Back to the blog

The AI Act is changing: what the Digital Omnibus brings and the delay to obligations

Pavel Čech 2. 7. 2026

u1437327296_digital_timeline_of_artiffical_inteligence_blank_sp_b8a55c7b-3d1e-42f9-a705-35d3e33ffc21

Do you use artificial intelligence in your company, or even develop your own AI product? Then you probably marked 2 August 2026 in your calendar – the day a large part of the obligations under the AI Act (Regulation (EU) 2024/1689) was due to apply in full. Write it in pencil, not pen. On 29 June 2026 the Council of the EU gave final approval to the so-called Digital Omnibus, which postpones key obligations, softens some rules and at the same time adds new prohibitions.

What exactly is being postponed, until when, what is being simplified and what newly poses a risk? We summarise everything essential for companies that both use and develop AI

Přejít na nejčastější dotazy

What happened: the Council approved the Digital Omnibus to the AI Act

The Digital Omnibus (officially the “digital package on simplification concerning artificial intelligence”, part of the Omnibus VII simplification programme) is an amendment that changes the AI Act itself. The European Parliament approved it on 16 June 2026, and the Council of the EU gave the final green light on 29 June 2026. The Regulation will enter into force on the third day after its publication in the Official Journal of the EU.

The reason is pragmatic: the standards, implementing guidance and national supervisory authorities are not ready, and launching obligations for high-risk systems without this infrastructure would burden companies needlessly. The EU therefore reached for three things at once - a delay, simplification and several targeted tightenings.

Translated into plain business terms: you get more time for the hardest part, administration drops for many systems, but for sensitive content (deepfake nudity, child abuse material) things are getting stricter.

Delay for high-risk systems: the new dates

This is the core of the whole amendment. Obligations for high-risk AI systems (Chapter III of the AI Act - risk management, data quality, technical documentation, human oversight, conformity assessment) were due to apply from 2 August 2026. They are now split according to the type of high-risk system:

Date

What starts to apply

2 December 2027

High-risk systems under Article 6(2) and Annex III (stand-alone systems - e.g. AI in HR and recruitment, scoring, education, biometrics)

2 August 2028

High-risk systems under Article 6(1) and Annex I (AI as a safety component of regulated products - machinery, medical devices)

In practice this means a delay of roughly 16 months for stand-alone systems (Annex III, from 2 August 2026 to 2 December 2027) and one year for AI in regulated products (Annex I, from the original 2 August 2027 to 2 August 2028). If you are building or deploying something that could fall into the “high-risk” category, you have significantly more room to prepare. But that does not mean a pause - it means time to do the preparation properly.

Labelling AI content: what applies from August 2026

If you have read our article on labelling AI content [internal link: article on labelling AI content], here is an important update. The transparency obligations under Article 50 of the AI Act (visible labelling of deepfakes, chatbots and AI texts for the public, machine-readable marking of synthetic outputs) are not being postponed - they generally apply from 2 August 2026.

The Omnibus only adds a transition for existing systems:

  • Providers of AI systems placed on the market before 2 August 2026 must comply with machine-readable marking (Article 50(2)) by 2 December 2026.
  • Visible labelling of deepfakes and chatbots applies from August 2026 to everyone without exception.

In other words: anyone who runs a chatbot or generates synthetic content today must prepare for the August deadline for visible labelling. The postponement to December concerns only the technical, machine-readable marking of already existing systems - and compared with the original Omnibus proposal it was even shortened from six months to three.

Do you run a chatbot or generate AI content? We will go through with you exactly what you must label from August 2026 and how to do it without unnecessary extra work. Get in touch →

New prohibitions: deepfake nudity and child abuse material

The Omnibus expands the list of prohibited practices in Article 5 of the AI Act. From 2 December 2026 it is prohibited to place on the market, put into service or use AI systems that create or manipulate:

  • non-consensual intimate material - a realistic depiction of the intimate parts of an identifiable person without their freely given, specific and explicit consent (so-called “nudifier” apps, deepfake nudity),
  • child sexual abuse material (CSAM), including wholly or partially synthetic material.

Key for anyone developing a generative tool: the prohibition does not apply only to applications designed for this purpose. It also applies to systems where such output is reasonably foreseeable and reproducible and where reasonable technical safeguards are missing (prompt filtering, output checks, detection and remediation of misuse, cleaning of training data). If you are building a generative model or service, this is a new obligation to build safeguards into the product - otherwise you risk falling under the prohibition even without ill intent.

