The EU AI Act Digital Omnibus (Regulation (EU) 2026/1744) is a targeted 2026 amendment that extends compliance deadlines, streamlines conformity assessment, and expands penalty protections for smaller companies. It does not change the AI Act’s risk-classification framework or the core obligations for high-risk AI systems.
Puntos clave
- The EU AI Act Digital Omnibus (Regulation (EU) 2026/1744) entered into force on July 27, 2026, amending the original AI Act (Regulation (EU) 2024/1689) rather than replacing it.
- The core risk-classification framework and Article 50 transparency duties are unchanged; nothing in the Omnibus reopens how a system gets labeled high-risk.
- Compliance deadlines were extended, not accelerated: high-risk AI systems under Annex III now have until December 2, 2027, and high-risk AI embedded in physical products under Annex I until August 2, 2028.
- The Omnibus extends the AI Act’s existing lower-penalty-cap treatment for SMEs to also cover small mid-cap companies (enterprises larger than an SME but with up to 500 employees) and streamlines conformity assessment under Article 28.
- The Omnibus also created a narrow allowance to process special-category personal data specifically for AI bias testing, an area where AI Act obligations and data protection rules had previously been in tension.
In This Article
The EU AI Act Digital Omnibus is Regulation (EU) 2026/1744, a targeted amendment to the EU AI Act that entered into force on July 27, 2026, adjusting specific deadlines, conformity-assessment steps, and penalty treatment without altering the Act's risk-based structure.
If you have spent the past two years building a compliance program around the AI Act’s risk tiers, the phrase Digital Omnibus probably read like a bigger deal than it is. It is not a rewrite. It is a set of procedural corrections, and knowing exactly which ones apply to you is more useful than reacting to a headline.
What Is the EU AI Act Digital Omnibus?
The EU AI Act Digital Omnibus, which entered into force on July 27, 2026, according to the European Commission, is an amendment that simplifies specific compliance mechanics in the EU AI Act without changing its underlying risk-based approach. It updates selected articles governing deadlines, conformity assessment, and penalty treatment, and it sits alongside the Act’s existing phased implementation timeline rather than replacing it.
For most organizations already working through AI Act compliance, the amendment is narrower than its name suggests. It changes procedure and timing in select areas. It does not touch the classification system or the core obligations attached to high-risk AI systems.
What Changed Under the Digital Omnibus?
The Digital Omnibus made six confirmed changes: it streamlined conformity assessment, extended key compliance deadlines, broadened lower-penalty-cap treatment to small mid-cap companies (larger than an SME, up to 500 employees), simplified AI literacy requirements, created a narrow allowance for bias-detection data processing, and expanded regulatory sandboxes. None of these changes reduce which systems qualify as high-risk.
The conformity-assessment change matters most if your organization is preparing a high-risk system for market. The revised Article 28 procedure adjusts how that assessment is conducted, and the Commission also clarified the procedures conformity assessment bodies themselves must follow, which can shorten the path to market for systems that previously faced a more rigid process.
The deferred deadlines under Article 113 are now dated, not open-ended: Annex III high-risk systems have until December 2, 2027, and Annex I high-risk systems embedded in physical products have until August 2, 2028. That runway is procedural, not a reprieve from the obligations themselves. The compliance work still has to happen, just on a confirmed schedule.
The penalty change is narrower than some early commentary suggested. It does not create a new SME exemption. It extends a lower-penalty-cap mechanism that already existed for SMEs to a new category: small mid-cap companies that previously sat just outside that protection.
The Omnibus also simplified AI literacy obligations, shifting more of that compliance-support role onto the Commission and Member States rather than leaving it entirely with providers and deployers.
It created a narrow, defined allowance for providers to process special categories of personal data specifically to detect and correct bias in AI systems, an area where AI Act bias-testing needs and general data protection rules had previously been in tension. And it expanded regulatory sandbox provisions, adding an EU-level testing environment alongside the national sandboxes Member States already operate.
What Stayed the Same Under the Digital Omnibus?
