Updated September 2, 2026. This article was written on the provisional agreement, before the final text existed. The Digital Omnibus on AI has been in force since July 27, 2026. The dates and text below have been corrected against the adopted text. A running record of everything that has changed lives in the AI Act Tracker.
If you’ve spent the last six months preparing for August 2, 2026, building documentation, mapping your AI systems, having the vendor conversations, dragging your product team into compliance meetings they didn’t want to attend, I have news.
On May 7, the European Parliament and the Council reached a deal to amend the EU AI Act. The high-risk AI obligations that were supposed to hit in August 2026? Pushed to December 2027. Some of them to August 2028.
You can exhale.
For about ten seconds.
Because not everything moved. The prohibited practices have applied since February 2025. The penalties regime applied from August 2025, which is when Member States were meant to have national penalty rules in place. The market surveillance machinery that supervises any of it only arrived in August 2026. Three dates, and the coverage collapses them into one.
AI literacy kicked in on that same February date. Transparency obligations still landed in August 2026. The omnibus gave you more time on the biggest thing. It also changed a good deal that the coverage skipped.
That’s the trap. The headline says “delayed”. The fine print says “some of it”.
The full text is now public. The Digital Omnibus on AI was published in the Official Journal on July 24, 2026 and entered into force on July 27, 2026. Everything below is checked against it rather than against the press release this article was originally built on.
What Happened
The Digital Omnibus on AI. Part of the Commission’s broader “simplification” agenda launched in late 2025. Targeted amendments to the AI Act, not a rewrite, but surgical changes to delay, simplify, and clarify.
The first trilogue on April 28 collapsed without agreement. The sticking point was how to handle AI systems embedded in products already regulated by other EU safety laws: the double regulation problem. Nine days later, the negotiators came back and struck a deal before dawn.
It made the deadline. Formal adoption, legal-linguistic revision and publication all completed before August 2, 2026, with six days to spare.
What the Digital Omnibus is not: a repeal. The EU AI Act’s core architecture is intact. But this is not a light-touch amendment either. It changes around thirty articles and adds new ones, and four of those changes contradict how May reported this. Article 5 gained two prohibitions. Article 4 was softened. Article 50(2) picked up a grace period. And Article 6, the classification article, was amended. Chapter V, the general-purpose AI obligations, is the block genuinely left alone.
What’s Already In Force, Unchanged
Everyone is writing about what moved. But I also want to list what didn’t.
February 2, 2025 - already enforceable:
Article 5, the prohibited practices. Eight bans on unacceptable-risk AI, and two more arriving in December. Social scoring, manipulative AI, real-time remote biometric identification (with exceptions), emotion recognition in workplaces and schools, untargeted scraping for facial recognition databases. Penalties became available in August 2025. Supervision arrived in August 2026. Up to EUR 35 million or 7% of global annual turnover, whichever is higher.
Article 4, AI literacy. Applicable since February 2025, and amended in July 2026. The duty was to ensure a sufficient level of AI literacy. It is now to take measures that support its development, with the text stating that no specific level has to be guaranteed. An obligation of effort rather than result.
That is a softening, not a removal. And the common reading of it, that no penalty attaches any more, is wrong in a specific way. Article 4 does not appear in the Article 99 list of finable provisions, so there is no harmonized EU ceiling for breaching it. National authorities can still penalize it, under the national laws Member States were required to adopt by August 2, 2025. The Commission says so in its own AI literacy Q&A. What is missing is the number, not the fine.
One thing did not move at all. If you deploy high-risk systems, the Article 26 duty to make sure the people running human oversight are trained for it is untouched.
August 2, 2025, already applicable:
GPAI model obligations. Articles 51-56. Transparency, documentation, copyright compliance, systemic risk assessment for high-capability models. If you’re a provider of a general-purpose AI model, you’re already in scope. The AI Office enforces this.
Governance structures (the AI Board, the Scientific Panel, the Advisory Forum) all required to be operational. Member States were supposed to have designated national competent authorities and adopted national penalty laws by this date.
