On July 27, 2026, Regulation (EU) 2026/1744 of the European Parliament and of the Council, the Digital Omnibus on AI, entered into force three days after its publication in the Official Journal on July 24, 2026 (EUR-Lex, OJ L 2026/1744). The act, adopted on July 8, 2026, amends the EU Artificial Intelligence Act (Regulation (EU) 2024/1689) and aligns it with the EASA Regulation (Regulation (EU) 2018/1139) and the Machinery Regulation (Regulation (EU) 2023/1230). Its central effect is to defer the stand-alone high-risk AI system obligations that were due to apply on August 2, 2026, while leaving the Article 50 transparency deadline on that same date untouched.

For AI providers, deployers and general-purpose AI model vendors selling into the EU, the Omnibus rewrites the compliance calendar rather than relaxing it. The prohibitions and GPAI rules already in force since 2025 stay in force, and a new layer of Article 5 prohibitions arrives in December 2026. The relief is concentrated on the Annex III high-risk class, which moves out by 16 months.

Which AI Act deadlines moved, and to what date?

The Omnibus postpones two high-risk application tracks. Stand-alone high-risk AI systems listed in Annex III (recruitment, credit scoring, biometric identification, critical-infrastructure emotion recognition, and similar) move from August 2, 2026 to December 2, 2027. High-risk AI systems embedded in products covered by Section A of Annex I, which are subject to third-party conformity assessment, move to August 2, 2028. The consolidated text is reachable through its European Legislation Identifier permalink (http://data.europa.eu/eli/reg/2026/1744/oj).

ObligationOriginal dateDigital Omnibus date
Article 5 prohibitions (manipulation, social scoring, real-time biometric ID)February 2, 2025Unchanged
GPAI model obligationsAugust 2, 2025Unchanged
Article 50 transparency (chatbot disclosure, deepfake labelling)August 2, 2026Unchanged
New Article 5 prohibitions (nudifiers, CSAM)n/aDecember 2, 2026
Annex III stand-alone high-risk systemsAugust 2, 2026December 2, 2027
Annex I Section A product-embedded high-risk systemsAugust 2, 2027August 2, 2028

The deferral does not suspend the underlying classification logic: a system that qualifies as high-risk today still qualifies as high-risk. Providers who have already built conformity-assessment workflows should treat the extra time as runway to complete them, not as a reason to pause.

What still applies on August 2, 2026, in six days?

Article 50 transparency obligations are not deferred. From August 2, 2026, providers and deployers of AI systems that interact with humans, generate deepfake or synthetic audio, image or video content, or classify biometric data must disclose the AI's involvement to the affected persons. Chatbot operators must indicate that the user is interacting with an AI, and synthetic-media publishers must label machine-generated content. Enforcement sits with national market-surveillance authorities and the EU AI Office, and the Omnibus leaves this date intact.

The AI literacy duty in Article 4 survives but is softened: providers and deployers must now "take measures to support" the development of AI literacy among staff and operators, replacing the stricter "ensure a sufficient level" formulation. The change matters for SME compliance documentation but does not remove the obligation.

What new prohibitions arrive on December 2, 2026?

The Omnibus inserts two new Article 5 prohibitions that apply from December 2, 2026: the creation of non-consensual intimate imagery using AI (so-called nudifiers), and AI-generated child sexual abuse material (CSAM). These join the existing Article 5 ban list (manipulative, social-scoring and real-time remote biometric identification practices, in force since February 2, 2025) and are unconditional: no conformity assessment, no transition, no exception for SMEs. Providers whose models can generate synthetic human imagery must have technical safeguards in place before that date.

Who benefits from the SME and scope clarifications?

Three substantive simplifications accompany the deferral. First, the "safety component" definition in Article 3(14) is narrowed: an AI system is a safety component only where its intended purpose is to prevent or mitigate risks to health and safety, not merely because it sits inside a regulated product. This removes borderline cases from the high-risk class. Second, the Omnibus introduces formal definitions for SMEs and small mid-cap enterprises (SMCs) and extends selected SME relief measures to SMCs. Third, where Union harmonisation legislation in Annex I Section A already achieves an equivalent level of protection, the Commission may, by delegated act, limit the application of specific AI Act requirements to avoid duplication.

Continuous, per-jurisdiction real-time monitoring surfaces the moment an amending regulation like this one publishes in the Official Journal, so compliance teams can re-baseline deadlines the same day rather than at the next quarterly review.

Take advantage of this real-time watch

AI Act: Omnibus and Article 50 transparencyLive
Monitor the EU AI Act's milestones for the AI, data and digital governance industry.
Hourly Email 10+ news
This live monitoring job detected the news you are reading.
Activate this watch free now

Verify which of your AI systems fall under Annex III versus Annex I Section A, reconfirm your Article 50 disclosure and synthetic-media labelling readiness for August 2, 2026, brief product and AI governance teams on the narrowed "safety component" test, and block December 2, 2026 in your roadmap for the new nudifier and CSAM prohibitions. Obsidian tracks these staggered AI Act milestones as they move, so the calendar your team works from stays the current one.