•
•
8 min read time
What changed
The EU's Digital Omnibus on AI is no longer a proposal. Regulation (EU) 2026/1744, which amends the EU AI Act, was adopted by the European Parliament and the Council on 8 July 2026, published in the Official Journal on 24 July, and entered into force on 27 July 2026, three days before the AI Act's original 2 August 2026 general application date. The European Commission confirmed the entry into force the same week. Executive Vice-President Henna Virkkunen has described the package as giving businesses "simpler and innovation-friendly rules" while "not lowering the bar on safety."
For enterprise AI governance teams, this matters because it removes the uncertainty that has shaped planning since the Omnibus was first proposed in November 2025. Until last week, the sensible advice was to treat the delay as contingency and keep building towards the original August 2026 deadline. That advice has now changed, because the delay is confirmed law with fixed backstop dates.
New deadlines for high-risk AI systems
The core change is timing. High-risk AI systems fall into two groups under the AI Act, and each now has a different, later deadline:
Standalone high-risk systems under Annex III (covering areas such as recruitment and worker management, credit scoring and creditworthiness assessment, biometric identification and categorisation, education and vocational training, access to essential services, and law enforcement) now have until 2 December 2027 to meet the full set of high-risk requirements. That is a deferral of roughly 16 months from the original date.
AI systems embedded in regulated products under Annex I (for example, safety components in machinery, medical devices, or aviation systems) now have until 2 August 2028, a 12-month deferral.
Both dates are described as backstops: they apply regardless of whether the harmonised technical standards that AI providers were originally meant to rely on have been finalised. That decoupling from the standards timeline was one of the more technical but consequential fixes in the Omnibus, because it removes a dependency that many providers and deployers had flagged as unworkable.
A new prohibition on AI-generated intimate imagery
The Omnibus does not only push deadlines back. It adds two new prohibited practices to Article 5 of the AI Act: placing on the market or using AI systems designed to generate, or that make it reasonably foreseeable will generate, child sexual abuse material, and AI systems that generate non-consensual intimate imagery of identifiable people, including so-called "nudifier" tools. This prohibition applies from 2 December 2026.
The scope is broader than purpose-built nudifier apps. General-purpose generative AI providers can also fall within it if such outputs are reasonably foreseeable in the absence of effective safeguards. There is a safe harbour for providers who put in place reasonable, proportionate and effective preventive measures, so this is a live design and documentation question for any organisation running or procuring image or video generation tools, not just a legal one. Penalties for breaching this prohibition sit at the top tier: up to €35 million or 7% of worldwide annual turnover, whichever is higher.
Other simplifications worth noting
A handful of smaller changes round out the package. The Commission has removed the requirement for providers to use a mandatory template for post-market monitoring plans. The regulatory sandbox regime has been expanded, including new EU-level sandboxes and coverage for some Annex I high-risk systems. Simplifications that were previously limited to small and medium enterprises now extend to small mid-cap companies. And the AI Office's supervisory scope has been broadened to reach AI systems built on general-purpose AI models within the same corporate group as the model provider, and to AI systems that are embedded in, or constitute, Very Large Online Platforms or Search Engines under the Digital Services Act.
What did not change
The most common misreading of this news is that "the AI Act got delayed," full stop. It did not. Several obligations are untouched and still land on their original dates.
Article 50 transparency rules still apply from 2 August 2026
The transparency obligations under Article 50 of the AI Act were not part of the Omnibus's deferral and still take effect on 2 August 2026, three days after this regulation entered into force. That means, from this weekend:
Providers of chatbots and other systems intended to interact with people must design them so users are informed they are talking to an AI.
Deployers using AI to create deepfakes must disclose that content has been artificially generated or manipulated.
Deployers publishing AI-generated text on matters of public interest must disclose that it is AI-generated, unless the text has undergone human review with an accountable natural or legal person taking editorial responsibility.
