What the Digital Omnibus on AI is
The AI Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024 with staggered application dates. In November 2025 the Commission proposed a "Digital Omnibus" to simplify the EU's digital rulebook, and the AI part went through on a fast track. The Parliament adopted its position on 16 June 2026 and the Council approved it on 29 June 2026. It was signed on 8 July 2026 and published as Regulation (EU) 2026/1744 in the Official Journal on 24 July 2026. It entered into force three days later, on 27 July 2026, just before the original 2 August 2026 deadline for high-risk systems would have hit.
It is an amending regulation. The AI Act stays the law, and the Omnibus changes specific articles. The dates below combine both texts.
The timeline at a glance
- 1 August 2024AI Act enters into force. Nothing applies yet.
- 2 February 2025Chapters I and II apply: definitions, AI literacy (Article 4) and the prohibited practices (Article 5), such as social scoring, manipulative AI, untargeted facial-image scraping, and emotion recognition at work and in education.
- 2 August 2025General-purpose AI model obligations (Chapter V), governance (AI Office, Board), notified-body rules, confidentiality and the penalty regime (Chapter XII, except the Commission's GPAI fines in Article 101). Member States had to designate authorities and set penalty rules.
- 27 July 2026 OmnibusRegulation (EU) 2026/1744 enters into force. Its amendments to other EU acts (Articles 102 to 110 of the AI Act) apply from this date.
- 2 August 2026General date of application. Article 50 transparency (chatbots, generated content, deepfakes) applies to every in-scope system, including those already in use. The Commission's fining powers over GPAI model providers (Article 101) start.
- 1 October 2026: you are here
- 2 December 2026 OmnibusMarking duty for generated content (Article 50(2)) for generative systems placed on the market before 2 August 2026. Two new prohibitions apply: systems generating non-consensual intimate or sexually explicit images of identifiable people, and systems generating child sexual abuse material (Article 5(1)(ba) and (bb)).
- 2 August 2027GPAI models already on the market before 2 August 2025 must comply (Article 111(3)). Deadline for each Member State to have at least one AI regulatory sandbox running Omnibus.
- 2 December 2027 was 2 Aug 2026High-risk AI under Annex III: biometrics, critical infrastructure, education, employment and HR, access to essential services (credit scoring, insurance pricing), law enforcement, migration, justice. Provider and deployer obligations of Chapter III, Sections 1 to 3.
- 2 August 2028 was 2 Aug 2027High-risk AI under Annex I: AI that is, or is a safety component of, a product covered by EU product legislation such as machinery, toys, lifts, radio equipment and medical devices.
- 2 August 2030Providers and deployers of high-risk systems used by public authorities that were already on the market must comply (Article 111(2)).
- 31 December 2030AI components of large-scale EU IT systems (Annex X, such as SIS and VIS) placed on the market before 2 August 2027 must comply.
Legacy high-risk systems: after the Omnibus, a high-risk system placed on the market before its high-risk rules apply (2 December 2027 or 2 August 2028) only falls under the high-risk requirements if its design changes significantly after that date. Prohibitions apply regardless, and public-sector systems must comply by 2 August 2030 anyway.
What changed, and what did not
| Topic | Before the Omnibus | After Regulation (EU) 2026/1744 |
|---|---|---|
| Annex III high-risk | 2 August 2026 | 2 December 2027 |
| Annex I high-risk (products) | 2 August 2027 | 2 August 2028 |
| Article 50 transparency | 2 August 2026 | Unchanged. Only the marking duty in 50(2) gets a grace period to 2 December 2026, for systems already on the market. |
| Article 4 AI literacy | "Ensure, to their best extent, a sufficient level" of AI literacy | "Take measures to support the development" of AI literacy; no guaranteed level. Commission and Member States must support SMEs. |
| Prohibitions | Article 5 list | Two added (sexual deepfakes without consent, CSAM generation), from 2 December 2026 |
| Bias detection | Special-category data only for high-risk providers (Article 10(5)) | New Article 4a: also other providers and deployers, under strict safeguards |
| SMEs and small mid-caps | Simplified documentation and lower fines for SMEs | Extended to small mid-caps (SMCs): simplified technical documentation form, proportionate quality management, fines capped at the lower amount |
| Registration of "not high-risk" Annex III systems (Article 6(3)) | Full registration | Still required, with fewer data fields (Annex VIII, Section B, points 7 and 9 deleted) |
What did not change: the risk categories, the list of Annex III use cases, the general-purpose AI model regime and its Code of Practice, the deployer duties in Article 26 for high-risk systems, and the fine ceilings in Article 99.
