The AI Act Just Moved: What the EU's Digital Omnibus Changes — and When
The EU has pushed back the AI Act's toughest deadlines, narrowed what counts as high-risk and added new prohibitions. It is the most consequential change to Europe's flagship AI law since it took effect.
Last updated
For two years, 2 August 2026 was the date every AI compliance roadmap was built around. It just moved. With the Digital Omnibus on AI, the EU has pushed back the AI Act's toughest deadlines, narrowed what counts as "high-risk" and added new prohibitions. It is the most consequential change to Europe's flagship AI law since it took effect.
Work the law: AI Act on Lawbster — the full consolidated text in Lawbster, your interconnected EU digital laws library (EN·DE·FR, free).
TL;DR
The AI Act's high-risk obligations are deferred: Annex III use-case systems now apply from 2 December 2027 and Annex I product-embedded systems from 2 August 2028, instead of 2 August 2026.
Two new prohibitions, covering AI-generated child sexual abuse material (CSAM) and non-consensual intimate imagery, take effect on 2 December 2026 (Art 5).
Transparency keeps its 2 August 2026 start, with one carve-out: systems already on the market on that date get until 2 December 2026 to meet the Article 50(2) watermarking duty (Art 50).
"Safety component" is clarified (Art 6), national AI sandboxes get until 2 August 2027, and the Commission loses the power to move the high-risk dates again.
Proposed on 19 November 2025; the European Parliament endorsed the package on 16 June 2026 and the Council gave final approval on 29 June 2026. It entered into force on 27 July 2026, on the third day after its publication in the EU Official Journal.
Key dates at a glance
| Change | New date | Previously |
|---|---|---|
| High-risk AI — Annex III (use cases: hiring, credit, biometrics) | 2 December 2027 | 2 August 2026 |
| High-risk AI — Annex I (embedded in regulated products) | 2 August 2028 | 2 August 2026 |
| New prohibitions: AI-generated CSAM & intimate-image abuse | 2 December 2026 | new |
| Art 50(2) watermarking, systems on the market before 2 Aug 2026 | 2 December 2026 | 2 August 2026 |
| National AI regulatory sandboxes operational | 2 August 2027 | 2 August 2026 |
What is the "Digital Omnibus on AI"?
The European Commission proposed the Digital Omnibus on 19 November 2025 as a simplification package for the EU's digital rulebook. It comes in two parts: one regulation making targeted changes to data and cyber laws (the GDPR, ePrivacy rules, the Data Act and incident-reporting duties), and a separate regulation amending the AI Act, the "Digital Omnibus on AI". After trilogue negotiations and a provisional agreement on 7 May 2026, the European Parliament endorsed the AI package on 16 June 2026 and the Council gave its final approval on 29 June 2026. It entered into force on 27 July 2026, on the third day after its publication in the Official Journal.
The headline change: high-risk deadlines deferred
The AI Act's high-risk regime was due to bite on 2 August 2026. It now follows a two-tier timeline:
Annex III systems, high-risk by use case, such as recruitment, credit scoring or biometric identification (Annex III): 2 December 2027.
Annex I systems, high-risk because they are embedded in already-regulated products, such as medical devices, machinery or lifts (Annex I): 2 August 2028.
The deferral is a concession to reality: the harmonised standards and support tools needed to comply on time were not ready. Crucially, the final text removes the Commission's power to move these dates again. This is meant to be the last extension.
What else changed
A narrower "high-risk" net. An AI system that merely assists a user or optimises performance is no longer automatically high-risk if its failure does not create a health or safety risk. The clarified definition of "safety component" takes many borderline tools out of scope (Art 6).
New outright prohibitions. From 2 December 2026, using AI to generate or manipulate child sexual abuse material and non-consensual intimate imagery is banned (Art 5).
Transparency: one carve-out. The 2 August 2026 start date for transparency duties stands. But generative systems already on the market on that date now have until 2 December 2026 to meet the Article 50(2) machine-readable watermarking duty (Art 50); systems placed on the market later must comply from the start.
More time for sandboxes. Member States now have until 2 August 2027 to run at least one national AI regulatory sandbox.
Targeted simplification. Lighter registration and documentation duties, with particular relief for SMEs.
The data side you shouldn't miss
The wider Digital Omnibus also reaches into the GDPR and adjacent laws. Among the most-discussed proposals: a more relative definition of personal data (information is only personal to those who can realistically identify the person), an explicit legitimate-interest basis for training and operating AI on personal data, and a new Article 4a permitting limited processing of sensitive data to detect and correct bias. These sit alongside the AI Act dates and matter just as much for anyone building AI in Europe.
What it means in practice
More runway, not a reprieve. The obligations have not gone away; they have been resequenced and, in places, sharpened. Prohibited-use rules, general-purpose AI obligations and, with the carve-out above, transparency duties keep their existing timelines, and the new prohibitions arrive in December 2026.
Since the May agreement, the question clients have asked me most often is whether AI governance work can now pause. My answer is no. The scope clarifications change what falls into the net, the new prohibitions arrive first, and December 2027 is a firm deadline: keep building now.
Reading the actual law, without the 1998 experience
Here is the practical catch: every deferral, carve-out and new prohibition lands as an amendment to the existing AI Act, in force since 27 July 2026. To know what truly applies, you have to read the consolidated text, the Act as amended, rather than a press release that freezes in time. On EUR-Lex that means stitching together the original regulation, the Omnibus amendment and a web of cross-references, mostly as PDFs.
That is exactly what Lawbster is built for. Read the Lawbster manifesto on why working with EU law still feels like 1998, and open the AI Act on Lawbster to read it with linked cross-references, recitals mapped to their articles and one-click language switching. The full consolidated AI Act with all Omnibus changes is live on Lawbster.
Related reading
New to the AI Act's phased deadlines? See the full EU AI Act Compliance Timeline, every key date from 2024 to 2030, kept current.
Frequently asked
- When do the EU AI Act high-risk rules now apply?
- 2 December 2027 for Annex III (use-case) high-risk systems and 2 August 2028 for Annex I (product-embedded) systems, instead of 2 August 2026.
- Is the AI Act delayed entirely?
- No. Only the high-risk obligations are deferred. Prohibited practices and general-purpose AI (GPAI) obligations keep their existing timelines. Transparency rules keep the 2 August 2026 date, though legacy systems get until 2 December 2026 for Article 50(2) watermarking, and the new prohibitions take effect on 2 December 2026.
- What is the Digital Omnibus on AI?
- An EU regulation amending the AI Act to simplify obligations and reset key deadlines. Proposed on 19 November 2025, given final approval by the Council on 29 June 2026 and in force since 27 July 2026.
- Can the Commission move the deadlines again?
- No. The final text removes the Commission's power to further amend the high-risk application dates.
- Where can I read the amended AI Act?
- The amending regulation is published in the Official Journal; the consolidated AI Act will appear on EUR-Lex once the EU publishes it. Lawbster will carry the consolidated version, fully cross-linked, as soon as it is published.