The Commission adopted final guidelines on these obligations on 20 July 2026, less than two weeks before they bite. Penalties for non-compliance reach €15 million or 3% of worldwide turnover. Teams that have been treating "the deadline moved" as a reason to slow down on transparency work should not: this is the one part of the original timeline that stayed exactly where it was.
Prohibited practices, GPAI obligations and AI Office enforcement powers are unaffected
The original Article 5 list of prohibited practices, in force since February 2025, is unchanged. General-purpose AI model obligations around transparency, copyright and systemic risk documentation, in force since August 2025, are unchanged. And critically, the Commission's enforcement powers over GPAI providers, including requests for information, model evaluation, corrective measures and the ability to restrict or withdraw a model from the EU market, still activate on 2 August 2026. The high-risk delay is a delay for high-risk systems. It is not a delay for the GPAI models many enterprises build on top of, and it is not a delay for transparency.
The penalty structure has not softened
The Omnibus simplifies process and timing. It does not reduce fines. The two-tier penalty structure, up to €35 million or 7% of worldwide turnover for the most serious breaches and up to €15 million or 3% for others, still applies in full, and now covers the new CSAM/NCII prohibition as well.
Five things to do this week
1. Correct the compliance calendar and the board deck
If your last board briefing said "we are working towards 2 August 2026 for high-risk systems, pending a possible delay," that line is now wrong in two ways: the delay is confirmed, and the new dates are specific (2 December 2027 for Annex III, 2 August 2028 for Annex I). Update the calendar and reissue the briefing this week so nobody is planning against a deadline that no longer exists, or assuming relief that does not extend to transparency obligations.
2. Finish the Article 50 work regardless of the delay
Chatbot disclosure, deepfake labelling and AI-generated text labelling still apply from 2 August 2026. If any part of your organisation has quietly deprioritised this because "the AI Act got pushed back," reverse that now. A clean AI inventory is the fastest way to find every chatbot, image generator and content tool that needs a disclosure mechanism before the weekend.
3. Screen generative AI tools for CSAM/NCII exposure ahead of December
You have four months, not four weeks, before the new prohibition bites on 2 December 2026, but the safe harbour requires "reasonable, proportionate and effective" preventive safeguards to already be built in, not bolted on after a complaint. Start now with any image or video generation capability, whether built in-house or procured, and document the safeguards as you go. This overlaps with existing deepfake governance work many teams already have underway.
4. Do not stand down high-risk AI system work, redirect it
An extra 16 months is real relief, but it is relief on timing, not on scope. The classification, documentation, conformity assessment and human oversight work for Annex III systems still needs to happen, and now you have room to do it properly instead of racing a deadline. Use the runway to build (or finish building) a defensible EU AI Act classification and control framework rather than shelving the project.
5. Re-check GPAI vendor documentation before 2 August
The AI Office's enforcement powers over general-purpose AI providers activate on 2 August 2026, and its supervisory reach has been extended to systems built on GPAI models within the same corporate group and to GPAI-embedded systems on very large platforms. If your organisation relies on third-party foundation models, this is a good week to pull current model documentation and confirm your vendor risk file is current, not scrambling for it after the Commission starts asking questions.
Where Enzai helps
Deadline changes like this one are exactly why AI governance needs to live in one place rather than in a set of spreadsheets and calendar reminders. Enzai's compliance frameworks track obligations against the dates that actually apply, so when a regulation like this one moves a deadline, the change propagates through your control library instead of sitting in an email thread. The AI inventory product is the practical starting point for both the Article 50 work due in days and the Annex III work due in 2027, since you cannot classify or govern a system you have not catalogued. And for teams tracking obligations across jurisdictions, not just the EU, our EU AI Act hub sets out the full picture, including the new high-risk deadlines and the unchanged Article 50 dates.
Empower your organization to adopt, govern, and monitor AI with enterprise-grade confidence. Built for regulated organizations operating at scale.








