The AI Omnibus: what has changed
Under the EU AI Act as originally adopted August 2026 was to mark the start of the core high-risk compliance regime for stand‑alone high‑risk AI systems, with 2 August 2027 for high-risk AI system embedded in regulated products. These milestones would also have triggered wide‑ranging transparency obligations and large‑scale enforcement.
However, in November 2025 the European Commission published its AI Omnibus,[3] proposing targeted amendments to simplify implementation and address delays in guidance, standards and national enforcement readiness.
In June 2026, the European Parliament and the Council formally adopted amendments to the EU AI Act based on the Digital Omnibus package, introducing a number of amendments including, but not limited to, a new prohibition on AI-generated non-consensual intimate imagery, safety-component clarifications and a stricter transitional period for watermarking obligations. The key changes are set out below.
Postponement of the High-Risk Obligations
The AI Omnibus replaces the original application dates with 2 December 2027 for standalone high-risk AI systems specified in Annex III (covering, among others, biometrics, employment, education, law enforcement, critical infrastructure and border management) and 2 August 2028 for AI systems embedded in products covered by EU sectoral safety legislation (Annex I).
On 19 May 2026, the EU Commission published draft guidelines[4] on the classification of high-risk AI systems. The draft was open for consultation until 23 June 2026, with no confirmed timeline for finalisation yet. Although not legally binding, it signals how the Commission and national authorities are likely to assess cases, making it a practical basis for organisations to plan against.
A new prohibition: AI systems generating harmful content
The AI Omnibus introduces a new prohibited practice under Article 5, banning AI systems capable of generating child sexual abuse material or non-consensual intimate imagery, including images, video or audio, which depict an identifiable person. This new prohibition arose out of the growing concern surrounding the increase of deepfakes and deepfake technology globally.
The prohibition applies where (1) a system is placed on the EU market with the specific purpose of generating that content; (2) it is placed on the market without reasonable technical safeguards to prevent such use; and (3) where a deployer actively uses it for that purpose. The new compliance deadline for this is 2 December 2026.
Law firms should ensure that any AI tools they use cannot be misused in ways that would fall within this category.
Watermarking: a tighter transitional deadline
Importantly, the Article 50(2) watermarking obligation under Article 50(2) which requires generative AI providers to mark synthetic content (audio, images, video or text) in a machine-readable way, will still apply from 2 August 2026. The AI Omnibus allows for a transitional window for systems already on the market before that date to be brought into compliance by 2 December 2026.
On 20 July 2026, the EU Commission published guidelines[5] on transparency obligations for certain AI systems to assist providers and deployers in meeting the EU AI Act’s transparency obligations.
Overlapping compliance obligations between EU AI Act and sectoral legislation
A recurring concern in the negotiation of the amendments was overlapping compliance obligations across various pieces of EU legislation.
To tackle these concerns, machinery has now been taken out of direct EU AI Act scope: instead, the Commission will introduce health and safety requirements for high-risk AI through delegated acts under the Machinery Regulation. For other sectoral safety regimes already containing AI-specific requirements equivalent to those in the EU AI Act, the Commission can limit how the EU AI Act applies through implementing acts.
Other elements of the deal
The AI Omnibus also introduced a number of significant other changes:
- The definition of "safety component" is narrowed so that AI that merely assists users or improves efficiency will not automatically attract high-risk status if any AI failure would not create a health or safety risk.
- Although providers and deployers of AI system must take measures to support the development of AI literacy of their staff, they are no longer obligated to guarantee any specific level of AI literacy of any individual. The Commission and EU Member States must support and facilitate providers and deployers in their AI literacy efforts.
- The legal basis for processing special category personal data for bias detection and correction is extended to providers and deployers of non-high-risk AI systems and models, subject to a strict necessity test.
- The AI Office’s supervisory and enforcement competence is expanded to include AI systems built by the same provider as the underlying GPAI model, with limited carve-outs, and AI systems integrated into very large online platforms or very large online search engines as designated under the Digital Services Act.
- SME exemptions are extended to small mid-cap enterprises, supporting smaller companies that fall just outside traditional SME thresholds.
- The deadline for national competent authorities to establish AI regulatory sandboxes is pushed back to 2 August 2027.