ISHIGHRISK AI
The amendment

The Digital Omnibus, and what it changed

The Digital Omnibus split one deadline into four, added a ninth prohibition and kept database registration. What changed, what did not, what is pending.

Reviewed 22 July 2026Regulation (EU) 2024/1689, as amended by the Digital Omnibus
In short

The Digital Omnibus on AI was adopted by Parliament on 16 June 2026 (423 for, 57 against, 174 abstentions) and by Council on 29 June 2026, signed on 8 July 2026, and as at 22 July 2026 is still not in the Official Journal; it enters into force three days after publication. It made four changes: the high-risk application dates reset, with standalone Annex III systems moving from 2 August 2026 to 2 December 2027 and Annex I embedded-product systems set at 2 August 2028, while 2 August 2026 stayed in place for Article 50 and a new 2 December 2026 date was created; a ninth Article 5 prohibition on AI generating CSAM or non-consensual intimate imagery, due 2 December 2026; a Machinery Regulation carve-out for embedded AI; and EU database registration kept in simplified form after the Commission proposed dropping it. The eight existing prohibitions, the Article 99 penalty tiers, the Article 6(3) conditions and the Article 25 role flip are exactly where they were.

Where the AI Act Digital Omnibus stands, and how it got there

The Digital Omnibus on AI was signed on 8 July 2026 and, as at 22 July 2026, has still not appeared in the Official Journal. It enters into force on the third day after publication. That leaves the amendment in an awkward but perfectly workable state: politically final, legally pending. The consolidated instrument on EUR-Lex is still Regulation (EU) 2024/1689 in its original form, and the Regulation (EU) 2026 number everyone will eventually cite does not yet exist in authoritative shape.

The route it took matters, because the text changed materially along the way and a note written from the Commission proposal is now wrong in at least one important place.

19 Nov 2025Commission proposal COM(2025) 836, presented as an AI Act simplification package.
7 May 2026Trilogue agreement between Parliament, Council and Commission.
2 Jun 2026Joint IMCO-LIBE committee position endorsing the trilogue outcome.
16 Jun 2026European Parliament adopts the text: 423 for, 57 against, 174 abstentions.
29 Jun 2026Council adopts the text.
8 Jul 2026Signed by the co-legislators.
PendingOfficial Journal publication. Entry into force on the third day after.

Until publication, the strictly correct citation is Regulation (EU) 2024/1689 as amended by the Digital Omnibus on AI, with a visible review date. Nobody is well served by planning to the original dates on the theory that the amendment is not formally in force yet: both co-legislators have voted, and the amended dates are the ones your regulator will work from. If you want the whole schedule in one place, the full application timeline as amended sets out each date and what it obliges.

Change one: the AI Act delay that turned one date into four

The original design put an enormous amount of the regulation on a single day. The Omnibus took that day apart. Article 50 transparency stayed exactly where it was. The machine-readable marking duty in Article 50(2) got a grace period for systems already on the market. The high-risk regime moved by more than a year for standalone Annex III systems, and the Omnibus sets 2 August 2028 for AI embedded in Annex I products.

DateWhat appliesStatus under the OmnibusWho it binds
2 Feb 2025Article 5 prohibitions (a) to (h); Article 4 AI-literacy dutyUnchangedProviders and deployers
2 Aug 2025GPAI model obligations; governance provisions; penaltiesUnchangedGPAI model providers; member states
2 Aug 2026Article 50(1), 50(3) and 50(4) transparency; Article 50(2) marking for generative systems placed on the market from this date; AI Office enforcement beginsUnchangedProviders for 50(1) and 50(2); deployers for 50(3) and 50(4)
2 Dec 2026Article 50(2) marking for generative systems placed on the market before 2 Aug 2026; the ninth prohibitionNew date created by the OmnibusProviders; and deployers for the prohibition
2 Dec 2027High-risk obligations for standalone Annex III systemsMoved from 2 Aug 2026, a seventeen-month extensionProviders, deployers, importers, distributors
2 Aug 2028High-risk obligations for Annex I embedded-product systemsSet by the OmnibusProduct manufacturers and providers

The half-truth that costs money. The headline that AI Act deadlines were delayed is true of the high-risk regime and false of everything landing on 2 August 2026. Chatbot disclosure under Art 50(1), emotion and biometric notice under Art 50(3) and deepfake and public-interest text disclosure under Art 50(4) bite on that day, for a population far wider than the high-risk one. If your programme stood down on the delay headline, start with what actually applies on 2 August 2026.

