Skip to main content

Talk to us: 0333 004 4488 | hello@brabners.com | Contact us

Digital Omnibus on AI to delay EU AI Act — what businesses need to know

AuthorsPaddy FearnonEleanore Beard

Person seated at a desk in a modern office, examining multiple monitors showing charts and a brain graphic, with hand on their chin.

The European Commission has pursued a wider Digital Omnibus simplification agenda across parts of the EU's digital regulatory framework. One element of that agenda is the Digital Omnibus on AI — now enacted through Regulation (EU) 2026/1744 — which makes targeted amendments to the EU AI Act, the Machinery Regulation and certain aviation legislation.

The Digital Omnibus on AI introduces the first significant amendments to the EU AI Act since its adoption in 2024. Regulation (EU) 2026/1744 entered into force on 27 July 2026 and revises parts of the AI Act's implementation timetable while preserving its fundamental risk-based framework. The intention isn’t to rewrite the AI Act or reduce protections for individuals. Instead, the Digital Omnibus seeks to provide additional time and regulatory clarity while maintaining the AI Act's central objectives of promoting trustworthy AI and protecting health, safety and fundamental rights.

These EU AI Act Digital Omnibus changes are particularly significant for organisations developing, deploying or procuring AI systems as they postpone several key compliance deadlines that businesses had been working towards. However, the Omnibus doesn’t delay the whole AI Act. Some obligations remain on track, meaning that organisations can’t afford to pause their AI compliance programmes altogether. The changes will have important implications for compliance strategies, procurement decisions and AI governance frameworks over the coming years.

Here Paddy Fearnon and Eleanore Beard from our data protection team examine the key changes introduced by the Digital Omnibus on AI, what remains unchanged and how businesses should respond.

 

What compliance deadlines have changed in the EU AI Act? 

The Digital Omnibus postpones obligations relating to certain high-risk AI systems:

  • Stand-alone high-risk AI systems (Annex III): compliance deadline has moved from 2 August 2026 to 2 December 2027.
  • High-risk AI systems embedded in regulated products (Annex I): compliance deadline has moved from 2 August 2026 to 2 August 2028.

The European Commission has acknowledged that additional time is needed for technical standards to be finalised and regulatory and conformity assessment frameworks to become fully operational.

For many organisations that have been preparing for the original August 2026 deadline, this extension provides breathing space to develop governance frameworks, assess AI use cases and prepare compliance documentation.

 

New prohibited AI practices

The Digital Omnibus also introduces new prohibited AI practices covering systems designed to generate or manipulate realistic non-consensual intimate imagery or material involving identifiable individuals and systems that generate or manipulate child sexual abuse material. The prohibition also captures certain systems where such outputs are reasonably foreseeable and reproducible in the absence of reasonable, proportionate and effective safeguards.

These prohibitions will take effect on 2 December 2026 and reflect increasing concerns about the misuse of AI-generated content and synthetic media.

 

Transparency obligations remain largely unchanged

Transparency obligations relating to AI-generated content, synthetic media and certain AI systems that interact with individuals will continue to apply from 2 August 2026. Limited transitional relief until 2 December 2026 has been introduced for some synthetic content marking requirements where systems were already placed on the market before 2 August 2026. However, many businesses using generative AI tools will need to consider their compliance obligations in the near future.

This means organisations can’t defer all AI compliance activity until 2027 or 2028.

 

Changes to AI literacy requirements

The Digital Omnibus also revises the AI Act's AI literacy provisions.

The amended wording requires organisations to take the measures necessary to develop AI literacy, rather than imposing a more prescriptive obligation of result. 

While businesses should continue investing in staff training and awareness programmes, the revised approach appears intended to provide greater flexibility in how organisations satisfy the requirement.

 

Greater oversight from the AI Office

The Digital Omnibus on AI strengthens the role of the European AI Office in relation to certain aspects of the general-purpose AI regime and oversight of particular AI systems.

At the same time, Member States have been given additional time to establish AI regulatory sandboxes, with the relevant deadline extended until 2 August 2027. These measures are intended to improve consistency and provide greater regulatory certainty as the AI Act is implemented across the EU. 

 

The sanctions framework remains unchanged

Importantly, while certain compliance deadlines have been postponed, the AI Act's enforcement and sanctions framework remains intact.

The Digital Omnibus on AI doesn’t reduce the penalties that may apply for non-compliance once the relevant obligations come into force. Depending on the nature of the breach, organisations may still face significant financial sanctions under the AI Act. The Regulation therefore provides additional preparation time rather than reducing the consequences of future non-compliance. 

 

What hasn't changed?

While the delayed deadlines have dominated headlines, it’s equally important to understand what the Digital Omnibus doesn’t change.

The Regulation leaves intact:

  • The AI Act's risk-based regulatory framework.
  • The core rules and timing for general-purpose AI models, which aren’t deferred by the high-risk deadline changes.
  • The regime for systemic-risk and frontier AI models.
  • The overall sanctions framework.
  • The objective of promoting trustworthy and human-centric AI. 

In short, key obligations have largely been deferred rather than removed and the core structure of the AI Act remains in place.

 

How businesses should prepare for the revised AI Act timeline

Businesses should use the additional implementation period proactively, rather than treating it as a reason to postpone compliance planning.

Key steps may include:

  • Identifying AI systems currently in use across the organisation.
  • Assessing whether any systems could fall within the AI Act's high-risk categories.
  • Reviewing supplier, procurement and contractual arrangements involving AI.
  • Implementing or updating AI governance and acceptable use policies.
  • Assessing transparency obligations associated with generative AI tools.
  • Continuing to develop AI literacy and staff training programmes.
  • Monitoring regulatory guidance and future harmonised standards.

For UK businesses operating in or supplying services to the EU market, the extended timeline should be viewed as an opportunity to strengthen compliance frameworks and reduce future implementation risks.

 

Talk to us

Artificial intelligence regulation is developing rapidly. Organisations need to understand how emerging obligations apply to the AI systems that they develop, procure and use.

Our specialist data protection team advises organisations on AI governance, confidentiality risk and information security — helping you to adopt new technology without undermining existing safeguards.

To discuss how this applies to your organisation, talk to us by giving us a call on 0333 004 4488, sending us an email at hello@brabners.com or completing our contact form.

Paddy Fearnon

Paddy is a Trainee Solicitor in our commercial and intellectual property team.

Read more
Paddy Fearnon

Eleanore Beard

Eleanore is a Legal Director and Data Protection Practitioner in our commercial team.

Read more
Eleanore Beard

Talk to us

Loading form...

Related insights

Data Protection FAQs

Working on laptop at night bokeh

Find answers to our most frequently asked questions about data protection and privacy from our lawyers.

Read more