The AI Act’s risk-classification framework is untouched. Systems are still tiered by risk level, and the criteria for what counts as high-risk have not changed. Article 50’s transparency obligations for AI-generated content remain in force, and the registration process for high-risk systems was simplified administratively rather than altered in substance.
If your program has already mapped your AI systems against the Act’s risk tiers, that mapping still holds. Nothing in the Omnibus requires you to reclassify a system you have already assessed.
Article 50 obligations, disclosing when content is AI-generated and labeling certain synthetic content as such, apply exactly as they did before. Registration in the EU database for high-risk systems is still required; the process itself was made more administratively efficient, not optional or reduced in scope.
What Got Stricter Under the Digital Omnibus?
Two areas became more restrictive, not less. Article 5 of the amended AI Act introduces a new prohibition on AI-generated non-consensual intimate imagery and child sexual abuse material, effective December 2, 2026, alongside new AI-generated content marking obligations (covering systems already on the market before August 2, 2026) that take effect the same day.
And the AI Office’s exclusive competence expanded in two specific ways: it now also reaches systems built on a general-purpose AI model developed by a different entity within the same undertaking, not just the same provider, and it gains competence over AI systems integrated into the very large online platforms and very large online search engines designated under the EU’s Digital Services Act. The Digital Omnibus is not a uniform loosening of the Act.
This is worth sitting with if your read on omnibus legislation defaults to deregulation. The Commission moved to reduce administrative burden in specific procedural areas while simultaneously hardening protections in the areas it judged highest-harm. Both things are true at once, and a compliance program built on the assumption that everything got easier will miss the parts that got harder.
What Does This Mean for Your Program Now?
If your AI governance program was already built around the AI Act’s risk tiers, the Digital Omnibus does not require you to rebuild it. What it does require is a review of your conformity-assessment timeline, a check on whether your organization now qualifies for small mid-cap penalty treatment, and a look at your documentation for any system touching the areas where enforcement tightened.
Use this checklist to prioritize that review.
| Area | What Changed | What to Do Now |
| Conformity assessment (Article 28) | Procedure streamlined; assessment body procedures clarified | Review your conformity-assessment timeline against the revised procedure |
| Compliance deadlines (Article 113) | Annex III systems due December 2, 2027; Annex I systems due August 2, 2028 | Build both dates into your compliance calendar now |
| Penalty treatment (SME/SMC) | Lower-penalty-cap treatment extended to small mid-cap companies (up to 500 employees, larger than an SME) | Confirm whether your organization now qualifies under the expanded category |
| Prohibited practices (NCII/CSAM) | New prohibition under Article 5, plus new content-marking obligations for pre-August 2026 systems, both effective December 2, 2026 | Confirm whether any systems fall under the new Article 5 prohibition, and whether any pre-August 2026 systems need updated AI-content marking before December 2 |
| AI Office competence | Now also reaches GPAI-based systems built by a different entity in the same corporate group, and systems embedded in DSA-designated very large online platforms/search engines (VLOPs/VLOSEs) | Confirm whether any of your systems now fall within this expanded scope |
| AI literacy requirements | Simplified; Commission and Member States assume greater role | Adjust internal AI literacy plans to reflect the reduced burden on your organization alone |
| Special category data for bias testing | New narrow allowance to process special-category personal data for bias detection | Coordinate with your privacy/DPO function before relying on this exception |
| Regulatory sandboxes | Expanded, including a new EU-level testing environment | Evaluate whether sandbox participation fits your development roadmap |
What Doesn’t Depend on the Digital Omnibus?
None of this changes the task in front of you: a defensible inventory of your AI systems, evidence that maps to the obligations each risk tier carries, and a record your board or regulator can review without a scramble. Frameworks like the NIST AI Risk Management Framework and ISO/IEC 42001 remain useful reference points for structuring that ongoing oversight, regardless of which specific EU articles shift next.
Where the Omnibus eased something, treat it as relief. Where it didn’t, nothing about your obligations has moved.
