This browser is not actively supported anymore. For the best passle experience, we strongly recommend you upgrade your browser.
| 3 minute read

The Digital Omnibus on AI: Key Changes to the EU AI Act

The EU’s Digital Omnibus (formally Regulation (EU) 2026/1744) came into force on 27 July and makes targeted changes to the EU AI Act to address certain difficulties that emerged during its early implementation.

Below, we break down the key changes and their practical implications for businesses.

Delayed implementation timeline

The most significant change is the delay to the compliance deadlines for high-risk AI systems under Chapter III of the AI Act. The rules will now apply to most high-risk AI systems from 2 December 2027 (originally 2 August 2026), while high-risk AI systems embedded as a safety component in regulated products have until 2 August 2028.

This gives businesses more time, but they should not treat the delay as a reason to defer compliance planning. Key standards and guidance are still being developed and are likely to be published before the new deadlines. Businesses should therefore use the extra time to assess their high-risk AI systems, close governance gaps and prepare for compliance.

Other parts of the EU AI Act are already in force, including the Article 50 transparency obligations (see our article here), so AI governance should remain a near-term priority.

New prohibitions

The Digital Omnibus adds two new prohibited AI practices, both concerning the placing on the market of an AI system that generates prohibited material. These cover:

  1. generating child sexual abuse material; or
  2. generating or manipulating realistic images, video or audio that depict an identifiable person's intimate parts, or portray them engaged in sexually explicit activity, without that person's consent.

Deployers are only prohibited from actively using AI systems for these purposes. Providers are prohibited from placing on the market AI systems that: (i) are intended to generate or manipulate such material; or (ii) where such generation is a reasonably foreseeable and reproducible outcome and the AI system does not have reasonable and adequate technical safety measures.

Critically, the second limb does not require that harmful generation be made impossible. Instead, providers must have put in place reasonable and adequate technical safety measures. The recitals to the Digital Omnibus offer examples of what this might include, such as data cleaning, safe prompt design and output controls, content classification and filtering, usage restrictions, and abuse detection mechanisms.

Both prohibitions apply from 2 December 2026.

AI literacy

Article 4 previously required businesses to ensure a sufficient level of AI literacy among relevant staff, which many saw as difficult to actually evidence. The Digital Omnibus replaces this with a duty to take measures to support the development of AI literacy, reframing it as an obligation of effort rather than outcome.

In light of this, businesses should ensure they can evidence the steps they have taken to support AI literacy within their organisation.

Clarifying safety components and high-risk AI systems

The Digital Omnibus amends Article 6 to clarify what qualifies as a “safety component” and is therefore classified as high-risk. AI systems used solely for non-safety purposes (such as user assistance, performance optimisation or quality control) will not qualify as safety components unless their failure or malfunction would endanger health and safety.

Many AI-enabled functions will consequently fall outside the high-risk classification. However, businesses should review their AI system inventories, given systems previously treated as high-risk may no longer need to meet those requirements.

Small mid-cap enterprise relief

The Digital Omnibus extends existing SME concessions to small mid-cap enterprises (SMCs). These are defined as being companies that are too large to qualify as SMEs but may still struggle to absorb compliance costs designed for larger enterprises.

SMCs will benefit from simplified obligations on technical documentation and conformity assessments, so businesses near the SME threshold should check whether they qualify.

Processing of special categories of personal data for bias detection and correction

Previously, only providers of high-risk AI systems could process special categories of personal data for bias detection and correction. The Digital Omnibus extends this to providers and deployers of any AI system.

The same strict conditions and safeguards apply, but the change allows a broader range of businesses to carry out this important task. GDPR obligations - including maintaining records of processing activities - continue to apply alongside this new provision.

Value chain obligations

Where an entity downstream assumes the role of new provider under Article 25, the initial provider must now cooperate with the new provider in three specific ways:

  1. Make available technical documentation sufficient to assess compliance with the high-risk obligations;
  2. Inform the new provider about known limitations and failure modes; and
  3. Provide the new provider with targeted technical access, including for testing and validation.

As a result, upstream providers now have more precisely defined cooperation duties, while downstream providers have a clearer legal basis to request the information and access they need.

Takeaways

Businesses should not pause compliance simply because implementation has been delayed, especially as several AI Act obligations are already in force, but use this additional time to plan for and achieve compliance with the high-risk aspects of the EU AI Act.

Businesses should also assess whether the Digital Omnibus changes affect their AI governance, product classification and supply chain arrangements – for example by:

  • identifying whether their tools are likely to be caught by the new prohibitions and, if so, implementing adequate safeguards;
  • reviewing their AI system inventories to assess whether any systems can now be reclassified as outside the high-risk tier; and
  • developing practical measures for supporting the development and ongoing increase in AI literacy.

Subscribe to receive our latest insights - on the topics that matter most to you - direct to your inbox, at your preferred frequency. Subscribe here

Tags

artificial intelligence, data protection and privacy, it and digital, technology, technology regulation, article