The Digital Omnibus is Regulation (EU) 2026/1744 of 8 July 2026, published in the Official Journal on 24 July 2026 and in force since 27 July 2026. It amends the AI Act, along with the aviation safety and machinery regulations.
Its most reported measure: the high-risk obligations were pushed to 2 December 2027 for Annex III and 2 August 2028 for Annex I. It did not postpone Article 50, the prohibited practices, or the obligations on providers of general-purpose AI models.
Postponed: Annex III high-risk (December 2027), Annex I high-risk (August 2028), and national regulatory sandboxes (August 2027), that last one binding Member States, not companies. Three dates of application, and three only.
Not postponed: prohibited practices (February 2025), AI literacy (February 2025), general-purpose AI model obligations (August 2025), Article 50 transparency (2 August 2026).
Added: several new deadlines, two of them on 2 December 2026.
Has the Digital Omnibus been adopted, or is it still a proposal?
Adopted, and in force. The AI strand is Regulation (EU) 2026/1744 of 8 July 2026, which entered into force on 27 July 2026. The Commission had presented it in November 2025 as two separate regulation proposals, one on data, cybersecurity and privacy, the other on AI; political agreement was reached in May 2026, and the Commission’s own digital rulebook page confirms the AI strand entered into force on 27 July 2026.
The point is worth settling first, because as at 1 September 2026 a great many pages on the subject still describe the November 2025 proposal, in the future tense, as a text still to come. It is not one.
This page covers the AI strand only, meaning Regulation (EU) 2026/1744. The other proposal, the one touching data and the GDPR, follows its own path and is not dealt with here.
What exactly does the Digital Omnibus postpone?
The two high-risk deadlines, and the duty on Member States to open a regulatory sandbox. Nothing else moves: the prohibitions, AI literacy and the Article 50 transparency duties keep their dates. The table gives, row by row, the original date, the new one and the article that carries it.
| Obligation | Original date | After Regulation (EU) 2026/1744 | Basis |
|---|---|---|---|
| High risk: Annex III | 2 August 2026 | 2 December 2027 | Art. 113, 3rd para., (c)(i) |
| High risk: Annex I | 2 August 2027 | 2 August 2028 | Art. 113, 3rd para., (c)(ii) |
| National regulatory sandboxes, a Member State obligation | 2 August 2026 | 2 August 2027 | Art. 57(1) |
| Transparency: Article 50 | 2 August 2026 | unchanged | Art. 113, 2nd para. |
| Prohibited practices, AI literacy | 2 February 2025 | unchanged | Art. 113, 3rd para., (a) |
| General-purpose AI models | 2 August 2025 | unchanged | Art. 113, 3rd para., (b) |
The proof that Article 50 was not postponed is structural. Regulation (EU) 2026/1744 rewrites the third paragraph of Article 113, which carries the exceptions, and it amends only points (a), (c) and (d). The general sentence is untouched: “It shall apply from 2 August 2026.” Article 50 sits in Chapter IV, which appears in none of the exceptions. It therefore falls under that general date.
One derived effect, rarely flagged. Moving the two Chapter III dates also moves the reference date of the grandfathering rule in Article 111(2), which points to “the date of application of Chapter III referred to in Article 113”. A system placed on the market before 2 December 2027 is therefore now a legacy system for Annex III purposes, which it would not have been before. That is not a fourth postponed date of application, but it is a deadline that moved.
That grandfathering has a limit, in the second sentence of the same paragraph: providers and deployers of high-risk systems intended to be used by public authorities must in any event have complied by 2 August 2030, whether or not any significant change occurred. That is the rule in the text in force; the documents on file do not establish whether the omnibus created it or carried it over.
What new deadlines does the Digital Omnibus add?
Several, and two of them bear directly on companies: 2 December 2026 and 2 August 2027. The first carries two distinct things — the two new prohibitions of Article 5, and the catch-up on Article 50(2) for systems already on the market. The second is the deadline for models placed on the market before 2 August 2025. A simplification text that adds nothing would be a curiosity.
