Digital Omnibus on AI to delay EU AI Act — what businesses need to know

We examine the key changes introduced by the Digital Omnibus on AI, what remains unchanged and how businesses should respond.
Talk to us: 0333 004 4488 | hello@brabners.com | Contact us
AuthorsPaddy FearnonEleanore Beard
6 min read

The European Commission has pursued a wider Digital Omnibus simplification agenda across parts of the EU's digital regulatory framework. One element of that agenda is the Digital Omnibus on AI — now enacted through Regulation (EU) 2026/1744 — which makes targeted amendments to the EU AI Act, the Machinery Regulation and certain aviation legislation.
The Digital Omnibus on AI introduces the first significant amendments to the EU AI Act since its adoption in 2024. Regulation (EU) 2026/1744 entered into force on 27 July 2026 and revises parts of the AI Act's implementation timetable while preserving its fundamental risk-based framework. The intention isn’t to rewrite the AI Act or reduce protections for individuals. Instead, the Digital Omnibus seeks to provide additional time and regulatory clarity while maintaining the AI Act's central objectives of promoting trustworthy AI and protecting health, safety and fundamental rights.
These EU AI Act Digital Omnibus changes are particularly significant for organisations developing, deploying or procuring AI systems as they postpone several key compliance deadlines that businesses had been working towards. However, the Omnibus doesn’t delay the whole AI Act. Some obligations remain on track, meaning that organisations can’t afford to pause their AI compliance programmes altogether. The changes will have important implications for compliance strategies, procurement decisions and AI governance frameworks over the coming years.
Here Paddy Fearnon and Eleanore Beard from our data protection team examine the key changes introduced by the Digital Omnibus on AI, what remains unchanged and how businesses should respond.
The Digital Omnibus postpones obligations relating to certain high-risk AI systems:
The European Commission has acknowledged that additional time is needed for technical standards to be finalised and regulatory and conformity assessment frameworks to become fully operational.
For many organisations that have been preparing for the original August 2026 deadline, this extension provides breathing space to develop governance frameworks, assess AI use cases and prepare compliance documentation.
The Digital Omnibus also introduces new prohibited AI practices covering systems designed to generate or manipulate realistic non-consensual intimate imagery or material involving identifiable individuals and systems that generate or manipulate child sexual abuse material. The prohibition also captures certain systems where such outputs are reasonably foreseeable and reproducible in the absence of reasonable, proportionate and effective safeguards.
These prohibitions will take effect on 2 December 2026 and reflect increasing concerns about the misuse of AI-generated content and synthetic media.
Transparency obligations relating to AI-generated content, synthetic media and certain AI systems that interact with individuals will continue to apply from 2 August 2026. Limited transitional relief until 2 December 2026 has been introduced for some synthetic content marking requirements where systems were already placed on the market before 2 August 2026. However, many businesses using generative AI tools will need to consider their compliance obligations in the near future.
This means organisations can’t defer all AI compliance activity until 2027 or 2028.
The Digital Omnibus also revises the AI Act's AI literacy provisions.
The amended wording requires organisations to take the measures necessary to develop AI literacy, rather than imposing a more prescriptive obligation of result.
While businesses should continue investing in staff training and awareness programmes, the revised approach appears intended to provide greater flexibility in how organisations satisfy the requirement.
The Digital Omnibus on AI strengthens the role of the European AI Office in relation to certain aspects of the general-purpose AI regime and oversight of particular AI systems.
At the same time, Member States have been given additional time to establish AI regulatory sandboxes, with the relevant deadline extended until 2 August 2027. These measures are intended to improve consistency and provide greater regulatory certainty as the AI Act is implemented across the EU.
Importantly, while certain compliance deadlines have been postponed, the AI Act's enforcement and sanctions framework remains intact.
The Digital Omnibus on AI doesn’t reduce the penalties that may apply for non-compliance once the relevant obligations come into force. Depending on the nature of the breach, organisations may still face significant financial sanctions under the AI Act. The Regulation therefore provides additional preparation time rather than reducing the consequences of future non-compliance.
While the delayed deadlines have dominated headlines, it’s equally important to understand what the Digital Omnibus doesn’t change.
The Regulation leaves intact:
In short, key obligations have largely been deferred rather than removed and the core structure of the AI Act remains in place.
Businesses should use the additional implementation period proactively, rather than treating it as a reason to postpone compliance planning.
Key steps may include:
For UK businesses operating in or supplying services to the EU market, the extended timeline should be viewed as an opportunity to strengthen compliance frameworks and reduce future implementation risks.
Artificial intelligence regulation is developing rapidly. Organisations need to understand how emerging obligations apply to the AI systems that they develop, procure and use.
Our specialist data protection team advises organisations on AI governance, confidentiality risk and information security — helping you to adopt new technology without undermining existing safeguards.
To discuss how this applies to your organisation, talk to us by giving us a call on 0333 004 4488, sending us an email at hello@brabners.com or completing our contact form.
Paddy Fearnon
Paddy is a Trainee Solicitor in our commercial and intellectual property team.
Read more
Eleanore Beard
Eleanore is a Legal Director and Data Protection Practitioner in our commercial team.
Read more
Loading form...

