Digital Omnibus and the AI Act: What Actually Applies From August 2, 2026
The short answer
Anyone classified as a provider or deployer of high-risk AI under Annex I or Annex III of the AI Act has been given more time. Anyone operating an AI system that interacts with people or generates content has not. August 2, 2026 remains a real deadline — just not for the high-risk obligations that most compliance projects have been built around.
The Digital Omnibus is law, not a proposal
Amending Regulation (EU) 2026/1744 was published in the EU Official Journal on July 24, 2026, and entered into force on July 27, 2026 — three days after publication, as is standard for EU regulations. It formally amends the AI Act (Regulation (EU) 2024/1689), the Aviation Framework Regulation, and the Machinery Regulation. Anyone still citing sources from May or June 2026 describing a "provisional agreement" is working from an outdated position: following the European Parliament's final vote on June 16, 2026, and the Council's formal adoption on June 29, 2026, the matter is settled.
What is actually postponed
The Omnibus shifts two blocks of high-risk deadlines:
- Standalone high-risk systems under Annex III — covering areas such as recruiting, creditworthiness assessment, education, and biometric identification — now have until December 2, 2027 to meet the full obligations, instead of the originally planned August 2, 2026.
- High-risk AI embedded in products under Annex I — machinery, medical devices, vehicles — now has until August 2, 2028, instead of the previous August 2, 2027.
For organizations whose AI applications fall into these categories, this creates genuine breathing room for conformity assessment, technical documentation, and risk management systems. That matters, but it changes nothing about the underlying question of whether an application qualifies as high-risk AI in the first place — that assessment still needs to happen; only the implementation deadline has moved.
What still becomes binding on August 2, 2026
The Omnibus does not touch the deadlines that were already fixed before it entered into force. Specifically, as of August 2, 2026:
- Transparency obligations under Art. 50: Chatbots and AI systems that interact directly with people must disclose that they are AI, unless this is already obvious from context. AI-generated content and deepfakes must be labeled.
- Watermarking obligation (Art. 50(2)): Newly placed-on-market systems are subject to the same August 2, 2026 deadline. Legacy systems get an extended deadline until December 2, 2026.
- General applicability of the AI Act: From this date, national market surveillance under Art. 70 kicks in — independent of the Omnibus. This makes the AI Act practically relevant to every company using AI, not just high-risk providers.
Also already in force and unaffected: the prohibited practices under Art. 5 and the AI literacy obligation under Art. 4 (since February 2, 2025), as well as GPAI governance rules under Art. 51 et seq. and the penalty framework under Art. 99 (since August 2, 2025). Enforcement of these begins in August 2026.
New via the Omnibus: an additional prohibition
The Digital Omnibus doesn't just push back deadlines — it also expands the list of prohibited practices under Art. 5: AI systems designed to generate non-consensual intimate imagery — so-called nudification tools — as well as systems generating child sexual abuse material, are now explicitly prohibited. The ban covers both providers and deployers, with compliance required by December 2, 2026.
The AI Office also gains its own investigative, inspection, and fining powers, effectively becoming an independent market surveillance authority. And existing SME relief measures are extended to a new category: Small Mid-Cap Enterprises — companies with fewer than 750 employees and up to €150 million in annual turnover or €129 million in balance sheet total — will benefit from the same special rules as SMEs.
What to do now
The postponement of high-risk deadlines is not a reason to pause compliance work. Two assessments remain urgent regardless of the new timeline:
- Whether existing AI systems fall under Art. 50 — i.e., interact with people or generate content requiring labeling. This obligation applies from August 2, 2026 with no transition period for new systems.
- Whether a classification as provider or deployer of high-risk AI under Annex I or III actually applies. The new deadlines (2027/2028) are not a free pass — they only move back the point of full compliance. The classification itself should already be settled so the extra time can actually be put to use.
The penalty framework under Art. 99 remains untouched throughout: up to €35 million or 7% of global annual turnover for violations of the prohibited practices under Art. 5 — regardless of whether a company qualifies as a high-risk provider.
Researched and drafted with AI assistance, reviewed and approved before publication by Martin Reichle. More
Start a conversation →