A simplification text that adds nothing would be a curiosity. This one adds several dates, two of which bear directly on companies.
| Deadline | Subject | Basis |
|---|---|---|
| 27 July 2026 | Articles 102 to 110 become applicable. Article 110 opens the consumer representative action against an infringement of the AI Act | Art. 113, 3rd para., (d), added |
| 2 December 2026 | Two new prohibitions in Article 5, points (ba) and (bb), and the paragraphs 1a and 1b that define their reach | Art. 113, 3rd para., (a), rewritten |
| 2 December 2026 | Providers of systems generating synthetic content placed on the market before 2 August 2026 must comply with Article 50(2) in full: machine-readable marking and detectability | Art. 111(4), added |
| 1 August 2027 | Commission guidelines on the interplay with Union harmonisation legislation | Art. 96(1)(g), added |
| 2 September 2027 | Commission guidance on the post-market monitoring plan | Art. 72(3), amended |
| 28 January 2028 | Deadline for notified bodies to apply for designation under Annex I, Section A | Art. 43(3), 2nd subpara. |
Why “the AI Act has been delayed” is wrong
Reading this text as a general postponement leads most organisations to a false conclusion: that they have until the end of 2027 to deal with the subject. The reasoning reverses in one sentence: if your systems are not high-risk, the postponement does not concern you, and the obligations that do are already enforceable, AI literacy since February 2025, Article 50 transparency since 2 August 2026.
What does the Digital Omnibus change on substance?
Two new prohibitions, Article 4 rewritten, a new Article 4a, and the safety-component test tightened. The prohibitions cover AI-generated non-consensual intimate material and child sexual abuse material, applicable on 2 December 2026. Add to that powers of its own for the AI Office, a reorganised Annex I, and a new cybersecurity presumption.
Beyond the calendar, Regulation (EU) 2026/1744 amends the AI Act on many points. The ones that matter most to an organisation:
Two new prohibited practices in Article 5: AI-generated or manipulated non-consensual intimate material, and child sexual abuse material or performance within the meaning of Article 2, points (c) and (e), of Directive 2011/93/EU, “except where a ‘without right’ defence applies under national law”. Applying from 2 December 2026. They come with a filter, in Article 5(1a) and (1b), that decides who is actually caught: placing on the market or putting into service is prohibited only where that generation “is the intended purpose of the AI system”, or where the system’s design or functionalities make it “a reasonably foreseeable and reproducible outcome, without requiring significant technical modification” and the system lacks “reasonable and adequate technical safety measures and other safeguards” to prevent it reliably and to correct observed or reported misuse. Use, by contrast, is prohibited only where the deployer uses the system for that purpose.
Article 4 on AI literacy was rewritten, and its new wording bounds the obligation: it “does not require providers or deployers to guarantee any specific level of AI literacy of any individual”. The obligation has existed since February 2025; that boundary dates only from 27 July 2026.
A new Article 4a allows, to the extent strictly necessary and under six cumulative conditions, the processing of special categories of personal data to ensure bias detection and correction. It is the most direct bridge to the GDPR the text has created, bearing in mind that its second paragraph “does not create any obligation to conduct such bias detection and correction”.
The safety component test was tightened, by three filters in Article 6. They read in order, because the second reverses the first.
- Systems “solely used for non-safety related aspects of user assistance, performance optimisation, service efficiency, automation or convenience or quality control” do not qualify as safety components.
- Notwithstanding that, systems “the failure or malfunctioning of which would endanger health and safety” do qualify. The first exclusion is therefore never absolute.
- A product required to undergo third-party conformity assessment “solely due to risks other than risks to health and safety, in particular risks relating to the distribution of radio spectrum or electromagnetic interference that do not affect health and safety” does not meet the condition in Article 6(1)(b).
SMEs and small mid-cap companies enter the text: two definitions inserted in Article 3, technical documentation that may be supplied in a simplified manner through a form the Commission is to draw up (which we have not found published as at 24 August 2026), a proportionate quality management system, and the extension to small mid-caps of the fine ceiling taken at the lower figure. Watch the reach of that last measure: for an SME the reversal applies to all three penalty tiers, Article 5 included; for a small mid-cap, Article 99(6a) covers only paragraphs 4 and 5. A small mid-cap that breaches a prohibited practice remains exposed to the highest ceiling.
