The EU's Digital Omnibus: streamlined AI Act compliance rules are now in force
Key contacts
On 27 Jul 2026 new rules to simplify and streamline key provisions of the EU AI Act came into force, having been granted final approval by the EU Council on 29 June 2026. The new law forms part of the EU’s broader “Omnibus VII” simplification package, and introduces significant changes to the compliance timeline. Following publication in the Official Journal of the European Union on 24 July 2026, the legislative act came into force on 27 July 2026. Whilst some deadlines have moved, obligations remain.
Background
The EU AI Act entered into force on 1 August 2024, and its provisions apply in phases. The ban on prohibited AI practices and AI literacy rules have been enforceable since 2 February 2025, and general-purpose AI model rules have applied since 2 August 2025. The Act’s provisions covering standalone (Annex III) high-risk AI systems and certain transparency obligations for providers and deployers were due to apply from 2 August 2026. In practice, delayed standards and guidance, together with the slow establishment of national authorities, created implementation challenges that the EU concluded justified extending the timeline. The Digital Omnibus on AI responded by extending parts of the timeline, while leaving the Act’s broader direction unchanged.
Key changes:
- High-risk AI deadlines pushed back. The new application dates are 2 December 2027 for standalone high-risk AI systems and 2 August 2028 for high-risk AI embedded in regulated products (such as medical devices, machinery, and toys).
- New prohibition on deepfakes and CSAM. AI systems that generate non-consensual intimate images of real people – including child sexual abuse material – are now explicitly prohibited. This ban is set to take effect from 2 December 2026.
- Sectoral overlap addressed. Where existing EU product safety legislation (e.g. for medical devices or machinery) already imposes AI-related requirements equivalent to the EU AI Act, the new regulation allows the EU AI Act’s application to be limited to avoid duplication in those specific cases n(through implementing acts). Machinery has been moved to a sectoral regime, with the Commission empowered to adopt secondary legislation incorporating AI-specific health and safety requirements.
- Grace period for certain transparency obligations for providers of generative AI systems. Providers of generative AI systems that have been placed on the market before 2 August 2026 will have a three-month grace period, until 2 December 2026, to comply with transparency and labelling requirements relating to artificially generated audio, image, video, or text content. Other Article 50 transparency obligations may still apply from 2 August 2026.
- Postponed deadline for establishing AI regulatory sandboxes. The deadline for Member States to establish national AI regulatory sandboxes has been extended to 2 August 2027, and the AI Office may now establish a sandbox at EU level.
Practical implications
The changes represent a targeted adjustment to the EU AI Act’s implementation timetable, rather than a broader change in policy direction. Organisations are likely to welcome the additional time to prepare for certain obligations, particularly in relation to high-risk AI systems. However, the phased application of the EU AI Act continues, and some requirements are already applicable or will apply shortly. Organisations should not treat the Digital Omnibus on AI as a general pause, rather they should keep preparing by mapping AI use cases, assessing applicable requirements and obligations, monitoring guidance and the development of harmonised standards, and planning for compliance by the relevant application dates. compliance plans should remain at the forefront of every business’ AI governance strategy.