On 27 July 2026, the long-awaited Digital Omnibus Regulation on artificial intelligence (Regulation (EU) 2026/1744) entered into force, amending the EU Artificial Intelligence (AI) Act (Regulation (EU) 2024/1689). The amendments postpone certain EU AI Act deadlines, clarify practical implementation and introduce new requirements. Despite the extension of the deadlines for high-risk AI systems, it should not be forgotten that the transparency obligations under Article 50 of the EU AI Act continue to apply from 2 August 2026.
Key points
- Transparency obligations (Article 50 of the EU AI Act) apply from 2 August 2026, and to facilitate their fulfilment the European Commission has published guidelines, while the AI Office has developed a voluntary code of practice on the marking of AI-generated content.
- Application of the obligations for high-risk AI systems has been postponed: for standalone Annex III systems they apply from 2 December 2027 (originally 2 August 2026), and for systems integrated into Annex I products from 2 August 2028 (originally 2 August 2027).
- From 2 December 2026, an addition to Article 5 of the EU AI Act becomes applicable, establishing a new prohibited practice: AI systems that generate or manipulate non-consensual intimate material or child sexual abuse material are prohibited.
- A new company category, “small mid-cap enterprises” (SMCs), to which the same compliance reliefs and support previously reserved only for small and medium-sized enterprises (SMEs) now apply.
- The additional time gained should be used wisely. A robust compliance framework cannot be built overnight, so we recommend not waiting for the extended deadline and continuing the work of ensuring compliance and implementing the requirements before the 2027-2028 deadlines.
- Compliance is a continuous process, not a one-off project. Post-market monitoring (monitoring the system’s performance and risks after it has been placed on the market), AI literacy, and the creation, maintenance and transfer of technical documentation across the AI value chain (between model providers, system providers and deployers) are ongoing obligations that require the continuous allocation of resources.
Amendments to the EU AI Act: what is changing
1. Application of the obligations for high-risk AI systems postponed to 2027 and 2028
The AI Omnibus postpones the point from which companies must comply with the requirements for high-risk AI systems. The reason is practical: harmonised standards, conformity assessment systems and the Commission’s guidelines on the application of the EU AI Act are still being developed. The new deadlines are as follows:
- 2 December 2027 applies to certain Annex III systems used, for example, in recruitment, creditworthiness assessment, education, law enforcement and border control.
- 2 August 2028 applies to AI integrated into regulated Annex I products, such as medical devices, machinery, lifts, radio equipment and vehicles.
The deadline by which each Member State must establish at least one “regulatory sandbox” – a controlled testing environment in which companies can trial AI solutions together with the supervisory authority before placing them on the market – has also been moved to 2 August 2027.
It is important to note that, for high-risk systems already on the market at the relevant date, the new requirements will apply only if those systems undergo substantial changes to their design after that date. What exactly counts as a “substantial” change is not clarified in the Regulation, so companies are left with a degree of uncertainty to reckon with.
2. New prohibition
From 2 December 2026, AI systems that generate or manipulate the following will be prohibited: (i) realistic images, videos or audio depicting an identifiable natural person’s intimate parts or sexually explicit activities without that person’s consent; (ii) material depicting child sexual abuse. The provider (the party that develops the AI system and places it on the market) must comply with the prohibition if the system generates such content intentionally, or if this is a reasonably foreseeable and reproducible outcome and the system does not have built-in safety measures to prevent it. The deployer (the party that uses the AI system in its activities) must comply with the prohibition if it uses the system specifically for that purpose. Where the content arises incidentally, the prohibition does not apply.
3. Marking of AI-generated content: a requirement that already applies now
From 2 August 2026, the requirement to mark AI-generated (artificially created or manipulated) content takes effect. Marking means that a technical, machine-readable mark, such as a watermark or metadata, is added to the content, by which it can be determined that it was created or edited by AI.
Who must comply: the obligation applies both to providers of AI systems (their developers) and, in certain cases, to deployers (natural or legal persons who use an AI system in their professional activity). Providers must ensure that AI-generated images, audio, video or text are marked in a machine-readable format. Deployers who create deep fakes or AI-generated text on matters of public interest must clearly disclose that the content has been artificially generated.
Transitional period: the core requirement applies to new systems from 2 August 2026. Generative AI systems (including general-purpose AI (GPAI) systems) that generate synthetic content and were already available on the market before that date have an additional four-month transitional period, until 2 December 2026. Content that entered circulation before 2 August does not have to be marked retroactively, although the Commission recommends doing so where technically feasible.
Practical support: compliance is facilitated by two documents recently published by the Commission: the guidelines on the Article 50 transparency obligations adopted on 20 July 2026, and the voluntary code of practice on the marking of AI-generated content published on 10 June 2026. Adherence to the code of practice is not mandatory, but it serves as a reference point for demonstrating compliance.
4. AI in regulated products: when sectoral laws apply
AI embedded in machinery covered by the separate Machinery Regulation (for example, industrial robots, automated production lines or CNC machine tools with AI control) largely remains outside the AI Act. The safety requirements for AI in such equipment will be set by the Commission later through specific supplementary rules. The Commission may also reduce the AI Act requirements for other regulated products, such as medical devices and toys, where sectoral laws already provide equivalent protection. This reduces the risk that a single product would have to comply with two overlapping sets of requirements.
