EU Digital Omnibus on AI (Regulation (EU) 2026/1744)
Amends the AI Act: Annex III high-risk obligations deferred to 2 December 2027 and Annex I to 2 August 2028; synthetic-media transparency and new bans on nudifier and CSAM-generating systems apply from 2 December 2026; creates a small mid-cap tier, widens the GDPR legal basis for bias-detection processing, and gives the AI Office exclusive jurisdiction over GPAI-based systems.
| Jurisdiction | European Union |
|---|---|
| Category | AI Regulations |
| Status | Active |
| Effective date | |
| Latest development |
Analysis
Regulation (EU) 2026/1744, the Digital Omnibus on AI, is now in force and formally amends the EU AI Act (Regulation (EU) 2024/1689) by deferring key high‑risk AI deadlines, introducing new synthetic‑media transparency duties and bans on “nudifier” and CSAM‑generating systems, and recalibrating obligations for small and mid‑cap providers, bias‑detection processing under the GDPR, and GPAI‑based systems under the AI Office’s exclusive jurisdiction.Regulation (EU) 2026/1744 – Official JournalAI Act – Official JournalEuropean Commission – AI Act overview
Because you requested multiple direct links for every significant statement, note that for several points (small mid‑cap tier, widened GDPR legal basis, exclusive AI Office jurisdiction over GPAI) detailed operational guidance is still emerging in secondary sources; wherever possible I link to the primary legal text and then to reputable legal analyses that interpret these provisions.
Key Requirements
1. Deferred application of high‑risk AI obligations (Annex III and Annex I)
- Annex III stand‑alone high‑risk AI systems (e.g., recruitment, education, credit scoring, law enforcement) now become subject to the main AI Act Chapter III obligations on 2 December 2027 rather than 2 August 2026.
- This deferral is expressly set out in Regulation (EU) 2026/1744, which amends the application dates in the AI Act.Regulation (EU) 2026/1744 – Official Journal
- The European Commission’s AI Act page confirms that high‑risk use cases in Annex III are extended to 2 December 2027 as part of the “AI Omnibus” simplification package.European Commission – AI Act overview
- Legal and policy briefings explain that stand‑alone Annex III systems must comply with key obligations—risk management, data governance, technical documentation, logging, transparency, human oversight, accuracy and robustness—by 2 December 2027.Innovation Law Insights – DLA PiperJones Walker – “Yes, August 2 Still Matters”
- Annex I high‑risk AI embedded in regulated products (e.g., medical devices, machinery, aviation) now apply from 2 August 2028.
- The Commission confirms that rules for high‑risk AI systems embedded into regulated products (Annex I) have an extended transition period to 2 August 2028.European Commission – AI Act overview
- Legal commentaries on Regulation (EU) 2026/1744 emphasise the shift of embedded high‑risk AI to 2 August 2028, aligning AI conformity with existing sectoral regimes (Machinery, Civil Aviation, etc.).Law & Technology EU – Digital Omnibus summaryMayer Brown – Omnibus overview
2. Synthetic‑media transparency obligations
- Transparency obligations for AI‑generated and manipulated content (“synthetic media”) apply from 2 August 2026, with further obligations for systems already on the market applying from 2 December 2026.
- The Digital Omnibus shifts the first AI Act enforcement date, but maintains transparency obligations from 2 August 2026, with additional content‑marking duties by 2 December 2026 for pre‑existing systems.Hunton Andrews Kurth – Omnibus in forceDLA Piper – Innovation Law Insights
- Industry reporting notes that companies must label AI‑generated or manipulated media, including deepfakes and other synthetic content, in line with AI Act provisions on transparency (e.g., Article 52) and the Omnibus’s implementation timeline.European Commission – AI Act overviewMayer Brown – transparency guidance
3. New bans on “nudifier” and CSAM‑generating AI systems
- AI systems that generate or manipulate non‑consensual intimate imagery (“nudifier” apps) and systems capable of generating child sexual abuse material (CSAM) become prohibited AI practices as of 2 December 2026.
- The AI Act’s prohibited practices list (Article 5) is expanded by the Digital Omnibus to include AI that generates/manipulates intimate depictions without consent, targeting “nudifier” applications.Regulation (EU) 2026/1744 – Official JournalAI Act – Official Journal
- Reporting on the Omnibus law emphasises a hard ban from 2 December 2026 on nudifier apps and CSAM‑generation capabilities, with enforcement linked to AI Act prohibited‑use provisions.TechTimes – Omnibus transparency & nudifier banHunton Andrews Kurth – Omnibus in force
4. Small and mid‑cap tier and eased documentation requirements
- Digital Omnibus introduces a “small mid‑cap” tier, easing certain documentation and conformity assessment obligations for medium‑sized providers, while preserving core safety and transparency requirements.
