EU AI Act Digital Omnibus: What the Deferral Does Not Cover

by | Jul 31, 2026

The EU AI Act Digital Omnibus became law on 27 July 2026, and most coverage of it led with a single word: delayed. That framing is causing a serious and expensive misreading. Yes, the high-risk regime moved to December 2027. However, the obligation that touches the widest range of ordinary businesses did not move at all, and it applies from 2 August 2026.

So if your board heard “the AI Act got pushed back” and quietly stood down the compliance work, this post is the correction. Below is what the EU AI Act Digital Omnibus actually deferred, what it left exactly where it was, and what a mid-market team should do in the next few days.

What the EU AI Act Digital Omnibus is

Formally, it is Regulation (EU) 2026/1744. The European Commission proposed it in November 2025 as a simplification package, negotiators reached political agreement on 7 May 2026, and the European Parliament approved it on 16 June 2026 by 423 votes to 57, with 174 abstentions. The Council gave final approval on 29 June 2026.

After signature on 8 July, publication in the Official Journal followed on 24 July 2026, and the regulation entered into force three days later on 27 July. It amends the AI Act itself, plus the Machinery Regulation and the Basic Aviation Regulation.

Crucially, the EU AI Act Digital Omnibus is a simplification package rather than a repeal. Its risk-based architecture, prohibited practices, and general-purpose AI rules survive intact. Only the calendar changed, and only in parts.

What actually got deferred

Three deadlines moved under the EU AI Act Digital Omnibus, and the reasoning was practical rather than political. The harmonised standards providers need to demonstrate conformity were never going to be ready for August 2026, so obligations that depend on them slipped.

Stand-alone high-risk systems: 2 December 2027

Annex III covers the categories most people picture when they think about AI regulation: recruitment and worker management, education, credit scoring, insurance pricing, access to essential services, critical infrastructure, and law enforcement. Those obligations, including risk management, technical documentation, human oversight, and conformity assessment, now apply from 2 December 2027. That is a 16-month deferral.

Embedded high-risk systems: 2 August 2028

AI built into products already governed by EU product safety law, such as medical devices and toys, moved from August 2027 to August 2028. Machinery is a special case, covered below.

Regulatory sandboxes: 2 August 2027

Member states now have until August 2027 to establish national AI regulatory sandboxes. Governments needed the time as much as businesses did.

What did not get deferred, and why it matters more

Here is the part the headlines buried. Article 50, which sets out transparency obligations, is not a high-risk provision. Instead, it applies as a separate layer across any AI system used in the situations it covers, regardless of risk classification. Consequently the EU AI Act Digital Omnibus left it untouched, and it applies from 2 August 2026.

Think about who that captures. A company running a customer service chatbot is in scope. A marketing team publishing AI-generated images is in scope. A recruitment firm using AI to draft outreach is in scope. None of those organisations necessarily operate a high-risk system, so none of them benefit from the December 2027 runway.

U AI Act Digital Omnibus comparison of deferred obligations and those applying from August 2026

The penalties arrive on the same day

Enforcement is not deferred either. National market surveillance authorities gain the power to act on Article 50 breaches from 2 August 2026, and fines reach EUR 15 million or 3% of worldwide annual turnover, whichever is higher. The obligation and the enforcement power land together.

Also worth noting: general-purpose AI obligations and the Article 5 prohibited practices stayed on their original timelines too. Prohibited practices and the AI literacy duty have in fact applied since February 2025 already.

The four transparency duties in Article 50

Four transparency duties under Article 50 of the EU AI Act split between providers and deployers

The Commission adopted guidelines on Article 50 on 20 July 2026, so the scope is now reasonably well defined. Four situations trigger obligations. Two fall on providers, and two fall on deployers.

