RR Roksana Radecka
← Back to writing

August 2026

EU AI Act 2026 Update: What the Digital Omnibus Changes for Companies

The EU's Digital Omnibus on AI, in force since July 2026, delays key AI Act deadlines to 2027–2028, narrows high-risk rules, and adds new prohibitions. Here's what changed and why.

In short: On June 29, 2026, the EU finalized the Digital Omnibus on AI, a law that delays the AI Act's high-risk compliance deadlines by 16 months (to December 2, 2027) to a year (to August 2, 2028), narrows what counts as a "high-risk" AI system, and adds a new ban on AI-generated non-consensual intimate imagery and CSAM. It entered into force on July 27, 2026. Transparency and labeling rules under Article 50 were not delayed and still apply from August 2, 2026.

For nearly two years, the EU AI Act stood as the world's most comprehensive attempt to regulate artificial intelligence, a rulebook other governments watched closely and companies scrambled to prepare for. The Digital Omnibus is the biggest rewrite of that Act since it was adopted in 2024, and it lands just as the law's toughest provisions were about to take effect.

What Is the EU Digital Omnibus on AI?

The Digital Omnibus on AI is a package of amendments to the EU AI Act, proposed by the European Commission on November 19, 2025, adopted by the European Parliament on June 16, 2026 (423 votes in favor), and given final approval by the Council of the EU on June 29, 2026. It entered into force on July 27, 2026, three days after publication in the Official Journal. Its stated purpose is to reduce overlapping compliance burdens across the AI Act, GDPR, and other digital-rulebook legislation.

What Changed Under the 2026 EU AI Act Update?

Compliance deadlines were extended. High-risk AI systems under Annex III (the "use-based" category, covering AI in hiring, credit scoring, education, and law enforcement) were due for full compliance on August 2, 2026. That date is now December 2, 2027, a 16-month delay. High-risk AI systems embedded in regulated products under Annex I (medical devices, lifts, radio equipment) move from August 2, 2027 to August 2, 2028.

Transparency rules were not delayed. Article 50, which requires disclosing AI interactions and labeling AI-generated content, keeps its original August 2, 2026 start date. One partial exception: generative AI systems already on the market before that date have until December 2, 2026 to meet the watermarking requirement specifically.

The definition of "high-risk" narrowed. AI systems used purely for user assistance, performance optimization, efficiency, automation, or convenience no longer count as safety components, unless a malfunction could actually endanger health or safety. This pulls a meaningful slice of everyday enterprise AI tooling out of high-risk scope.

A new prohibition was added. AI systems can no longer be used to generate non-consensual sexual or intimate imagery, or child sexual abuse material (CSAM). This ban applies with no phase-in.

GDPR and enforcement powers were expanded. The legal basis under GDPR for processing sensitive data to detect and correct AI bias was broadened, and the AI Office's enforcement authority was strengthened.

Why Did the EU Delay the AI Act Deadlines?

The Commission's official rationale is simplification. It argued that overlapping obligations across the AI Act, GDPR, and other digital legislation created compliance burdens without a proportionate safety benefit, particularly for smaller companies without the legal resources to interpret them in time. Framed this way, the Omnibus is a recalibration of the AI Act's timeline to match technical and administrative reality, not a retreat from regulating AI.

Industry groups lobbied heavily for this outcome, warning that the original August 2026 deadline would have forced companies to comply with detailed technical standards that weren't even finalized yet.

Why Are Critics Calling the Digital Omnibus a Rollback?

Civil society groups see it differently. More than 130 organizations urged the Commission not to reopen the AI Act at all, and 60 groups specifically opposed the transparency rollbacks during the legislative process. Their core argument: delaying high-risk obligations by 16 months leaves people unprotected from AI systems already in use for biometric identification, school admissions, and other sensitive decisions, precisely the use cases the AI Act was written to guard against. Groups including EDRi, Article 19, and the European Center for Not-for-Profit Law have described the process as shaped disproportionately by industry pressure, with public consultation functioning more as formality than genuine input.

What Does the Digital Omnibus Mean for Companies Operating in Europe?

Frequently Asked Questions

What is the EU AI Act Digital Omnibus?
It's a set of amendments to the EU AI Act that delays high-risk compliance deadlines, narrows the definition of high-risk AI systems, and adds new prohibitions and enforcement powers. It entered into force on July 27, 2026.

When do EU AI Act high-risk obligations now apply?
December 2, 2027 for use-based (Annex III) high-risk systems, and August 2, 2028 for product-embedded (Annex I) high-risk systems.

Did the EU delay the AI Act's transparency rules too?
No. Article 50 transparency and labeling requirements still apply from August 2, 2026, with a partial extension to December 2, 2026 for watermarking on generative AI systems already on the market.

Why is the Digital Omnibus controversial?
Civil society groups argue it weakens protections against high-risk AI uses, such as biometric identification and AI in education, by delaying enforcement, while industry groups supported it as necessary simplification.

Does the Digital Omnibus affect companies outside the EU?
Yes, if they place AI systems on the EU market or their outputs affect people in the EU. The AI Act's extraterritorial scope was not changed by the Omnibus.


Sources:

← Back to all posts