The AI Office receives powers of its own, in Articles 75 and 75a to 75d: exclusive competence over systems built on general-purpose AI models developed by the same provider or by providers within the same undertaking (subject to four exceptions) and over AI systems that constitute, or are integrated into, a very large online platform or search engine within the meaning of Regulation (EU) 2022/2065. That competence targets the providers of those systems; a deployer falls under it only where it is also the provider, or part of the same undertaking. Investigation powers, on-site inspections with the affixing of seals, and the power to make an operator’s commitments binding.
AI Office fines and periodic penalty payments are two regimes, not one. The fines have no ceiling of their own: the text refers back to the Article 99 scale. The 5 % ceiling applies only to periodic penalty payments, and its base is an alternative: 5 % of average daily income or of worldwide annual turnover in the preceding financial year, per day. Writing “5 % of daily turnover” is not an abbreviation of that formula; it is a third base, which does not exist in the text.
Annex I is reorganised: the machinery regulation (EU) 2023/1230 moves from Section A to Section B, which changes the regime for systems falling under it. A new Article 60a organises testing in real world conditions outside a sandbox for those systems.
A cybersecurity presumption appears: a high-risk system falling within the scope of Regulation (EU) 2024/2847 and meeting the conditions of its Article 12(1) “shall be deemed to comply with the cybersecurity requirements set out in Article 15” of the AI Act.
What to take from the omnibus
If your systems fall under Annex III, you have sixteen additional months (twelve for Annex I) and they will be needed: technical documentation, risk management and data governance are not built in a quarter.
If they do not, which is the more common case, the postponement changes nothing for you. Your deadlines are elsewhere: February 2025 for prohibited practices and AI literacy, 2 August 2026 for Article 50, and 2 December 2026 if you provide a system generating synthetic content that was placed on the market before 2 August 2026. A system placed on the market on or after 2 August 2026 gets no extra time at all.
What this page rests on
Regulation (EU) 2026/1744 of 8 July 2026, and Regulation (EU) 2024/1689 in its consolidated version of 27 July 2026, where the passages it introduced are marked as amendments, the authentic text remaining the one published in the Official Journal. Quotations are reproduced from the official English text and are never translated from another language version.
Sources. Regulation (EU) 2024/1689, consolidated text of 27 July 2026 and Regulation (EU) 2026/1744, both consulted on 27 August 2026. The institutional timeline of the text, the November 2025 proposal, the May 2026 political agreement and the entry into force of the AI strand on 27 July 2026, is established from the European Commission’s digital rulebook page, consulted on 1 September 2026.
Frequently asked questions
Does the Digital Omnibus repeal the AI Act?
No. Regulation (EU) 2026/1744 amends Regulation (EU) 2024/1689: it moves three dates of application, adds several new ones, and lightens some requirements. The AI Act remains in force, and the obligations already applying (prohibited practices, AI literacy, general-purpose AI models, Article 50 transparency) were not postponed. All of them were amended on substance, to varying degrees: Article 4 rewritten in full, two prohibitions added to Article 5 together with the filter that bounds them, Article 50(7) modified, and Article 56(6) rewritten on the model side.
Are Digital Omnibus, AI Omnibus and the digital omnibus package the same text?
For the AI part, yes: all three names are used for Regulation (EU) 2026/1744 of 8 July 2026. They are political file names with no legal value. One caution: the same nickname is used for other files. When this site refers to Regulation (EU) 2026/1744, it means the AI strand and nothing else.
Why was Article 50 not postponed?
Because the text did not provide for it. The postponement works through the rewriting of the third paragraph of Article 113, which carries the exceptions, and only points (a), (c) and (d) were amended. The general sentence is unchanged: it shall apply from 2 August 2026. Article 50 sits in Chapter IV, which appears in none of the exceptions, so it falls under that general date. The only paragraph of Article 50 the omnibus touched is paragraph 7, on codes of practice. The Regulation gives no reason for that choice, and commentary that supplies one is going beyond the text.
What should I do with the extra sixteen months?
They apply to Annex III only. Annex I gained twelve. If your systems are high-risk, that time goes into technical documentation, the risk management system and data governance, none of which is built in a quarter. Note one indirect effect too: postponing the Chapter III dates also moves the reference date of the grandfathering rule in Article 111(2), so a system placed on the market before 2 December 2027 is now a legacy system for Annex III purposes.
This content is a technical and regulatory information resource. It does not constitute legal advice.