AI literacy after the Omnibus
During the negotiations there was a proposal to turn Article 4 into a duty for Member States and the Commission only. That is not what was adopted. The new Article 4(1) reads:
"Providers and deployers of AI systems shall take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf [...]. This obligation does not require providers or deployers to guarantee any specific level of AI literacy of any individual."
Article 4(2) adds that the Commission and Member States must support providers and deployers, "in particular SMEs", and that the Commission will publish practical examples. For an SME, a proportionate response is still a short, role-based briefing for the people who choose, configure and use AI tools, plus a record that it took place. The obligation has applied since 2 February 2025.
Penalties
- Prohibited practices: up to EUR 35 million or 7% of worldwide annual turnover.
- Most other obligations (provider, deployer, importer, distributor and Article 50 duties): up to EUR 15 million or 3%.
- Incorrect or misleading information to authorities: up to EUR 7.5 million or 1%.
- SMEs, start-ups and, since the Omnibus, small mid-caps: the lower of the amount or percentage applies.
- GPAI model providers: fined by the Commission (Article 101), possible since 2 August 2026.
Penalty rules are set nationally, within these ceilings. Check which authority supervises AI in your Member State.
What to do now, per role
Most SMEs are deployers (they use AI tools). Fewer are providers (they build or sell AI systems, or put them into service under their own name). Many are both.
- Keep an inventory of AI tools in use, with owner, purpose and vendor.
- Screen it against Article 5. Stop anything prohibited (for example emotion recognition of staff).
- Run and record an AI literacy briefing per role (Article 4).
- Check transparency: deepfakes and AI-written public-interest text you publish (50(4)), and emotion recognition or biometric categorisation (50(3)).
- Flag Annex III use cases (CV screening, performance monitoring, credit scoring). Plan for the Article 26 deployer duties by 2 December 2027: human oversight, logs, informing workers, and in some cases a fundamental rights impact assessment.
- Ask vendors of high-risk tools for their conformity roadmap.
- Classify each system: prohibited, high-risk (Annex I or III), Article 50, or minimal risk. Document any Article 6(3) "not high-risk" assessment and register it.
- Chatbots: AI disclosure designed in from the first interaction (in force now).
- Generative features: machine-readable marking of outputs by 2 December 2026 for existing systems, immediately for new ones.
- Check your product against the two new prohibitions before 2 December 2026.
- High-risk: start the quality management system, risk management, data governance, technical documentation (simplified SME/SMC form), logging and post-market monitoring now. 2027 is closer than it looks.
- Built on a GPAI model? Collect the model provider's downstream documentation.
Put the AI Act on a schedule
Dazr Compliance ships an EU AI Act framework with these obligations as recurring controls, an asset and vendor register for your AI inventory, and evidence with expiry alerts, so the 2027 deadline does not arrive as a surprise.
FAQ
Is the EU AI Act delayed?
Partly. The Digital Omnibus (Regulation (EU) 2026/1744) moved the high-risk rules to 2 December 2027 (Annex III) and 2 August 2028 (Annex I). Prohibitions, AI literacy, general-purpose AI model rules and the Article 50 transparency duties were not delayed.
Does Article 4 AI literacy still apply to my company?
Yes. Since the Omnibus, providers and deployers must take measures to support the AI literacy of their staff, without having to guarantee a specific level. It has applied since 2 February 2025.
When do the chatbot transparency rules apply?
From 2 August 2026, for all chatbots in use, including older ones. Only the machine-readable marking of generated content has a grace period, until 2 December 2026, for generative systems placed on the market before 2 August 2026.
What happens to high-risk systems already on the market before December 2027?
They only fall under the high-risk requirements if their design changes significantly after the rules start to apply. Systems used by public authorities must comply by 2 August 2030 regardless.
Related
Sources (as of 1 October 2026)
- Regulation (EU) 2024/1689 (AI Act), Articles 4, 5, 50, 99, 101, 111 and 113.
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), signed 8 July 2026, OJ L 24 July 2026, in force 27 July 2026.
- Commission Guidelines on Article 50 transparency obligations, 20 July 2026, section 8.4 on entry into application.
- Cloud Security Alliance research note on the Omnibus deadline delay (secondary).
This guide reflects the consolidated legal texts as of 1 October 2026 and is not legal advice.