CPDForge AI
AI Governance21 June 2026

The EU AI Act in 2026: What the Digital Omnibus Actually Changes — and What It Doesn't

CPDForge Knowledge Hub | AI Governance Series | June 2026

For two years, "2 August 2026" has functioned as the single most-cited date in European AI compliance planning — the moment the bulk of the EU AI Act's remaining provisions were due to bite. That date has now effectively been redrawn. On 7 May 2026, negotiators from the Council, the European Parliament, and the Commission reached a provisional agreement on the so-called Digital Omnibus on AI, the first substantive amendment package since the Regulation was adopted in 2024. For compliance, legal, and risk teams, the practical question is no longer "are we ready for August?" but "which August, for which obligations, and what still needs to happen regardless?"

This article sets out where the Act actually stands as of mid-2026, what the Omnibus changes, and what remains unaffected — because the temptation to read "deadline extended" as "pressure off" is the single biggest compliance risk currently circulating in the market.

A regulation that was never going live in one block

The AI Act was never designed to switch on all at once. Under its phased structure, prohibited practices and AI literacy obligations became applicable first, in February 2025. Governance rules and obligations for general-purpose AI (GPAI) models followed in August 2025, bringing the European AI Office and Member State enforcement bodies into formal existence. The remaining bulk — high-risk system requirements and transparency obligations — was originally slated for August 2026, with product-embedded high-risk systems following a year later.

It is that middle tranche the Digital Omnibus reshapes.

What the Omnibus changes

The headline shift is a staggered deferral of high-risk system obligations, split by category. For "Annex III" high-risk systems — the use-based category covering things like employment screening, credit scoring, and biometric identification — compliance obligations move from August 2026 to 2 December 2027, a sixteen-month extension. For "Annex I" high-risk systems, which are embedded in already-regulated products such as medical devices, lifts, or machinery, the deadline shifts from August 2027 to August 2028.

Transparency obligations are treated differently and far more narrowly. The requirement for AI systems that generate or manipulate synthetic content to watermark outputs in a machine-readable, detectable format is deferred — but only for four months, from August to 2 December 2026, and only for systems already on the market before the original deadline. Systems entering the market after 2 August 2026 must comply from the moment they launch. The broader Article 50 transparency duties — informing users they are interacting with an AI system, labelling deepfakes, disclosing AI-generated content of public interest — remain on track for August 2026.

The Omnibus also narrows the definition of a "safety component," exempting AI used purely for user assistance, efficiency, or convenience from automatic high-risk classification unless a malfunction could plausibly endanger health or safety. It extends SME-style simplified compliance treatment to mid-sized companies (up to 750 employees and €150 million in revenue), and it eases use of sensitive personal data specifically for bias detection and mitigation purposes — a carve-out from GDPR's special-category data restrictions that financial services and HR technology providers in particular have been pushing for.

Notably, the package adds rather than removes obligations in one area: a new prohibition on AI systems used to generate non-consensual intimate imagery or child sexual abuse material takes effect 2 December 2026, amending Article 5's list of banned practices.

What hasn't moved

It is worth being precise about what the Omnibus does not touch, because the deferral has generated a degree of complacency in the market that the underlying legal position doesn't support.

The prohibitions that took effect in February 2025 — social scoring, subliminal manipulation, real-time biometric identification in public spaces, exploitation of vulnerable groups — remain fully in force. The GPAI governance regime that became applicable in August 2025 is unaffected; providers of general-purpose models, including those with systemic risk designations, are already operating under it, and providers whose models predate August 2025 still face a hard compliance deadline of August 2027. The core Article 50 transparency obligations for chatbots and AI-system disclosure remain on the original August 2026 timeline. And critically, the Omnibus has not yet been formally adopted — political agreement was reached in May 2026, with formal adoption by Parliament and Council expected by July, ahead of entry into force. Until that formal step completes, the legally operative deadlines remain the original ones.

The Commission has also been active on the interpretive side. Draft guidelines on high-risk system classification, published 19 May 2026, work through each of the eight Annex III use-case categories and clarify an important point for providers tempted to draft around the rules: classification turns on a system's actual intended purpose — as evidenced by instructions for use, marketing materials, and technical documentation taken together — not on disclaimers buried in terms of service. A draft Code of Practice on labelling AI-generated content, and parallel guidelines on transparency obligations, are also out for consultation, with final versions expected in the coming weeks.

What this means for compliance planning

The practical read for organisations operating in or selling into the EU is threefold.

First, the deferral of high-risk obligations to December 2027 (or August 2028 for product-embedded systems) is real relief on paper, but the underlying compliance lift — risk management systems, technical documentation, conformity assessment, EU database registration — has not gotten any smaller, and the standards, templates, and harmonised guidance organisations need to execute it have historically arrived late relative to deadlines. Treating an extended deadline as permission to pause is a documented pattern from the original timeline that regulators and law firms are now actively warning against repeating.

Second, the transparency and labelling obligations under Article 50 are the nearer-term priority. Chatbot disclosure duties and most AI-generated content labelling requirements still land in August 2026; only the narrow watermarking sub-obligation for legacy systems gets a four-month reprieve to December. Any organisation deploying generative AI customer-facing tools in the EU should treat August 2026 as the operative date, not December.

Third, the GPAI regime is already live and enforceable, with Member State penalty regimes in place since August 2025. Organisations building on or fine-tuning foundation models — rather than simply deploying high-risk applications — are already inside the Act's enforcement perimeter, regardless of where the high-risk deadline lands.

The broader signal

The Digital Omnibus is best read as evidence that the EU's "Brussels effect" regulatory model is adapting in real time to implementation friction, not retreating from it. The amendments arrived via the Commission's wider Digital Omnibus simplification agenda, which also touches GDPR, the NIS2 cybersecurity directive, DORA, and the Data Act — a sign that Brussels is consolidating its digital rulebook for coherence and reduced duplication rather than diluting substantive protections. For organisations building durable AI governance programmes, the sound approach remains the one regulators and practitioners have converged on throughout 2026: keep classifying systems against Annex III criteria, keep building documentation and risk management infrastructure, and treat extended deadlines as planning runway rather than reduced scope.

Sources consulted: European Commission Digital Strategy directorate; Council of the European Union (Consilium) press materials, May 2026; legal analysis from Covington & Burling (Inside Privacy), Latham & Watkins, Travers Smith, Kennedys Law, and K&L Gates, current as of June 2026. This article is provided for general informational purposes as part of CPDForge's continuing professional development content and does not constitute legal advice. Organisations should seek jurisdiction-specific counsel before relying on any compliance timeline discussed here.

Explore your platform options

Take the 3-minute assessment to find the right fit for your needs.

Get email alerts for new articles

We'll email you when a new Knowledge Hub article goes live — roughly 3 a month. Confirm once and unsubscribe any time.

Free newsletter — no card required, and completely separate from any CPDForge plan or subscription.

Related articles

AI Governance

AI Literacy Training: The EU AI Act Obligation Everyone Has Had Since 2025 (and No One Trained For)

Read
AI Governance

America's AI Governance Crossroads: Federal Preemption Meets the State Patchwork

Read
AI Governance

Governing the Agent: Liability, Standards, and the Race to Regulate Autonomous AI

Read

We value your privacy

We use cookies to analyse site usage and improve your experience. You can accept all cookies, use essential cookies only, or reject non-essential cookies entirely.