27.07.2026
Practice Areas: Intellectual Property and Information Technology
Services: Data Protection and Cybersecurity
Digital Omnibus Regulation on AI: the key amendments to the AI Act
On 24 July 2026, Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026 (the “Digital Omnibus Regulation on AI” or the “Regulation“) was published in the Official Journal of the European Union, amending Regulation (EU) 2024/1689 (the “AI Act“), among others, with the aim of simplifying the application of the harmonised rules on artificial intelligence.
1. Key amendments:
-
- New prohibited practices
The Regulation adds two new prohibitions to Article 5 of the AI Act, applicable from 2 December 2026, and not simultaneously with the remaining prohibitions under the same article, which are already in force.
Accordingly, the placing on the market, putting into service or use of AI systems that:
- create or manipulate non-consensual intimate material; or
- create, manipulate or reproduce child sexual abuse material or performances.
-
- More flexible rules on AI literacy
The AI literacy obligation becomes less demanding. Providers and deployers are no longer required to ensure a sufficient level of AI knowledge. Instead, they are only required to adopt measures that promote the development of such skills, such as training activities or the provision of informational materials.
-
- Reduction of the scope of systems classified as high-risk
The Regulation narrows the definition of “safety component”, reducing the scope of systems covered by the high-risk regime. This concept now only encompasses systems whose purpose is to prevent or mitigate risks to the health and safety of persons or property.
Systems used exclusively to provide assistance, increase convenience, optimise performance, automate processes or carry out quality controls are therefore excluded. However, systems whose failure or malfunction could endanger the health or safety of persons or property are excepted.
-
- Simplification measures for SMEs and small mid-cap companies
The Regulation strengthens support measures for small and medium-sized enterprises (“SMEs“) and introduces the definition of “small mid-cap company”, extending to the latter the flexibility measures previously reserved for SMEs. Key simplification measures include:
- use of a simplified technical documentation form for conformity assessment purposes;
- priority access to AI regulatory sandboxes at national and Union level;
- capped fines and consideration of the economic viability of small mid-cap companies.
-
- New framework for detecting and correcting biases
Article 4a of the AI Act now allows, on an exceptional basis, the processing of special categories of personal data in order to detect and correct biases in AI systems, extending this possibility beyond providers of high-risk systems and subjecting it to strict requirements of necessity, pseudonymisation and data deletion.
-
- Strengthening of innovation and real-world testing mechanisms
The Regulation broadens the possibility of testing AI systems in real-world conditions before their placing on the market, now covering not only Annex III systems but also high-risk systems integrated into regulated products, such as medical devices and vehicles. Member States may also authorise testing in sectors such as aviation and machinery, subject to appropriate safeguards.
-
- AI Office with reinforced competences
The European Commission’s AI Office is granted exclusive supervisory and enforcement competence over certain AI systems, including those based on general-purpose AI models.
To that end, it has investigative powers, being able to request information, carry out inspections, appoint external experts and impose fines and periodic penalty payments. Its decisions are public and subject to the jurisdiction of the Court of Justice of the European Union.
The Regulation also provides for measures to coordinate with sectoral legislation, with a view to reducing the duplication of obligations.
2. Practical implications and next steps
The amendments introduced by the Regulation have direct operational implications, namely:
- Update implementation timelines: compliance projects relating to high-risk systems must be adjusted to the new application deadlines.
- Reassess risk classifications: providers and manufacturers must verify whether systems previously classified as safety components remain covered by the new definition.
- Adapt incident notification procedures: providers of high-risk systems subject to the exclusive competence of the AI Office must report serious incidents directly to that Office.
- Review AI literacy measures: it remains necessary to promote adequate AI knowledge, although ensuring a specific level is no longer mandatory.
3. Application timeline
The application timeline of the AI Act, as amended by the Regulation, is as follows:
| Date | Regulatory milestone |
| 27 July 2026 | Entry into force of the Digital Omnibus Regulation on AI, on an urgent basis. |
| 2 August 2026 | General application of AI Act provisions not yet applicable, including transparency obligations. |
| 2 December 2026 | Application of the new prohibitions relating to non-consensual intimate material and child sexual abuse material; end of the transitional period for the labelling of synthetic content by systems placed on the market before 2 August 2026 |
| 1 August 2027 | Deadline for the Commission to publish guidelines on the articulation of the AI Act with sectoral legislation |
| 2 August 2027 | Deadline for the establishment of national regulatory sandboxes |
| 2 December 2027 | Application of obligations relating to high-risk AI systems under Annex III, including systems used in the fields of biometrics, employment, law enforcement, migration and justice |
| 2 August 2028 | Application of obligations relating to high-risk AI systems under Annex I, including systems integrated into certain regulated products |
| 2 August 2030 | Adaptation deadline for high-risk AI systems intended for use by public authorities |