Alessandro Del Ninno
News
Regulation 2026/1744 (Digital Omnibus on AI) comes into force: more time for high-risk sys-tems, fewer burdens on businesses and new powers for the AI Office.
INFORMATION TECHNOLOGY
27/07/2026

Regulation (EU) 2026/1744, known as the Digital Omnibus on AI, has been in force since 27 July 2026. It amends the AI Act with the aim of simplifying its implementation, reducing certain administrative burdens and promoting innovation, without undermining the safeguards put in place to protect security and fundamental rights.

The most significant change concerns the postponement of the provisions on high-risk AI systems:

  • from 2 December 2027, the rules relating to systems identified in Article 6(2) and Annex III of the AI Act will apply; these systems are used, amongst other things, in the fields of biometrics, employment, education, infrastructure, migration and access to essential services;

  • from 2 August 2028, the rules on high-risk systems incorporated into safety products or components governed by the European legislation listed in Annex I, such as machinery, toys and lifts, will apply.

This does not, however, constitute a general postponement of the AI Act. The provisions already in force and the further deadlines set out in the Regulation remain unchanged. In particular, system providers, including those of AI for general- purposes, which generate synthetic audio, images, video or text content and which were placed on the market before 2 August 2026, must comply with the labelling requirement set out in Article 50(2) by 2 December 2026.

The AI Omnibus also introduces proportionality measures for SMEs, start-ups and small mid-cap enterprises, extending to the latter certain concessions previously reserved for SMEs. These include, amongst other things, simplified procedures for technical documentation, quality management systems proportionate to the size of the organisation, and priority access to regulatory sandboxes.

The requirement for AI literacy has also been amended. Providers and deployers are no longer required to guarantee, in abstract terms, that a specific level of competence is achieved, but must take appropriate measures to support the development of the knowledge of staff and other persons who use or manage AI systems on their behalf, taking into account their skills, the context of use and the individuals affected by the systems. The obligation is therefore not removed: organisations must continue to provide training, internal instructions and documented organisational measures.

Opportunities for experimentation have been expanded. Member States will be required to have at least one national sandbox operational by 2 August 2027, whilst the AI Office may establish a Union-wide sandbox. The scope for conducting tests under real-world conditions has also been extended, subject to the safeguards set out in the AI Act and data protection legislation.

With regard to the protection of fundamental rights, the Regulation:

  • prohibits, from 2 December 2026, systems designed to generate non-consensual intimate or sexually explicit content and child sexual abuse material, including so-called ‘nudification’ applications;

  • allows, on an exceptional basis and where strictly necessary, the processing of special categories of personal data to identify and correct bias, provided that ordinary, synthetic or anonymised data cannot be used effectively and that strict security measures, access restrictions, documentation and erasure procedures are in place.

The Regulation also simplifies certain information required for registration in the European database of systems deemed exempt from high-risk classification, clarifies the coordination between the AI Act and European product safety legislation, and streamlines the procedures applicable to conformity assessment bodies.

Finally, the powers of the AI Office are strengthened; it has exclusive competence for the supervision of certain categories of systems based on general-purpose AI models and of systems integrated into very large online platforms and search engines. The AI Office will be able to request information, carry out investigations and inspections, and impose corrective measures and sanctions.

Actions to be taken by businesses.

The extension of the deadlines does not justify suspending compliance programmes. Providers and deployers should:

  1. update the inventory of AI systems developed, purchased or used;

  2. verify the classification of each system and distinguish between cases covered by Annex III and those relating to products listed in Annex I;

  3. review their compliance roadmaps in light of the new deadlines of 2 December 2027 and 2 August 2028;

  4. manage separately those obligations that are already applicable or have not been deferred, in particular those relating to prohibited practices and the transparency of synthetic content;

  5. update AI literacy programmes, keeping records of training, instructions and measures taken;

  6. verify eligibility as an SME or small mid-cap and identify the simplifications that can be practically utilised;

  7. review contracts with providers, developers and suppliers, clarifying roles, documentation, access to information and responsibilities throughout the value chain;

  8. coordinate AI governance with the GDPR, cybersecurity, product regulations and intellectual property protection;

  9. assess access to regulatory sandboxes for innovative projects or systems still under development.

The AI Omnibus grants businesses more time and proportionate compliance tools, whilst at the same time strengthening European controls and supervision. The additional period should therefore be used to establish effective AI governance that is documented and integrated into business processes.