The grace period, and why you should quote the date and not the month count

Article 50(2) requires providers of systems generating synthetic audio, image, video or text to mark those outputs in a machine-readable format. Systems placed on the market from 2 August 2026 comply from the moment of placement. Systems already on the market before that day get until 2 December 2026. Sources describe the length of that window inconsistently, some calling it three months and some four, because one tracks the negotiating framing and the other counts the calendar span. Every source agrees on the date. Put 2 December 2026 in your calendar and never a month count, and the discrepancy stops mattering. The duty-by-duty breakdown sits on the Article 50 transparency page.

Change two: a ninth Article 5 prohibition on CSAM and intimate imagery

Article 5 carried eight prohibitions, clarified by Commission guidelines in February 2025 and applicable since 2 February 2025: manipulative or deceptive techniques, exploitation of vulnerability, social scoring, individual predictive criminal-risk assessment based solely on profiling, untargeted facial scraping, emotion recognition at work and in education, biometric categorisation inferring sensitive traits, and real-time remote biometric identification in public spaces for law enforcement.

The Omnibus adds a ninth: AI systems that generate child sexual abuse material, or images, video or audio depicting an identifiable person in an intimate or sexually explicit way without consent. The so-called nudifier tools are the obvious target, but the drafting is not limited to them. Law-firm analysis of the agreed text reads the provider test as extending to any system where such generation is a reasonably foreseeable and reproducible outcome, without requiring significant technical modification. Providers may not place such systems on the market without adequate technical safeguards, and the prohibition binds deployers too.

Two features make this different from the other eight. First, it is the only prohibition with a future compliance date: 2 December 2026, not 2 February 2025. Second, it lands in the top enforcement tier, because breaches of Article 5 attract €35M or 7% of total worldwide annual turnover, whichever is higher for a company and whichever is lower for an SME or start-up under Article 99(6). The penalties and enforcement breakdown sets out how the three tiers divide.

Foreseeable output, not intended purpose. If you provide a general-purpose image or video generator, the question is not whether you built it for this. It is whether a user can get there without significant technical modification. That makes safeguard testing, red-teaming and refusal behaviour a compliance artefact with a deadline attached, not a trust-and-safety nice-to-have.

Change three: the Machinery Regulation carve-out for embedded AI

A system reaches high-risk status by two routes. The Annex III route lists eight use areas: biometrics, critical infrastructure, education and vocational training, employment and worker management, access to essential private and public services including credit scoring and health and life insurance pricing, law enforcement, migration and border control, and the administration of justice and democratic processes. The Annex I route is different in kind: the AI is a safety component of, or is itself, a product already covered by EU harmonisation legislation that requires third-party conformity assessment.

The Omnibus gives AI embedded in Machinery Regulation products a targeted carve-out from the direct high-risk rules of the AI Act, with the AI-specific requirements layered into the Machinery Regulation instead. Read that as a change of route rather than an exemption. A machinery maker still has to satisfy AI-specific requirements; it does so inside the conformity assessment it was already running, rather than through a second, parallel AI Act process.

The carve-out is narrow and does not travel. Medical devices and toys with AI safety components remain fully inside the AI Act high-risk regime, on the 2 August 2028 date. Nothing about the Annex III route changed. If you are unsure which route your system takes, the guide to what counts as a high-risk AI system walks both tests in order.

Change four: the database registration the Commission proposed to drop

This is the change most likely to be wrong in your notes, because the proposal and the adopted text point in opposite directions.