What Still Lands in August 2026, Unchanged
August 2, 2026, not delayed by the Omnibus:
Transparency obligations under Article 50. If your AI system interacts with people, they need to know. Deepfake labelling. AI-generated content disclosure. Still on the original schedule.
National enforcement begins. Market surveillance authorities start supervising. This is when regulators gain teeth: for everything already in force plus the transparency rules.
GPAI enforcement powers. The AI Office can start imposing fines on GPAI providers.
August 2, 2026 was supposed to be the date when everything came into force: the full high-risk regime, transparency, enforcement, all of it. The omnibus carved out the high-risk obligations. It left the rest.
What Moved & The Actual Changes
December 2, 2026, new:
The new Article 5 prohibitions. Two of them, covering AI-generated child sexual abuse material and non-consensual intimate imagery. This isn't a delay. It's a tightening, and it is the one thing in the omnibus that moved against industry. Full treatment further down.
Watermarking obligations. Providers must implement marking of AI-generated content, and this is not a blanket move to December. Systems already on the market before August 2, 2026 have until December 2, 2026, four months. Anything placed on the market from August 2 marks its output from day one. The date only helps systems that already existed.
December 2, 2027, delayed from August 2, 2026:
High-risk obligations for Annex III systems. These are the standalone high-risk AI systems, classified by use case rather than by product category. Biometric identification. Critical infrastructure. Education and vocational training. Employment and workers management. Credit scoring and access to essential services. Law enforcement. Migration and border control. Administration of justice.
This is the big one. The most-discussed change. The one that moved every compliance officer’s calendar by 16 months.
August 2, 2028, delayed from August 2, 2027:
High-risk obligations for Annex I systems, meaning AI embedded in products regulated by other EU sectoral safety legislation. Medical devices. In vitro diagnostics. Lifts. Toys. Radio equipment. Pressure equipment. These are the Section A products, and they are the ones the full high-risk regime reaches on this date. Eight months after the Annex III deadline.
Section B is a different animal. Aviation, motor vehicles, rail and marine equipment sit there, and under Article 2(2) only a thin slice of the AI Act reaches them: Article 6(1), the new Article 60a on real-world testing, and Articles 102 to 112. Nothing new lands for those products in August 2028. If someone tells you the aviation deadline moved, ask which obligation they think is arriving.
These are fixed dates. You can plan around them.
Other changes worth knowing:
National regulatory sandboxes. The deadline for Member States to establish at least one moved from August 2026 to August 2027.
The EU-level sandbox. Article 57(3a) lets the Commission establish one. It says “may,” not “shall,” and it is scoped to the systems the AI Office supervises under Article 75(1). The priority access for SMEs, start-ups and small mid-caps sits in the national sandbox provisions, not this one.
SME privileges extended to small mid-cap companies. Fewer than 750 employees, turnover not exceeding EUR 150 million or a balance sheet total not exceeding EUR 129 million, and not already an SME. The definition sits in Commission Recommendation (EU) 2025/1099. Simplified documentation. Proportionate quality management. Tailored penalty caps.
The machinery carve-out, the issue that collapsed the first trilogue. Machinery Regulation products were migrated out of Annex I Section A into Section B and handed to delegated acts. The Commission must adopt those by August 2, 2028, adding AI-specific health and safety requirements under the Machinery Regulation itself.
Migrated, not released. Article 5, Article 50 and the Chapter V obligations still apply to AI in machinery. What changed is that the Chapter III high-risk requirements no longer arrive on a date. They arrive in a different instrument.
The EU high-risk database registration obligation, reinstated. The Commission had proposed removing the requirement for providers to register AI systems they'd self-assessed as non-high-risk. Both Parliament and Council said no. If you determine your system isn't high-risk, you still register that determination. Regulators, and the public, can see who's claiming exemptions.
New Article 4a creates a legal basis for processing special categories of personal data to detect and correct bias, under six cumulative conditions. It used to sit with providers of high-risk systems. It now reaches all providers and deployers, and the co-legislators tightened the Commission’s proposed necessity test to strict necessity.
