The European Union formally adopted Regulation (EU) 2026/1744 on July 27, 2026, which is commonly known as the Digital Omnibus on AI, or the AI Omnibus Regulation. With it, those seeking to comply with AI regulation in the E.U. have some additional things to consider. But rather than replacing the E.U. AI Act entirely, this regulation introduces targeted amendments that are designed to simplify compliance, reduce regulatory overlap, and give businesses additional time to implement the necessary changes.
Below are the eight most important changes that companies—and the professionals those companies rely upon—should understand.
Trying to figure out what this means for your specific systems? Our E.U. AI Act Compliance Toolkit includes a Compliance Checker built for exactly this, it screens your use cases against the regulatory obligations in minutes.
The 8 Biggest Changes to the E.U. AI Act
1. High-Risk AI Deadlines Have Been Extended
The most significant change introduced by the regulation is the postponement of certain obligations that apply to high-risk AI systems. High-risk systems listed under Annex III, which include hiring, credit scoring, education, and biometric use cases, among other things, now have until December 2, 2027 to achieve compliance. High-risk AI systems that are embedded in regulated products, such as medical devices, now have until August 2, 2028 to comply. The E.U. introduced these extensions because key standards, guidance documents, and national enforcement structures were not ready in time for the original deadlines.
2. New AI Prohibitions Have Been Added
Starting in December 2026, it will be illegal to build or sell AI tools that generate fake intimate images of real people without their consent (the so-called "nudify" apps), or AI that generates child sexual abuse material, even if it's entirely computer-generated. (This ban includes a narrow exception for lawful conduct under national law, such as legitimate law enforcement investigations or authorized red-teaming to test whether a system complies with this very prohibition.) Companies that make image- or video-generating AI will also need to add reasonable safeguards to prevent their tools from being misused in this way, even if that wasn't the intended purpose.
Separately, the update also gives a short grace period on an obligation that already existed. The AI Act's labeling requirement for generative AI systems (marking AI-generated content as such) was already scheduled to apply from August 2, 2026. Under the new regulation, providers who had already placed their system on the market before that date now have until December 2, 2026 to bring their labeling into compliance. It's a four-month extension for a specific group of existing providers, not a brand-new rule.
3. A New "Small Mid-Cap" Business Category Has Been Created
The regulation introduces a new category of business known as the small mid-cap company. These companies are larger than traditional small and medium-sized enterprises, but they do not have the resources that large enterprises typically have. As a result, they will benefit from simplified documentation requirements, more proportionate compliance obligations, and a reduced administrative burden overall. This change allows growing companies to scale gradually, rather than suddenly facing the full compliance obligations that are expected of large corporations.
4. AI Literacy Requirements Are Now More Flexible
The original AI Act required organizations to ensure that employees working with AI systems had a sufficient level of AI literacy. The updated regulation takes a more practical approach to this requirement. Companies must still promote AI literacy, provide appropriate support and training, and take reasonable measures to help their staff understand the AI systems they work with. However, they are no longer expected to guarantee a specific level of AI literacy for every individual employee.
5. Companies Can Use Sensitive Data to Detect AI Bias Under Strict Conditions
The update expands the legal basis that allows companies to process sensitive personal data when doing so is strictly necessary to identify and correct bias in AI systems. This provision is particularly relevant for recruitment systems, credit scoring systems, education tools, and public sector decision-making systems. The overall goal of this change is to improve fairness in AI outcomes, while still maintaining strong data protection safeguards for individuals.
6. The Definition of a "Safety Component" Has Been Clarified
One of the most important technical changes in this new regulation concerns the definition of a safety component. Previously, many businesses feared that almost any AI system embedded in a regulated product could be classified as high-risk. Under the new rule, the definition is much clearer. An AI system will generally be considered a safety component only when its intended purpose is to prevent or reduce health and safety risks, or when its failure could endanger people or property. AI that is used merely for convenience, efficiency, automation, or general improvements to user experience will generally not qualify as a safety component.
7. The EU Is Reducing Regulatory Duplication
The Omnibus Regulation is heavily focused on reducing unnecessary compliance work for businesses. The key simplifications include greater alignment between the AI Act and existing sector-specific legislation, unified conformity assessment procedures, single application processes for certain notified bodies, and reduced duplication between AI Act obligations and other existing regulatory requirements. For manufacturers that are already subject to medical device, machinery, or other E.U. regulations, this change could significantly reduce their overall compliance costs.
8. The E.U. AI Office Receives Stronger Enforcement Powers
The reform also strengthens the powers of the E.U. AI Office. The AI Office can now conduct inspections, request information directly from providers, negotiate and enforce binding commitments, order corrective measures, and impose penalties within its jurisdiction. These changes are particularly relevant for general-purpose AI systems and for AI that is integrated into very large online platforms and search engines.
Key Dates
Change |
Previous Date |
Updated Date |
|---|---|---|
|
Ban on non-consensual intimate imagery and AI-generated child sexual abuse material |
Not included in the original AI Act |
December 2, 2026 |
|
Labeling requirements for generative AI systems already on the market before August 2026 |
August 2, 2026 |
December 2, 2026 (transitional compliance period) |
|
High-risk AI systems under Annex III (e.g., hiring, credit scoring, education) |
August 2, 2026 |
December 2, 2027 |
|
High-risk AI systems embedded in regulated products (Annex I) |
August 2, 2027 |
August 2, 2028 |
Key Considerations
The 2026 AI Omnibus Regulation does not fundamentally change the E.U. AI Act. The E.U. AI Act remains a risk-based regulatory framework with extra-territorial reach. Instead, this update gives companies more time to comply, introduces targeted simplifications, clarifies previously ambiguous concepts, strengthens enforcement in key areas, and reduces regulatory overlap with existing E.U. legislation.
The destination has not changed, and the compliance requirements are still coming. What has changed is that the path toward compliance is now clearer, more practical, and easier for businesses to navigate.
The compliance destination hasn't changed, only the runway did. If you want a head start, our E.U. AI Act Compliance Toolkit bundles the checklists, registers, and assessments you'll need to get there.