Skip to content
SimpleAct Logo

EU AI Act · Digital Omnibus

As of 4 October 2026 · Regulation (EU) 2026/1744 in force since 27 July 2026

Digital Omnibus on the AI Act: what changes – and what does not

The Digital Omnibus on AI postpones the high-risk obligations, rewrites Art. 4 on AI literacy, adds two prohibitions and gives relief to SMEs and small mid-caps. Every change is listed here with its reference in the Official Journal – before, after, and what it means for your system.

  • Before → after from the Official Journal
  • Every new key date
  • Check by system type and role
  • Sources on EUR-Lex
app.simpleact.de

High-risk AI under Annex III

Start of application, Chapter III Sections 1–3

A
beforeafter
  • Annex III02.08.202602.12.2027
  • Annex I02.08.202702.08.2028
  • Art. 50(2) (legacy)02.08.202602.12.2026
  • National sandboxes02.08.202602.08.2027

Source: Art. 113, 111, 57 AI Act as amended by Regulation (EU) 2026/1744

In short

The Digital Omnibus on AI is Regulation (EU) 2026/1744, in force since 27 July 2026. High-risk obligations apply to Annex III systems from 2 December 2027 instead of 2 August 2026, and to Annex I systems from 2 August 2028. Art. 4 was softened and two prohibitions apply from 2 December 2026. Art. 50 and the GDPR stay as they are.

Basics

What is the Digital Omnibus on AI?

"Digital Omnibus" is the EU’s label for a package meant to simplify existing digital laws. For the AI Act, that is the "Digital Omnibus Regulation on AI", officially Regulation (EU) 2026/1744 of 8 July 2026. It amends the AI Act, Regulation (EU) 2024/1689, in 43 points and also adjusts the civil aviation Regulation (EU) 2018/1139 and the Machinery Regulation (EU) 2023/1230.

The European Parliament adopted its position on 16 June 2026 and the Council approved it on 29 June 2026. The regulation was published in the Official Journal of the EU on 24 July 2026 and entered into force on the third day after that, 27 July 2026 (Art. 4 of Regulation 2026/1744). The new dates and rules are therefore law, not an announcement.

The regulation states the reason for the delay itself: standards, common specifications and guidance were not available in time, and many Member States had not yet set up their competent authorities. Keeping 2 August 2026 would, in the legislator’s view, have raised implementation costs disproportionately (recital on Art. 113).

Important for the bigger picture: the Omnibus is more than a postponement. It rewrites the AI literacy duty, creates a dedicated legal basis for processing sensitive data to correct bias (Art. 4a), extends the list of prohibited practices, gives the AI Office its own supervisory and fining powers and widens the relief for smaller companies. The basic architecture – risk classes, roles, catalogue of obligations – stays the same.

number of the amending regulation
2026/1744
number of the amending regulation
entered into force
27.07.2026
entered into force
amendment points to the AI Act
43
amendment points to the AI Act

Before → after

Every key change at a glance

On the left the 2024 text of the AI Act, on the right the text after Regulation (EU) 2026/1744. The reference points to the article of the AI Act as it applies today.

