The Digital Omnibus on AI, Regulation (EU) 2026/1744, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026, days before several EU AI Act obligations were due to apply. It amends Regulation (EU) 2024/1689 and completes the process that began with the Commission's November 2025 proposal and the political agreement reached in May.
The headline change is timing. Obligations for stand-alone high-risk AI systems listed in Annex III - covering uses such as employment, education, credit and access to essential services - now apply from 2 December 2027 instead of 2 August 2026. High-risk systems embedded in products covered by EU product legislation under Annex I, such as machinery and medical devices, move to 2 August 2028. Article 50 transparency obligations were not deferred and applied from 2 August 2026, with a four-month transition to 2 December 2026 for the machine-readable marking duty in Article 50(2), but only for generative systems already on the market before 2 August 2026.
The Omnibus also changes the substance of the Act. It adds two new prohibited practices to Article 5, covering AI systems that generate or manipulate realistic intimate imagery of an identifiable person and AI systems that generate child sexual abuse material. The AI literacy duty is relaxed: providers and deployers must take measures supporting AI literacy rather than ensure a sufficient level for every individual, with the Commission and Member States taking a stronger role. Registration requirements for systems self-assessed as not high-risk under Article 6(3) are simplified, the deadline for Member States to set up regulatory sandboxes moves to 2 August 2027, and the legal basis for processing special category data to detect bias now extends beyond high-risk systems, subject to strict necessity.
For most organisations the deferral is time to prepare, not a reprieve. The high-risk requirements themselves - risk management, data governance, technical documentation, human oversight and conformity assessment - are unchanged; only the start dates have moved.
Acompli perspective: The new dates give organisations a defined runway, and the practical first step does not change: know which AI systems you use, what role you play for each, and which risk category each falls into. An inventory built now against the Annex III and Annex I dates, and linked to the GDPR records for any system that processes personal data, is what makes the 2027 and 2028 deadlines manageable. Acompli's EU AI Act workflow keeps that classification human-approved, Code Scan can surface AI components already present in code, and our EU AI Act requirements guide sets out the updated timeline for Ireland and the UK.
