07/24/2026 | Press release | Archived content
EU Official Journal publishes Digital Omnibus on AI, amending AI Act
On July 24, the Official Journal of the European Union published Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 as regards the simplification of the implementation of harmonised rules on artificial intelligence (the "Digital Omnibus on AI" or the "Omnibus"). The Omnibus will enter into force three days after its publication, bringing the legislative process to a close. We have followed its progress on this blog since the European Commission (the "Commission") presented its proposal in November 2025 until the European Parliament and the Council formally adopted it.
Below, we summarize the main changes introduced to Regulation (EU) 2024/1689 (the "AI Act").
The most important change in practical terms is that relating to the implementation schedule for the obligations of chapter III, sections 1 to 3, of the AI Act, regulating high-risk AI systems.
New article 113 of the AI Act establishes the new application date of December 2, 2027, for high-risk AI systems classified under article 6.2 and annex III-those known as stand-alone systems, in fields such as biometrics, employment, education, migration or access to essential services-and August 2, 2028, for high-risk AI systems embedded in products regulated by the harmonised legislation on product safety (article 6.1 and annex I, section A). This is a significant postponement of the general application date of August 2, 2026, originally established in the AI Act.
Together with this general postponement, the Omnibus clarifies the scope of the grace period under article 111.2 of the AI Act: the decisive factor for benefiting from that period is that at least one unit of the type and model of the high-risk AI system has been lawfully placed on the market before the corresponding date of application, so that other units of the same type and model may continue to be placed on the market, without any additional obligations, as long as the design of that system remains unchanged. However, any significant change to the design after the date specified will trigger the obligation to fully comply with the provisions applicable to high-risk AI systems, including the conformity assessment requirement.
Legislative origin of the provision: this fixed date was not the date originally proposed by the Commission, whose proposal included a flexible mechanism that made application of these obligations subject to a prior decision by the Commission confirming the availability of harmonised standards and compliance tools, with maximum deadlines of six and 12 months after that decision. The Council and the European Parliament both rejected that conditional mechanism and opted instead for the fixed, certain dates ultimately included in the published text.
The Omnibus adds two new prohibited AI practices to article 5 of the AI Act:
The regulation specifies that, for providers, the prohibition is only triggered when that generation or manipulation is the intended purpose of the AI system, or when the system's design, training, architecture, or functionalities make that outcome reasonably foreseeable and reproducible, without reasonable and adequate technical safety measures to prevent it. For deployers, however, the prohibition only operates when they use the system for the specific purpose of generating or manipulating such material. Also, it clarifies that the alteration of existing material in a way that does not increase the exposure of any depicted intimate parts or alter the nature of any depicted sexually explicit activities does not constitute "manipulation".
Legislative origin of the provision: this is one of the most significant new developments of the Omnibus and was not part of the Commission's initial proposal of November 2025. It was the Council that first introduced it in its March 2026 negotiating mandate, focusing on "nudifier apps" and AI-generated child sexual abuse material, while the European Parliament simultaneously included an equivalent prohibition focused on non-consensual intimate content. The final text sets out the circumstances triggering the prohibition in greater detail than either position.
New article 4 of the AI Act maintains, although in a revised form, the obligation of providers and deployers of AI systems to adopt measures to support the AI literacy of staff and other persons operating AI systems on their behalf, considering their technical knowledge, experience, training, and the use context of the system. The article itself expressly clarifies that this obligation does not require a specific literacy level of anyone in particular. In addition, the Commission must publish practical examples of compliance on the single information platform, and the AI Council will adopt recommendations with common objectives to support the Commission and the Member States in this area.
Legislative origin of the provision: this outcome illustrates the course of the negotiations, as the Commission's original proposal completely eliminated the direct obligation on providers and deployers, replacing it with a mere mandate for the Commission and the Member States to encourage compliance. It was the European Parliament that, in its March 2026 position, rejected this suppression and proposed maintaining the obligation reformulated in terms of "support"; the final wording follows that formula almost word for word.
New article 4a of the AI Act introduces a legal basis allowing, on an exceptional basis, the processing of special categories of personal data to detect and correct biases. Providers of high-risk AI systems can do this when it is "strictly necessary" to detect and correct biases in line with article 10.2, paragraphs f) and g), and provided that the specific safeguards in the provision are met, including that the processing of other data (synthetic or anonymized) would not make it possible to achieve that objective, that the data is subject to technical limitations on the re-use of personal data, and state-of-the-art security measures, and is deleted once the bias has been corrected. This possibility is extended to the providers and deployers of AI systems and models other than high-risk ones, and to deployers of high-risk systems when the processing is strictly necessary to detect biases that could affect the health and safety of persons, have a negative impact on fundamental rights or lead to discrimination prohibited under EU law. The rule clarifies that it does not create any obligation to conduct such bias detection and correction.
