AI Act: How the Digital Omnibus on AI Postpones and Simplifies AI Compliance
Key Takeaways
The Digital Omnibus on AI, adopted on July 8, 2026, is intended to simplify and streamline certain rules relating to artificial intelligence. It does not repeal the AI Act. Instead, it adjusts certain of its mechanisms to facilitate its implementation.
The Digital Omnibus on AI, adopted on July 8, 2026, is intended to simplify and streamline certain rules governing artificial intelligence. (1) It forms part of a broader initiative to simplify the European regulatory framework applicable to businesses.
The Digital Omnibus on AI does not repeal the Artificial Intelligence Act (AI Act), which was adopted less than two years ago. (2) Instead, it refines certain of its mechanisms in order to facilitate its implementation.
The Digital Omnibus on AI is intended to preserve the objectives of the AI Act while preventing its implementation from becoming excessively complex, costly, or uncertain for economic operators. It should therefore be viewed as an operational refinement of the AI Act: it postpones certain compliance deadlines, clarifies several key concepts, and introduces targeted new measures.
1. Main Measures Adopted Under the Digital Omnibus on AI
Most of the measures adopted amend or adjust existing provisions of the AI Act, primarily those concerning high-risk AI systems. The Digital Omnibus on AI also introduces several new measures, including a prohibition on certain intimate or sexual content generated or manipulated by AI.
1.1 Amendments to the AI Act
1.1.1 Postponement of the Application Timeline for High-Risk AI Systems
The provisions relating to high-risk AI systems were originally scheduled to apply from August 2, 2026, and August 2, 2027. However, businesses could not reasonably comply with their legal obligations due to the European authorities being late in developing the necessary technical framework.
The Digital Omnibus on AI changes the dates from which the relevant compliance obligations will apply:
- For AI systems classified as high-risk under Annex III to the AI Act: the application date is postponed from August 2, 2026, to December 2, 2027.
This category includes, in particular, systems used in the areas of biometrics, critical infrastructure, education, employment, access to certain essential services, law enforcement (where permitted), migration, and the administration of justice.
- For AI systems classified as high-risk under Annex I to the AI Act: the application date is postponed from August 2, 2027, to August 2, 2028.
Annex I covers AI systems that are intended to be used as safety components of products, or that are themselves products, covered by the Union harmonisation legislation listed in Annex I, such as medical devices, radio equipment, lifts, and toys.
These postponements should therefore give businesses additional time to organise their compliance processes to the AI Act.
1.1.2 Reducing Duplication with Sector-Specific Legislation
One of the objectives of the Digital Omnibus on AI is to reduce overlaps between the AI Act and certain sector-specific Union legislation.
A new paragraph 13 is added to Article 2 of the AI Act. It limits the application of certain requirements or obligations set out in Articles 9 to 15 and Articles 17 to 25 where high-risk AI systems are already covered by Union harmonisation legislation listed in Annex I, Section A, and that legislation ensures an equivalent or higher level of protection.
This measure is particularly relevant to industrial and regulated sectors, in which a product incorporating AI may already be subject to safety, conformity, or certification requirements. It is intended to avoid duplicate assessments, redundant requirements, and divergent interpretations, without reducing the overall level of protection provided by the AI Act.
1.1.3 Clarification of the Concept of a “Safety Component”
The concept of a safety component, defined in Article 3(14) of the AI Act, is clarified. This concept is significant as it may result in an AI system being classified as a high-risk AI system.
The Digital Omnibus on AI specifies that a component performs a safety function where its intended purpose is to prevent or mitigate risks to the health and safety of persons or property. It also clarifies that systems used solely for purposes unrelated to safety, such as user assistance, performance optimisation, or automation, are not considered safety components unless their failure or malfunction endangers health and safety.
This clarification should prevent certain systems from being classified too broadly as high-risk AI systems where they do not perform a safety function as such.
1.1.4 Proportionality Measures for SMEs, Startups, and Small Mid-Cap Enterprises
The Digital Omnibus on AI introduces several measures intended to adapt AI compliance requirements for small and medium-sized enterprises (SMEs), startups, and small mid-cap enterprises. These include simplified technical documentation, proportionality in the implementation of the quality management system, and consideration of economic viability under the penalty regime. (3)
1.1.5 Strengthening AI Regulatory Sandboxes and Real-World Testing
AI regulatory sandboxes (Art. 57 of the AI Act) are controlled frameworks that enable innovative AI systems to be developed, trained, tested, and validated under the supervision of the competent authorities before being placed on the market or put into service.