  1. Direct interaction (providers). People must be told they are interacting with an AI system, unless that fact is obvious to a reasonably observant person.
  2. Synthetic content marking (providers). AI-generated image, audio, video, and text output must carry machine-readable marking that identifies it as artificially generated.
  3. Emotion recognition and biometric categorisation (deployers). Exposed individuals must be informed that the system is operating.
  4. Deepfakes and public-interest text (deployers). Deepfake content requires disclosure, as does AI-generated text published to inform the public on matters of public interest.

The one narrow grace period

The EU AI Act Digital Omnibus granted exactly one concession here, and it is narrower than most summaries suggest. Generative AI systems placed on the market before 2 August 2026 have until 2 December 2026 to meet the machine-readable marking requirement under Article 50(2). Content generated before 2 August 2026 does not require retroactive labelling, according to the Commission’s own guidance.

Everything else in Article 50 applies from Sunday. So the chatbot disclosure, the deepfake labelling, and the emotion recognition notice all bite immediately.

Who is outside scope

Purely personal, non-professional use falls outside these rules. Furthermore, systems performing an assistive editing function that does not substantially alter the input, such as grammar correction, are carved out, as are certain law enforcement applications. One common misconception deserves correction though: open-source AI systems are not exempt from Article 50.

Six other changes worth knowing about

1. Two new prohibitions

Article 5 now prohibits AI systems used to generate child sexual abuse material or non-consensual intimate imagery, covering both placing on the market and use. Providers of in-scope systems have until 2 December 2026 to put technical safeguards in place, including output controls and content filtering.

2. The AI literacy duty softened

Article 4 previously required organisations to ensure staff had sufficient AI literacy. Now it asks them to take measures to support it. The wording is gentler, yet the practical advice is unchanged, because documented training remains the easiest evidence to produce during any inspection.

3. The AI Office gained significant powers

Supervision previously covered general-purpose AI models and systems built on them by the same provider. Now it extends to all AI systems based on GPAI models developed within the same undertaking, plus systems that constitute or sit inside very large online platforms and search engines under the Digital Services Act. Cooperation with national authorities also gained an explicit legal basis.

4. Registration was not narrowed

Many teams assumed this one went through. The Commission had proposed exempting providers who self-assess their system as falling outside the high-risk category, but that proposal did not survive negotiations. Therefore systems self-assessed as non-high-risk must still be registered in the EU database, albeit with a lighter administrative burden.

5. A targeted machinery carve-out

AI embedded in products governed by the Machinery Regulation now falls outside the direct scope of the high-risk rules, since applying both regimes created duplication. Medical devices and toys remain fully in scope. Separately, the Commission can still impose AI-specific health and safety requirements through delegated acts under the Machinery Regulation.

6. Wider legal basis for bias testing

Processing special categories of personal data for bias detection and correction was previously limited to providers of high-risk systems. That permission now extends to providers and deployers of all AI systems. However, a strict necessity standard applies, so this is not an open door.

What to do this week

If you serve EU customers and use AI anywhere in a customer-facing process, work through these four steps before Sunday. None of them require a lawyer to start.

  1. Inventory every customer-facing AI touchpoint. Chatbots, voice agents, AI-assisted email, generated images on your site, synthetic video, AI-written published content. List them.
  2. Check your chatbot discloses itself. A named bot with an obvious interface may already satisfy this. An assistant that reads as human does not.
  3. Decide your labelling standard for published synthetic media. Then write it down as policy, so the decision survives staff turnover.
  4. Ask your vendors, in writing, how they handle Article 50 marking. If you deploy someone else’s model, their compliance gap becomes your operational problem.

Realistically, nobody expects perfect compliance by Sunday. Regulators generally look at whether an organisation was making a good-faith effort, so a documented, dated plan is worth considerably more than silence.

How to use the extra 16 months

For teams genuinely operating Annex III systems, the runway the EU AI Act Digital Omnibus created sounds generous. It is not. Building risk management processes, technical documentation, and conformity assessment evidence takes most organisations a year of real work, and the underlying obligations did not soften at all.

