AI Act: What the Digital Omnibus Really Changes for Companies


The Digital Omnibus on AI, which entered into force on July 27, 2026, through Regulation (EU) 2026/1744, postpones a significant part of the regime applicable to high-risk AI systems. However, it does not suspend the AI Act: transparency obligations have applied since August 2, 2026, the AI literacy obligation remains in place, and several simplifications and new prohibitions have already been legally established.
The Digital Omnibus on AI does not challenge the overall architecture of the European Artificial Intelligence Regulation or its risk-based approach. Instead, it introduces targeted adjustments designed to address delays in the adoption of harmonised standards, the designation of conformity assessment bodies and the development of supporting tools.
The interpretation that “the AI Act has been postponed” is therefore misleading. Only certain provisions in Sections 1 to 3 of Chapter III, primarily concerning the classification, requirements and obligations applicable to high-risk AI systems, benefit from new deadlines.
At the same time, the transparency obligations under Article 50 have applied since August 2, 2026. The rules concerning general-purpose AI (GPAI) models have already applied since August 2025, with the Commission's enforcement powers against their providers becoming operational in August 2026. The AI literacy obligation also remains in force, with more flexible wording.
Key takeaway: the high-risk AI timeline has been postponed, but immediate compliance priorities already include transparency, AI literacy, GPAI models, governance and preparation for future high-risk AI compliance files.
Regulation (EU) 2026/1744 establishes specific deadlines. The mechanism initially considered, which would have linked the application of the high-risk regime to a Commission decision confirming the availability of standards and compliance tools, was not retained in the final text.
August 2, 2026: Article 50 transparency obligations; general application of provisions that were not postponed; enforcement powers against GPAI providers.Organizations must immediately review their interfaces, synthetic content, deepfakes and information provided to individuals.
December 2, 2026: New prohibitions relating to non-consensual intimate content and AI-generated or manipulated child sexual abuse material. End of the Article 50(2) transitional period for generative systems already placed on the market before August 2, 2026.Relevant providers must have deployed the required technical safeguards; deployers may not use a system for the purpose of producing such content.
August 2, 2027: At least one regulatory sandbox must be operational at national level.Innovative companies, particularly SMEs and small mid-caps, will be able to benefit from a supervised testing environment.
December 2, 2027: Sections 1 to 3 of Chapter III for high-risk AI systems falling under Article 6(2) and Annex III.The regime will notably apply to certain uses in recruitment, education, access to essential services, creditworthiness, justice, migration and law enforcement.
August 2, 2028: Sections 1 to 3 of Chapter III for high-risk AI systems falling under Article 6(1) and Annex I.This primarily concerns systems that constitute regulated products or safety components subject to third-party conformity assessment.
This timeline is based on Article 113 of the AI Act as amended by Regulation (EU) 2026/1744.
The first immediate compliance priority concerns Article 50. It does not create a uniform obligation to “label all AI-generated output”. Requirements vary depending on the nature of the system, the content concerned and the role played by the organization.
Providers of systems designed to interact directly with individuals must ensure that those individuals are informed that they are interacting with an AI system, unless this is obvious to a reasonably informed, attentive and discerning person, taking into account the circumstances.
Providers of systems generating synthetic audio, image, video or text content must ensure that their outputs are marked in a machine-readable format and detectable as artificially generated or manipulated.
The regulation does not prescribe a single visual “watermark”. Rather, it requires a technical outcome whereby the content can be detected, subject to the exceptions provided for by the legislation.
The date of December 2, 2026 does not constitute a general postponement of this obligation. It only marks the end of the transitional period granted to generative systems already placed on the market before August 2, 2026.
Deployers of systems generating or manipulating deepfakes must disclose the artificial nature of the content.
A disclosure obligation also applies to certain texts published to inform the public about matters of public interest, subject in particular to situations where the content has undergone human or editorial review and a person assumes responsibility for it.
Article 50 also covers informing individuals exposed to certain emotion recognition or biometric categorisation systems. A compliance review limited to chatbots alone would therefore be insufficient.
The new Article 4 replaces the obligation to guarantee a sufficient level of AI proficiency with an obligation to take measures designed to support the development of AI literacy among staff and other persons using AI systems on behalf of the organization.
The text now specifies that no particular level of proficiency must be guaranteed for every individual. However, this flexibility does not exempt companies from implementing an appropriate framework. Measures must remain proportionate to technical knowledge, experience, training, the context of use and the individuals potentially affected.