5. Clarified definition of a “safety component”
The AI Omnibus amendments clarify the definition of a “safety component”. This concept determines whether an AI system is regarded as a part that ensures the safe operation of a product, and it matters because this characteristic often determines whether a system is high-risk. Previously the definition was broad and created uncertainty, so it has now been narrowed. From now on, a system is a safety component only if its function is to prevent or mitigate risks to human health or safety, that is, if its failure or malfunction would create those risks. If AI only provides assistance to the user, improves performance, efficiency or quality control, and its failure or malfunction does not endanger health or safety, it is not a safety component, even if it is embedded in a regulated product. As a result, fewer systems will automatically fall into the high-risk category.
6. Bias detection
To detect and correct bias in AI systems (for example, unfair treatment of a particular group of people), it is sometimes necessary to process special categories of personal data (so-called sensitive data) within the meaning of Article 9 of the General Data Protection Regulation, such as data on a person’s race or health. The new Article 4a of the EU AI Act allows such data to be used for this purpose not only by providers of high-risk systems, but for all AI systems and general-purpose AI models. In return, strict conditions must be met: the data may be used only to the extent genuinely necessary, and it must be protected, that is, access must be restricted, security ensured, and the data deleted once it is no longer needed.
7. AI literacy: from “ensuring a sufficient level” to “taking measures to support”
Article 4 of the EU AI Act has been softened. Previously, companies had to guarantee that their staff had a certain level of AI knowledge. Now it is sufficient to take reasonable measures to promote that knowledge, for example by organising training. The Commission and the Member States will support this work, and the AI Board will issue recommendations. Regardless of the requirements, employees’ understanding of AI remains important in practice.
8. AI Office supervision: centralised oversight with exceptions
The AI Omnibus clarifies the supervisory mechanism. The AI Office acquires exclusive competence for supervising (i) AI systems based on a general-purpose AI model from the same provider group, and (ii) AI systems integrated into very large online platforms and search engines within the meaning of the Digital Services Act. National authorities retain competence over Annex I products, critical infrastructure uses within the meaning of point 2 of Annex III, and AI systems provided by law enforcement authorities, border management authorities and financial institutions.
9. SMEs and small mid-cap enterprises (SMCs)
A new company category has been introduced, small mid-cap enterprises (SMCs), namely companies that have grown beyond the thresholds of small and medium-sized enterprises (SMEs). Until now, as soon as a company exceeded the SME threshold, the full requirements applied to it immediately. The new category softens this: SMCs can benefit from lighter requirements, such as reduced technical documentation and more flexible quality management rules. Under the new Article 99(6a), a fine for an SMC does not exceed either the percentage of the company’s total annual turnover set for the relevant infringement or a fixed amount, whichever is lower.
10. Post-market monitoring and the Cyber Resilience Act
Providers of high-risk AI systems must continuously monitor the system even after it has been placed on the market (so-called post-market monitoring) in order to detect problems in practice in good time. By 2 September 2027, the Commission will publish guidance on this, including a voluntary template for the post-market monitoring plan. In addition, if a high-risk AI system complies with the essential cybersecurity requirements of Article 12 of the Cyber Resilience Act (Regulation (EU) 2024/2847), it is deemed to comply with the cybersecurity requirements set out in Article 15 of the AI Act, to the extent that those requirements are covered by the EU declaration of conformity. This way, the same work does not have to be done twice.
Updated timeline for the application of the EU AI Act
The table below summarises the implementation deadlines – both those already in force and unchanged, and those that the AI Omnibus has moved.
| Date | Key provisions | Status | Note |
| 1 August 2024 | The AI Act enters into force. | In force | No change. |
| 2 February 2025 | Prohibitions on prohibited AI practices (Article 5); AI literacy obligation (Article 4). | In force | A new prohibition added to Article 5 with a transitional period until 2 December 2026. The wording of Article 4 softened. |
| 2 August 2025 | Obligations for GPAI models (Articles 51 to 56); the EU AI Office becomes operational. | In force | The competence and enforcement tools of the EU AI Office reinforced. |
| 2 August 2026 | Transparency obligations for AI-generated content (Article 50). | Partially postponed | Four-month transitional period for the Article 50(2) marking for systems already on the market. The obligations for Annex III high-risk AI systems and the sandbox deadlines have been moved. |
| 2 December 2026 | The marking transitional period ends; the transitional period for the new Article 5 prohibition ends. | New | Introduced by the AI Omnibus. |
| 2 August 2027 | Deadline for Member States to establish at least one AI regulatory sandbox (Article 57). | Postponed | Annex I high-risk AI systems were originally to apply from this date; moved to 2 August 2028. |
| 2 December 2027 | The obligations for Annex III high-risk AI systems start to apply. | New | Originally 2 August 2026. |
| 2 August 2028 | The obligations for Annex I high-risk AI systems start to apply. | New | Originally 2 August 2027. |
Practical steps to take
Companies are advised to use the additional time to ensure compliance in good time, put procedures in place and prepare the necessary documentation in line with the EU AI Act, without waiting for the Commission’s model documents expected later in 2027. To this end, we recommend that companies take at least the following steps:
- Update the inventory of AI systems and review the high-risk classification in line with the clarified definition of a “safety component”.
- Review general-purpose AI tools and content flows in light of the new Article 5 prohibition, before 2 December 2026.
- Treat the Article 50 transparency and marking deadlines of 2 August 2026 and 2 December 2026 as a priority.
- Update contracts with suppliers and other value chain participants to reflect the changes to the EU AI Act.
- Assess whether the organisation qualifies as an SME or a small mid-cap enterprise, and document that assessment.