The Digital Omnibus on AI strengthens these experimental mechanisms. In particular, it allows the AI Office to establish a regulatory sandbox at the European level for certain systems falling within its competence, with priority access for SMEs, startups, and small mid-cap enterprises. It also introduces a new Article 60a, which provides a framework for the real-world testing of certain high-risk AI systems covered by Union harmonisation legislation.
For innovative businesses, these mechanisms may facilitate exchanges with the competent authorities and help them prepare for compliance before their systems are placed on the market or put into service.
1.2 New Measures Introduced by the Digital Omnibus on AI
1.2.1 Prohibition of Certain Intimate or Sexual Content Generated or Manipulated by AI
From December 2, 2026, AI systems that generate or manipulate intimate or sexual content depicting an identifiable person without that person’s consent will be prohibited under Article 5 of the AI Act, which concerns prohibited AI practices. The provision also covers content related to child sexual abuse.
This prohibition applies in particular to so-called nudification systems, sexual deepfakes, and tools that artificially remove a person’s clothing from an image.
1.2.2 A New Legal Basis for Processing Certain Sensitive Data to Detect and Correct Bias
The Digital Omnibus on AI inserts a new Article 4a into the AI Act to govern the processing of special categories of personal data for the purpose of detecting and correcting bias in high-risk AI systems.
This possibility is strictly limited. The processing must be necessary, the same objective must not be achievable using other data, and enhanced security and privacy safeguards must be implemented, particularly with regard to security, access controls, documentation, confidentiality, and data deletion.
This does not constitute a general authorisation to process special categories of personal data in AI projects. Rather, it provides a targeted and regulated legal basis that must be applied in conjunction with the requirements of the General Data Protection Regulation (GDPR).
2. Other Measures
The Digital Omnibus on AI contains several more technical measures intended to streamline the implementation of the AI Act and clarify certain obligations.
2.1 Streamlining Measures Intended to Avoid Regulatory Duplication
2.1.1 Simplification of Impact Assessments
The AI Act requires a fundamental rights impact assessment to be carried out for certain high-risk AI systems under Article 27. This provision is amended, in particular, to avoid duplication with the data protection impact assessment required under Article 35 of the GDPR.
Where certain elements are already covered by a data protection impact assessment conducted under the GDPR, the deployer may refer to the relevant sections of that assessment in its fundamental rights impact assessment.
2.1.2 A Single Procedure for Certain Notified Bodies
The Digital Omnibus on AI amends Articles 28 and 29 to facilitate the designation of notified bodies where they have already been designated under sector-specific legislation. The text therefore provides for a single application and a single assessment procedure, with the aim of accelerating and streamlining the designation process.
2.1.3 Interaction Between the AI Act and the Cyber Resilience Act
High-risk AI systems that fall within the scope of the Cyber Resilience Act and satisfy the conditions laid down in that Regulation are deemed to comply with the cybersecurity requirements set out in Article 15 of the AI Act.(4)
This measure avoids requiring a separate demonstration of compliance where the applicable cybersecurity requirements are already covered by the Cyber Resilience Act.
2.2 Technical Clarifications, Coordination Measures, and Transitional Provisions
2.2.1 Rewording of the AI Literacy Provision
The Digital Omnibus on AI replaces Article 4 of the AI Act, which concerns AI literacy. The revised wording maintains measures aimed at promoting AI literacy in relation to providers and deployers. However, it clarifies that they are not required to guarantee that each individual achieves a specific level of AI literacy.
2.2.2 Clarification of the Relationships Between Original Providers, New Providers, and Integrated Third Parties
Article 25 is amended to clarify the cooperation obligations that apply where an AI system is modified, integrated, or reused in a manner that results in another party being considered the provider of the system.
Original providers must cooperate with new providers, make certain information available, provide technical access, and provide the assistance that may reasonably be expected to enable compliance with the obligations laid down in the AI Act.
This measure is important in complex contractual chains, as it requires the various parties involved to clearly define their respective roles and obligations in their contracts.
2.2.3 Addition of Annex XIV
A new Annex XIV is added to the AI Act. It establishes the list of codes, categories, and corresponding types of AI systems to be used for the notification of conformity assessment bodies and for specifying the scope of their designation as notified bodies.
