The EU AI Act has been amended. Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026 and moved the deadlines for high-risk AI systems, narrowed the scope, and cut documentation requirements for smaller companies. This article gives a high-level overview of what changed, what stayed the same, and what the new timeline means for your planning.
The Digital Omnibus on AI is an amending regulation, Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force since 27 July 2026. It does not replace the EU AI Act. It edits it: some deadlines moved, some definitions were tightened, some obligations were relaxed for smaller companies, and a few new ones were added. It also amends the Civil Aviation and Machinery Regulations, which matters if your product falls under either.
The Commission framed it as a simplification package rather than a change of direction. The consolidated text of the AI Act is the reference worth bookmarking.
The two routes into the high-risk class now have different deadlines:
Everything else keeps its original date. The prohibitions and the AI literacy duty have applied since February 2025, the rules for general purpose AI models since August 2025, and the Act became generally applicable, including the transparency obligations, in August 2026. The AI Office and national authorities took up their enforcement powers on 2 August 2026 as well.
The Omnibus narrowed the high-risk class on one route only: Annex I. Classification under Annex III did not change.
A system is high-risk under this route only if two conditions are both met: it is itself a product covered by the Annex I legislation, or a safety component of one, and that product has to undergo third-party conformity assessment.
The Omnibus tightened the first condition twice. A component now only counts as a safety component if its intended purpose is to prevent or mitigate risks to health and safety. And systems used solely for non-safety purposes, such as user assistance, performance optimization, service efficiency, automation, convenience or quality control, expressly do not qualify as safety components.
One important limit: if failure or malfunction of the system would endanger health and safety, it still counts. The carve-out is for genuinely non-safety functions.
Critical infrastructure under Annex III point 2 is the exception on the other side. That point is itself defined by reference to safety components, so the narrowed definition reaches it too.
Annex III classification did not change, but there is an exclusion in the original 2024 text that is worth knowing. Under Article 6(3), a system in an Annex III area is not high-risk if it poses no significant risk of harm to health, safety or fundamental rights, including by not materially influencing the outcome of decisions, and it only performs a narrow procedural task, improves the result of a previously completed human activity, detects decision-making patterns without replacing or influencing the prior human assessment, or performs a preparatory task. If the system profiles natural persons, it is always high-risk.
Two practical points if you rely on either exclusion: document the assessment before you place the system on the market, and register the system anyway. The Omnibus simplified what has to go into the registration, but it kept the registration itself. Our overview of the risk classes walks through the full classification logic.
Article 4 used to require organizations to ensure a sufficient level of AI literacy. It now requires them to take measures that support the development of AI literacy, and it states expressly that you do not have to guarantee any particular level of AI literacy for any individual.
The duty to act is unchanged, and the reference point for adequate measures is about to get more concrete: the Commission now has to publish practical compliance examples on its information platform, and the AI Board has to issue recommendations. Documented, reviewable training records remain the most defensible position. We cover the practical side in our guide to building AI literacy under the AI Act.
The Omnibus was very focused on reducing compliance efforts for smaller companies under the EU AI Act. Four things to highlight:
The new SMC category is worth checking against your own headcount and turnover. It exists for companies that had outgrown the SME thresholds but were still being asked to carry enterprise-scale compliance overhead.
One more simplification worth knowing if you are a deployer: a fundamental rights impact assessment may now cross-reference or incorporate parts of a data protection impact assessment, instead of potentially duplicating the assessment.
Two aspects have now become relevant for December 2026.
Two new prohibitions apply from 2 December 2026: AI systems that generate or manipulate non-consensual intimate imagery, and AI systems that generate or manipulate child sexual abuse material. These are additions to the list of practices already prohibited since February 2025, which the Commission summarizes on its AI Act page.
A marking deadline also falls on 2 December 2026. If you placed an AI system on the market before 2 August 2026 that generates synthetic audio, image, video or text, you have until then to comply with the machine-readable marking requirement in Article 50(2). This is not limited by risk class, so a minimal-risk product with a generative feature shipped in 2025 is in scope, though it does not catch systems that only perform an assistive editing function or do not substantially alter the input. If you have a generative feature that predates last summer, this is your nearest hard deadline under the AI Act.
Quite a lot of the EU AI Act has not been subject to changes:
The postponement is preparation time, not a pause. Traceable development, documentation processes, and a risk management process that survives a real project all take longer to embed than the calendar suggests. The organizations that treated the original 2026 deadline as a forcing function are the ones that now have a governance function they can point an auditor at.
Three things are worth doing now, whatever your risk class:
Knowing that a system has moved out of scope is worth as much as knowing what stayed in, but only if you can show how you reached that conclusion. That is what we built trail for: keeping your AI inventory, classifications and evidence current as a by-product of how your teams already work, rather than as a project you restart every time a deadline moves. See how trail supports EU AI Act compliance, or get in touch to learn more about our AI governance solutions.
No. It postpones the high-risk requirements in Chapter III to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems. The prohibitions, the AI literacy duty, the rules for general purpose AI models and the transparency obligations all keep their original dates, and enforcement began on 2 August 2026.
In short: February 2025 for the prohibitions and AI literacy. August 2025 for general purpose AI models. August 2026 for general application, including transparency. December 2026 for two new prohibitions and the marking of generative systems already on the market. December 2027 and August 2028 for the two high-risk categories.
Yes. The obligation was reworded, not removed. What changed is that you no longer have to guarantee a specific level of literacy for any individual, but you still have to take measures.
It is worth re-checking. The narrowed definition of a safety component and the new exclusion for non-safety optimization uses may have moved borderline systems out of the class, on the Annex I route. The Annex III areas themselves are unchanged, and the Article 6(3) exclusion that applies to them was already in the 2024 text.
Not structurally. The risk classes, the high-risk requirements and the penalty tiers are intact, and two prohibitions were added. What the Omnibus changed is timing and proportionality: later deadlines, a tighter definition of what counts as high-risk, and less documentation overhead for smaller companies. For a summary of the Act as it now stands, see our EU AI Act overview.