We examine the key changes introduced by the Digital Omnibus on AI, what remains unchanged and how businesses should respond.

We explore the legal issues under consideration by the ICO and Ofcom and what the case tells us about the UK's future regulation of AI-generated content.

What can we learn from the BrewDog shareholder emails? We outline key compliance risks and practical steps to consider before sending communications.

We explore the allegations against Roblox, wider challenges of protecting children online and steps that platforms are expected to take.

We explore how the Housing Ombudsman’s role is changing and outline the practical steps to remain compliant.

We explain why uncontrolled use of public AI tools creates real confidentiality and data protection risks and outline how you can manage them safely.

We delve into the key changes coming into force on 19 June 2026 and explain how businesses should prepare.

We explore the implications of the attacks for UK businesses and outline the practical measures that can help to mitigate similar disruption.

We explore why retailers are particularly affected by deepfakes and the implications around data protection, IP, advertising compliance and more.

We explore how AI is transforming data protection, the risks that organisations now face and what effective compliance looks like today.

We break down what the ICO found and outline three key steps that UK businesses should take now.

We look at the UK GDPR and the Data Protection Act 2018 and outline how the GDPR can apply to both organisations and individuals as data controllers.

We break down the key proposed reforms in the Digital Omnibus Package and outline what businesses should do to prepare.

Find answers to our most frequently asked questions about data protection and privacy from our lawyers.

We explore the key developments that in-house lawyers should have on their radar and what they mean for your organisation in the year ahead.

We explain the impact of the cyber-attack on JLR's workforce and outline what to do to protect your business and minimise the impact if an incident occurs.

We outline eight key steps to put your organisation in the strongest position for a prompt and effective response to any cyber-attack.

We explore how charities will need to manage their marketing activities and supporter consent once the secondary legislation takes effect.

We explore how weak cybersecurity and slow responses can trigger major data breaches and resulting ICO fines.

The EU Data Act is a regulation designed to reshape the European data economy by establishing harmonised rules for data access, sharing and portability.

Designed to amend the UK’s existing data privacy regime, the DUA Act will affect the UK GDPR, PECR and the Data Protection Act 2018.

We delve further into cyber attacks on three major retailers and outline five key steps to take in any cyber-attack preparedness and response plan.

The EU Commission handed out fines of €500m and €200m to Apple and Meta respectively. We outline each fine and the legality of 'consent or pay' models.

Prevention is always better than cure. Assess your compliance with data protection law and the changes that could lie ahead in the year to come.

Athletes might be asked to provide highly sensitive forms of personal data when competing. Here's eight steps to comply with data protection legislation.