Contact us

The EU AI Act “Simplified”: What the Digital Omnibus Means

Yuliya Shapovalova Yuliya Shapovalova Ambassador / Legal Advisor
Table of contents
  • Digital Omnibus on Artificial Intelligence
  • More Time, Not Less Regulation
  • Transparency Requirements Are Accelerating
  • A New Ban
  • Regulatory Sandboxes Are Postponed
  • Less Regulatory Overlap
  • Machinery Receives a Separate Compliance Path
  • Greater Clarity Around Regulatory Supervision
  • What Does This Mean for Businesses and Individuals?
  • Looking Ahead

Digital Omnibus on Artificial Intelligence

On 29 June 2026, the Council of the European Union formally adopted the Digital Omnibus on Artificial Intelligence[1], introducing the first substantial amendments to the EU AI Act since its adoption in 2024. While the reform does not weaken the AI Act, it significantly reshapes its implementation by postponing key compliance deadlines, clarifying regulatory responsibilities, reducing overlaps with sector-specific legislation, and introducing new prohibitions aimed at protecting individuals.

For organisations developing, deploying or using AI systems, the Digital Omnibus provides greater legal certainty and additional time to prepare. For individuals, it strengthens safeguards against some of the most harmful uses of artificial intelligence.

More Time, Not Less Regulation

The most significant change concerns high-risk AI systems.

Under the original AI Act, obligations for many high-risk systems were due to apply from 2 August 2026. The Digital Omnibus postpones these requirements to allow businesses, regulators and conformity assessment bodies additional time to prepare.

The new deadlines are:

  • 2 December 2027 for standalone high-risk AI systems listed in Annex III of the AI Act.
  • 2 August 2028 for high-risk AI systems embedded within regulated products, such as medical devices, machinery and other products subject to sector-specific legislation.

This extension is intended to support a smoother implementation of the AI Act rather than to reduce regulatory obligations. Companies should therefore use this additional time to establish robust AI governance frameworks instead of postponing compliance efforts.

Transparency Requirements Are Accelerating

The Digital Omnibus shortens the implementation period for transparency measures relating to AI-generated content.

Providers will now have only three months, rather than six, to implement appropriate technical solutions for identifying artificially generated content, with the revised deadline set for 2 December 2026.

For many organisations, this means introducing mechanisms such as:

  • watermarking;
  • metadata labelling;
  • machine-readable identifiers;
  • clear user disclosures indicating that content has been generated or manipulated by AI.

As synthetic media becomes increasingly indistinguishable from authentic content, transparency obligations are expected to become one of the most visible aspects of AI compliance.

A New Ban

One of the most notable additions is the introduction of a new prohibited AI practice.

The Digital Omnibus bans AI systems that generate or manipulate non-consensual sexual or intimate content involving real individuals, including so-called “nudification” applications capable of digitally removing clothing from photographs. The prohibition also covers AI-generated child sexual abuse material.

Unlike many of the delayed compliance obligations, these restrictions will apply much sooner, reflecting the EU’s growing concern regarding the misuse of generative AI technologies.

For businesses operating image generation platforms, social media services, content creation tools or consumer AI applications, this change requires immediate attention. Products, moderation systems and terms of service should be reviewed to ensure that such capabilities are either prevented or effectively controlled.

Regulatory Sandboxes Are Postponed

The deadline for Member States to establish AI regulatory sandboxes has also been postponed until 2 August 2027.

Regulatory sandboxes are intended to provide controlled environments in which innovative AI systems can be tested under regulatory supervision before entering the market.

Although the postponement gives national authorities additional time to establish these programmes, businesses should not delay their own compliance preparations while waiting for sandbox opportunities to become available.

Less Regulatory Overlap

Another important objective of the Digital Omnibus is to reduce unnecessary duplication between the AI Act and existing sector-specific legislation.

Where products are already subject to comprehensive regulatory frameworks, including legislation governing medical devices, toys, lifts or recreational watercraft, implementing measures may limit the application of overlapping AI Act requirements.

This represents a practical improvement for manufacturers, who previously faced the prospect of complying with multiple sets of substantially similar obligations.

Machinery Receives a Separate Compliance Path

The amendments also establish a specific approach for products regulated under the Machinery Regulation.

Rather than applying the AI Act directly, the European Commission will be empowered to introduce AI-related health and safety requirements through secondary legislation under the machinery framework.

For companies operating in industrial automation, robotics, advanced manufacturing and engineering, AI compliance will increasingly become integrated with existing product safety obligations rather than operating as a standalone regulatory regime.

Greater Clarity Around Regulatory Supervision

The Digital Omnibus clarifies the supervisory responsibilities of the European AI Office for AI systems based on general-purpose AI (GPAI) models developed by the same provider.

At the same time, national authorities retain competence in several sensitive sectors, including law enforcement, border management, judicial authorities and financial services.

For multinational organisations, these clarifications help reduce uncertainty regarding which regulator will oversee particular AI systems and under what circumstances.

What Does This Mean for Businesses and Individuals?

The additional implementation period should not be interpreted as a reason to pause compliance programmes. Instead, businesses should use this opportunity to build mature AI governance structures before regulatory obligations become fully enforceable.

Key priorities include:

  • identifying all AI systems used across the organisation;
  • determining whether the organisation acts as a provider, deployer, importer or distributor;
  • assessing whether any AI systems fall within the high-risk category;
  • reviewing contracts with AI vendors and technology providers;
  • implementing internal AI governance policies;
  • establishing procedures for transparency, record-keeping and human oversight;
  • aligning AI compliance with GDPR, cybersecurity, consumer protection and sector-specific regulatory obligations.

Organisations that begin this work now are likely to face significantly lower compliance costs than those waiting until the revised deadlines approach.

For individuals, the Digital Omnibus delivers stronger protections while preserving innovation.

The new rules will:

  • prohibit some of the most harmful forms of AI-generated abuse;
  • increase transparency around AI-generated content;
  • improve regulatory consistency across the European Union;
  • provide greater accountability for developers and deployers of AI systems.

As artificial intelligence becomes increasingly integrated into employment, healthcare, financial services, education and public administration, public trust will depend not only on technological innovation but also on effective governance and responsible deployment.

Looking Ahead

The Digital Omnibus should not be viewed as a retreat from AI regulation. Rather, it represents a pragmatic recalibration of one of the world’s most ambitious regulatory frameworks.

The European Union has recognised that effective regulation requires realistic implementation timelines, legal certainty and coherent interaction between different regulatory regimes. At the same time, it has demonstrated that it is prepared to respond rapidly where artificial intelligence poses serious risks to fundamental rights and personal dignity.

For businesses, the message is clear: the compliance timeline has changed, but the strategic importance of AI governance has not. Those that use the additional time to establish robust compliance programmes will be best positioned to compete in an increasingly regulated AI landscape.

[1] General Secretariat of the Council of the EU. Artificial Intelligence: Council Gives Final Green Light to Simplify and Streamline Rules. 29 June 2026, data.consilium.europa.eu/doc/document/PE-30-2026-INIT/en/pdf.