU) 2022/2065 of the European Parliament and of the Council of 19 October 2022 on a Single Market For Digital Services and amending Directive 2000/31/EC (Digital Services Act)
  6. Tools to Address Known Exploitation by Immobilizing Technological Deepfakes on Websites and Networks Act ("TAKE IT DOWN Act"), Pub. L. No. 119-12, 139 Stat. 55 (2025)
  7. Act of May 7, 2026, ch. 72, 2026 Minn. Laws (codified at Minn. Stat. § 325E.91)
  8. Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)
  9. Proposal for a Regulation of the European Parliament and of the Council amending Regulations (EU) 2016/679, (EU) 2018/1724, (EU) 2018/1725, (EU) 2023/2854 and Directives 2002/58/EC, (EU) 2022/2555 and (EU) 2022/2557 as regards the simplification of the digital legislative framework, and repealing Regulations (EU) 2018/1807, (EU) 2019/1150, (EU) 2022/868, and Directive (EU) 2019/1024 (Digital Omnibus)
  10. Recitals 30, 33 of Digital Omnibus.
  11. Vera Lúcia Raposo, A Frozen Clock and a Frozen Problem, The Digital Omnibus Missed an Opportunity to Fix the AI Act (2026), Verfassungsblog.
  12. Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on privacy and electronic communications)
  13. Regulation (EU) 2023/2854 of the European Parliament and of the Council of 13 December 2023 on harmonised rules on fair access to and use of data and amending Regulation (EU) 2017/2394 and Directive (EU) 2020/1828 (Data Act)
  14. Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (NIS 2 Directive)
  15. Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act)
  16. Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011

The world's most informed compliance team is one call away.

Book a discovery call