- Legal analysis highlights that the Omnibus extends simplified documentation and QMS measures beyond SMEs to include mid‑sized companies, reducing administrative burdens while keeping essential controls.Hunton Andrews Kurth – Omnibus in forceWhite & Case – Omnibus in force
- Commentaries describe this as a new intermediate category for providers that are not micro‑enterprises but also not large caps, which benefits from streamlined conformity assessment pathways.Mayer Brown – Omnibus overviewLicentium – Omnibus changes
5. Broader GDPR legal basis for bias‑detection processing
- The Omnibus widens the GDPR legal basis for processing, specifically to enable bias‑detection and fairness testing in AI systems, including processing of certain personal data and outputs for audit purposes.
- Analyses note that the Omnibus clarifies and extends lawful grounds under the GDPR for bias‑monitoring and fairness assessments of AI systems, reducing uncertainty around whether necessary dataset and output analysis is permissible.Hunton Andrews Kurth – Omnibus in forceWhite & Case – Omnibus in force
- These changes interact with GDPR Articles 6 and 9 on lawful processing, and the AI Act provisions on data governance for high‑risk AI (e.g., quality, representativeness, absence of bias).GDPR – Consolidated text (EUR‑Lex)AI Act – Official Journal
6. Exclusive jurisdiction of the EU AI Office over GPAI‑based systems
- The Omnibus reinforces the EU AI Office’s central role and effectively gives it exclusive jurisdiction for certain GPAI‑based systems and related obligations.
- The AI Act already establishes the AI Office within the Commission as a central authority to oversee GPAI models and cross‑border enforcement.European Commission – AI Office overviewAI Act – Official Journal
- Omnibus‑focused legal briefings describe expanded powers of the AI Office, including oversight and coordination for GPAI‑based systems, concentrating supervisory and standard‑setting authority at EU level to avoid fragmentation.Hunton Andrews Kurth – Omnibus in forceMayer Brown – Omnibus overview
Compliance Challenges
1. Complex, moving implementation timeline
- Organizations struggle to track multiple staggered dates: early transparency obligations (2 August 2026), bans on nudifiers/CSAM (2 December 2026), Annex III obligations (2 December 2027), and Annex I obligations (2 August 2028).European Commission – AI Act overviewHunton Andrews Kurth – Omnibus in forceDLA Piper – Innovation Law Insights
- Practical guidance notes that many providers initially prepared for August 2026 high‑risk enforcement, and must now re‑sequence compliance projects while still meeting earlier transparency duties.Jones Walker – timeline analysisGibson Dunn – Omnibus agreement
2. Classification of systems as high‑risk vs GPAI vs non‑high‑risk
- Many organizations find it challenging to determine whether a system falls under Annex III high‑risk, Annex I embedded high‑risk, GPAI, or lower‑risk categories, which drives differing obligations and timelines.AI Act – Official JournalArtificialIntelligenceAct.eu – implementation timeline
- Industry commentary stresses that misclassification can lead to under‑compliance (missed QMS, documentation, CE‑marking duties) or over‑compliance (unnecessary costly conformity assessments).Mayer Brown – risk classification guidanceWhite & Case – Omnibus analysis
3. Synthetic‑media detection and labeling in complex pipelines
- Companies operating multi‑modal AI systems (text‑to‑image, video generation, editing tools) face technical challenges detecting, tagging and watermarking synthetic outputs, especially when content passes through third‑party tools.European Commission – AI Act overviewMayer Brown – transparency obligations
- Reports on the Omnibus warn that failure to visibly disclose AI‑generated or manipulated content could lead to enforcement actions once transparency provisions are in force.Hunton Andrews Kurth – Omnibus in forceTechTimes – transparency deadline
4. Integrating AI Act duties with GDPR, sectoral safety and existing QMS
- Organizations must integrate AI Act data‑governance and logging obligations with GDPR requirements (lawful basis, data minimization, purpose limitation) and with sector‑specific safety regimes (e.g., medical devices, machinery).GDPR – Official JournalAI Act – Official JournalRegulation (EU) 2023/1230 – Machinery
- Commentaries on Regulation (EU) 2026/1744 note that while the Omnibus aims to simplify overlaps with aviation and machinery law, organizations still have to reconcile multiple technical‑standard regimes and notified‑body procedures.Regulation (EU) 2026/1744 – Official JournalLaw & Technology EU – Omnibus summary
5. GPAI‑specific governance and AI Office oversight
- Providers of general‑purpose AI models must comply with AI Act and Omnibus rules on model documentation, safety policies, cybersecurity, and downstream information sharing under the AI Office’s supervision.AI Act – Official JournalEuropean Commission – AI Office
- Legal guidance highlights uncertainty about how the AI Office will exercise its expanded powers and how GPAI obligations interact with sectoral regulators and national market‑surveillance authorities.Mayer Brown – GPAI guidanceHunton Andrews Kurth – Omnibus in force
Implementation Best Practices
1. Build a dated AI Act/Omnibus compliance roadmap
- Map obligations to dates (2 Aug 2026, 2 Dec 2026, 2 Dec 2027, 2 Aug 2028) per system, and maintain a live register of AI use cases and their classification (Annex III, Annex I, GPAI, low risk).
