Key upcoming changes introduced under the EU Digital Omnibus on AI
The question
What is the Digital Omnibus on AI (Digital Omnibus)? And how might it affect businesses operating in the EU digital and technology sectors?
The key takeaway
The Digital Omnibus makes targeted amendments to the EU AI Act. Its main aims are to give businesses and regulators more time to prepare for the high-risk AI requirements and to simplify or clarify parts of the regime. The Omnibus does not repeal or fundamentally rewrite the AI Act.
Key changes include: revised deadlines for high-risk AI systems; a new prohibition targeting “nudifier” and child sexual abuse material applications; a transitional period for certain transparency obligations; narrower rules on safety components; measures to reduce overlap with product legislation; broader permission to process sensitive data for bias correction; additional support for small mid-cap enterprises; and changes to the AI literacy and regulatory sandbox requirements.
The background
The EU AI Act, which entered into force in August 2024, introduced a risk-based framework for the development and use of AI in the EU, with the most stringent obligations applying to “high-risk” systems. Under the original timetable, the first wave of requirements was due to apply from 2 August 2026, with the regime for high-risk AI embedded in regulated products following from 2 August 2027. As the first deadline approached, concerns emerged that key compliance infrastructure (including harmonised standards, guidance, national governance arrangements and the conformity-assessment framework) would not be fully in place, and industry queried how the AI Act would interact with existing sector-specific product and safety rules.
Against this background, on 19 November 2025 the Commission presented a broader “Digital Package” aimed at simplifying digital and AI regulation, comprising:
- a general Digital Omnibus amending data, cybersecurity and related digital rules, and
- a Digital Omnibus on AI targeting the AI Act and related product legislation.
The development
The Digital Omnibus officially came into force on 27 July 2026. The principal changes are:
- New deadlines for high-risk AI: The high-risk AI regime is postponed. High-risk systems under Article 6(2) and Annex III (eg recruitment, education, credit scoring, access to public services, and law enforcement) now apply from 2 December 2027. High-risk systems under Article 6(1) used as safety components of products regulated under the EU product-safety legislation listed in Annex I (eg AI-enabled machinery, medical devices, toys, vehicles and lifts) now apply from 2 August 2028.
- “Nudifier” prohibition: A new prohibited AI category is introduced, namely systems intended, or foreseeably capable of, generating or manipulating non-consensual intimate material or child sexual abuse material. Providers are restricted from placing such systems on the market or putting them into service, and use of AI systems for these purposes is prohibited. In-scope providers and deployers must comply by 2 December 2026.
- Grace period for transparency obligations: Under Article 50(2), providers of systems generating synthetic audio, image, video or text must mark outputs in a machine-readable format and ensure outputs are detectable as artificially generated/manipulated. A four-month transitional period applies for systems placed on the market before 2 August 2026, with compliance due by 2 December 2026. The 2 August 2026 deadline remains for systems placed on the market on/after that date and for other Article 50 transparency obligations.
- Reducing duplication with sector-specific product rules: The Commission may limit certain AI Act requirements for Article 6(1) high-risk systems where Section A of Annex I product rules provide equivalent or higher protection (without reducing overall protection). Delegated acts on operation are due by 02/08/2027.
- For AI-enabled machinery, most AI Act requirements will no longer apply directly: Equivalent AI-related health and safety requirements will be incorporated into the EU Machinery Regulation via delegated acts.
- Narrower definition of “safety component”: AI embedded in a product is a “safety component” where it performs a safety function (preventing/reducing risks to people/property) or where failure/malfunction could endanger people/property. AI used only for assistance/optimisation/ efficiency/automation/convenience/non-safety quality control generally falls outside of the definition’s scope.
- Expanded permission to process sensitive data for bias correction: The limited legal basis for processing special-category personal data for bias detection and correction is extended beyond providers of high-risk AI systems to certain providers and deployers of other AI systems and models
- Small mid-cap protections: Simplification measures are extended to small mid-cap enterprises (simplified technical documentation, proportionate implementation of quality management, and proportionate penalties).
- Revised AI literacy requirement: Article 4 shifts from ensuring staff have “sufficient AI literacy” to an obligation to take measures supporting AI literacy development.
- Extended deadline and EU-level AI sandbox: Member States have until 2 August 2027 to ensure at least one national AI regulatory sandbox is operational. The AI Office may establish an EU-level sandbox (priority access for SMEs, start-ups and small mid-caps).
Why is this important?
The Digital Omnibus introduces key protections while aiming to simplify the regulatory regime. Postponing the application of certain obligations gives providers, businesses and Member States more time to prepare and achieve compliance.
The changes may also reduce the number of systems caught by the most demanding requirements. A narrower definition of “safety component”, and measures to address overlap with product legislation, should limit duplicate regulation and conformity assessment. This is particularly relevant for medical devices, machinery, toys and lifts, where classification affects development costs, approval routes and time to market. However, much of this relief depends on further delegated acts and guidance.
Any practical tips?
Businesses operating in, or supplying technology into, the EU should consider:
- updating high-risk AI compliance roadmaps for the revised 2027/2028 deadlines
- auditing AI-generated content tools already on the market and implementing the required machine-readable marking and detection measures by 2 December 2026
- reassessing AI-enabled products against the narrower “safety component” definition and updating classifications, technical documentation, and compliance plans where necessary
- identifying systems capable of generating/manipulating non-consensual intimate material or child sexual abuse material, and withdrawing, disabling or redesigning prohibited functionality by 2 December 2026
- mapping overlap with sector product rules, without assuming that overlapping AI Act requirements have been removed before the relevant delegated acts and guidance are adopted
- maintaining proportionate AI literacy measures for those involved in operating AI systems
- tightening AI supply-chain contracts to explicitly include responsibility allocation, cooperation, and monitoring/change, and
- monitoring regulatory guidance, standards and further legislation.
Autumn 2026
Stay connected and subscribe to our latest insights and views
Subscribe Here