EU AI Act Update: Digital Omnibus Finalizes 8 Compliance Changes


5 minute read | July.29.2026

The final text of the EU Digital Omnibus on AI has been published in the Official Journal of the European Union, and its amendments to the EU AI Act (Regulation (EU) 2024/1689) are now in force.

What changed now that the EU AI Act Digital Omnibus is in force? The Omnibus changes the EU AI Act compliance roadmap for AI system developers (providers) and users (deployers). It delays high-risk AI obligations for many systems, adds new prohibited AI categories, extends the General Data Protection Regulation (GDPR) legal basis for certain bias-detection processing and expands the AI Office’s enforcement role.

Below are 8 changes to prioritize:

1. High-Risk AI Deadlines Move to 2027 and 2028

  • Obligations for high-risk AI systems designated under Article 6(2) and Annex III of the AI Act will now take effect on 2 December 2027 instead of 2 August 2026. AI systems placed on the EU market before that date will be subject to those requirements only if they are substantially modified after that date. (Note that deployers and providers of any type of AI system intended for use by public authorities must be in compliance with the Act by 2 August 2030.)
  • High-risk AI systems subject to existing EU harmonization legislation listed in Annex I and Article 6(1) will follow a later date: 2 August 2028. Providers of AI systems placed on the market before 2 August 2026 and that generate synthetic audio, image, video or text context will have until 2 December 2026 to comply with the Article 50(2) transparency obligations.

2. New AI Bans Target NCII, “Nudifier” Apps and CSAM

Two new prohibitions have been added to Article 5 of the Act, targeting AI systems that generate or manipulate realistic non-consensual intimate imagery/material (NCII/NCIM) of identifiable individuals without their consent – including so-called “nudifier” applications – and child sexual abuse material (CSAM). The latter prohibition is subject to application of a “without right” defence under EU Member State law. 

Within scope are systems designed for those purposes, or systems where such outputs are reasonably foreseeable and reproducible in the absence of reasonable, proportionate and effective safeguards.

These prohibitions apply from 2 December 2026.

3. AI Act Extends the GDPR Legal Basis for Bias Detection

The AI Act is amended to extend the legal basis for processing special category data under the GDPR for bias detection and correction, in connection with AI models and systems.

The amendment will build on the existing rule provided by Article 10(5) (Data & Data Governance), which today only covers providers of high-risk systems. Processing will be subject to a “strict necessity” standard and mandatory safeguards. These include considering non-sensitive or synthetic data first, pseudonymization, access controls, limits on onward sharing and timely deletion. The amendment does not create any obligation to perform bias detection.

4. Sector Rules May Limit Overlapping AI Act Duties

The AI Omnibus introduces a sector-specific compromise to address possible overlaps between the high-risk AI obligations under the AI Act and requirements of existing sectoral legislation set out in Annex I of the Act, in particular in relation to the EU Machinery Regulation (EU) 2023/1230, which is moved from Section A to Section B of Annex I, reducing the number of applicable EU AI Act obligations.

A new mechanism will enable the Commission, through implementing acts, to resolve situations where sectoral law contains AI-specific requirements equivalent to those of the AI Act, by limiting the latter's application in those specific cases. A delegated act that will clarify these rules must be adopted by the European Commission by 2 August 2028.

5. “Safety Component” Gets a Narrower, Safety-Focused Test

The definition of “safety component” (Article 3(14)) has been narrowed through the addition of wording that clarifies that an AI system will serve a safety function if it has “an intended purpose of preventing or mitigating risks to health and safety.”

Article 6 is amended to provide that AI systems used solely for non-safety related aspects of user assistance, performance, optimization, service efficiency or automation convenience are not to be considered “safety components”.

Nonetheless, AI systems whose failure or malfunction would endanger human health and safety will still qualify as safety components.

6. Small Mid-cap Companies Receive Targeted Relief with New Category

More companies will be able to use simplified AI Act compliance tools. 

The AI Omnibus extends several AI Act measures intended to simplify compliance for small and medium enterprises (SMEs), SME-focused measures to a newly defined category of “small mid-cap” enterprises, including: 

  • Simplified technical documentation templates that notified bodies must accept
  • More proportionate quality management expectations
  • Priority access to regulatory sandboxes
  • Tailored penalty caps

The new category of small mid-cap enterprises is defined as enterprises that are not considered small or medium-sized enterprises, employ fewer than 750 people and have an annual turnover not exceeding €150 million or an annual balance sheet total not exceeding €129 million.

7. Stronger, Centralized Enforcement by the AI Office

The AI Omnibus strengthens central EU-level enforcement by giving the AI Office (AIO) exclusive supervisory competence over AI systems based on a general-purpose AI (GPAI) model developed by the same provider or same group of undertakings, and over AI systems integrated into "very large online platforms" or "very large online search engines" as designated under the EU Digital Services Act.

Additions to Article 75 of the EU AI Act also expand and clarify the AI Office’s supervision and enforcement powers. The AIO will receive serious incident reports from the providers in relation to which it has exclusive jurisdiction and will be responsible for their conformity assessments (subject to specific exceptions). The information provided by the AIO when it makes simple or decision-based requests for information is stipulated, and powers of remote and on-site inspections are clarified.

The AIO will be entitled to reclaim the costs it incurs in relation to established non-conformities with the Act.

8. Unified Technical Standards

Technical standards have been a major implementation challenge and helped drive the extension of the compliance deadline for high-risk AI systems.

To simplify reliance on technical standards as a means of demonstrating conformity, a new paragraph has been added to Article 40(2) that requires the Commission to ask European standards bodies to create unified technical standards that cover both the AI Act and existing harmonization laws at the same time, so that companies building high-risk AI systems only need to follow one set of standards to comply with both regimes, rather than dealing with two separate ones.

This Omnibus also introduces amendments to the Act that address testing AI systems in real world conditions, the framework for regulatory sandboxes and provisions relevant to national notifying bodies and authorities.