Scroll the table sideways →

Every key change at a glance
TopicBefore (Reg. 2024/1689)After (Reg. 2026/1744)ReferenceAffects
High-risk AI under Annex IIIObligations from 2 August 2026Obligations from 2 December 2027Art. 113(3)(c)(i)Providers, deployers
High-risk AI under Annex I (products)Obligations from 2 August 2027Obligations from 2 August 2028Art. 113(3)(c)(ii)Providers, deployers
AI literacyMeasures to ensure, "to their best extent", a sufficient level of AI literacyMeasures to support the development of AI literacy; Commission and Member States promote it, examples will be publishedArt. 4(1)–(3)All providers and deployers
Prohibited practicesList in Art. 5(1)(a)–(h)New point (ba) (non-consensual intimate depictions of identifiable persons) and (bb) (child sexual abuse material), from 2 December 2026Art. 5(1)(ba), (bb), (1a), (1b); Art. 113(3)(a)Providers, deployers of generative AI
Marking synthetic content (legacy systems)From 2 August 2026 for all systemsSystems placed on the market before 2 August 2026: by 2 December 2026Art. 111(4)Providers of generative AI
Sensitive data for bias correctionHigh-risk providers only, in Art. 10(5)Own Art. 4a: high-risk providers (para. 1) and, exceptionally, other providers and deployers (para. 2), under strict conditionsArt. 4a; Art. 10(5) deletedProviders, some deployers
Technical documentationSimplified form for SMEs including start-upsCommission’s simplified form also for small mid-caps; notified bodies must accept itArt. 11(1), 2nd subpara.Providers (SMEs, small mid-caps)
Quality management systemProportionate to size; simplified elements for microenterprises only (Art. 63)Proportionality explicitly for SMEs and small mid-caps; simplified elements for all SMEs without partner or linked enterprisesArt. 17(2); Art. 63(1)Providers (SMEs, small mid-caps)
Fines for small mid-capsLower amount for SMEs only (Art. 99(6))Lower amount for small mid-caps too; interests of both groups considered in penaltiesArt. 99(1), (6a)SMEs, small mid-caps
Change of providerInitial provider cooperates, provides information and technical access (unless clearly excluded)Specified: technical documents on Art. 16, known limitations and failure modes, targeted access for testing; breaches now subject to finesArt. 25(2), (4); Art. 99(4)(da)Providers, suppliers
Fundamental rights impact assessmentFRIA complements an existing DPIADeployers may refer to relevant DPIA sections or include parts of it; the AI Office template questionnaire is to allow thisArt. 27(4), (5)Deployers required to do a FRIA
Registration under the Art. 6(3) exceptionRegistration in the EU databaseRegistration remains mandatory; two data items in Annex VIII Section B removedArt. 49(2); Annex VIII Section B points 7, 9 deletedProviders
Safety componentGeneral definitionClarified: pure comfort, efficiency or quality-control functions without a safety role are not a safety componentArt. 3(14); Art. 6(1a)–(1c)Providers of product AI
MachineryMachinery Directive in Annex I Section AMachinery Regulation (EU) 2023/1230 in Annex I Section B (sectoral approach)Annex I; Art. 2(2)Machinery manufacturers
Supervision of AI built on own GPAI modelsNational market surveillanceAI Office exclusively, with its own investigative and fining powersArt. 75(1); Art. 75a–75dProviders of GPAI models and systems based on them
National AI regulatory sandboxesOperational by 2 August 2026Operational by 2 August 2027; an EU-level sandbox is also possibleArt. 57(1), (3a)Member States, innovators
CybersecurityRequirements in Art. 15Where a system meets the conditions of the Cyber Resilience Act (Reg. 2024/2847, Art. 12(1)), the cybersecurity requirements of Art. 15 are deemed metArt. 42(3)Providers

A selection of the points that matter most to companies. Only the regulation itself is complete; procedural changes (notified bodies, boards, fees) are not listed here.

Key dates

The key dates after the Omnibus

Every date that matters to companies, in order. What the Omnibus postponed or introduced is marked.

Scroll the table sideways →

The key dates after the Omnibus
DateWhat appliesReferenceOmnibus effect
2 February 2025Prohibitions under Art. 5(1)(a)–(h) and the AI literacy duty (Art. 4)Art. 113(3)(a)unchanged
2 August 2025Obligations for providers of general-purpose AI models (Chapter V), governance, penaltiesArt. 113(3)(b)unchanged
27 July 2026Omnibus in force: new Art. 4, Art. 4a, SME and mid-cap relief, among othersArt. 4 Reg. 2026/1744new
2 August 2026General application, Art. 50 transparency duties; the Commission can fine GPAI providers (Art. 101)Art. 113(2)unchanged
2 December 2026New prohibitions Art. 5(1)(ba) and (bb); Art. 50(2) marking for legacy systemsArt. 113(3)(a); Art. 111(4)new
2 August 2027National AI regulatory sandboxes operational; legacy GPAI models (placed on the market before 2 August 2025) must complyArt. 57(1); Art. 111(3)postponed (sandboxes)
2 December 2027Obligations for high-risk AI under Annex III (providers and deployers)Art. 113(3)(c)(i)postponed
2 August 2028Obligations for high-risk AI under Annex I (products such as medical devices)Art. 113(3)(c)(ii)postponed
2 August 2030High-risk AI intended for use by public authorities: providers and deployers complyArt. 111(2)unchanged
31 December 2030AI components of large-scale IT systems under Annex XArt. 111(1)unchanged
Deadline finder with calendar export

Interactive

Omnibus check: what changes for your system?

Pick the system type, your role and company size. The check lists which Omnibus changes apply to that combination – with references. It does not replace a case-by-case assessment.

What kind of AI system is it?
Your role
Placed on the market or put into service before 2 December 2027?
Is the system intended for use by public authorities?
Company size

SMEs as defined in Recommendation 2003/361/EC, small mid-caps as defined in Recommendation (EU) 2025/1099.

