The AI Act Digital Omnibus entered into force on 27 July 2026, just days before the original high-risk AI compliance deadline would have applied. It is the first formal set of amendments to the EU AI Act since the regulation was adopted in June 2024, and it makes targeted adjustments rather than a structural rewrite. For SMBs using or building AI systems, understanding exactly what changed and what stayed the same is now a compliance priority, not a future consideration.
The short version: deadlines moved, some obligations were scaled back for smaller businesses, and two new prohibitions were added. The core risk-based framework, the prohibited practices, and the underlying compliance requirements for high-risk AI systems all remain intact. What follows is a clear breakdown of each change, who it affects, and what it means in practice.
Key obligations dropped or scaled back
The Omnibus reduced administrative burden without dismantling the substance of the AI Act. Several specific obligations were softened or narrowed, particularly for smaller organisations.
The Article 4 AI literacy obligation was the most visible change. Under the original AI Act, providers and deployers were required to ensure a sufficient level of AI literacy among their staff. The Omnibus softens this to an obligation to “take measures to support” AI literacy, shifting the broader promotion of AI literacy to the European Commission and Member States. The absolute duty on individual companies is removed.
The definition of “safety component” was also narrowed. AI systems that only assist users or optimise performance will not automatically face high-risk obligations if their failure or malfunction does not create health or safety risks. This is a meaningful carve-out for productivity and workflow tools that were previously caught by an overly broad definition.
On EU database registration, the Commission’s original proposal had sought to remove the registration obligation entirely for providers relying on Article 6(3) exemptions (self-assessed non-high-risk systems). The final agreement kept the obligation but simplified the registration procedure, requiring fewer data fields. Registration is still required; only the process is lighter.
AI embedded in machinery products is addressed through a sector-specific carve-out. Machinery-embedded AI will be removed from direct AI Act application, with AI-related safety measures instead introduced through delegated acts under the Machinery Regulation. The Commission also gained new powers to use implementing acts to disapply overlapping AI Act requirements where equivalent sectoral rules already cover the same ground. Fines remain unchanged at up to €35 million or 7% of global annual turnover for the most serious violations.
Who the changes actually affect
The Omnibus introduces a new formal category of company that sits between SMEs and large enterprises, and it extends meaningful regulatory relief to a much wider population of businesses than before.
The new category is “small mid-cap enterprises” (SMCs), defined as companies that are not SMEs but employ fewer than 750 people and have annual turnover not exceeding €150 million or a balance sheet total not exceeding €129 million. Several flexibilities previously reserved for SMEs now extend to SMCs, closing a gap where growing companies lost SME-level support the moment they crossed the SME threshold.
What SMEs and SMCs now benefit from
SMCs gain access to simplified technical documentation requirements using templates that notified bodies must accept, more proportionate quality management system (QMS) expectations, and penalty caps calibrated to their size. SMEs themselves gain access to the further simplified QMS requirements previously reserved only for microenterprises. Both categories also gain priority access to AI regulatory sandboxes.
For providers of high-risk AI systems in the standalone Annex III category (which includes recruitment screening tools, credit scoring systems, biometric categorisation, education platforms, and law enforcement tools), the compliance deadline has moved from 2 August 2026 to 2 December 2027. Systems already on the EU market before that new deadline are not subject to high-risk AI system (HRAIS) requirements unless they are substantially modified after that date.
Providers of AI systems built on GPAI models, where the model and the system are developed by the same provider or within the same corporate group, now fall under the exclusive competence of the EU AI Office rather than national authorities. The AI Office also gains new enforcement tools, including powers to conduct investigations, carry out on-site inspections, accept binding commitments, and impose fines directly.
One change that affects all providers and deployers: the legal basis for processing special categories of personal data (such as ethnicity or health data) for bias detection and correction has been expanded beyond high-risk AI providers to all providers and deployers. The “strict necessity” threshold was reinstated by the co-legislators, and mandatory safeguards apply, including considering non-sensitive or synthetic data first, pseudonymisation, access controls, and timely deletion.
What the revised timeline looks like
The Omnibus replaced a conditional “stop-the-clock” mechanism (which the Commission’s original November 2025 proposal had tied to the availability of harmonised standards) with fixed calendar dates. That shift removes planning ambiguity for businesses. The reason the deadlines moved at all is that harmonised technical standards from CEN/CENELEC, needed for conformity assessments, were not finalised by the original August 2026 deadline. Without those standards, conformity assessments could not be completed properly.
The complete revised compliance calendar, now in force as of 27 July 2026, is as follows:
- 2 February 2025 (already in force): Prohibited AI practices (Article 5) and AI literacy obligations (Article 4)
- 2 August 2025 (already in force): GPAI model obligations (Chapter 5) and governance and enforcement rules
- 2 August 2026 (now in force): Article 50 transparency obligations, including chatbot disclosure and deepfake labelling, except Article 50(2) watermarking for legacy systems
- 2 December 2026: Article 50(2) watermarking for AI systems already on the market before 2 August 2026; new prohibited practices covering nudification apps and CSAM generation take effect
- 2 December 2027: High-risk obligations for standalone Annex III systems (recruitment, credit scoring, biometrics, education, law enforcement, border control)
- 2 August 2028: High-risk obligations for AI embedded in regulated products under Annex I (medical devices, machinery, vehicles)
- 2 August 2030: Compliance deadline for AI systems intended for use by public authorities
The national AI regulatory sandbox deadline has also been postponed by one year to 2 August 2027. The Omnibus also introduces an EU-level regulatory sandbox, planned to be operational from 2028, giving companies more structured space to develop and test AI systems under regulatory supervision.