2.2.4 Strengthening the Role of the AI Office
The Digital Omnibus on AI clarifies the powers of the AI Office, particularly with regard to the supervision and enforcement of certain AI systems based on general-purpose AI (GPAI) models where the model and the system are developed by the same provider or by providers belonging to the same group of companies.
The AI Office is also granted powers of supervision, enforcement, information gathering, and inspection in relation to AI systems falling within its competence.
2.2.5 Transitional Provisions for Systems Already Placed on the Market
Article 111 of the AI Act is amended to adapt the transitional provisions to the revised application timeline.
For high-risk AI systems already placed on the market or put into service before the new application dates, the obligations laid down in Chapter III will, in principle, apply only where those systems undergo a substantial modification to their design. However, AI systems intended to be used by public authorities must be brought into compliance no later than August 2, 2030.
The Digital Omnibus on AI also establishes a specific deadline for generative AI systems placed on the market before August 2, 2026, where they generate synthetic audio, image, video, or text content. Providers of those systems must comply with the transparency obligations laid down in Article 50(2) no later than December 2, 2026.
3. Practical Recommendations Relating to the Digital Omnibus on AI
The Digital Omnibus on AI combines two types of measures: adjustments to the existing AI Act, on the one hand, and a limited number of new measures, on the other, particularly concerning intimate or sexual content generated by AI and the processing of certain special categories of personal data for the purpose of detecting and correcting bias.
For AI professionals, this Regulation provides both an opportunity to prepare for compliance more effectively within the extended timelines and a reminder of the vigilance required in relation to certain uses of AI that are now expressly regulated.
In practice, the professionals concerned should focus their efforts on four priorities:
1. Update AI System Inventories and Compliance Timelines: businesses should identify the systems affected by the Digital Omnibus on AI, distinguish between systems covered by Annex III and those covered by Annex I, and incorporate the new compliance deadlines into their roadmaps: December 2, 2027, for the former and August 2, 2028, for the latter.
2. Reassess High-Risk AI System Classifications in Light of the New Clarifications: the clarification of the concept of a safety component and the interaction between the AI Act and sector-specific legislation require businesses to review their classification assessments. The objective is to distinguish between systems that are genuinely subject to the high-risk AI system regime and those that may benefit from streamlined requirements.
3. Adapt Documentation and Contracts Across the AI Value Chain: the various actors across the AI value chain should clarify their respective roles, particularly with regard to cooperation obligations, access to technical information, and responsibilities where an AI system is modified.
4. Address the Newly Regulated Risks Without Delay: AI systems that generate or manipulate non-consensual intimate or sexual content, systems that generate synthetic content, and the processing of special categories of personal data for the purpose of detecting or correcting bias should be reviewed as a matter of priority.
The Digital Omnibus on AI does not represent a retreat from the AI Act. Rather, it is an operational revision intended to prevent implementation from being too rapid, excessively burdensome, or insufficiently coordinated among the competent authorities.
The main obligations applicable to high-risk AI systems have been postponed, but AI compliance remains a priority. The businesses concerned should use this additional time to map their AI systems, strengthen their contractual arrangements, organise their governance, document their technical choices, and anticipate the forthcoming obligations.
(1) Regulation of 8 July, 2026, amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI).
In addition to the AI Act, the Digital Omnibus on AI amends two other Regulations: the 2018 Regulation on civil aviation and establishing a European Union Aviation Safety Agency, and the 2023 Machinery Regulation concerning the health and safety of machinery. This article addresses only the provisions relating to artificial intelligence.
It should be noted that, as of the date of this article, the Digital Omnibus on AI had not yet been published in the Official Journal of the European Union.
(2) Regulation (EU) 2024/1689 of 13 June, 2024, laying down harmonised rules on artificial intelligence (Artificial Intelligence Act).
(3) Under Commission Recommendation (EU) 2025/1099 of 21 May, 2025, on the definition of small mid-cap enterprises, small mid-cap enterprises are enterprises that are not SMEs, employ fewer than 750 persons, and have either an annual turnover not exceeding EUR 150 million or an annual balance sheet total not exceeding EUR 129 million.
(4) Regulation (EU) 2024/2847 of 23 October, 2024, on horizontal cybersecurity requirements for products with digital elements (Cyber Resilience Act or CRA).
Bénédicte DELEPORTE
Avocat
Deleporte Wentz Avocat
www.dwavocat.com
July 2026