The AI Omnibus brings challenges that will reshape AI Act compliance

Legal Eubdate
7 August 2026

With the AI Omnibus, the European legislator introduced targeted amendments to the AI Act. This culminated in the adoption of Regulation (EU) 2026/1744 of the European Parliament and of the Council (“AI Omnibus”) on 8 July 2026, which entered into force on 27 July 2026. 

The AI Omnibus aims to make the application of Regulation (EU) 2024/1689 (“AI Act”) clearer and more workable for organisations through targeted amendments. In doing so, it maintains the existing level of protection for safety and fundamental rights, while at the same time focusing on reducing administrative burdens, adjusting certain deadlines and providing additional support. The AI Omnibus should also be seen in the broader context of the EU’s recent digital simplification agenda to make the EU digital rulebook more coherent and operational.

What does this mean in practice? The six key changes are set out below.

Rules for high-risk AI systems are postponed

In the face of significant delays in the availability of compliance-supporting tools, such as guidelines to be issued by the European Commission, as well as harmonised European technical standards, the application of the obligations on high-risk AI systems has been delayed from their original 2026 deadlines. Whilst the Commission initially proposed making the application of those rules contingent upon these compliance-supporting tools under the AI Act, the final text of the AI Omnibus postpones the application of the high-risk AI rules to fixed dates. For stand-alone high-risk AI systems under Annex III, the deadline is postponed from 2 August 2026 to 2 December 2027. For embedded high-risk AI systems under Annex I, the new deadline is 2 August 2028.

Transparency rules have already entered into force

In contrast to the high-risk obligations, from 2 August 2026 the first transparency obligations for limited-risk AI systems under Article 50 AI Act apply in full. These rules impose transparency obligations for AI-generated or AI-manipulated content to ensure that individuals are clearly informed when they are interacting with AI or are exposed to AI content.

The AI Omnibus introduces a limited transitional period for AI systems that generate synthetic content and were already placed on the market before 2 August 2026. For those systems, compliance with the transparency obligations under Article 50(2) AI Act is deferred until 2 December 2026. 

The AI Omnibus also amends Article 50(7) AI Act and thereby gives a more prominent role to Union-level codes of practice in facilitating compliance with the obligations on the detection, marking and labelling of artificially generated or manipulated content.

AI literacy is softened

The amendment to Article 4 AI Act simplifies the original obligation regarding AI literacy. Instead of a strict obligation to ensure an adequate level of AI literacy, providers and deployers of AI systems must henceforth take measures to support the development of AI literacy among their staff and other persons who operate or use AI systems on their behalf. The emphasis thus shifts from guaranteeing a certain level of knowledge to actively promoting it. 

In addition, the European Commission and the Member States are given a supporting role, including through training initiatives, information resources and the exchange of good practices. The AI Board will also contribute by formulating recommendations and facilitating cooperation between the Commission and the Member States.

Bias detection is extended

The AI Omnibus expands the existing legal basis for the processing of special categories of personal data to detect, prevent and correct bias in AI systems. Whereas under the AI Act this option originally applied mainly to providers of high-risk AI systems, it now applies to all providers and deployers of AI systems and models.

A more proportionate approach for SMCs

The EU legislator recognises that not only SMEs but also small mid-cap enterprises (SMCs) often face administrative burdens similar to those of SMEs in the application of the AI Act. This fits within a broader EU policy trend to better reflect the situation of SMCs in the design of regulatory compliance obligations. By way of comparison, the European Commission has also proposed, in the context of the Omnibus IV Package, a targeted simplification of certain GDPR obligations for SMEs and SMCs. However, these amendments are still part of a proposal rather than adopted law. 

Other adjustments 

The AI Omnibus introduces further adjustments to facilitate implementation and supervision under the AI Act.

  • From 2 December 2026, the prohibition under Article 5 AI Act explicitly includes AI systems that generate or manipulate non-consensual intimate material and child sexual abuse material. 

  • The designation of conformity assessment bodies is streamlined by enabling a single application and a single conformity assessment procedure where designation is sought under both the AI Act and other relevant Union harmonisation legislation (e.g. where a lift already subject to sector-specific compliance requirements incorporates an AI-based safety component).

  • The deadline for Member States to establish AI regulatory sandboxes is postponed until 2 August 2027, while the AI Omnibus at the same time empowers the AI Office to establish an EU-level regulatory sandbox, including integrated real-world testing where appropriate.

  • Finally, the AI Office is granted a more centralised supervisory role, including exclusive competence for AI systems based on general-purpose AI models, subject to limited exceptions, and for AI systems that constitute or form part of very large online platforms (VLOPs) or very large online search engines (VLOSEs) designated under the Digital Services Act, together with corresponding market surveillance and coordination powers.

***

The AI Omnibus does not alter the fundamental architecture of the AI Act but introduces a series of adjustments intended to improve its practical application. By postponing certain obligations, clarifying specific rules, easing administrative burdens and strengthening institutional support and supervision, the European legislator seeks to make the framework more workable without lowering the level of protection for safety and fundamental rights.