EU signs 'Digital Omnibus' easing parts of AI Act
Amendments delay high‑risk deadlines, ramp up EU AI Office powers and prompt immediate guidance
The European Union has adopted a package of targeted amendments known as the Digital Omnibus that simplify parts of the bloc’s AI Act, reset key implementation dates for high‑risk AI systems, and broaden the powers of the EU AI Office. The co‑legislators reached a provisional agreement in May and the Council gave final approval in early July 2026.
Under the changes, the strictest high‑risk compliance obligations tied to Annex III have been pushed back into late 2027, giving providers and deployers additional time to prepare technical documentation, risk‑management systems, and conformity assessments. The co‑legislators wrote the new timetable into the law as part of the omnibus simplification drive.
At the same time, mandatory transparency duties in Article 50 — requiring disclosure when content is generated or materially manipulated by AI — remain on the original schedule and become enforceable on August 2, 2026. To help with that immediate deadline, the European Commission published guidance for providers and deployers on July 20, 2026.
The Digital Omnibus also inserts new prohibitions and targeted concessions. One notable change writes a ban on non‑consensual intimate‑image generators, so‑called ‘nudification’ apps, into the Act with effect from December 2026, while some documentation and procedural obligations are relaxed for SMEs and small mid‑caps to reduce compliance burden.
A major institutional shift is the strengthening of the Commission’s AI Office. The amendments expand its coordinating role, broaden its power to issue guidance and compliance warnings, and give it a clearer mandate to support implementing acts and technical standards needed to operationalize the regulation.
Those enhanced AI Office powers are already being used. The Commission has rolled out practical guidance and a voluntary Code of Practice on transparency for AI‑generated content; businesses that sign the Code can gain a temporary, guidance‑first enforcement posture from regulators rather than immediate penalties.
National enforcement bodies remain central. Member‑state data protection authorities and designated market‑surveillance authorities will still exercise enforcement on the ground, and several authorities — notably Ireland’s Data Protection Commission, which oversees many U.S. tech platforms’ EU operations — have signaled firms should be prepared for Article 50 obligations on August 2.
For cloud providers, model hosts, and AI vendors the package creates a mixed message: immediate action is required for transparency, provenance and disclosure systems, while the most onerous high‑risk assessment processes have a later deadline. That bifurcation makes near‑term project triage essential for compliance teams.
The implementing acts and harmonised standards that give the AI Act its technical teeth remain in progress. The Commission and standardisation bodies are expected to publish implementing acts on high‑risk classification, conformity assessment and general‑purpose AI models in the months ahead, but timelines for notified bodies and harmonised standards likely stretch into 2027.
Policy bodies and privacy watchdogs welcomed simplification but urged caution. The European Data Protection Board and the European Data Protection Supervisor supported steps to streamline implementation, while also calling for safeguards to ensure fundamental rights are protected as the timetable shifts.
The Digital Omnibus reflects a pragmatic pause: it preserves near‑term transparency rules, delays heavier obligations to allow supporting rules and accreditation processes to mature, and centralises coordination in the AI Office. For vendors and cloud operators that serve European customers, the immediate takeaway is clear — act now on Article 50 transparency, prepare for further Commission implementing acts, and expect the EU AI Office to play a more active compliance role going forward.