What is being softened

Alongside the delays, the Omnibus also brings a number of reliefs that will be welcomed mainly by smaller firms and technology companies:

  • AI literacy (Article 4). The hard obligation to ensure staff literacy is softened into an obligation to “take measures to support” literacy. It is not explicitly required to guarantee a specific level for individuals, and the obligation is decoupled from penalties.
  • New category of “small mid-caps”. They gain reliefs similar to small and medium-sized enterprises - simplified documentation, a simplified quality management system and a cap on fines.
  • Narrowing of the “safety component” definition (Article 6). Systems used solely for user assistance, performance optimisation, service efficiency, automation, convenience or quality control without any link to safety are not considered a safety component. Fewer systems will therefore fall into the high-risk category under Article 6(1).
  • Cybersecurity without duplication (Article 42). Compliance with the Cyber Resilience Act (Regulation (EU) 2024/2847, CRA) establishes a presumption of conformity with the cybersecurity requirements under Article 15 of the AI Act. You do not have to prove the same thing twice.
  • Simplified registration in the EU database and fewer implementing acts (the Code of Practice on labelling no longer has to be approved by an implementing act).

Not sure whether your system is “high-risk”? We will review a specific AI product or process through the lens of the AI Act and tell you which category it falls into and what follows from that. Get in touch →

The full timeline after the Omnibus

Date

What happens

2 Aug 2026

General applicability; Article 50 (transparency) applies; AI literacy in softened form

2 Dec 2026

New prohibitions (non-consensual intimate material, CSAM); end of the transition for machine-readable marking of older genAI systems

2 Aug 2027

Regulatory sandboxes operational; Commission guidance on overlap with sectoral legislation

2 Dec 2027

High-risk systems under Annex III (Article 6(2))

2 Aug 2028

High-risk systems under Annex I (Article 6(1)); rules for machinery

Penalties remain high

A delay to obligations does not mean a softer sanction. The fine rates are unchanged:

  • Breach of the prohibitions under Article 5 (including the new prohibitions on deepfake nudity and CSAM): up to EUR 35 million or 7% of total worldwide annual turnover, whichever is higher.
  • Breach of the transparency obligations under Article 50 (labelling AI content): up to EUR 15 million or 3% of turnover.

For small and medium-sized enterprises, and now also for small mid-caps, the lower of the two amounts applies. But alongside the fine there is also reputational risk - an unlabelled deepfake or a generative tool without safeguards damages trust faster than any sanction.

Who is affected and what to do now

The delay is an opportunity to prepare calmly, not a reason to do nothing. We recommend these five steps:

  1. Map where you use and develop AI. Which teams generate content, do you run a chatbot, are you building your own AI features?
  2. Determine your role - provider, deployer, or both? The scope of your obligations depends on this.
  3. Sort out transparency by August 2026. Chatbots, deepfakes and AI content for the public need visible labelling this year already.
  4. Build safeguards into generative products. The new prohibitions in Article 5 apply from December 2026 and also cover “reasonably foreseeable” misuse.
  5. Use the deferred time for high-risk preparation. System classification, risk management, documentation and conformity assessment are done better in advance than under the threat of sanctions.

 

Frequently asked questions

Answering the most common questions about the AI Act following the approval of the digital omnibus — what is being postponed, what applies right away, and what companies now risk.

1
Does the omnibus postpone the entire AI Act?
No. What is postponed are mainly the obligations for high-risk systems (to 2 December 2027 and 2 August 2028 respectively). The bans on unacceptable practices, the rules for general-purpose AI models and the transparency requirements under Article 50 all apply.
2
Does AI content labelling still apply from August 2026?
Yes. Visible labelling of deepfakes, chatbots and AI-generated texts for the public applies from 2 August 2026. The postponement to 2 December 2026 only concerns machine-readable marking for systems placed on the market before August 2026.
3
What are the new bans in Article 5 and when do they apply?
From 2 December 2026. It is prohibited to create or modify AI systems that generate intimate material without the consent of the person depicted, as well as child sexual abuse material. This also applies to general-purpose generative tools that lack sufficient technical safeguards.
4
How high are the fines?
Up to EUR 35 million or 7% of turnover for Article 5; up to EUR 15 million or 3% of turnover for Article 50. For smaller companies, the lower of the two amounts applies.
5
When will the omnibus take effect?
Soon. The Council approved it on 29 June 2026. The regulation enters into force on the third day after its publication in the Official Journal of the EU. The new dates of applicability apply as set out in the timeline above.

Do not face the delay alone

The Digital Omnibus gave companies time, but also new work: transparency from August 2026, safeguards in generative products from December, and calmer but more thorough preparation for high-risk obligations. Whoever puts their house in order now - which AI systems they run and in what role - will save costly rework later.

At SEDLAKOVA LEGAL we have long helped companies with AI compliance - from auditing AI use through risk classification and setting internal rules to contracts with AI tool suppliers and reviewing product functional specifications. Take a look at our services in IT and TMT law, personal data protection and cybersecurity.

Need advice on the AI Act? Get in touch →

Do you need help in this area?

Invalid phone number

Share this article on social media

Facebook ↗ Linkedin ↗