What Changed Under the EU AI Act Digital Omnibus?

A practitioner’s look at what the EU AI Act Digital Omnibus changed, what it didn’t, and what your compliance program should do now.

Imagen decorativa

The EU AI Act Digital Omnibus (Regulation (EU) 2026/1744) is a targeted 2026 amendment that extends compliance deadlines, streamlines conformity assessment, and expands penalty protections for smaller companies. It does not change the AI Act’s risk-classification framework or the core obligations for high-risk AI systems.

Puntos clave

  • The EU AI Act Digital Omnibus (Regulation (EU) 2026/1744) entered into force on July 27, 2026, amending the original AI Act (Regulation (EU) 2024/1689) rather than replacing it.
  • The core risk-classification framework and Article 50 transparency duties are unchanged; nothing in the Omnibus reopens how a system gets labeled high-risk.
  • Compliance deadlines were extended, not accelerated: high-risk AI systems under Annex III now have until December 2, 2027, and high-risk AI embedded in physical products under Annex I until August 2, 2028.
  • The Omnibus extends the AI Act’s existing lower-penalty-cap treatment for SMEs to also cover small mid-cap companies (enterprises larger than an SME but with up to 500 employees) and streamlines conformity assessment under Article 28.
  • The Omnibus also created a narrow allowance to process special-category personal data specifically for AI bias testing, an area where AI Act obligations and data protection rules had previously been in tension.
In This Article
  1. What Is the EU AI Act Digital Omnibus?
  2. What Changed Under the Digital Omnibus?
  3. What Stayed the Same Under the Digital Omnibus?
  4. What Got Stricter Under the Digital Omnibus?
  5. What Does This Mean for Your Program Now?
  6. What Doesn’t Depend on the Digital Omnibus?
  7. Preguntas frecuentes

The EU AI Act Digital Omnibus is Regulation (EU) 2026/1744, a targeted amendment to the EU AI Act that entered into force on July 27, 2026, adjusting specific deadlines, conformity-assessment steps, and penalty treatment without altering the Act's risk-based structure.

If you have spent the past two years building a compliance program around the AI Act’s risk tiers, the phrase Digital Omnibus probably read like a bigger deal than it is. It is not a rewrite. It is a set of procedural corrections, and knowing exactly which ones apply to you is more useful than reacting to a headline.

What Is the EU AI Act Digital Omnibus?

The EU AI Act Digital Omnibus, which entered into force on July 27, 2026, according to the European Commission, is an amendment that simplifies specific compliance mechanics in the EU AI Act without changing its underlying risk-based approach. It updates selected articles governing deadlines, conformity assessment, and penalty treatment, and it sits alongside the Act’s existing phased implementation timeline rather than replacing it.

For most organizations already working through AI Act compliance, the amendment is narrower than its name suggests. It changes procedure and timing in select areas. It does not touch the classification system or the core obligations attached to high-risk AI systems.

What Changed Under the Digital Omnibus?

The Digital Omnibus made six confirmed changes: it streamlined conformity assessment, extended key compliance deadlines, broadened lower-penalty-cap treatment to small mid-cap companies (larger than an SME, up to 500 employees), simplified AI literacy requirements, created a narrow allowance for bias-detection data processing, and expanded regulatory sandboxes. None of these changes reduce which systems qualify as high-risk.

The conformity-assessment change matters most if your organization is preparing a high-risk system for market. The revised Article 28 procedure adjusts how that assessment is conducted, and the Commission also clarified the procedures conformity assessment bodies themselves must follow, which can shorten the path to market for systems that previously faced a more rigid process.

The deferred deadlines under Article 113 are now dated, not open-ended: Annex III high-risk systems have until December 2, 2027, and Annex I high-risk systems embedded in physical products have until August 2, 2028. That runway is procedural, not a reprieve from the obligations themselves. The compliance work still has to happen, just on a confirmed schedule.

The penalty change is narrower than some early commentary suggested. It does not create a new SME exemption. It extends a lower-penalty-cap mechanism that already existed for SMEs to a new category: small mid-cap companies that previously sat just outside that protection.

The Omnibus also simplified AI literacy obligations, shifting more of that compliance-support role onto the Commission and Member States rather than leaving it entirely with providers and deployers.

It created a narrow, defined allowance for providers to process special categories of personal data specifically to detect and correct bias in AI systems, an area where AI Act bias-testing needs and general data protection rules had previously been in tension. And it expanded regulatory sandbox provisions, adding an EU-level testing environment alongside the national sandboxes Member States already operate.

What Stayed the Same Under the Digital Omnibus?

The AI Act’s risk-classification framework is untouched. Systems are still tiered by risk level, and the criteria for what counts as high-risk have not changed. Article 50’s transparency obligations for AI-generated content remain in force, and the registration process for high-risk systems was simplified administratively rather than altered in substance.

If your program has already mapped your AI systems against the Act’s risk tiers, that mapping still holds. Nothing in the Omnibus requires you to reclassify a system you have already assessed.

Article 50 obligations, disclosing when content is AI-generated and labeling certain synthetic content as such, apply exactly as they did before. Registration in the EU database for high-risk systems is still required; the process itself was made more administratively efficient, not optional or reduced in scope.

What Got Stricter Under the Digital Omnibus?

Two areas became more restrictive, not less. Article 5 of the amended AI Act introduces a new prohibition on AI-generated non-consensual intimate imagery and child sexual abuse material, effective December 2, 2026, alongside new AI-generated content marking obligations (covering systems already on the market before August 2, 2026) that take effect the same day.

And the AI Office’s exclusive competence expanded in two specific ways: it now also reaches systems built on a general-purpose AI model developed by a different entity within the same undertaking, not just the same provider, and it gains competence over AI systems integrated into the very large online platforms and very large online search engines designated under the EU’s Digital Services Act. The Digital Omnibus is not a uniform loosening of the Act.

