The AI Act is changing: what the Digital Omnibus brings and the delay to obligations
Pavel Čech 2. 7. 2026
Do you use artificial intelligence in your company, or even develop your own AI
product? Then you probably marked 2 August 2026 in your calendar – the day
a large part of the obligations under the AI Act (Regulation (EU) 2024/1689) was
due to apply in full. Write it in pencil, not pen. On 29 June 2026 the Council
of the EU gave final approval to the so-called Digital Omnibus, which postpones
key obligations, softens some rules and at the same time adds new prohibitions.
What exactly is being postponed, until when, what is being simplified and what newly poses a risk? We summarise everything essential for companies that both use and develop AI
What happened: the Council approved the Digital Omnibus to the AI Act
The Digital Omnibus (officially the “digital package on simplification concerning artificial intelligence”, part of the Omnibus VII simplification programme) is an amendment that changes the AI Act itself. The European Parliament approved it on 16 June 2026, and the Council of the EU gave the final green light on 29 June 2026. The Regulation will enter into force on the third day after its publication in the Official Journal of the EU.
The reason is pragmatic: the standards, implementing guidance and national supervisory authorities are not ready, and launching obligations for high-risk systems without this infrastructure would burden companies needlessly. The EU therefore reached for three things at once - a delay, simplification and several targeted tightenings.
Translated into plain business terms: you get more time for the hardest part, administration drops for many systems, but for sensitive content (deepfake nudity, child abuse material) things are getting stricter.
Delay for high-risk systems: the new dates
This is the core of the whole amendment. Obligations for high-risk AI systems (Chapter III of the AI Act - risk management, data quality, technical documentation, human oversight, conformity assessment) were due to apply from 2 August 2026. They are now split according to the type of high-risk system:
|
Date |
What starts to apply |
|
2 December 2027 |
High-risk systems under Article 6(2) and Annex III (stand-alone systems - e.g. AI in HR and recruitment, scoring, education, biometrics) |
|
2 August 2028 |
High-risk systems under Article 6(1) and Annex I (AI as a safety component of regulated products - machinery, medical devices) |
In practice this means a delay of roughly 16 months for stand-alone systems (Annex III, from 2 August 2026 to 2 December 2027) and one year for AI in regulated products (Annex I, from the original 2 August 2027 to 2 August 2028). If you are building or deploying something that could fall into the “high-risk” category, you have significantly more room to prepare. But that does not mean a pause - it means time to do the preparation properly.
Labelling AI content: what applies from August 2026
If you have read our article on labelling AI content [internal link: article on labelling AI content], here is an important update. The transparency obligations under Article 50 of the AI Act (visible labelling of deepfakes, chatbots and AI texts for the public, machine-readable marking of synthetic outputs) are not being postponed - they generally apply from 2 August 2026.
The Omnibus only adds a transition for existing systems:
- Providers of AI systems placed on the market before 2 August 2026 must comply with machine-readable marking (Article 50(2)) by 2 December 2026.
- Visible labelling of deepfakes and chatbots applies from August 2026 to everyone without exception.
In other words: anyone who runs a chatbot or generates synthetic content today must prepare for the August deadline for visible labelling. The postponement to December concerns only the technical, machine-readable marking of already existing systems - and compared with the original Omnibus proposal it was even shortened from six months to three.
Do you run a chatbot or generate AI content? We will go through with you exactly what you must label from August 2026 and how to do it without unnecessary extra work. Get in touch →
New prohibitions: deepfake nudity and child abuse material
The Omnibus expands the list of prohibited practices in Article 5 of the AI Act. From 2 December 2026 it is prohibited to place on the market, put into service or use AI systems that create or manipulate:
- non-consensual intimate material - a realistic depiction of the intimate parts of an identifiable person without their freely given, specific and explicit consent (so-called “nudifier” apps, deepfake nudity),
- child sexual abuse material (CSAM), including wholly or partially synthetic material.