Background: under Article 6(3), an Annex III system is not high-risk if it does not pose a significant risk of harm to health, safety or fundamental rights, including by not materially influencing the outcome of decision making, and it meets at least one of four conditions. Those are a narrow procedural task, improving the result of a previously completed human activity, detecting decision-making patterns or deviations without replacing or influencing the prior human assessment absent proper review, or performing a preparatory task to an assessment relevant to an Annex III use case. A system that performs profiling of natural persons is always high-risk, with no exceptions. Article 6(4) then requires the provider to document that assessment before the system is placed on the market.

The Commission proposal would have removed the obligation to register systems self-assessed as not high-risk in the EU database. That deletion did not survive negotiations. Registration was reinstated, in a simplified and lighter form. So the derogation remains a documented, filed position rather than a quiet internal decision: you write the Article 6(4) assessment before placement, and you register.

No worked examples to lean on. The Commission missed its statutory February 2026 deadline for the Article 6 high-risk classification guidelines, so authoritative examples of a successful derogation are scarce. Until they arrive, the conservative posture is the only defensible one: document thoroughly, register, and assume profiling forecloses the off-ramp entirely. The Article 6(3) derogation page covers where the test gets over-claimed, and the free triage classifier runs the four conditions and the profiling override against your own system.

What this EU AI Act amendment did not change

An amendment marketed as simplification invites the assumption that everything got lighter. It did not. The Omnibus moved dates, added one prohibition, rerouted one product family and simplified one filing. The architecture of the regulation is untouched, and so are the obligations that have been enforceable since 2 August 2025.

ProvisionPosition after the Digital Omnibus
Article 5 prohibitions (a) to (h)In force since 2 February 2025, wording untouched
Article 4 AI-literacy dutyIn force since 2 February 2025
Article 99 penalty tiers€35M or 7%, €15M or 3%, €7.5M or 1%; enforceable since 2 August 2025
Article 6(3) derogationSame four conditions, same absolute profiling override
Article 6(4) documentationAssessment still documented before market placement
Article 25 role flipSame three triggers, same full Article 16 consequence
GPAI duties, Articles 53 and 55Applying since 2 August 2025; 10^23 and 10^25 FLOP thresholds unchanged
Article 2 exclusionsMilitary, pre-placement R&D, personal use, open source with carve-outs
Annex III use areasThe same eight areas; only the application date moved
Annex IV technical documentationThe same nine blocks; the deadline moved with the high-risk regime

Two consequences worth stating plainly. Penalties did not move, so an Article 5 breach today is enforceable today. And the seventeen months added to the standalone Annex III date buy engineering time, not documentation relief: the Annex IV blocks, the Article 9 risk management system and the conformity assessment all still have to exist before placement, and the volume of work is the same as it was.

What happens at Official Journal publication, and what to re-check

On publication the amendment gets its Regulation (EU) 2026 number and a publication date, enters into force on the third day after, and the consolidated version of the AI Act on EUR-Lex is updated to carry the amended text. Watch the instrument page on EUR-Lex and the Commission AI regulatory framework pages, and the European Parliament site if you need the procedural history for a file.

Five things to re-check that day, in order of how much rework they cause:

  1. The regulation number and publication date. Every compliance record citing the amendment needs a real instrument to point at. Replace the placeholder wording in your policies and self-assessment templates.
  2. The consolidated Article 113 dates. Read them against the four dates you planned to. They should match, but a plan built on a press summary rather than the operative text deserves a check against the text.
  3. The operative wording of the ninth prohibition and its transitional provision. If you provide a generative image, video or audio system, this is the paragraph your safeguard testing will be measured against on 2 December 2026.
  4. The simplified registration article. The obligation survived; what a simplified entry actually requires is the detail to confirm, especially if you are carrying self-assessed non-high-risk Annex III systems.
  5. Renumbering. Amending regulations move recitals and occasionally article references. Anything in your internal documentation that quotes a recital number needs a pass.

None of that changes what you should be building now. The nearest binding date is 2 August 2026 and it did not move, the ninth prohibition follows on 2 December 2026, and the high-risk work merely has a longer runway. If you have not yet established which of those actually reach your system, run the seven-stage triage and start from the answer.

Check your own system

The free classifier walks the same tests in order and tells you which of them your system actually trips, with the article each answer rests on.

Run the triage →

Frequently asked questions

What is the Digital Omnibus on AI?

