Skip to content

The Digital Omnibus didn't delay the AI Act. It rewrote parts of it.

Every headline since 24 July has said the same thing: the AI Act got pushed back. True, and also the least interesting part of Regulation (EU) 2026/1744, the "Digital Omnibus on AI," which entered into force on 27 July 2026. I went through the consolidated EUR-Lex text rather than the summaries. Sixty-nine amendment markers, thirty-nine locations in the Act. Two new prohibited practices. A deleted article replaced by a wider one. A redefinition of what counts as a safety component. A new category of company the Act now treats differently. None of that is a date.

What actually moved, date-wise

This part the briefings got right. Three dates changed, and one didn't.

Provision Applies from
Chapters I and II (definitions, prohibited practices baseline, AI literacy) 2 February 2025, unchanged
Chapter V, GPAI obligations 2 August 2025, unchanged
New prohibitions, Art 5(1)(ba) and (bb) 2 December 2026
Annex III high-risk systems (use-based), Chapter III Sections 1 to 3 2 December 2027, was 2 August 2026
Annex I high-risk systems (product-embedded) 2 August 2028, was 2 August 2027

So the enforceable-today set is the prohibitions baseline, AI literacy, and GPAI. The bulk of what people mean when they say "AI Act compliance," the high-risk chapter, is now sixteen to thirty-six months out. That's a genuine and material relief, and if that's all you take from this post, take that.

But stop there and you'd miss why I don't think "delay" is the right word for the instrument as a whole.

The part the delay headlines skipped

Article 10(5) is gone. The old, narrow permission to process special-category personal data for bias monitoring is deleted and replaced by a free-standing Article 4a, which is both broader and more conditional. Providers of high-risk systems may now process special-category data for bias detection and correction under Art 10(2)(f) and (g), but only where all six conditions hold: no adequate substitute (including synthetic or anonymised data), state-of-the-art security including pseudonymisation, strict access controls and documentation, no transmission to other parties, deletion once the bias is corrected or the retention period ends, and a GDPR Art 30 record stating why the processing was strictly necessary. Article 4a(2) extends the same six-condition permission to deployers, to providers and deployers of GPAI models, and to anyone handling non-high-risk systems, where bias could affect health, safety, or fundamental rights, "especially where data outputs influence inputs for future operations." The regulation is explicit that this creates no obligation to look for bias, only a conditional permission if you do. It's the cleanest bridge between the AI Act and GDPR Article 9 in the whole text, and it's new work for anyone whose bias testing touches special categories, delay or no delay.

Two new prohibited practices, and they're not exotic. Article 5(1)(ba) and (bb), applying from 2 December 2026, prohibit AI systems that generate non-consensual intimate imagery of identifiable people, and CSAM, without the safety measures the article requires. The trigger isn't just intent. Article 5(1a) also catches a system where that output is "a reasonably foreseeable and reproducible outcome" of its design, training or capabilities, if the system lacks "reasonable and adequate technical safety measures" to prevent and correct it. Read that again: the absence of safeguards is what makes an image or video generator's output unlawful, not just deliberate misuse. If you provide or deploy any generative image, video or audio capability, that's a control you need by December, not 2027, regardless of risk tier.

"Safety component" got narrower, on purpose. Article 6 gains three new paragraphs. Systems used solely for non-safety aspects, convenience, performance, service efficiency, don't count as safety components, unless their failure would endanger health and safety, in which case they still do. And a product that needs third-party conformity assessment only for non-health-and-safety reasons, the example given is radio spectrum interference, doesn't trigger high-risk status on that basis alone. This is a real classification decision now, and it's the kind organisations tend to get wrong in their own favour, so document the negative case, not just the positive one.

A new size class threads through the whole Act. Alongside the existing SME definition, Article 3(14b) introduces "small mid-cap enterprise" (SMC), and it shows up in simplified technical documentation (Art 11), proportionate QMS implementation (Art 17(2), though the rigour and protection level still have to hold), and capped penalties (Art 99(6a)). Worth knowing if your organisation sits just above the SME threshold.

What didn't change

This is the reassuring half, and it matters as much as the rest. No amendment marker touches the risk management system (Art 9), record-keeping (Art 12), transparency to deployers (Art 13), human oversight (Art 14), accuracy and cybersecurity (Art 15), provider or deployer obligations (Arts 16, 26), the GPAI chapter including systemic-risk models (Arts 51 to 55), or serious incident reporting (Art 73). If you've been building a control framework against the 2024 text for any of those, it stands. The omnibus changed the shape of the Act's edges, not its core.

The one I went back and checked

I read the amendment markers against the consolidated text first, which tells you what changed with certainty. It doesn't tell you why with the same certainty, that sits in the omnibus's own recitals. One claim from that gap was worth resolving before publishing rather than leaving as a caveat: several summaries circulating since late July mention a "watermarking relief" for systems already on the market, and it didn't show up in the amendment markers I'd extracted, so I said I wasn't repeating it until checked. Checked now. It's real. A recital gives providers who placed a system on the market before 2 August 2026 a four-month transitional period, to 2 December 2026, for the Article 50(2) machine-readable marking duty specifically. It does not touch the rest of Article 50's transparency obligations, which took effect on schedule. Worth being precise about the scope, since "watermarking relief" as a headline undersells how narrow it actually is.

One more check while I was at it: whether the ESAs, EBA, ESMA, EIOPA, had said anything about the Digital Omnibus specifically, given how directly it touches the AI Act side of the DORA relationship. Their 31 July statement on frontier AI cyber risk, covered here, doesn't mention the omnibus at all, different document, different month. If they weigh in on how the deferred high-risk timeline changes anything for DORA-regulated entities, that's the next thing worth checking.

Primary source: Regulation (EU) 2026/1744 on EUR-Lex, consolidated against Regulation (EU) 2024/1689. Not legal advice, and consolidated texts carry the standard EUR-Lex disclaimer that the OJ version is the only authentic one, cite that for anything client-facing.

I'm migrating a full AI Act control framework against this same verified text, checked article by article rather than assumed. More on that, and on the tool that catches the gaps, soon.