The AI Office got powers of its own. Amended Article 75 gives it exclusive competence over AI systems built on general-purpose models within the same undertaking, and over systems embedded in very large online platforms and search engines under the Digital Services Act. New Articles 75a to 75d give it information requests, inspections, a commitments procedure and its own fining power. From August 2, 2026.
Article 42(3) now grants a presumption of conformity with the AI Act’s cybersecurity requirement to systems complying with Article 12(1) of the Cyber Resilience Act. Small, and useful if you are already doing Cyber Resilience Act work.
The updated timeline
Feb 2, 2025: Prohibited practices (Art. 5) and AI literacy (Art. 4). Already in force. Art. 4 softened July 2026, Art. 5 extended December 2026.
Aug 2, 2025: GPAI obligations, governance, national authority designation, penalties regime. Already in force.
Jul 27, 2026: Digital Omnibus on AI enters into force.
Aug 2, 2026: Transparency (Art. 50), market surveillance, GPAI enforcement. Unchanged.
Dec 2, 2026: New Article 5 prohibitions, and the watermarking grace period. New.
Aug 2, 2027: GPAI legacy compliance, and the national sandbox deadline. Sandbox delayed one year.
Dec 2, 2027: High-risk, Annex III. Delayed from Aug 2, 2026.
Aug 2, 2028: High-risk, Annex I Section A. Delayed from Aug 2, 2027. Machinery moved to delegated acts, same date.
The Traps in the Fine Print
The two-date trap. If someone on your team says “high-risk was pushed to 2027,” they’re half right. Annex III systems hit December 2, 2027. Annex I Section A systems hit August 2, 2028. That’s an eight-month gap. If your AI systems span both, you’re planning for two deadlines, not one. And if you’re not sure which category your system falls into, that’s the question to answer first.
The enforcement paradox. National supervisory authorities started enforcing in August 2026. But the high-risk obligations, the most substantial compliance requirements in the entire AI Act, just moved to 2027 and 2028. So what are regulators actually doing?
Enforcing the prohibited practices. AI literacy. Transparency obligations. GPAI compliance, primarily through the AI Office. Lighter than the full high-risk regime, and still real. If you’ve been ignoring AI literacy because you were focused on the high-risk deadline, that is now your problem. Regulators will ask what you’ve been doing since February 2025. Eighteen months of nothing is not a defensible answer.
The Regulation says the quiet part itself. Recital 2 gives the delayed preparation of standards and “the delayed establishment of the governance and the conformity assessment frameworks at national level” as the reason the compliance burden turned out heavier than expected. The obligations were deferred partly because the machinery to supervise them was never built.
The permission to procrastinate. The most predictable outcome of the delay, and the most dangerous for the companies doing it.
The requirements aren’t changing. Only the deadline moved. The risk management system, the quality management, the technical documentation, the conformity assessment, the human oversight, the logging: all of it is still coming. Companies that treat December 2027 as permission to deprioritize will be scrambling again in 15 months. Same panic. Same compressed timelines. Different year.
The companies that keep going, using the extra time for quality instead of delay, will be the ones who are ready.
The One Thing That Got Tighter
While everything else in the Digital Omnibus on AI is about giving industry more time, the new prohibitions went the other direction.
Two prohibitions were added. Article 5(1)(ba) covers AI systems that generate or manipulate realistic material showing an identifiable person’s intimate parts, or that person engaged in sexually explicit conduct, without their freely given, specific, informed, unambiguous and explicit consent. Article 5(1)(bb) covers child sexual abuse material within the meaning of Directive 2011/93/EU, with a narrow exception where the conduct is lawful under national law.
The material has to be realistic. The person has to be identifiable. The consent standard is active consent, not the absence of an objection. And a separate paragraph carves out alterations that are not intimate.