It is the amending regulation that rewrites parts of Regulation (EU) 2024/1689, the EU AI Act. The Commission proposed it as COM(2025) 836 on 19 November 2025, negotiators reached a trilogue agreement on 7 May 2026, the European Parliament adopted it on 16 June 2026 by 423 votes to 57 with 174 abstentions, the Council adopted it on 29 June 2026 and it was signed on 8 July 2026. It made four substantive changes: it reset the high-risk application dates, with standalone Annex III systems moving from 2 August 2026 to 2 December 2027 and Annex I embedded-product systems set at 2 August 2028, while 2 August 2026 stayed in place for Article 50 and a new 2 December 2026 date was created; it added a ninth Article 5 prohibition; it carved AI embedded in Machinery Regulation products out of the direct high-risk rules; and it simplified rather than removed EU database registration.

Is the Digital Omnibus already law?

It is adopted and signed but not yet published in the Official Journal, as at 22 July 2026. It enters into force on the third day after publication, and the consolidated text plus the final Regulation (EU) 2026 number only become authoritative at that point. In practice the amended dates are settled: they were agreed in trilogue and voted through both co-legislators, so plan against them. Cite Regulation (EU) 2024/1689 as amended by the Digital Omnibus in your records for now, and add the new regulation number once EUR-Lex carries it.

Did the EU AI Act deadlines get delayed?

Two of them did, and the most immediate one did not. High-risk obligations for standalone Annex III systems moved from 2 August 2026 to 2 December 2027, a seventeen-month extension, and Annex I embedded-product systems are set at 2 August 2028. Article 50 transparency still applies on 2 August 2026 exactly as written, and the only piece of Article 50 that moved is the 50(2) machine-readable marking duty, which reaches 2 December 2026 and only for generative systems already on the market before 2 August 2026. Reading the headline as a general AI Act delay is the most expensive mistake available right now.

What is the ninth prohibition in the Digital Omnibus?

It bans AI systems that generate child sexual abuse material or non-consensual intimate imagery of an identifiable person. It sits alongside the eight prohibitions that have applied since 2 February 2025 and is the only Article 5 entry with a future compliance date: 2 December 2026. It binds deployers as well as providers, and law-firm analysis of the agreed text reads the provider test as extending to any system where such generation is a reasonably foreseeable and reproducible outcome without requiring significant technical modification. Article 5 breaches carry the top penalty tier of €35M or 7% of worldwide annual turnover.

Does the Digital Omnibus remove EU database registration?

No. The Commission proposal would have dropped registration for Annex III systems that a provider self-assesses as not high-risk under the Article 6(3) derogation, but that deletion did not survive negotiations. Registration was reinstated in a simplified, lighter form. So the derogation still costs you paperwork: an Article 6(4) assessment documented before the system is placed on the market, plus a database entry. Treat a claimed derogation as a filing obligation with evidence behind it, not as an exit from the regime.

Which AI systems got the Machinery Regulation carve-out?

AI that is a safety component of, or is itself, a product covered by the Machinery Regulation. The Omnibus takes those systems out of the direct high-risk rules in the AI Act and layers the AI-specific requirements into the Machinery Regulation instead. It is a change of route, not an exemption, so the substance still reaches machinery makers through their existing product-safety conformity work. Every other Annex I product category is untouched: medical devices and toys with AI safety components remain fully inside the AI Act high-risk regime, on the 2 August 2028 date.

What should I re-check when the Omnibus is published?

Five things. The final Regulation (EU) 2026 number and publication date, so your records cite a real instrument. The consolidated Article 113 dates on EUR-Lex, against the four dates you have planned to. The operative wording of the ninth prohibition and its transitional provision. The simplified registration article, to see exactly which fields a self-assessed non-high-risk system has to supply. And any article or recital renumbering that your internal policies quote. None of that changes what you should be building now.

This page is triage guidance, not legal advice. It reflects Regulation (EU) 2024/1689 as amended by the Digital Omnibus, reviewed 22 July 2026, when the Omnibus was adopted and signed but awaiting Official Journal publication. Final classification for ambiguous cases needs qualified counsel.