Less than two years after the AI Act entered into force, the European Union has adopted its first significant revision of the Regulation. Published in the Official Journal of the European Union on 24 July 2026, the Digital Omnibus introduces a series of targeted amendments aimed at simplifying implementation without altering the AI Act’s underlying risk-based approach.
Why it exists
The AI Act entered into force in August 2024, built around a risk-based approach: the higher the risk an AI system poses, the more obligations apply to it. As the implementation deadlines approached, though, several practical problems surfaced. Harmonised technical standards for high-risk systems still didn’t exist. Several member states hadn’t designated their national market surveillance authorities. Conformity assessment bodies weren’t ready to certify anything. Businesses, meanwhile, were flagging the cumulative weight of complying with the AI Act on top of the GDPR, the Data Act, NIS2 and other EU digital rules at the same time.
The Digital Omnibus is the Commission’s response to that pressure. It doesn’t rewrite the AI Act’s principles or its risk-based logic. It amends specific provisions to make the framework more workable in practice, while, in a couple of places, actually tightening it.
What changes, point by point
The compliance timeline moves. This is the central amendment. The AI Act’s high-risk obligations were due to apply from 2 August 2026. The Omnibus pushes that deadline to 2 December 2027, with a further extension to 2 August 2028 for high-risk systems embedded in products that were already regulated under other EU law, such as medical devices, machinery, or aviation systems.Â
AI literacy obligations are softened. The obligation itself remains binding on every provider and deployer, regardless of risk level, but its standard has changed: instead of having to ensure “a sufficient level” of AI literacy among staff, organisations now only have to take measures to support its development. It moves from a duty of result to a duty of effort, with national authorities gaining formal power to supervise it from 2 August 2026.
Bias mitigation gets a clearer legal basis. A new provision allows processing of special category personal data (race, health status, sexual orientation and similar) specifically to detect and correct discriminatory outcomes in AI systems, under strict safeguards. It extends to providers and deployers of AI more broadly. It removes a practical obstacle: GDPR’s default restrictions on sensitive data made it legally awkward to even test a model for bias in the first place.
Small Mid-Cap companies get SME-level treatment. The lighter documentation and more proportionate quality management obligations already available to SMEs are extended to Small Mid-Cap companies, with financial penalties expected to account for a company’s actual economic capacity to pay them.
Two prohibitions are strengthened. New rules explicitly target AI systems that generate non-consensual sexually explicit synthetic content of identifiable individuals, as well as synthetic CSAM. Both prohibitions become applicable from 2 December 2026. These are additions to the Act, not simplifications and they sit alongside the rest of the package as a reminder that “simplification” here isn’t a single uniform gesture.
The AI Office’s supervisory role expands. It gains stronger powers over particularly complex systems, including certain general-purpose AI models and AI systems embedded in very large online platforms and search engines, with the stated goal of centralising enforcement rather than leaving it fragmented across 27 national authorities.
Where things stand now
The Digital Omnibus was published in the Official Journal of the European Union on 24 July 2026 and entered into force on 27 July 2026. However, its provisions do not all apply immediately. While some amendments became applicable upon entry into force, others follow different implementation timelines, particularly those concerning high-risk AI systems.
For organisations preparing for the AI Act, the revised compliance deadlines are now the relevant ones: most obligations for high-risk AI systems will apply from 2 December 2027, while those relating to high-risk AI systems embedded in products already regulated under sectoral EU legislation will apply from 2 August 2028. At the same time, obligations that were not postponed continue to follow the AI Act’s original timetable. In particular, the transparency obligations under Article 50 have applied since 2 August 2026 and organisations should ensure they remain compliant with those requirements while preparing for the later application of the high-risk regime.
A reading worth keeping in mind
The Commission has framed the Digital Omnibus as a simplification exercise rather than a change of direction for the AI Act. However, this interpretation has not gone unchallenged.
In a recent policy brief, the Jacques Delors Centre, a European policy think tank, argues that the Omnibus goes beyond mere technical adjustments. According to the Centre, several amendments introduce substantive policy changes without a comprehensive impact assessment and may weaken fundamental rights safeguards, increase legal uncertainty and create loopholes, while offering uncertain economic benefits.
These concerns are particularly relevant when considering the revised implementation timeline for high-risk AI systems. Delaying the application of the AI Act’s most demanding obligations may be justified by the need to give companies and Member States more time to prepare for their implementation. At the same time, postponing enforcement inevitably delays the moment when the Regulation’s strongest safeguards become fully effective.
Whether this should ultimately be understood as pragmatic implementation or as a substantive policy shift remains open to debate. What is clear is that the Digital Omnibus is more than a purely technical update: it reflects the EU’s attempt to reconcile regulatory ambition with operational feasibility, while reopening important discussions about the balance between innovation, competitiveness and the protection of fundamental rights.