Start with inventory, not policy

Most organisations cannot yet answer a simple question: which AI systems do we operate, and how would each be classified? Answer that first. Afterwards, classification tells you which obligations apply and which deadline governs each system.

Next, build the documentation habit while the stakes are low. Teams that start logging model decisions, data sources, and human oversight steps now will find the 2027 conformity work mostly clerical. Teams that start in 2027 will find it frantic. If you are still deciding whether a use case is worth pursuing at all, our 12-question AI readiness assessment covers the governance dimension in more detail.

If you are based outside the EU

Territorial reach catches more companies than expected. The Act applies to providers and deployers whose AI system output is used inside the EU, whatever the company’s home jurisdiction. So a US software firm with European customers, or an Indian agency producing synthetic media for European brands, can sit squarely in scope.

Frequently asked questions

What is the EU AI Act Digital Omnibus?

The EU AI Act Digital Omnibus is Regulation (EU) 2026/1744, the first set of amendments to the EU AI Act since its adoption in 2024. It entered into force on 27 July 2026 and defers several high-risk compliance deadlines, adds two new prohibitions, expands the AI Office’s supervisory powers, and softens the AI literacy duty. It does not change the Act’s risk-based architecture.

Did the Digital Omnibus delay the whole EU AI Act?

No. The EU AI Act Digital Omnibus deferred stand-alone Annex III high-risk obligations to 2 December 2027 and embedded Annex I obligations to 2 August 2028. Article 50 transparency obligations, general-purpose AI rules, and the Article 5 prohibited practices all remain on their original timelines. Article 50 applies from 2 August 2026.

What applies from 2 August 2026?

Article 50 transparency obligations apply in full from that date, covering chatbot disclosure, synthetic content marking, emotion recognition notices, and deepfake labelling. National market surveillance authorities can enforce from the same day, with fines up to EUR 15 million or 3% of worldwide annual turnover. One narrow exception exists for machine-readable marking on generative systems already on the market, which runs to 2 December 2026.

Does my chatbot need a disclosure notice?

Probably yes, if EU users interact with it. Article 50 requires that people be informed they are dealing with an AI system unless that is obvious from the context to a reasonably well-informed person. A clearly labelled bot widget may satisfy this. An assistant presented with a human name and no indication of automation almost certainly does not.

Are open-source AI systems exempt?

Not from Article 50. Providers and deployers of AI systems released under free and open-source licences must still meet the transparency obligations where their use falls within the four covered situations. Other parts of the AI Act do contain open-source exemptions, so the position varies by provision.

Does the EU AI Act apply to companies outside Europe?

It can. The Act reaches providers and deployers whose AI system outputs are used within the EU, regardless of where the organisation is established. As a result, many US and Asian firms serving European customers fall in scope without having any EU entity.

What are the penalties for getting this wrong?

Transparency and general-purpose AI breaches sit in a tier carrying fines up to EUR 15 million or 3% of total worldwide annual turnover, whichever is higher. Prohibited practices attract higher maximums. National market surveillance authorities handle enforcement for Article 50.

Find out where you stand before Sunday

Most teams we speak to discover they have three or four AI touchpoints in scope that nobody had catalogued, usually a support chatbot, a content workflow, and something a marketing team adopted without telling IT. Finding them takes an afternoon. Explaining them to a regulator later takes considerably longer.

Book a 30-minute AI transparency review and we will map your customer-facing AI touchpoints against Article 50, then tell you which ones need attention first. You can also read more about our AI and automation consulting and business consulting work.


This article summarises publicly available information about Regulation (EU) 2026/1744 and the EU AI Act as at 31 July 2026. The Expert Community is a technology and marketing consultancy, not a law firm, and nothing here constitutes legal advice. Classification under the AI Act depends on specific facts, so please consult qualified counsel before making compliance decisions.

Related Posts

Subscribe To Our Newsletter

Subscribe To Our Newsletter

Join our mailing list to receive the latest news and updates from our team.

You have Successfully Subscribed!