Relevant changes

4
  • changedArt. 113(3)(c)(i)

    High-risk obligations postponed

    before: 2 August 2026→2 December 2027

    Chapter III Sections 1 to 3 – requirements, provider and deployer obligations including Art. 26 – apply to Annex III systems only from 2 December 2027. The substance of the obligations is essentially unchanged.

  • changedArt. 27(4), (5)

    The FRIA can refer to the DPIA

    If you must carry out a fundamental rights impact assessment (public bodies, private providers of public services, Annex III point 5(b) and (c)): you may refer to the relevant sections of your data protection impact assessment or include parts of it – previously the FRIA merely "complemented" the DPIA. The AI Office template questionnaire is to allow such references.

  • changedArt. 4

    AI literacy rewritten

    Since 27 July 2026, Art. 4 requires measures that support the development of your staff’s AI literacy – no longer ensuring a sufficient level "to their best extent". The duty still applies to all providers and deployers. Recommendation: keep documenting training and guidance anyway.

  • unchangedArt. 99(1), (6)

    Fines: lower amount for SMEs

    For SMEs, each fine is capped at the lower of the fixed amount and the turnover percentage. New: Member States must expressly consider the economic viability of SMEs when imposing penalties.

Guidance, not legal advice. Whether a system is high-risk depends on the actual use – check the classification first.

Check the classification: Annex III in detail

In detail

The changes that affect companies most

What the text actually says – and what it means in practice. Recommendations are marked as such.

Art. 113(3)(c)

Postponement of the high-risk obligations

Chapter III Sections 1 to 3 of the AI Act – classification, requirements for high-risk systems and the obligations of providers, deployers and other operators – apply to Annex III systems from 2 December 2027 and to Annex I systems from 2 August 2028. The deployer obligations in Art. 26 move with them, for example keeping logs for at least six months and informing workers’ representatives in advance.

The rule for legacy systems matters in practice (Art. 111(2)): what is placed on the market or put into service before the date of application is covered by the high-risk obligations only if its design changes significantly afterwards. Systems intended for public authorities must comply by 2 August 2030 regardless. Recommendation: record the date each system went live and any later changes – that is the only way to show later whether a system benefits from the legacy rule.

Art. 4

AI literacy: support instead of ensure

Until now, providers and deployers had to take measures to ensure, "to their best extent", a sufficient level of AI literacy among their staff. The new text requires measures to support the development of AI literacy – taking into account knowledge, experience, training and the context of use. Paragraphs 2 and 3 are new: the Commission and Member States promote implementation, the Commission publishes practical examples and the AI Board issues recommendations.

So the duty has not gone away; it is worded more softly. The AI Act itself provides no separate fine bracket for Art. 4 (Art. 99(4)). Since the Digital Omnibus (Regulation (EU) 2026/1744), however, Member States can penalise any infringement (Art. 99(1) as amended); in Germany Art. 4 is currently not subject to fines (§ 15 KI-MIG). Recommendation: keep documenting training, guidance and approval rules – it is the simplest evidence that you took measures, and high-risk deployers need it anyway because human oversight must be assigned to competent persons (Art. 26(2)).

Art. 5(1)(ba), (bb), (1a), (1b)

Two new prohibitions

From 2 December 2026, AI systems are prohibited that generate or manipulate realistic image, video or audio content depicting the intimate parts or sexually explicit acts of an identifiable person without that person’s free, specific consent (point (ba)). Systems that generate or manipulate child sexual abuse material within the meaning of Directive 2011/93/EU are prohibited too (point (bb)).

Paragraph 1a draws the line: for providers, the ban applies where such content is the system’s purpose, or a foreseeable and reproducible result of its design and functions without significant technical changes – and the system lacks reasonable safeguards. For deployers it applies where they use the system for such content. Recommendation for providers of generative AI: document filters and abuse protection by December.

Art. 50; Art. 111(4)

Transparency under Art. 50

The transparency duties apply as originally planned since 2 August 2026: notice of direct interaction with AI (para. 1), machine-readable marking of synthetic content (para. 2), information on emotion recognition and biometric categorisation (para. 3), disclosure of deepfakes (para. 4).

The Omnibus only adds a transition: generative systems placed on the market before 2 August 2026 have until 2 December 2026 for marking under para. 2. Para. 7 on codes of practice was also reworded. The code of practice on marking AI-generated content has been final since 10 June 2026; it is voluntary.