Legislative origin of the provision: the standard of "strict necessity" was not used in the Commission's proposal, which merely referred to a "necessity." It was the Council and the European Parliament that both raised the threshold to "strict necessity," a criterion that has prevailed in the final text.
Providers of generative AI systems-including general-purpose AI systems that generate synthetic audio, image, video and text content-that have introduced their systems on the market before August 2, 2026, will have a transitional period until December 2, 2026, to meet the marking obligation in article 50(2) of the AI Act, which is the equivalent of four additional months after the general date of application.
Legislative origin of the provision: this timeline does not coincide exactly with any previous position. The Commission had proposed a six-month period (until February 2, 2027), the European Parliament reduced it to three months (until November 2, 2026), and the Council, in its March 2026 mandate, had maintained the six-month proposal by the Commission, until February 2, 2027. Therefore, the final outcome of four months constitutes a last-minute agreement made during trilogue negotiations, which does not reflect any of the three previous positions.
New article 75 of the AI Act confirms that the AI Office will have exclusive competence to supervise and enforce the act's obligations regarding AI systems based on general-purpose AI models, when the model and the system are developed by the same provider, extending this criteria to cases in which both are developed by providers that are part of the same company. This exclusive competence is also extended to systems that constitute or are embedded into very large
online platforms or very large online search engines designated in accordance with the Digital Services Act. Excluded from this exclusive competence are, among others, the systems related to products covered by the harmonisation legislation listed in annex I, the biometric systems referred to in point 2 of annex III, and the systems used by law enforcement authorities, border management authorities and financial institutions subject to sectoral rules.
The AI Act also develops a detailed regime of the AI Office's powers through article 75a to article 75d: the possibility to request information and carry out on-site inspections, the possibility to make binding those commitments offered by the operator investigated, and the power to adopt decisions establishing non-compliance, and impose fines and periodic penalty payments, with the corresponding procedural safeguards and access to the file.
Legislative origin of the provision: the extension of the exclusive competence to "companies of the same group" goes beyond the Commission's proposal, which limited the criteria to the "same provider," and coincides with the formula that the Council had already introduced in its March 2026 mandate.
The Omnibus moves Regulation (EU) 2023/1230 on Machinery (the "Machinery Regulation") from section A to section B of annex I of the AI Act. Consequently, only article 6.1, new article 60a, and articles 102 through to 112 of the AI Act will apply directly to high-risk AI systems embedded in machines. The substantive requirements of chapter III, section 2, of the AI Act, however, will be incorporated into the Machinery Regulation through delegated acts that the Commission must adopt on August 2, 2028, at the latest. Until those delegated acts or the corresponding harmonised standards are adopted, manufacturers will be able to continue referring to the harmonised standards or common specifications adopted under the AI Act, to prove the presumption of conformity.
Legislative origin of the provision: this sectoral approach had already been announced by the Council in its March 2026 mandate and, more broadly, by the European Parliament, which had proposed moving all the references to a harmonised product legislation from section A to section B of annex I. However, the final text has opted for limiting this solution specifically to the machinery sector.
The AI Act incorporates in article 3 respective definitions of "SME" (point 14a, by reference to Commission Recommendation 2003/361/EC) and of "small mid-cap enterprise" ("SMC") (point 14b, by reference to Commission Recommendation (EU) 2025/1099). On this basis, several regulatory privileges up until now reserved for SMEs have been extended to SMCs: the possibility to submit the technical documents in a simplified way, the proportionality in the implementation of the management system, and a rule of proportionality of fines under which, in the case of SMCs, the fines will not exceed the lower of the applicable percentages or amounts.
Legislative origin of the provision: this extension already appeared in the Commission's initial proposal and has remained substantially unchanged throughout the entire negotiation.
The Omnibus postpones the deadline until August 2, 2027, for the Member States to establish at least one national regulatory sandbox, and it confirms the possibility for the AI Office to establish an AI regulatory sandbox at Union level for AI systems subject to its exclusive competence, with priority access for SMEs and SMCs. Likewise, new article 60a allows the Member States to enable real-world testing, outside AI regulatory sandboxes, of high-risk AI systems covered by the harmonised product legislation in section B of annex I, through national frameworks that Member States must notify to the Commission.
Legislative origin of the provision: a Union-level regulatory sandbox was already considered in the Commission's proposal and has been maintained by the Council and the Parliament. However, the deadline of August 2, 2027, for national sandboxes does not coincide with the position of the Council, whose mandate of March 2026 had proposed a considerably later date: December 2, 2027.
The Digital Omnibus on AI introduces significant amendments to the AI Act concerning relevant matters, such as its implementation schedule, the prohibited AI practices, the legal basis for processing personal data, the governance of the AI Office, and the interaction with the sectoral product legislation.