EU AI Omnibus enters into force, amending the AI Act

Alert
|
8 min read

On 27 July 2026, the Digital Omnibus on AI (the "AI Omnibus") entered into force, following publication in the Official Journal of the EU on 24 July 2026 as Regulation (EU) 2026/1744. The AI Omnibus amends the AI Act and introduces delayed enforcement of key obligations, eased requirements for certain categories of business, and adds further prohibited AI practices. Businesses gain additional time for compliance with the requirements regarding high-risk AI systems and should update their compliance roadmaps accordingly.

Background

The AI Omnibus is the AI-specific strand of the broader Digital Omnibus Package (the "Package") published by the European Commission (the "Commission") on 19 November 2025. The Package also proposes amendments to the GDPR, the ePrivacy Directive, NIS2, and the Data Act; however, those amendments remain subject to ongoing negotiations in the European Parliament and the Council of the EU (the "Council") and are not yet law.

The AI Omnibus was separated from the rest of the Package and fast-tracked through the legislative process in order to ensure that the amended deadlines for high-risk AI system obligations took effect before the original 2 August 2026 enforcement date set out in the AI Act. The AI Omnibus was signed on 8 July 2026 and published in the Official Journal on 24 July 2026, entering into force three days later, on 27 July 2026.

Key changes for businesses

The AI Omnibus introduces a number of material changes to the AI Act:

  1. Extended deadlines for high-risk AI systems
    The most significant change for the majority of businesses is the extension of the enforcement deadline for the bulk of the obligations governing high-risk AI systems under Chapter III of the AI Act. The AI Omnibus introduces a fixed timeline under which those obligations will apply from:
  • 2 December 2027, for stand-alone high-risk AI systems – i.e., those AI systems that are intended to be used for any of the purposes that are deemed to be high-risk, as set out in Annex III of the AI Act (covering the use of AI in areas such as biometrics, critical infrastructure, employment, education, access to essential private and public services, law enforcement, migration, and the administration of justice); and
  • 2 August 2028, for high-risk AI systems used as a safety component of a product (or otherwise subject to EU health and safety harmonisation legislation under Annex I of the AI Act), such as those embedded in medical devices, machinery, or aviation equipment.

These extensions are intended to allow businesses more time to understand and implement the applicable technical standards, guidelines, and conformity assessment procedures, many of which are still being developed. It should be noted that this deferral is limited to Chapter III and does not apply to other obligations relevant to high-risk AI systems (notably the transparency requirements discussed further below). 

  1. Watermarking grace period
    AI systems that generate synthetic audio, image, video, or text content and that were placed on the market before 2 August 2026 benefit from a short grace period: compliance with the watermarking obligation is required by 2 December 2026. Systems placed on the market on or after 2 August 2026 must comply from that date. Businesses deploying generative AI systems should therefore verify whether their systems were on the market before 2 August 2026 and plan their compliance accordingly.
  2. Clarification of "safety component"
    The AI Omnibus clarifies the term "safety component" for the purposes of the AI Act (which is important because being a "safety component" is one of the main ways that an AI system becomes a high-risk AI system under Annex I or paragraph 2 of Annex III of the AI Act). AI systems that only assist users or optimise performance will not automatically be treated as safety components if their failure or malfunction does not create health or safety risks. This is a helpful clarification for businesses deploying AI in operational or productivity contexts, as it narrows the circumstances in which such systems are drawn into the high-risk category.
  3. Reduced regulatory overlap with sectoral legislation
    For businesses operating in sectors with their own product safety or conformity requirements (such as medical devices, lifts, or toys) the AI Omnibus reduces the risk of duplicative compliance obligations. It allows for the limitation of the AI Act's application in other cases where sectoral law contains AI-specific requirements equivalent to those in the AI Act, through the adoption of delegated acts by the Commission. Businesses in regulated sectors should monitor the Commission's exercise of this power and assess the extent to which it reduces their compliance burden under the AI Act. 

    The draft further removes machinery from the list of products where safety components need to comply with the full set of high-risk AI rules. In exchange, the relevant machinery products regulation has been added to the group of regulations that require additional legislative projects to establish high-risk AI rules.