Key for anyone developing a generative tool: the prohibition does not apply only to applications designed for this purpose. It also applies to systems where such output is reasonably foreseeable and reproducible and where reasonable technical safeguards are missing (prompt filtering, output checks, detection and remediation of misuse, cleaning of training data). If you are building a generative model or service, this is a new obligation to build safeguards into the product - otherwise you risk falling under the prohibition even without ill intent.
What is being softened
Alongside the delays, the Omnibus also brings a number of reliefs that will be welcomed mainly by smaller firms and technology companies:
- AI literacy (Article 4). The hard obligation to ensure staff literacy is softened into an obligation to “take measures to support” literacy. It is not explicitly required to guarantee a specific level for individuals, and the obligation is decoupled from penalties.
- New category of “small mid-caps”. They gain reliefs similar to small and medium-sized enterprises - simplified documentation, a simplified quality management system and a cap on fines.
- Narrowing of the “safety component” definition (Article 6). Systems used solely for user assistance, performance optimisation, service efficiency, automation, convenience or quality control without any link to safety are not considered a safety component. Fewer systems will therefore fall into the high-risk category under Article 6(1).
- Cybersecurity without duplication (Article 42). Compliance with the Cyber Resilience Act (Regulation (EU) 2024/2847, CRA) establishes a presumption of conformity with the cybersecurity requirements under Article 15 of the AI Act. You do not have to prove the same thing twice.
- Simplified registration in the EU database and fewer implementing acts (the Code of Practice on labelling no longer has to be approved by an implementing act).
Not sure whether your system is “high-risk”? We will review a specific AI product or process through the lens of the AI Act and tell you which category it falls into and what follows from that. Get in touch →
The full timeline after the Omnibus
|
Date |
What happens |
|
2 Aug 2026 |
General applicability; Article 50 (transparency) applies; AI literacy in softened form |
|
2 Dec 2026 |
New prohibitions (non-consensual intimate material, CSAM); end of the transition for machine-readable marking of older genAI systems |
|
2 Aug 2027 |
Regulatory sandboxes operational; Commission guidance on overlap with sectoral legislation |
|
2 Dec 2027 |
High-risk systems under Annex III (Article 6(2)) |
|
2 Aug 2028 |
High-risk systems under Annex I (Article 6(1)); rules for machinery |
Penalties remain high
A delay to obligations does not mean a softer sanction. The fine rates are unchanged:
- Breach of the prohibitions under Article 5 (including the new prohibitions on deepfake nudity and CSAM): up to EUR 35 million or 7% of total worldwide annual turnover, whichever is higher.
- Breach of the transparency obligations under Article 50 (labelling AI content): up to EUR 15 million or 3% of turnover.
For small and medium-sized enterprises, and now also for small mid-caps, the lower of the two amounts applies. But alongside the fine there is also reputational risk - an unlabelled deepfake or a generative tool without safeguards damages trust faster than any sanction.
Who is affected and what to do now
The delay is an opportunity to prepare calmly, not a reason to do nothing. We recommend these five steps:
- Map where you use and develop AI. Which teams generate content, do you run a chatbot, are you building your own AI features?
- Determine your role - provider, deployer, or both? The scope of your obligations depends on this.
- Sort out transparency by August 2026. Chatbots, deepfakes and AI content for the public need visible labelling this year already.
- Build safeguards into generative products. The new prohibitions in Article 5 apply from December 2026 and also cover “reasonably foreseeable” misuse.
- Use the deferred time for high-risk preparation. System classification, risk management, documentation and conformity assessment are done better in advance than under the threat of sanctions.
Do not face the delay alone
The Digital Omnibus gave companies time, but also new work: transparency from August 2026, safeguards in generative products from December, and calmer but more thorough preparation for high-risk obligations. Whoever puts their house in order now - which AI systems they run and in what role - will save costly rework later.
At SEDLAKOVA LEGAL we have long helped companies with AI compliance - from auditing AI use through risk classification and setting internal rules to contracts with AI tool suppliers and reviewing product functional specifications. Take a look at our services in IT and TMT law, personal data protection and cybersecurity.
Need advice on the AI Act? Get in touch →