5 minute read | July.29.2026
The final text of the EU Digital Omnibus on AI has been published in the Official Journal of the European Union, and its amendments to the EU AI Act (Regulation (EU) 2024/1689) are now in force.
What changed now that the EU AI Act Digital Omnibus is in force? The Omnibus changes the EU AI Act compliance roadmap for AI system developers (providers) and users (deployers). It delays high-risk AI obligations for many systems, adds new prohibited AI categories, extends the General Data Protection Regulation (GDPR) legal basis for certain bias-detection processing and expands the AI Office’s enforcement role.
Below are 8 changes to prioritize:
Two new prohibitions have been added to Article 5 of the Act, targeting AI systems that generate or manipulate realistic non-consensual intimate imagery/material (NCII/NCIM) of identifiable individuals without their consent – including so-called “nudifier” applications – and child sexual abuse material (CSAM). The latter prohibition is subject to application of a “without right” defence under EU Member State law.
Within scope are systems designed for those purposes, or systems where such outputs are reasonably foreseeable and reproducible in the absence of reasonable, proportionate and effective safeguards.
These prohibitions apply from 2 December 2026.
The AI Act is amended to extend the legal basis for processing special category data under the GDPR for bias detection and correction, in connection with AI models and systems.
The amendment will build on the existing rule provided by Article 10(5) (Data & Data Governance), which today only covers providers of high-risk systems. Processing will be subject to a “strict necessity” standard and mandatory safeguards. These include considering non-sensitive or synthetic data first, pseudonymization, access controls, limits on onward sharing and timely deletion. The amendment does not create any obligation to perform bias detection.
The AI Omnibus introduces a sector-specific compromise to address possible overlaps between the high-risk AI obligations under the AI Act and requirements of existing sectoral legislation set out in Annex I of the Act, in particular in relation to the EU Machinery Regulation (EU) 2023/1230, which is moved from Section A to Section B of Annex I, reducing the number of applicable EU AI Act obligations.
A new mechanism will enable the Commission, through implementing acts, to resolve situations where sectoral law contains AI-specific requirements equivalent to those of the AI Act, by limiting the latter's application in those specific cases. A delegated act that will clarify these rules must be adopted by the European Commission by 2 August 2028.
The definition of “safety component” (Article 3(14)) has been narrowed through the addition of wording that clarifies that an AI system will serve a safety function if it has “an intended purpose of preventing or mitigating risks to health and safety.”
Article 6 is amended to provide that AI systems used solely for non-safety related aspects of user assistance, performance, optimization, service efficiency or automation convenience are not to be considered “safety components”.
Nonetheless, AI systems whose failure or malfunction would endanger human health and safety will still qualify as safety components.
More companies will be able to use simplified AI Act compliance tools.
The AI Omnibus extends several AI Act measures intended to simplify compliance for small and medium enterprises (SMEs), SME-focused measures to a newly defined category of “small mid-cap” enterprises, including:
The new category of small mid-cap enterprises is defined as enterprises that are not considered small or medium-sized enterprises, employ fewer than 750 people and have an annual turnover not exceeding €150 million or an annual balance sheet total not exceeding €129 million.
The AI Omnibus strengthens central EU-level enforcement by giving the AI Office (AIO) exclusive supervisory competence over AI systems based on a general-purpose AI (GPAI) model developed by the same provider or same group of undertakings, and over AI systems integrated into "very large online platforms" or "very large online search engines" as designated under the EU Digital Services Act.
Additions to Article 75 of the EU AI Act also expand and clarify the AI Office’s supervision and enforcement powers. The AIO will receive serious incident reports from the providers in relation to which it has exclusive jurisdiction and will be responsible for their conformity assessments (subject to specific exceptions). The information provided by the AIO when it makes simple or decision-based requests for information is stipulated, and powers of remote and on-site inspections are clarified.
The AIO will be entitled to reclaim the costs it incurs in relation to established non-conformities with the Act.
Technical standards have been a major implementation challenge and helped drive the extension of the compliance deadline for high-risk AI systems.
To simplify reliance on technical standards as a means of demonstrating conformity, a new paragraph has been added to Article 40(2) that requires the Commission to ask European standards bodies to create unified technical standards that cover both the AI Act and existing harmonization laws at the same time, so that companies building high-risk AI systems only need to follow one set of standards to comply with both regimes, rather than dealing with two separate ones.
This Omnibus also introduces amendments to the Act that address testing AI systems in real world conditions, the framework for regulatory sandboxes and provisions relevant to national notifying bodies and authorities.