AI Omnibus comes into force: extended timeline and administrative simplification
The first major amendment to the EU AI Act has entered into force, introducing longer implementation timelines for key obligations, reducing regulatory overlap and simplifying compliance requirements for businesses. While the AI Omnibus provides organisations with additional time to prepare for certain high-risk AI obligations, several transparency requirements remain unchanged and will continue to apply from 2 August 2026. The AI Omnibus became applicable across the European Union on 27 July 2026. The reforms are intended to ease administrative burdens, improve legal certainty and create a more proportionate compliance framework, particularly for smaller businesses and companies developing innovative AI solutions.
1. Extended deadlines for high-risk AI systems
One of the most significant changes concerns the implementation timeline for high-risk AI systems. Obligations relating to stand-alone high-risk AI systems listed in Annex III of the AI Act have been postponed until 2 December 2027, while requirements for high-risk AI systems embedded in products covered by Annex I will apply from 2 August 2028. These extensions provide organisations with additional time to assess their AI portfolios, implement governance frameworks and prepare the documentation and processes required under the AI Act.
2. New prohibited AI practices
The AI Omnibus also introduces new prohibited AI practices. From 2 December 2026, AI systems designed to generate non-consensual intimate content, commonly referred to as “nudifier” applications, will be prohibited. The same prohibition will apply to AI systems generating child sexual abuse material. These additions reflect growing concerns regarding the misuse of generative AI technologies and the need for targeted safeguards against particularly harmful applications.
3. Reducing overlap with sector-specific regulation
The amendments aim to reduce duplication between the AI Act and existing sectoral legislation. The European Commission is now empowered to limit the application of certain AI Act requirements where equivalent obligations already exist under sector-specific frameworks, such as those governing medical devices, toys and elevators. In addition, products regulated under the Machine Regulation are no longer subject to direct applicability under the AI Act framework in the same manner as before. This development should help reduce compliance burdens for organisations operating in heavily regulated sectors that are already subject to detailed product safety and conformity assessment requirements.
4. A more flexible approach to AI literacy
The AI Omnibus also revises the AI literacy obligation. Under the amended text, providers and deployers are required to “support the development” of AI literacy rather than ensure “a sufficient level” of AI literacy as in the current version. The legislation now expressly clarifies that organisations are not required to guarantee any specific level of AI literacy for individual persons. The amendments place greater emphasis on support from the European Commission and Member States, providing businesses with a more practical and proportionate framework for meeting this requirement.
5. Bias detection and the use of sensitive personal data
The reforms provide additional clarity regarding bias detection in high-risk AI systems. The processing of special categories of personal data is now expressly permitted where necessary to detect and correct bias in high-risk AI systems. This clarification is intended to facilitate the development of fairer and more reliable AI systems while maintaining the broader safeguards applicable to sensitive personal data.
6. Expanded support for SMEs and innovation
Simplified compliance measures previously available to SMEs have been extended to include small mid-cap companies. As a result, a substantially larger group of organisations will benefit from a more proportionate regulatory approach. The AI Omnibus also expands access to regulatory sandboxes and introduces a new EU-level sandbox operating under regulatory supervision. The deadline for Member States to establish national AI regulatory sandboxes has been extended to 2 August 2027. These changes are intended to encourage innovation by providing organisations with greater opportunities to test and develop AI systems within controlled regulatory environments.
7. Transparency requirements remain a priority
Despite the extended deadlines for many high-risk obligations, certain transparency requirements remain unchanged. Providers of AI systems generating synthetic audio, image, video or text content that are already on the market have only until 2 December 2026 to implement the required transparency measures for AI-generated content. In addition, transparency obligations for deployers under Article 50(3) and 50(4), as well as obligations for providers of AI systems intended to interact directly with natural persons under Article 50(1), remain unchanged and become applicable on 2 August 2026. Organisations should therefore ensure that any required transparency mechanisms are implemented without delay.
8. Key takeaway
The AI Omnibus provides businesses with additional time to prepare for high-risk AI compliance while reducing regulatory overlap and introducing a more proportionate approach for a wider range of companies. However, the extension of certain deadlines should not be viewed as a reason to delay compliance preparations. Organisations should continue to map their AI systems, assess their risk classifications, review applicable obligations and implement any required transparency measures. While the regulatory timetable has become more flexible, the direction of travel remains unchanged: robust AI governance and compliance frameworks will continue to be essential for organisations operating in the European AI ecosystem.
Download the Client Alert in English