Guide · Last reviewed 26 August 2026
The Digital Omnibus on AI: what Regulation (EU) 2026/1744 actually changed
The Digital Omnibus on AI — Regulation (EU) 2026/1744, adopted 8 July 2026, published in the Official Journal 24 July 2026, in force 27 July 2026 — amended the EU AI Act: it moved the high-risk deadlines to 2 December 2027 (Annex III) and 2 August 2028 (Annex I), softened Article 4 AI literacy, added CSAM/NCII prohibitions applying from 2 December 2026, inserted Article 4a on bias detection, extended SME fine relief to small mid-caps, and moved machinery to Annex I Section B.
Last reviewed: 26 August 2026 · Primary source: Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744.
The instrument: dates and identity
Get the citation right, because much online commentary does not: the amending act is Regulation (EU) 2026/1744, commonly called the Digital Omnibus on AI. It was adopted on 8 July 2026, published in the Official Journal on 24 July 2026, and entered into force on 27 July 2026 — three days after publication. References to a 'Digital Omnibus of June 2026' describe the political agreement stage, not the law. The Omnibus amends Regulation (EU) 2024/1689 in place; there is no separate parallel regime, and consolidated versions of the AI Act now incorporate the changes.
The headline effect is a rebalanced timeline: the general framework that took effect on 2 August 2026 stands, while the heaviest obligations — the high-risk regime — shift to 2 December 2027 (Annex III) and 2 August 2028 (Annex I Section A), with 2 August 2030 as the longstop for certain pre-existing public-authority systems.
Article 4 softened: 'support the development of' AI literacy
The Omnibus rewrote Article 4. Providers and deployers must now take measures to 'support the development of' a sufficient level of AI literacy among their staff and other persons operating or using AI systems on their behalf, taking into account technical knowledge, experience, education and training and the context of use. The amendment makes explicit that there is no duty to guarantee a particular literacy level for any individual, and that formal training is one possible measure among several — usage guidance, briefings and documented onboarding also qualify. The obligation remains real and ongoing; what changed is the standard: reasonable supporting measures, not certified outcomes. Companies should relabel any fixed training cadences or retention periods in their policies as internal choices — Article 4 prescribes neither. Full guide: Article 4 AI literacy.
New prohibitions: CSAM and non-consensual intimate imagery (2 December 2026)
The Omnibus inserted new prohibitions into Article 5 targeting AI systems that generate or manipulate child sexual abuse material and non-consensual intimate imagery of identifiable persons. Two things matter for compliance planning:
- Timing: these prohibitions apply from 2 December 2026 — they were never part of the original 2 February 2025 prohibition set, and the old line 'Article 5 has no grace period' is no longer accurate for them.
- Scope for providers: the provider-level prohibition is conditional, not absolute. It bites where such content is the system's intended purpose, or a reasonably foreseeable and reproducible outcome — by reason of design, training, architecture or capabilities — in the absence of adequate safeguards. A general-purpose generative system with proportionate safeguards is not banned merely because misuse is conceivable.
Deployers and providers should extend their Article 5 screening accordingly before December 2026; criminal liability for such content additionally arises under national laws implementing EU law, separately from the AI Act.
New Article 4a: a legal basis for bias detection, not a bias-testing duty
The Omnibus moved the special-categories-of-data mechanism formerly in Article 10(5) into a new Article 4a and broadened it. Providers of high-risk AI systems — and now also providers and deployers of other AI systems and models — may process special categories of personal data where strictly necessary for detecting and correcting bias, subject to safeguards: technical limits on re-use, security and pseudonymisation measures, strict access controls, deletion once the bias is corrected, and documentation of the processing. Equally important is what Article 4a is not: it explicitly creates no general obligation to carry out bias detection or correction. It is a GDPR-compatible permission for those who do that work, not a new duty for everyone.
Fine relief for SMEs and small mid-caps; machinery moved; post-market changes
Penalties. Article 99(6) already capped fines for SMEs and start-ups at the lower of the percentage or fixed amount (whereas most undertakings face whichever is higher). The Omnibus extends this proportionate treatment to the new small mid-cap (SMC) category — enterprises below roughly 750 employees within defined turnover and balance-sheet ceilings, per Commission Recommendation (EU) 2025/1099. Details: AI Act fines.
Machinery. The Machinery Regulation (EU) 2023/1230 moved from Annex I Section A to Section B: AI-enabled machinery leaves the AI Act's direct high-risk conformity path, and AI safety requirements will instead be integrated into machinery law via Commission delegated and implementing acts. The Omnibus also narrowed the 'safety component' definition (Article 3(14)) to functions whose intended purpose is preventing or mitigating health-and-safety risks.
Post-market monitoring. The former Article 72(3) empowerment for an implementing act establishing a monitoring-plan template (originally due 2 February 2026, never adopted) was removed; the Commission must instead adopt guidance, including a template, by 2 September 2027. The Omnibus also strengthened the AI Office's market-surveillance role under Article 75 for AI systems built on a general-purpose model from the same provider, and for systems integrated into very large online platforms.
What the Omnibus did NOT change
Just as important for planning:
- The original Article 5 prohibitions stand unchanged and have applied since 2 February 2025.
- Article 50 transparency duties took effect on 2 August 2026 as scheduled — the only relief is the marking grace period to 2 December 2026 for generative systems on the market before 2 August 2026. There is still no SME exemption in Article 50(2).
- The Article 49(2) registration duty for Article 6(3) self-assessments was retained — the proposal to abolish it was rejected (only two data points of Annex VIII Section B were deleted).
- The GPAI framework (Chapter V) continues to apply since 2 August 2025, with fines of up to €15 million or 3% enforceable since August 2026.
- The substance of the high-risk requirements (Articles 8-15, conformity assessment, registration) is intact — only the calendar moved.
In short: the Omnibus bought time on high-risk and trimmed edges elsewhere; it did not shrink the core compliance programme. Our compliance checklist reflects the amended state of the law throughout.
Related reading
- Compliance Calendar template
- Prohibited-Practices Screening template
- AI Literacy Policy template
- Risk Classification Assessment template
- Post-Market Monitoring Plan template
- The EU AI Act, explained
- Timeline & deadlines
- High-risk AI systems
- EU AI Act for SMEs
- Fines & the SME cap
- AI literacy (Article 4)
Frequently asked
When did the Digital Omnibus enter into force?+
Regulation (EU) 2026/1744 was adopted on 8 July 2026, published in the Official Journal on 24 July 2026, and entered into force on 27 July 2026.
Did the Omnibus delay the whole AI Act?+
No. It moved the high-risk deadlines (Annex III to 2 December 2027, Annex I to 2 August 2028). The prohibitions, Article 4 literacy, Article 50 transparency and GPAI rules apply on their original schedule — and the Omnibus added new prohibitions applying from 2 December 2026.
Does Article 4a require us to test our AI for bias?+
No. Article 4a permits processing special categories of personal data where strictly necessary for bias detection and correction, under strict safeguards. It explicitly creates no general obligation to carry out bias detection or correction.
Are the new CSAM/NCII prohibitions an outright ban on generative AI?+
No. For providers the prohibition applies where such content is the intended purpose or a reasonably foreseeable and reproducible outcome and adequate safeguards are not in place. Generative systems with proportionate safeguards are not banned merely because misuse is possible.
Did the Omnibus remove the registration duty for Article 6(3) self-assessments?+
No. The Commission's proposal to drop registration was rejected; providers relying on Article 6(3) must still document the assessment and register under Article 49(2). Only two data points of Annex VIII Section B were deleted.