Digital Omnibus on AI
What is the Digital Omnibus on AI?
The Digital Omnibus on AI is Regulation (EU) 2026/1744, the first substantial rewrite of the EU AI Act. It was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It does not replace the AI Act, it amends it, the way a patch amends software. The AI Act still carries the rules; this regulation says which of them start when, and in what form.
Most of what it does is move dates. The heavy duties for high-risk AI systems, which were supposed to land on 2 August 2026, went back by roughly sixteen months. A handful of substantive changes came along with them: the AI literacy duty is worded more softly, two practices are banned outright, and small companies get a lighter paperwork route.
The name comes from a wider package. In November 2025 the Commission published a set of proposals to simplify EU digital law, covering data protection, cybersecurity reporting and AI. The AI part travelled through Parliament and Council on its own, which is why it arrived as a single regulation in July 2026.
The dates that moved
Four things in the calendar changed.
Stand-alone high-risk systems (Annex III), the list that covers CV screening, credit scoring, worker monitoring, access to education and a set of public-sector uses: from 2 August 2026 to 2 December 2027.
High-risk AI built into regulated products (Annex I), such as machinery, medical devices, lifts and toys: from 2 August 2027 to 2 August 2028.
Machine-readable marking of generated content, for generative systems that were already on the market before 2 August 2026: those providers have until 2 December 2026. Anything put on the market after 2 August 2026 marks from day one.
National regulatory sandboxes, which member states had to have running by 2 August 2026: now 2 August 2027.
The list that did not move matters just as much. The prohibitions in Article 5 have applied since February 2025. The rules for general-purpose AI models have applied since August 2025. The transparency duties in Article 50, so the chatbot disclosure, the deepfake label and the note under AI-written public-interest text, applied on 2 August 2026 and are still in place. So is the AI literacy duty. The fine ceilings are untouched.
What changed besides the calendar
Article 4 now asks for effort instead of a result. The original wording told providers and deployers to guarantee a sufficient level of AI literacy among the people working with their systems. The new wording asks them to take measures that support the development of that literacy, in proportion to the job, the context of use and the people affected. No certificate is prescribed. The duty itself has applied since 2 February 2025 and did not move.
Two new prohibitions. AI systems designed to generate non-consensual intimate imagery, the nudifier apps, and systems designed to generate child sexual abuse material, are banned. The ban reaches systems where that output is a reasonably foreseeable and reproducible result without significant technical modification, so an image generator with no safeguards is not automatically outside it. Providers have until 2 December 2026 to comply.
A simplified route for small companies. The Commission has to publish a simplified technical documentation form for SMEs, start-ups and the newer category of small mid-caps, companies that outgrew the SME definition but stay well short of a large group. A notified body has to accept that form. This only bites if you are the provider of a high-risk system.
Registration stayed. The Commission had proposed dropping the duty in Article 49(2) to register a system in the EU database when the provider has concluded for itself that the system is not high-risk. Parliament and Council kept the duty and trimmed the information it asks for. This was the most contested item in the whole file.
The AI Office got its own enforcement powers. The regulation gives the European AI Office investigation and inspection powers over general-purpose AI and very large online platforms, with fines it can impose itself rather than through a national authority.
Why the deadlines moved, and who objected
The official reason is that the machinery a company needs in order to comply with the high-risk rules was not built yet. The harmonised standards from CEN and CENELEC, which are what a provider points at to show its risk management and data governance are adequate, were running late. The Commission guidance was still in draft. Several member states had not designated or funded the authorities meant to supervise any of it. Without the standards, a provider would have had to guess what an adequate risk management system looks like and then defend the guess.
Underneath that sits an argument that started earlier. Mario Draghi's report on European competitiveness, presented in September 2024, said Europe is falling behind the United States and China in advanced technology and pointed at its own regulatory burden as one of the causes. Industry associations and several governments used that argument to press for a delay. The Commission first proposed tying the start date to the standards actually being ready; Parliament and Council replaced that with fixed dates, and the fixed dates are what passed.
The objection came from the other direction. A joint letter from 127 civil-society organisations and trade unions opposed the wider omnibus package as a rollback of core digital rights, and sixty organisations, public authorities and individuals, European Digital Rights among them, signed a separate letter against the AI part. Their argument was that a deregulation package presented as simplification takes protection away from the people on the receiving end of AI decisions and gives them nothing back, and that dropping the registration duty would have turned a public register into self-declaration. On registration they won. On the delay they did not.
The AI Act in 2024 versus the AI Act now, for a company that is not high-risk
If your AI use sits outside Annex III, and most Belgian SME use does, the omnibus changed close to nothing for you. Worth spelling out, because a lot of the coverage read like a general reprieve.
As adopted in 2024. Prohibitions from February 2025. AI literacy from February 2025. Rules for general-purpose models from August 2025. Transparency duties and the high-risk regime both from August 2026.
After the omnibus. The first three are identical. The transparency duties still started on 2 August 2026. Only the high-risk regime moved, and it moved to a date on which you would not have had duties anyway.
The one change you may actually feel is the softer wording of Article 4. Before, a supervisor could ask you to show that your staff had reached a sufficient level. Now the question is whether you took reasonable measures. A half-day session on what a model can and cannot do, with an attendance list, answers the new question, and it was already the sensible answer to the old one.
What a Belgian SME should do about it
Change the dates in your plan, not the plan. If you had a project to get a recruitment screening tool or a credit scoring model ready for the AI Act by August 2026, you now have until 2 December 2027. Spend it on the work you were about to rush: an inventory of every AI system in use, a defensible risk classification per system, the fundamental rights impact assessment where it applies, and a documentation trail. The date moved once. Betting on a second move is betting on a political process you have no hand in.
Leave your Article 50 work alone. The chatbot on your website still has to say it is a chatbot. Photo-realistic AI images of people, places or events still need a visible label. Nothing there was postponed.
Ask each generative AI vendor one question. If a tool you bought was already on the market before 2 August 2026, its provider had until 2 December 2026 to add machine-readable marking to the output. Ask whether it now does, and write the answer into your AI register next to that tool.
Keep the AI literacy session on the calendar. The wording got softer, the duty did not disappear, and it has applied since February 2025 with no transition period left to lean on.
Know which of the new bans touch your suppliers. The nudification and CSAM prohibitions bind providers, not the companies deploying a tool. You are not the one being fined. You do want to know whether the image generator inside your marketing tool has safeguards, because a provider that has not sorted this out by 2 December 2026 is a supplier risk.