  4. Simplified conformity assessment
    The AI Omnibus streamlines conformity assessment procedures by allowing a conformity assessment body to submit a single application and undergo a single assessment procedure in order to be designated under both the AI Act and relevant EU harmonisation legislation. In addition, certain Notified Bodies already designated under sector-specific EU law may, for a transitional period, carry out conformity assessments for high-risk AI systems while awaiting formal designation under the AI Act.
  5. Further relief measures for SMEs and SMCs
    The AI Omnibus extends certain existing relief measures for small and medium-sized enterprises ("SMEs") and small mid-cap enterprises ("SMCs"). These include simplified technical documentation requirements, proportionate quality management obligations, and mitigated penalties. Priority access to regulatory sandboxes is also maintained. While the simplified pathway does not reduce many of the substantive requirements that SMEs and SMCs must ultimately meet, it does provide a more proportionate route to demonstrating compliance.
  6. New prohibited AI practices
    The AI Omnibus adds new prohibitions on using AI systems to generate or manipulate child sexual abuse material (CSAM), or using AI systems to generate non-consensual intimate or sexually explicit content depicting identifiable individuals (so-called "nudifier" applications). The prohibition applies to images, video, and audio content. Businesses providing or deploying generative AI systems capable of producing such content should review their technical safeguards, content moderation policies, and terms of use as a matter of priority.
  7. AI Literacy revised
    The AI Omnibus softens the AI literacy obligation under Article 4 of the AI Act. Providers and deployers are now required to take measures to support the development of a sufficient level of AI literacy among their staff and other persons dealing with the operation and use of AI systems on their behalf, rather than to ensure such a level. The amended provision obliges the Commission and Member States to support and facilitate providers' and deployers' efforts (including through practical examples of compliance published by the Commission). Although the underlying expectation of workforce AI literacy remains, businesses have a reduced risk in case of individuals not having the necessary level of AI literacy. Existing training programmes may be reviewed to reflect this shift and may be adapted regularly to the materials provided by Member States and the Commission in the future.
  8. AI Office supervision strengthened
    The AI Omnibus expands the powers of the AI Office (the body within the Commission responsible for supervising providers of general-purpose AI (“GPAI”) models) and extends its supervisory reach to certain AI systems provided by the GPAI model provider and to AI systems that constitute or are integrated into very large online platforms and search engines regulated under the Digital Services Act. Providers of GPAI models and businesses operating large online platforms should take note of this expanded supervisory framework and ensure that their governance arrangements are adapted accordingly.

Practical outlook for businesses

The AI Omnibus provides welcome certainty by resolving some of the uncertainty that had existed ahead of the original 2 August 2026 deadline and providing extensions to many (though not all) of the critical compliance deadlines. The extension of the enforcement deadlines for high-risk AI system obligations gives businesses additional time to prepare, although it does not materially reduce the work required. 
Businesses should consider taking the following steps:

  • Update compliance roadmaps to reflect the new enforcement dates (2 December 2027 for stand-alone Annex III systems; 2 August 2028 for Annex I embedded systems) and prioritise obligations that continue to apply from 2 August 2026 (notably the bulk of the transparency requirements in Article 50).
  • Assess watermarking obligations and, where relevant, determine whether systems placed on the market before 2 August 2026 can rely on the grace period until 2 December 2026.
  • Review AI inventories to identify whether any systems could be drawn into the newly prohibited categories and, if so, make appropriate changes.
  • Assess the impact of the safety component clarification on the risk classification of AI systems, as this clarification may provide justification for treating certain AI systems as not being high-risk.
  • Support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, and maintain records of the measures taken.
  • Stay up-to-date on sectoral delegated acts (i.e., new rules that the Commission has the power to issue) that may affect the AI Act's application to AI systems in regulated product categories.
  • Continue monitoring the legislative process for the broader Digital Omnibus Package, which – when adopted – will introduce further changes to the GDPR, ePrivacy, NIS2, and the Data Act.

 

White & Case means the international legal practice comprising White & Case LLP, a New York State registered limited liability partnership, White & Case LLP, a limited liability partnership incorporated under English law and all other affiliated partnerships, companies and entities.

This article is prepared for the general information of interested persons. It is not, and does not attempt to be, comprehensive in nature. Due to the general nature of its content, it should not be regarded as legal advice.

© 2026 White & Case LLP

Top