This is worth sitting with if your read on omnibus legislation defaults to deregulation. The Commission moved to reduce administrative burden in specific procedural areas while simultaneously hardening protections in the areas it judged highest-harm. Both things are true at once, and a compliance program built on the assumption that everything got easier will miss the parts that got harder.

What Does This Mean for Your Program Now?

If your AI governance program was already built around the AI Act’s risk tiers, the Digital Omnibus does not require you to rebuild it. What it does require is a review of your conformity-assessment timeline, a check on whether your organization now qualifies for small mid-cap penalty treatment, and a look at your documentation for any system touching the areas where enforcement tightened.

Use this checklist to prioritize that review.

Area What Changed What to Do Now
Conformity assessment (Article 28) Procedure streamlined; assessment body procedures clarified Review your conformity-assessment timeline against the revised procedure
Compliance deadlines (Article 113) Annex III systems due December 2, 2027; Annex I systems due August 2, 2028 Build both dates into your compliance calendar now
Penalty treatment (SME/SMC) Lower-penalty-cap treatment extended to small mid-cap companies (up to 500 employees, larger than an SME) Confirm whether your organization now qualifies under the expanded category
Prohibited practices (NCII/CSAM) New prohibition under Article 5, plus new content-marking obligations for pre-August 2026 systems, both effective December 2, 2026 Confirm whether any systems fall under the new Article 5 prohibition, and whether any pre-August 2026 systems need updated AI-content marking before December 2
AI Office competence Now also reaches GPAI-based systems built by a different entity in the same corporate group, and systems embedded in DSA-designated very large online platforms/search engines (VLOPs/VLOSEs) Confirm whether any of your systems now fall within this expanded scope
AI literacy requirements Simplified; Commission and Member States assume greater role Adjust internal AI literacy plans to reflect the reduced burden on your organization alone
Special category data for bias testing New narrow allowance to process special-category personal data for bias detection Coordinate with your privacy/DPO function before relying on this exception
Regulatory sandboxes Expanded, including a new EU-level testing environment Evaluate whether sandbox participation fits your development roadmap

What Doesn’t Depend on the Digital Omnibus?

None of this changes the task in front of you: a defensible inventory of your AI systems, evidence that maps to the obligations each risk tier carries, and a record your board or regulator can review without a scramble. Frameworks like the NIST AI Risk Management Framework and ISO/IEC 42001 remain useful reference points for structuring that ongoing oversight, regardless of which specific EU articles shift next.

Where the Omnibus eased something, treat it as relief. Where it didn’t, nothing about your obligations has moved.

See How Mitratech Extends Your ERM Program to Cover AI Risk

Discover More About Mitratech Alyne

Preguntas frecuentes

What is the EU AI Act Digital Omnibus?

The EU AI Act Digital Omnibus, formally Regulation (EU) 2026/1744, is a 2026 amendment to the EU AI Act that adjusts specific deadlines, conformity-assessment procedures, and penalty treatment for smaller organizations. It does not change the AI Act’s risk-classification framework or its core obligations for high-risk AI systems.

Does the Digital Omnibus change how AI systems are classified as high-risk?

No. The risk-classification criteria in the EU AI Act are unchanged. The Digital Omnibus adjusts procedural and timing elements, such as conformity assessment and select compliance deadlines, without altering which AI systems qualify as high-risk or the obligations attached to that classification.

Who benefits from the penalty changes in the Digital Omnibus?

The Digital Omnibus extends an existing lower-penalty-cap approach, previously available to small and medium-sized enterprises, to also cover small mid-cap companies, enterprises larger than an SME but with up to 500 employees. Organizations outside these categories see no change to penalty exposure under the amendment.

Did the Digital Omnibus loosen any AI Act prohibitions?

No. Article 5 of the amended AI Act introduces a new prohibition on non-consensual intimate imagery and child sexual abuse material, effective December 2, 2026, and the AI Office’s exclusive competence expanded in two specific ways: it now also reaches systems built on a general-purpose AI model developed by a different entity within the same undertaking, not just the same provider, and it gains competence over AI systems integrated into the very large online platforms and very large online search engines designated under the EU’s Digital Services Act. The Omnibus reduces administrative burden in specific procedural areas; it does not broadly loosen the Act’s restrictions.

What should compliance teams do now that the Digital Omnibus is in effect?

Compliance teams should review conformity-assessment timelines against the revised Article 28 procedure, confirm whether their organization now falls into the small mid-cap category (larger than an SME, up to 500 employees) for penalty treatment, and re-check documentation for systems touching areas where enforcement tightened. The underlying AI Act compliance program does not need to be rebuilt.

When did the EU AI Act Digital Omnibus take effect?

The Digital Omnibus entered into force on July 27, 2026, according to the European Commission. It also reset key compliance dates under the AI Act: high-risk AI systems covered by Annex III now have until December 2, 2027, and high-risk AI embedded in physical products under Annex I until August 2, 2028.

Does the Digital Omnibus change conformity assessment requirements for high-risk AI systems?

Yes, procedurally. Article 28 of the amended EU AI Act streamlines how conformity assessment is conducted for certain high-risk AI systems, which can shorten the path to market. The requirement to complete a conformity assessment before deploying a high-risk system has not been removed or made optional.

Is the EU AI Act Digital Omnibus a new law or part of the AI Act?

It is not a new law. The Digital Omnibus, Regulation (EU) 2026/1744, is an amending regulation that changes specific provisions within the existing EU AI Act, Regulation (EU) 2024/1689. The two regulations are meant to be read together; the amendment does not stand on its own.