- Use the Commission’s timeline and official AI Act text to construct a roadmap.European Commission – AI Act overviewAI Act – Official Journal
- Public timelines and guides (prepared after the Omnibus agreement) provide structured views of deadlines and obligations.[ArtificialIntelligenceAct.eu
Recent developments
- — Overview of Regulation (EU) 2026/1744 entering into force on 27 July 2026, summarising its role as the Digital Omnibus on AI and outlining key changes to the AI Act’s implementation and timelines. (source)
- — Sector-focused analysis of how the Digital Omnibus on AI affects mobility and transport, including the new 2 August 2028 date for high‑risk AI obligations in Annex I product‑safety contexts such as vehicle safety components. (source)
- — Law‑firm briefing noting that the Digital Omnibus on AI entered into force on 27 July 2026 and amended the AI Act just days before its main application date, with emphasis on postponed obligations and practical compliance implications. (source)
- — Client alert explaining that the Digital Omnibus on AI, published on 24 July and effective from 27 July 2026, defers high‑risk AI obligations to 2 December 2027 (Annex III) and 2 August 2028 (Annex I), eases some requirements, and adds further prohibited AI practices. (source)
- — Policy update detailing how the Omnibus delays key EU AI Act deadlines while clarifying that GPAI and prohibited‑practice rules still apply from August 2026, urging companies not to pause compliance planning despite extended timelines. (source)
- — Research note analysing that Regulation (EU) 2026/1744, effective 27 July 2026, defers standalone high‑risk AI obligations from 2 August 2026 to 2 December 2027 and embedded high‑risk AI obligations to 2 August 2028, framing the change as a deferral rather than cancellation. (source)
- — Update confirming publication and applicability of the Digital Omnibus on AI from 27 July 2026, highlighting its aim to simplify AI Act implementation, adjust risk‑classification guidance, and interact with forthcoming rules on GPAI and transparency. (source)
- — Industry news article arguing that the Digital Omnibus weakens the “teeth” of the EU AI Act by deferring high‑risk obligations by roughly 16 months, while describing how private actors and AI governance vendors are moving to fill the regulatory gap. (source)
- — Analysis piece describing how the Digital Omnibus on AI, published 24 July 2026 and in force 27 July 2026, rewrites the AI Act’s compliance calendar, introduces a conditional ban on non‑consensual intimate‑image generation effective 2 December 2026, and realigns AI/product‑safety boundaries. (source)
- — Legal news noting the Official Journal publication of Regulation (EU) 2026/1744 and related sectoral legislation, summarising its purpose to reduce legal uncertainty, streamline compliance obligations, and better align AI Act implementation with harmonised standards and conformity‑assessment tools. (source)
Related regulations
- EU AI Act - Annex III High-Risk System Requirements (2 Dec 2027) — European Union, Upcoming, effective 2027-12-02
- EU Data Act — European Union, Phased, effective 2025-09-12
- EU Cyber Resilience Act (CRA) — European Union, Phased, effective 2027-12-11
- EU AI Act - GPAI Model Obligations (2 Aug 2025) and Enforcement (2 Aug 2026) — European Union, Active, effective 2025-08-02
- EU AI Act - Synthetic Media Transparency and New Prohibitions (2 Dec 2026) — European Union, Upcoming, effective 2026-12-02
- EU AI Act - Annex I High-Risk Systems (2 Aug 2028) — European Union, Upcoming, effective 2028-08-02
- EU Cyber Resilience Act - Vulnerability and Incident Reporting (11 Sep 2026) — European Union, Active, effective 2026-09-11
- EU Cybersecurity Act Revision (CSA2) — European Union, Proposed
Put it into practice
- Generate the policy: EU AI Act policy generator (generatepolicy.com)
- Buy the policy pack: EU AI Act Compliance Policy (cyberpolicy.shop)
- Build it yourself: Pillar 06 Companion — The 2026 AI Risk Register (ciso.diy)
Browse all regulations · Compliance deadlines · Latest updates