EU Digital Omnibus (AI)
Digital Omnibus on AI Regulation Proposal
Amendments to the EU AI Act (Regulation (EU) 2026/1744, in force July 27, 2026) that delay high-risk AI system obligations by up to 16 months, make compliance timing conditional on availability of harmonised standards and support tools, and add a new Article 5 prohibition on AI systems for generating non-consensual intimate imagery (nudification tools) and CSAM.
Jurisdiction
European Union
Enacted
Jun 29, 2026
Effective
Jul 27, 2026
Enforcement
European Commission, Member State authorities
Adopted as Regulation (EU) 2026/1744 of 8 July 2026. Published in the Official Journal on July 24, 2026; enters into force on July 27, 2026, the third day following publication.
EUR-Lex — Regulation (EU) 2026/1744 (Digital Omnibus on AI)Why It Matters
If adopted, would provide additional time for AI Act compliance preparation, particularly for high-risk AI systems. Creates uncertainty about enforcement timeline.
Recent Developments
Published in the Official Journal on July 24, 2026 as Regulation (EU) 2026/1744, amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230. Recital 46 provides for entry into force on the third day following publication, on an urgency basis, ahead of the general application of the AI Act. Substantive deferrals are unchanged: Annex III high-risk obligations to December 2, 2027, Annex I high-risk to August 2, 2028, and regulatory sandboxes to August 2, 2027.
At a Glance
Harms addressed
Requires
Who Must Comply
- Providers of high-risk AI systems
- Deployers of high-risk AI systems
- Providers of AI systems generating synthetic content
Safety Provisions
- High-risk AI system requirements (Annex III) delayed to December 2, 2027 (long-stop date)
- High-risk systems in regulated products delayed to August 2, 2028 (long-stop date)
- AI-generated content labeling (Art. 50) deadline extended to February 2, 2027 for existing systems
- Earlier compliance if Commission confirms sufficient support measures are available
- Removes mandatory AI literacy obligation for providers/deployers (shifts to member states)
- New Article 5 prohibition on AI systems intended to generate non-consensual sexual/intimate imagery or CSAM, applicable December 2, 2026; providers liable where prohibited output is a reasonably foreseeable outcome absent adequate technical safeguards
Compliance & Enforcement
Key Dates
Dec 2, 2026
New Article 5 prohibition on AI systems intended to generate non-consensual intimate imagery or CSAM becomes applicable (end of transitional period; top penalty tier, up to EUR 35M or 7% turnover)
Dec 2, 2027
Deferred Annex III high-risk obligations apply (long-stop date)
Aug 2, 2028
Deferred Annex I regulated-product high-risk obligations apply (long-stop date)
View on map
European Union
Focus Areas
Cite This
APA
European Union. (2026). Digital Omnibus on AI Regulation Proposal.
Related Regulations
EU AI Act
World's first comprehensive risk-based regulatory framework for AI systems. Classifies AI by risk level with escalating requirements from prohibited practices to high-risk obligations.
EU CRA
Mandatory cybersecurity requirements for all products with digital elements placed on the EU market, including AI software. Requires security by design, vulnerability handling, incident reporting to ENISA, software bills of materials, and CE marking for market access.
Italy AI Act
First EU member state comprehensive national AI law complementing the EU AI Act. 28 articles covering AI governance principles, sector-specific rules for healthcare, employment, justice, and public administration, criminal provisions, copyright protections, and a EUR 1 billion AI investment fund.
Singapore OSRA
Creates a dedicated Online Safety Commission (OSC) with powers to order takedowns and disable access, establishes statutory torts providing victims of online harms with direct civil remedies against platforms and perpetrators.
FR SREN
France's 2024 "digital space" law strengthening national digital regulation and enforcement levers via ARCOM across platform safety and integrity issues.
DE JuSchG §24a (KidD)
Requires providers of certain telemedia services to implement provider-side precautionary measures ("Vorsorgemaßnahmen") with regulator-facing evaluability via published BzKJ criteria.
Last updated August 3, 2026. Verify against primary sources before relying on this information.