In practice, a credible approach may rely on several levels:
The Digital Omnibus introduces a new Article 4a concerning the processing of special categories of personal data to detect and correct certain biases.
The possibility, previously linked to providers of high-risk AI systems, is extended under certain conditions to deployers of high-risk AI systems as well as providers and deployers of other AI systems and models.
This provision is neither a general exemption from the GDPR nor an obligation to collect sensitive data.
Processing must be strictly necessary and must target biases that could affect health or safety, infringe fundamental rights or result in discrimination prohibited by EU law.
The organization must in particular be able to demonstrate that the objective cannot be effectively achieved using other data, including synthetic or anonymised data.
It must implement appropriate pseudonymisation and security measures, restrict and document access, prevent the transfer of data to other parties, delete the data as soon as the bias has been corrected or the retention period has expired, and justify this strict necessity in its records of processing activities.
Implementation of this possibility should therefore be preceded by a joint AI Act–GDPR assessment and, depending on the level of risk, a Data Protection Impact Assessment (DPIA).
Several simplifications are extended to small mid-cap enterprises.
SMEs, start-ups and small mid-caps may notably use simplified technical documentation for high-risk AI systems.
The implementation of the quality management system must be proportionate to the size of the organization, without reducing the level of rigour required.
Certain fines applicable to small mid-caps are also capped at the lower of the applicable amount or percentage.
The definition of a safety component is clarified to prevent every AI function integrated into a regulated product from automatically being classified as high-risk.
Functions limited to assistance, performance optimisation, efficiency, automation, convenience or certain quality controls are not, in principle, considered safety components unless their failure or malfunction could endanger health or safety.
The regulation also provides a mechanism for limiting certain AI Act requirements where sector-specific legislation already guarantees an equivalent level of protection.
Machinery is subject to specific treatment: it is removed from the direct application route under Annex I, with AI-related requirements to be incorporated into the Machinery Regulation through secondary legislation.
Where a requirement of the Fundamental Rights Impact Assessment (FRIA) under Article 27 is already covered by a DPIA carried out under the GDPR, the deployer may now refer to the relevant parts of the DPIA or reproduce them in the FRIA.
This clarification should help avoid duplication, provided that both assessments remain complete with regard to their respective purposes.
The Digital Omnibus adds two categories of prohibited practices to Article 5:
For providers, the prohibition applies to systems designed for such generation or manipulation, as well as systems where such an outcome is reasonably foreseeable and reproducible when reasonable and adequate technical measures and safeguards are not sufficient to prevent and correct observed or reported misuse.
For deployers, use is prohibited when they use the system for the purpose of generating or manipulating such content.
This distinction between placing a system on the market and using it should be reflected in usage policies, contractual terms and control mechanisms applicable to the relevant providers.
The additional time granted for the high-risk regime does not justify either a general pause or the immediate production of disproportionate compliance files.
It should instead be used to address obligations that already apply and build a realistic compliance roadmap.
Identify conversational interfaces, synthetic content, deepfakes, emotion recognition systems and the respective responsibilities of providers and deployers.
Define target populations, training levels, expected skills and evidence requirements, taking into account the new wording of Article 4.
Identify authorised or experimental systems, qualify the organization's role and document the initial risk assessment.
Obtain the information, access rights, technical safeguards and assistance arrangements required from software vendors, model providers and integrators.
Address risk governance, data quality, documentation, human oversight, traceability, incident management, FRIA requirements and alignment with DPIAs.
The Digital Omnibus gives high-risk AI system stakeholders additional time, but it does not reduce AI compliance to a deadline in 2027 or 2028.
Since August 2, 2026, operational transparency obligations have already applied. AI literacy remains mandatory. The rules applicable to GPAI models are in force, and several new possibilities and simplifications must be incorporated into AI and data governance.
The priority is therefore to adopt a two-speed approach: immediately address obligations that already apply while using the additional time to build, without rushing but without waiting passively, compliance for future high-risk AI systems.
DPO Consulting supports organizations in mapping and classifying their AI systems, complying with Article 50, structuring AI literacy programmes, implementing AI Act governance, conducting risk assessments, FRIA and DPIA assessments, and preparing the compliance documentation applicable to high-risk AI systems.
Do you want to assess your AI systems, understand which AI Act obligations already apply to your organization and prepare for the upcoming high-risk requirements?
Discover DPO Consulting's AI Act compliance support and get help with AI system mapping, Article 50 compliance, AI governance, AI literacy, risk assessments, FRIA and DPIA.