Art. 3(14a), (14b); Art. 11, 17, 63, 99

Relief for SMEs and small mid-caps

"SME" (Recommendation 2003/361/EC) and "small mid-cap" (Recommendation (EU) 2025/1099) are now defined. Small mid-caps are companies that have outgrown the SME thresholds but are not yet large; the exact thresholds are in the recommendation.

Both groups may provide technical documentation through the Commission’s simplified form (Art. 11), implement the QMS proportionately (Art. 17(2)) and benefit from the lower amount for fines (Art. 99(6) and (6a)). SMEs without partner or linked enterprises may meet certain QMS elements in a simplified way (Art. 63). The level of protection does not drop – the form is simplified, not the requirement.

Art. 4a; Art. 2(7)

Sensitive data for bias correction

The new Art. 4a exceptionally allows providers of high-risk AI to process special categories of personal data to detect and correct bias. Paragraph 2 extends this, under the same conditions, to providers and deployers of other AI systems and models and to deployers of high-risk AI where the bias could affect health, safety, fundamental rights or lead to prohibited discrimination – it does not create a duty to test for bias.

The conditions are strict: not achievable with other data, including synthetic or anonymised data; pseudonymisation and limits on re-use; strict, documented access control; no transfer to third parties; deletion after correction or at the end of the retention period; reasons recorded in the record of processing activities. Art. 2(7) makes clear that the GDPR otherwise remains unaffected.

Art. 27(4), (5)

Fundamental rights impact assessment and DPIA

Deployers who must carry out a fundamental rights impact assessment – public bodies, private entities providing public services and deployers of systems under Annex III point 5(b) and (c) – may refer to the relevant sections of their DPIA for duties already met by it.

Previously the text only said the FRIA "complements" the DPIA. The AI Office template questionnaire, also as an automated tool, is now expressly to offer the option of including such references. Recommendation: run DPIA and FRIA in one joint process so that references are easy to trace.

Art. 75, 75a–75d

Supervision by the AI Office

For AI systems based on a general-purpose AI model where model and system come from the same provider or group, the AI Office is now exclusively competent. The same applies to AI systems that constitute or are integrated into a very large online platform or search engine under the Digital Services Act. Exceptions include product AI under Annex I and systems under Annex III point 2.

The AI Office gets its own powers: requests for information, inspections, binding commitments, fines under Art. 99 and periodic penalty payments of up to 5% of average daily turnover per day. For deployers, this competence applies only if they are also the provider or part of the provider’s group.

Unchanged

What the Omnibus does not change

The postponement is often read as a "pause". These points continue to apply unchanged:

  • Prohibited practices since 2025

    The prohibitions under Art. 5(1)(a)–(h) apply since 2 February 2025, with fines of up to €35 million or 7% of worldwide annual turnover (Art. 99(3)).

  • Transparency since 2 August 2026

    Art. 50 applies on the original date; only legacy systems get until 2 December 2026 for para. 2.

  • GPAI obligations

    Obligations for providers of general-purpose AI models apply since 2 August 2025; legacy models by 2 August 2027.

  • Fine levels

    The maximum amounts in Art. 99 (€35m/7%, €15m/3%, €7.5m/1%) are unchanged.

  • Substance of the high-risk obligations

    Risk management, data governance, logging, human oversight, deployer duties under Art. 26 – postponed, not deleted.

  • The GDPR

    Regulation (EU) 2026/1744 does not amend the GDPR. Records of processing, data subject rights, DPIAs and breach notification apply as before.

Approach

What to do with the extra time

Editorial recommendation – not a legal sequence. The extra time is most valuable when you use it for the groundwork every later obligation depends on.

  1. 01

    Complete the inventory

    Record every AI system with purpose, provider, role, go-live date and data types. Without an inventory you can prove neither the classification nor the legacy rule under Art. 111(2).

  2. 02

    Check the classification

    For each system: Annex III, Annex I, Art. 50 or minimal risk? Document and register exceptions under Art. 6(3). The Commission’s guidelines on high-risk classification are expected by the end of 2026.

  3. 03

    Secure generative AI by December

    Art. 50(2) marking for legacy systems by 2 December 2026; reflect the new prohibitions from the same day in usage policies and safeguards.

  4. 04

    Keep AI literacy going

    Role-based training, short guides, a contact person. The softer wording of Art. 4 is no reason to stop existing programmes.

  5. 05

    Plan high-risk projects

    Plan backwards from 2 December 2027: request provider documents, define logging and oversight, link DPIA and FRIA, involve workers’ representatives.

  6. 06

    Use the relief

    Check whether you are an SME or a small mid-cap – then plan for the simplified documentation form and a proportionate QMS.