Obligations that did not change
The Omnibus adjusted timelines and reduced some administrative requirements, but the substance of what the AI Act demands from high-risk AI providers remains unchanged. This distinction matters because some businesses are treating the deadline extension as a pause. It is not.
The four-tier risk classification (unacceptable, high, limited, minimal risk) is intact. The Omnibus did not change what makes a system high-risk; it only moved when compliance is required. All prohibited AI practices under Article 5 have been in force since 2 February 2025 and were not touched by the Omnibus. These include bans on subliminal manipulation, social scoring by public authorities, and real-time biometric identification in public spaces (with narrow law enforcement exceptions).
GPAI model obligations under Chapter 5, including transparency requirements, technical documentation, and copyright compliance, have been in force since 2 August 2025 and were not changed. GPAI models placed on the market before that date have until 2 August 2027 to comply.
For high-risk AI systems, the full set of underlying compliance obligations remains completely unchanged: conformity assessment, quality management system, technical documentation, CE marking, EU database registration, human oversight, post-market monitoring, and fundamental rights impact assessments. Only the deadlines shifted.
The Omnibus also added two new prohibited practices to Article 5, effective 2 December 2026. AI systems that generate non-consensual intimate imagery (“nudifier” apps) and AI systems that generate child sexual abuse material (CSAM) are now explicitly prohibited. These prohibitions apply both to providers, who may not place such systems on the market, and to deployers, who are liable for intentional misuse.
Practical compliance steps under the new rules
Extended deadlines create a window for proper preparation, not a reason to delay. Conformity assessment, QMS setup, technical documentation, and EU database registration for high-risk AI systems require an estimated 12 to 24 months of preparation. Starting now for a December 2027 deadline is not early; it is on time.
The European Commission published Guidelines on Transparency of AI-generated content under Article 50 on 20 July 2026, along with a Code of Practice on Transparency. These provide practical guidance for the transparency obligations already in force. The Commission also published draft Guidelines on the classification of high-risk AI systems on 19 May 2026, with practical examples across sectors to guide Annex III assessments.
A structured starting point
Compliance practitioners and legal teams consistently recommend the following sequence:
- AI system inventory: Map every AI system in use, including shadow AI tools adopted informally by staff. Document purpose, provider, department, and internal stakeholders.
- Risk classification: Determine the risk level of each system against Annex III categories, using the Commission’s May 2026 draft classification guidelines as a reference.
- Provider vs. deployer role: Establish clearly whether the organisation acts as a provider or deployer for each system. Obligations differ substantially between the two.
- SME or SMC status: Assess whether the organisation qualifies as an SME or SMC to access simplified documentation templates and QMS requirements.
- Article 50 compliance: Verify that chatbot disclosure, AI-content marking, and deepfake labelling are in place. These obligations are already in force.
- Watermarking check: Determine whether any generative AI systems placed on the market before 2 August 2026 require machine-readable watermarking by 2 December 2026.
- High-risk roadmap: Re-baseline high-risk compliance planning to 2 December 2027 (Annex III) or 2 August 2028 (Annex I) and begin building risk management frameworks and governance structures now.
One legal uncertainty worth flagging: the concept of “substantial modification” is compliance-critical because AI systems placed on the market before the new deadlines avoid full HRAIS obligations unless substantially modified after the applicable date. The threshold for what constitutes a substantial modification has not yet been formally defined. Until official guidance is published, legal counsel should assess any planned updates to existing AI systems against this unresolved standard.
For businesses managing content at scale alongside AI compliance work, tools that automate structured content production (such as WP SEO AI’s content scaling service) can help maintain publishing velocity while internal resources focus on regulatory preparation.
What the Omnibus signals for future AI regulation
The AI Omnibus is part of “Omnibus VII,” the seventh simplification package in a broader EU-wide agenda launched in response to the Draghi and Letta competitiveness reports. Its passage signals that the EU is willing to revisit its own regulation when implementation is demonstrably off track, but it does not signal deregulation. The core risk-based framework, fundamental rights protections, and prohibited practices all remain intact.
Running in parallel is the broader Digital Fitness Check, a comprehensive review of the EU’s entire digital rulebook covering the AI Act, GDPR, the Data Act, ePrivacy, and cybersecurity laws. The public consultation closed in March 2026, with Commission findings planned for Q1 2027. This process could lead to more structural changes to digital regulation beyond the Omnibus’s targeted fixes.
The Omnibus also introduces a new mechanism: the Commission can now use implementing acts to disapply overlapping AI Act requirements where equivalent sectoral protection already exists. This could be applied iteratively as more sector-specific legislation is reviewed, making the AI Act more adaptive over time rather than a fixed monolith.
The critical path for the entire AI Act implementation is now the CEN/CENELEC harmonised standards process. If those standards are not finalised before December 2027, the EU will face pressure for a second extension, with reduced credibility. Industry observers note that the standards timeline is the single variable most likely to determine whether the December 2027 deadline holds.
The EU Council’s final approval of the Omnibus in June 2026 came with clear political messaging: simplification is welcome, but the fundamental rights architecture of the AI Act is not up for negotiation. For businesses planning their AI compliance roadmap, that framing is the most useful signal of all. Build for the framework as it stands. The deadlines may flex; the obligations will not.
This content was generated with the help of AI and it may contain mistakes