Symbolic representation of the EU AI Act: On the left, a judge's gavel symbolizes regulation and law; on the right, a glowing microchip with the inscription “AI” is surrounded by digital circuitry. The composition illustrates the connection between artificial intelligence and legal control.

Digital Omnibus on AI – What Changes Are Coming to the EU AI Act, and What Does This Mean for Businesses?

30. July 2026

The EU AI Act remains in effect, but the timeline is shifting: with the “Digital Omnibus on AI,” the EU is making its first substantial changes to the AI Regulation (Regulation (EU) 2024/1689, AI Regulation). For businesses, the message is clear: the Digital Omnibus on AI postpones key deadlines and eases the strain on companies in some areas, but the substantive obligations themselves remain unchanged. Those who misinterpret the gained time as a breather risk facing the very time pressure that the postponement was actually intended to alleviate.

In this article, we outline the specific changes brought about by the Digital Omnibus on AI, which deadlines remain in effect, and what steps we recommend companies take now.

What the Digital Omnibus on AI Means in Practice

The Digital Omnibus on AI is not a new legal framework but rather a targeted amending regulation. The European Commission submitted the proposal to resolve implementation issues related to the EU AI Act. In particular, it addresses delays in the adoption of harmonized standards and in the designation of the competent national authorities.

The European Parliament adopted the package on 16 June 2026; the Council gave its final approval on 29 June 2026; and it was signed on 8 July 2026. It was published in the Official Journal of the EU on 24 July, and the legal act came into effect on 27 July 2026.

Important clarification: The Digital Omnibus on AI is part of a larger “Digital Omnibus” package. The amendments to the GDPR, the Data Act, the ePrivacy Regulation, and cybersecurity regulations (including NIS-2) that are also being discussed in this context are not covered by this legislative act and remain in the legislative process. An agreement on these is expected in the first half of 2027. In this article, we focus exclusively on the portion concerning the EU AI Act.

The Key Change: Postponement of High-Risk Obligations

The most significant change concerns high-risk AI systems. According to the original timeline, the obligations for autonomous high-risk systems under Annex III – such as those in the areas of employment, education, critical infrastructure, law enforcement, and creditworthiness assessments – were to take effect on 2 August 2026. Since the necessary harmonized standards are not expected to be finalized in time, the Digital Omnibus on AI Act now links the applicability of these requirements to the availability of the standards and support tools while setting binding deadlines:

  • Standalone high-risk systems as defined in Annex III: no later than 2 December 2027
  • AI embedded in regulated products as defined in Annex I (e.g., medical devices, toys): no later than 2 August 2028

Our recommendation: The additional timeframe is more realistic and sensible, but it does not reduce either the scope or the complexity of the requirements. Experience shows that establishing risk management, technical documentation, data quality, and governance structures takes significantly longer than initially anticipated. Companies should therefore view the postponement as an extended implementation window and as an opportunity to tackle the implementation in a structured manner and at an early stage.

Not Postponed: Transparency Requirements Under Article 50

Not everything will be deferred. The transparency requirements under Article 50 of the AI Regulation will continue to apply starting 2 August 2026, such as the requirement to inform users that they are interacting with an AI system.

There is one exception: for the machine-readable labeling of AI-generated content (images, audio, video, and text) in accordance with Article 50 (2), a transition period extending until 2 December 2026 applies to systems placed on the market before 2 August 2026.

Our recommendation: Companies should assess which of their systems or functions fall under Article 50 as soon as possible. 2 August 2026 should continue to be treated as a binding date; the three-month transition period applies exclusively to content labeling and only to systems already placed on the market prior to the effective date.

Expanded Supervisory Powers of the AI Office

The AI Office, which is part of the European Commission, will be granted significantly expanded supervisory powers. Until now, it has supervised general-purpose AI (GPAI) models and the systems based on them only if the model and the system came from the same provider.

Going forward, jurisdiction will extend to all AI systems based on GPAI models from the same company, as well as to systems that constitute or are embedded in very large online platforms or search engines. In addition, an explicit legal basis for cooperation between the AI Office and national supervisory authorities will be established.

Overview of Additional Changes

In addition to the major changes, the Digital Omnibus on AI includes several targeted, detailed amendments, the most important of which are listed below:

  • Processing of special data categories for bias detection (Art. 4a): The authorization to process special categories of personal data using AI is being expanded from high-risk systems to all AI systems and models. However, the strict necessity standard remains in place, meaning that processing is permitted only if it is strictly necessary for the detection or correction of biases.
  • AI-Competence (Art. 4): The requirement is being relaxed: Instead of ensuring a sufficient level of proficiency, providers and operators will have to take “measures to promote” their staff’s AI proficiency in the future.
  • Machinery Regulation: AI embedded in products covered by the so-called “Machinery Regulation” is specifically excluded from the direct scope of the high-risk rules. Other products (such as medical devices and toys) remain fully covered. However, the Commission may use the Machinery Regulation to tighten AI-specific safety requirements.
  • Registration Requirements: The exemption proposed by the Commission for systems classified as “low-risk” was not approved. These systems must also continue to be registered in the EU database, albeit with a reduced administrative burden.

2 August 2026 Remains a Key Date

Despite all postponements, 2 August 2026 is by no means a less significant date. On this date, several mechanisms will take effect or become enforceable:

  • The transparency requirements under Article 50 (with the narrow exception mentioned above regarding content labeling).
  • The enforceability of the GPAI obligations (applicable as of August 2025, with fines effective as of August 2026).
  • Market surveillance by the competent authorities.

Our Expert's Conclusion: More Time, Same Substance

"The Digital Omnibus on AI provides significant relief regarding deadlines and creates greater consistency and legal certainty in several areas. At the same time, the fundamental architecture and protective intent of the EU AI Act remain unchanged. The substantive requirements for high-risk systems – namely, risk management, data governance, technical documentation, and human oversight – remain unchanged.

I therefore recommend that the affected companies promptly and thoroughly fulfill the obligations that remain due as of 2 August 2026, such as transparency, GPAI, and market monitoring, while at the same time using the time gained to systematically and robustly establish governance structures and technical documentation for high-risk AI."

Maximilian Müller, Principal usd Security Consulting | AI Governance
Maximilian Müller, Principal usd Security Consulting, in a suit. Expert for AI Governance, the EU AI Act, and the Digital Omnibus on AI.

Do you need assistance with AI governance? Get in touch with us. We offer tailored support wherever you need it: whether you’re setting up an AI management system in accordance with ISO/IEC 42001 or implementing specific requirements, such as those outlined in the EU AI Act.

Also interesting:

Security Advisories on Teamcenter and EcoStruxure Building Operation

Security Advisories on Teamcenter and EcoStruxure Building Operation

The pentest professionals at usd HeroLab identified several vulnerabilities during a web application and fat-client penetration test. These include two cross-site scripting vulnerabilities in the Teamcenter web application, as well as hardcoded credentials in Siemens...

more security at TU Darmstadt: Another Award for Maximilian Müller

more security at TU Darmstadt: Another Award for Maximilian Müller

The Computer Science Student Council of TU Darmstadt has awarded Prof. Dr. Michael Waidner and our colleague Maximilian Müller as the best lecture of the winter semester 2025/26 for their course "Information Security Management". The prizes for the best lecture and...

Categories

Categories