AI Check

Am I affected by the EU AI Act?

Answer 5 short questions in under 1 minute and find out whether your company needs AI documentation.

Step 0 of 5

What is your role in the company?

This lets us tailor the results to your situation.

What you’ll get

  • Instant risk classification
    Are you affected by the EU AI Act – and at which risk level?
  • Steps tailored to your role
    Concrete recommendations for Compliance, IT, Legal or Management.
  • In under a minute, no sign-up
    5 quick questions – that’s it.
Example result
High-risk AI

→ Create an AI inventory and document your high-risk systems.

Which systems count as high-risk (Annex III) →

⚖️ This check is not legal advice. If in doubt we recommend legal review.

FAQ

Frequently asked questions about the Digital Omnibus

Yes. The European Parliament approved it on 16 June 2026 and the Council on 29 June 2026. Regulation (EU) 2026/1744 was published in the Official Journal of the EU on 24 July 2026 and entered into force on 27 July 2026. The new dates are binding.
For high-risk AI under Annex III (e.g. recruitment, creditworthiness, education) from 2 December 2027; for AI in products under Annex I (e.g. medical devices) from 2 August 2028. High-risk systems used by public authorities must also comply by 2 August 2030 (Art. 111(2)).
No. Art. 50 applies since 2 August 2026. Only generative systems placed on the market before that date have until 2 December 2026 for machine-readable marking under Art. 50(2) (Art. 111(4)).
No, it was reworded. Providers and deployers take measures to support the development of their staff’s AI literacy, instead of ensuring a sufficient level "to their best extent". The AI Act provides no separate fine bracket for Art. 4 (Art. 99(4)), but since the Omnibus Member States can penalise any infringement (Art. 99(1) as amended); in Germany Art. 4 is currently not subject to fines (§ 15 KI-MIG). We recommend continuing to document training.
From 2 December 2026, AI systems that generate or manipulate realistic intimate depictions of identifiable persons without consent, and systems that generate child sexual abuse material (Art. 5(1)(ba) and (bb)). Paragraph 1a sets out when providers and deployers are covered.
A small mid-capitalisation company within the meaning of point 2 of the Annex to Recommendation (EU) 2025/1099 – in simple terms, companies that exceed the SME thresholds but are not yet large. The AI Act refers to it in Art. 3(14b); the exact thresholds are in the recommendation.
For systems placed on the market or put into service before Chapter III applies, the regulation applies only if their design changes significantly afterwards (Art. 111(2)). Exceptions: prohibitions under Art. 5 always apply, and systems for public authorities must comply by 2 August 2030.
Regulation (EU) 2026/1744 does not amend the GDPR. Art. 2(7) of the AI Act makes clear that, apart from Art. 4a and Art. 59 of the AI Act, the GDPR remains unaffected. Your data protection duties continue regardless of the AI Act dates.
Yes. Art. 49(2) is unchanged: providers who classify an Annex III system as not high-risk under Art. 6(3) register it in the EU database. The Omnibus only removed two data items from Annex VIII Section B.
Only exceptionally and under the conditions of Art. 4a: strictly necessary, not achievable with other data, pseudonymisation, strict access control, no transfer, deletion after correction and reasons recorded in the record of processing. Art. 4a(2) does not create a duty to run such tests.
Deployer obligations under Art. 26 apply to Annex III systems only from 2 December 2027. Art. 4 is worded more softly, the FRIA can refer to the DPIA, and from 2 December 2026 using AI for the newly prohibited content is banned. Art. 50(3) and (4) apply unchanged.
We do not recommend it. Inventory, classification and documentation typically take months, Art. 4, Art. 5 and Art. 50 already apply, and for the legacy rule in Art. 111(2) you need to show go-live dates and changes per system.

More questions? We're happy to help. Send email · Get started

Sources and status

As of · SimpleAct editorial team

This page is an overview and not legal advice. Only the text published in the Official Journal is authoritative. Examples and approaches are editorial recommendations.

Changes to this page

  • 2026-10-04 – Page rebuilt: before/after table from the Official Journal text, key dates, Omnibus check, details on Art. 4, 4a, 5, 27, 50, 75 and SME relief, sources. Corrected the statement that it "only changes deadlines"; removed survey figures we could not verify.
  • 2026-10-03 – Legal status updated: publication in the Official Journal (24.7.2026) and entry into force (27.7.2026).
  • 2026-07-08 – First published.

Use the extra time in a structured way

SimpleAct keeps your AI inventory, risk classification, deadlines and evidence in one place – so you are not under time pressure before 2 December 2027.