What matters in AI.

Subscribe

Learn / AI governance

Definition · AI governance

Digital Omnibus on AI

The Digital Omnibus on AI is Regulation (EU) 2026/1744, an EU law that amends the EU AI Act rather than replacing it. In force since 27 July 2026, the Digital Omnibus on AI delays the high-risk AI rules, adds two prohibitions, streamlines how notified bodies are designated, and gives the AI Office direct powers over some AI systems.

Last reviewed

Key points

  • The Digital Omnibus on AI is Regulation (EU) 2026/1744. It amends the EU AI Act rather than replacing it, and has been in force since 27 July 2026.
  • It delayed the high-risk rules: to 2 December 2027 for the Annex III uses such as hiring, and to 2 August 2028 for AI in regulated products such as medical devices.
  • From 2 December 2026 it bans AI built to make realistic sexual material of a real person without explicit consent, or child sexual abuse material, and AI whose foreseeable, reproducible output it is unless reliably prevented.
  • It made the AI Office the sole supervisor of the providers of some AI systems built on general-purpose AI models, and of AI in the largest online platforms, with powers to inspect and fine.
  • It eased AI Act designation for notified bodies under some product laws, such as the medical device rules, and wrote the Cyber Resilience Act's cybersecurity presumption into the AI Act.

What it changes

The Digital Omnibus on AI rewrites specific articles of the EU AI Act. It entered into force on 27 July 2026.

Later dates for high-risk AI. The requirements for high-risk AI systems now apply from 2 December 2027 for Annex III uses, such as hiring and education, and from 2 August 2028 for AI in products under Annex I, such as medical devices. The old dates were 2 August 2026 and 2 August 2027. The stated reason: standards, guidance and national authorities arrived late (recital 40).

Two new bans. From 2 December 2026, the Act bans AI that makes realistic sexual material of an identifiable person without their explicit consent, and AI that makes child sexual abuse material. A provider is caught if that is the system’s purpose. It is also caught if the output is foreseeable and reproducible without significant modification, and the system lacks safeguards that reliably prevent it and correct reported misuse (Article 5(1a)). A deployer is caught only when using it for that purpose.

A stronger AI Office. The AI Office already supervised AI systems built on a provider’s own general-purpose AI model. It is now the sole supervisor of the providers of those systems, including ones in the same corporate group, with exceptions such as AI in regulated products. Other deployers stay under national supervision. It also alone supervises AI in the largest online platforms and search engines under the Digital Services Act, and can inspect and fine (Articles 75 to 75d).

Why it matters

A guide saying the high-risk rules apply from 2 August 2026 is out of date. A provider of a hiring tool now has until 2 December 2027.

In practice

Notified bodies. Annex I lists product laws. Section A laws, such as the medical device rules, apply alongside the AI Act. Section B laws, such as aviation, get only a few of its articles. A notified body approved under a Section A law can make a single application for AI Act designation, where that law provides for one (Article 28(8)). Until 28 January 2028 it can assess AI in those products without AI Act designation, if its notification checked the Act’s independence and competence rules; it must apply by then (Article 43(3), recital 18). A new Annex XIV lists codes for the product laws, biometric uses and AI technologies each body can cover.

The Cyber Resilience Act. A high-risk system meeting the Cyber Resilience Act’s conditions is deemed to meet the AI Act’s cybersecurity requirement (Article 42(3)). Recital 19 says this mirrors a rule already in the Cyber Resilience Act.

Smaller firms. The Omnibus adds small mid-cap enterprises (SMCs), a size band defined in a 2025 EU recommendation. SMEs and SMCs can file technical documentation on a simplified Commission form that notified bodies must accept (Article 11(1)). For an SMC, the fines in Article 99(4) and (5) are capped at the lower of the percentage and the fixed amount (Article 99(6a)).

AI literacy. Article 4 used to require measures to ensure, “to their best extent, a sufficient level of AI literacy”. It now requires measures “to support the development of AI literacy”, and says no specific level has to be guaranteed.

Products with AI. Adding an AI safety component does not by itself force a product into third-party conformity assessment. A manufacturer can skip the third party where its product law allows, but only if it applied harmonised standards or common specifications covering all the AI Act’s high-risk requirements (Article 43(3)).

Machinery. Machinery moved from Section A to Section B of Annex I, now citing the 2023 Machinery Regulation. The Commission must add AI requirements to that regulation by delegated acts that apply by 2 August 2028 (Article 3).

Questions and answers

When do the EU AI Act's high-risk rules apply after the Digital Omnibus?

From 2 December 2027 for the high-risk uses listed in Annex III, such as employment and education, and from 2 August 2028 for AI in products covered by the laws listed in Annex I. Before the Digital Omnibus on AI, those dates were 2 August 2026 and 2 August 2027 (original Article 113). The new dates are in Article 113 as amended by Regulation (EU) 2026/1744.

Does the Digital Omnibus on AI replace the EU AI Act?

No. Regulation (EU) 2026/1744 amends the AI Act, Regulation (EU) 2024/1689, and two other laws, on civil aviation and machinery. The AI Act remains the law that applies, read with the amendments in place.

Sources

  1. Regulation (EU) 2026/1744 (Digital Omnibus on AI), title, Articles 1 to 4, and Article 1 point 37European Union, 24 Jul 2026
  2. Regulation (EU) 2024/1689 (EU AI Act), original Articles 4 and 113European Union, 12 Jul 2024