The part that reaches ordinary businesses is Article 5(1a). A system is not caught because a determined user could eventually coax something out of it. It is caught where that generation is the intended purpose, or where the system’s design, training, architecture, capabilities or user-facing functionality make it a reasonably foreseeable and reproducible outcome, and the provider has no reasonable and adequate technical safety measures capable of reliably preventing it or correcting misuse once reported.
So the standard is not undefined. It is defined and untested, which is a different problem and a worse one.
Note what it attaches to. Article 5 speaks to AI systems, not to models. A general-purpose model provider is caught in its capacity as the provider of a system it places on the market, not by virtue of having a model.
Deployers get the narrower test. Caught only where they use the system for the purpose of generating that material, including by circumventing the provider’s safeguards. Accidental output is not caught.
Same prohibition, two different questions. Of a provider: what does your system reliably prevent? Of a deployer: what did you use it for?
The Political Context
In November 2025, 127 civil society organizations signed an open letter against the Digital Omnibus. Access Now, Amnesty International, European Digital Rights, noyb, Privacy International, AlgorithmWatch. Their target was broader than this deal: the letter opposed the whole package, GDPR and ePrivacy included, not the AI amendments that eventually emerged in May.
Their argument is that the systems most likely to affect vulnerable people, meaning biometric surveillance, AI in law enforcement, AI in employment, AI in education, now get one to two more years without full compliance requirements. That’s not simplification, they say. That’s rollback.
The Commission’s counter-argument is practical. You cannot measure conformity against standards that do not exist, and the harmonized standards do not exist. That argument is correct. It also does not make the deferral costless, and the people carrying the cost are not the people who asked for it.
What to Do Now
Were you preparing for August 2026 high-risk compliance? Don’t stop. Shift the goal to December 2027 for Annex III, or August 2028 for Annex I Section A. Use the runway for quality, not delay.
Been ignoring AI literacy? That’s your most immediate problem. Supervision started in August 2026. The obligation is softer than it was. It is not gone, there may well be a national penalty attached to it, and regulators will still ask what you have been doing since February 2025.
Do you place a generative AI system on the market? You have a near-term clock: safeguards under the new Article 5 prohibitions by December 2026. That reaches general-purpose image and video generators, API providers and white-label resellers, not only purpose-built tools.
Companies with fewer than 750 employees that are too big to count as an SME should check whether they qualify for the new small mid-cap category. Simplified documentation. Lighter compliance.
And if you’re not sure whether your AI system is even high-risk, start there. The classification question determines everything else.
Then read Article 6 again. The Omnibus did change the classification rules. Article 6 gained three new paragraphs. Two narrow the safety-component route into high-risk, one widens it back. Article 6(3), the filter companies rely on to argue they are out, is untouched. So the answer to “are we high-risk” may have changed even though the date for acting on it moved further away.
The AI Act is two years old. It’s already been amended before it’s fully in effect. More amendments are coming, the Commission has said so. The regulation that was supposed to be a settled text is becoming a moving one.
But underneath the shifting deadlines, the obligations that have been running since February 2025 haven’t stopped. AI literacy. The prohibited practices. Those don’t have a new date. They have an old one, and it already passed.
The Omnibus gave you time. Not a pardon.
Scope is where this becomes something you can use in a meeting: the regulation map, the role assignment, the vendor questions, the AI inventory spreadsheet, the AI policy template, with sources attached and kept current as the law changes.







I think one of the most important points in all of this is hidden inside the phrase:
“the omnibus gave you time, not a pardon.”
Because many of the hardest governance problems were never really about documentation deadlines to begin with.
The deeper problem is that highly capable systems increasingly participate in real-world relational and operational continuity long before regulatory structures fully understand how to govern the downstream consequences.
Which means delaying compliance timelines does not delay:
uncertainty,
interaction,
behavioral influence,
or consequence propagation.
And that’s probably why runtime governance, epistemic accountability, and continuity-aware system design are becoming more important than static compliance snapshots alone.
The question is slowly shifting from:
“Was the system compliant at deployment?”
to:
“How does the system remain accountable to what it sets into motion after deployment?”