Did the Digital Omnibus delay the EU AI Act?
It delayed part of it, and expanded another part. The high-risk obligations moved out by 16 months for Annex III use cases and 12 months for Annex I products. Nothing already in force was rolled back, and two new prohibited practices were added, taking the Article 5 list from eight to ten.
That combination is why “the AI Act was delayed” is a misleading summary. An organisation reading it that way risks missing two bans that bite on 2 December 2026 and a marking deadline on the same date.
Which deadlines moved
Two high-risk deadlines in Article 113 were deferred, and one date was created that does not appear in the adopted text at all.
See every application date in context, including the dates the Omnibus left untouched.
Every change, before and after
The amending act reaches beyond the timetable. It rewrote an obligation, inserted two prohibitions, created an enforcement chapter and resolved two ambiguities.
High-risk deadline (Annex III use cases)
Article 113A 16-month deferral for the eight Annex III use-case areas. The stated reason was that the infrastructure the deadline depends on, harmonised standards and designated notified bodies, was not ready.
Applies from 2 December 2027Read the detail →
High-risk deadline (Annex I products)
Article 113A 12-month deferral, keeping the product-safety route eight months behind Annex III so sectoral conformity assessment has time to absorb it.
Applies from 2 August 2028Read the detail →
New prohibition: non-consensual intimate imagery
Article 5(1)(ba)A ninth ban, inserted rather than deferred. It sits in the €35 million / 7% penalty tier alongside the original eight prohibitions.
Applies from 2 December 2026Read the detail →
New prohibition: child sexual abuse material
Article 5(1)(bb)A tenth ban, on the same date and in the same penalty tier. Anyone still working from a list of eight prohibitions is working from the superseded text.
Applies from 2 December 2026Read the detail →
What counts as a safety component
Article 6(1a) to (1c)BeforeNo definition; any AI in a regulated product risked being caught
AfterAI used solely for non-safety purposes is not a safety component
This narrows the Annex I route rather than deferring it. AI used solely for user assistance, performance optimisation, service efficiency, automation, convenience or quality control does not qualify as a safety component, unless its failure would endanger health and safety. A product needing third-party assessment only for non-health-safety risks, such as radio spectrum or electromagnetic interference, no longer meets the Article 6(1)(b) condition.
In force since 27 July 2026Read the detail →
AI literacy duty
Article 4BeforeProviders and deployers shall ensure a sufficient level of AI literacy
AfterProviders and deployers shall take measures to support AI literacy
Softened from a duty of result to a duty of effort. The obligation still binds every operator regardless of risk tier, and has applied since 2 February 2025, but it is now assessed on the measures taken rather than the level achieved.
In force since 27 July 2026Read the detail →
Marking of existing synthetic content
Article 111(4), applying the duty in Article 50(2)BeforeNo transitional window
AfterLegacy systems must comply by 2 December 2026
Generative systems already on the market before 2 August 2026 got a transitional window to implement machine-readable marking of synthetic output. The deadline is set by a new transitional paragraph, Article 111(4); the duty it defers is the existing Article 50(2). The only amendment to Article 50 itself is to paragraph 7, on codes of practice.
Applies from 2 December 2026Read the detail →
AI Office enforcement powers
Articles 75a-75dBeforeNo direct supervisory powers over these operators
AfterInformation requests, evaluations, remedial measures and fines, with periodic penalty payments
A new enforcement chapter. The AI Office can impose periodic penalty payments of up to 5% of average daily turnover for each day a breach continues, which on a long-running infringement can exceed the headline maximum fine.
In force since 27 July 2026Read the detail →
Penalties for small mid-cap enterprises
Article 99(6a), with new definitions in Article 3(14a) and (14b)BeforeOnly SMEs, including start-ups, faced the lower figure
AfterSMCs also face the lower of the fixed sum and the turnover percentage
A new category. SMEs already had the lower figure under Article 99(6); this extends the same treatment to small mid-cap enterprises, companies that have outgrown the SME thresholds. “SMC” is defined by new Article 3(14b) as a small mid-cap enterprise under point (2) of the Annex to Recommendation (EU) 2025/1099.
In force since 27 July 2026Read the detail →
Processing special-category data for bias detection
Article 4aBeforeOnly the narrow Article 10(5) basis
AfterA broadened legal basis for bias detection and correction
Addresses a practical deadlock: testing a high-risk system for discriminatory outcomes can require the very special-category data the GDPR restricts.
In force since 27 July 2026Read the detail →
Scope of a notified body's designation
Annex XIVAfterNew annex: a list of codes, categories and corresponding types of AI systems
Notification under Article 30 now uses a fixed taxonomy of AIA codes, so a notified body's designation states exactly which types of system it may assess. A body designated for one category cannot assess another.
In force since 27 July 2026Read the detail →
What this means for compliance work
The deferral buys time on the heaviest workstream and buys none at all on the nearest deadline.
- Do not stand down high-risk work. Conformity assessment for an Annex III system is a multi-quarter programme. December 2027 is a schedule change, not a reprieve.
- Check exposure to the two new prohibitions before December 2026. They apply in the €35 million / 7% tier, the same as the original eight.
- Confirm synthetic-content marking on legacy systems. Generative systems already on the market must carry machine-readable marking by 2 December 2026 under Article 50(2).
- Revisit AI literacy evidence. The duty is now about measures rather than outcomes, which changes what you should be recording, not whether you owe it.
- Re-check any guidance dated before 27 July 2026. Deadlines, prohibition counts and penalty mechanics in older material are likely to be wrong.
Frequently asked questions
What is the Digital Omnibus on AI?
The Digital Omnibus on AI is Regulation (EU) 2026/1744, an amending act that entered into force on 27 July 2026 and changed Regulation (EU) 2024/1689: the EU AI Act. It deferred the high-risk compliance deadlines, added two prohibited practices, softened the AI literacy duty, gave the AI Office direct enforcement powers, and clarified how penalties apply to SMEs.
Did the Digital Omnibus delay the EU AI Act?
It delayed part of it. The high-risk obligations moved: Annex III use cases from 2 August 2026 to 2 December 2027, and Annex I product-safety systems from 2 August 2027 to 2 August 2028. Nothing already in force was rolled back: the prohibitions, the AI literacy duty, the general-purpose AI model obligations and the Article 50 transparency rules all continue to apply, and the Omnibus added two new prohibitions.
How many prohibited AI practices are there now?
Ten. Eight have been unlawful since 2 February 2025. The Digital Omnibus inserted Article 5(1)(ba) on non-consensual intimate imagery and Article 5(1)(bb) on child sexual abuse material, both applying from 2 December 2026. Material that still refers to eight prohibitions is describing the superseded text.
When do high-risk AI obligations apply after the Omnibus?
2 December 2027 for AI systems in the eight Annex III use-case areas, and 2 August 2028 for AI systems that are safety components of products covered by the Annex I harmonisation legislation. Both dates are later than the adopted text provided.
What changed about AI literacy under Article 4?
The duty was softened from ensuring a sufficient level of AI literacy to taking measures to support it. It still applies to every provider and deployer regardless of risk tier and has done since 2 February 2025, but compliance is now assessed on the measures taken rather than the level of literacy achieved.
Can the AI Office fine companies directly?
Yes. Articles 75a to 75d, added by the Digital Omnibus, give the AI Office powers to request information, run evaluations, require remedial measures and impose fines on general-purpose AI model providers. It can also impose periodic penalty payments of up to 5% of average daily turnover for each day a breach continues.