The Digital Omnibus: What Actually Changed for the EU AI Act in 2026
In July 2026 the EU adopted the Digital Omnibus, pushing back the AI Act’s high-risk obligations by more than a year. It did not touch Article 50. Here is what actually changed, in one place, without the confusion.
- The Digital Omnibus is Regulation (EU) 2026/1744, in force since 27 July 2026.
- Annex III standalone high-risk AI systems: deadline moved from 2 August 2026 to 2 December 2027.
- Annex I high-risk products (safety components under EU harmonization law): moved from 2 August 2027 to 2 August 2028.
- Article 50 transparency obligations were NOT delayed: still in force since 2 August 2026.
- Article 50(2) watermarking for systems already on the market at 2 August 2026 got a 4-month extension, to 2 December 2026.
Why this matters if you read anything about the AI Act before September 2026
If you read an AI Act explainer, a compliance checklist, or even an official-sounding summary published before mid-2026, its high-risk deadlines are now wrong. The EU adopted the Digital Omnibus in July 2026, and it specifically rewrote the timeline for the AI Act’s high-risk provisions. Anything citing "2 August 2026" as the date Annex III high-risk obligations kick in is describing the old law, not the current one.
This page exists because that confusion is common and expensive: acting on a stale deadline either wastes budget rushing something that isn’t due yet, or worse, leads you to assume you have more time on something that was never delayed in the first place (Article 50).
What the Digital Omnibus actually is
The Digital Omnibus on AI is Regulation (EU) 2026/1744, a legislative package that amends Regulation (EU) 2024/1689 (the AI Act itself). It was adopted after the European Commission and Parliament acknowledged that the infrastructure the AI Act depends on, national market surveillance authorities, harmonised technical standards, and conformity assessment bodies, was not ready in time for the original high-risk deadlines. It entered into force on 27 July 2026.
It is a targeted amendment, not a rewrite: most of the AI Act is untouched. It specifically defers high-risk obligations and adds a new prohibition (AI-generated non-consensual intimate imagery and CSAM, folded into Article 5). It does not touch Article 50, and it does not touch the Article 4 AI literacy obligation.
What actually moved
Two deadlines shifted, both tied to high-risk AI systems:
- Annex III standalone high-risk systems (recruitment, credit scoring, biometric categorization, and similar listed use cases): full compliance obligations now apply from 2 December 2027, not 2 August 2026.
- Annex I high-risk products (AI embedded as a safety component in products already regulated under EU harmonization law, e.g. medical devices, machinery): now apply from 2 August 2028, not 2 August 2027.
What did NOT move
This is the part that gets missed. Article 50 transparency obligations, disclosing AI-generated or manipulated content, telling people they’re talking to a chatbot, labelling deepfakes and synthetic audio, were left untouched by the Omnibus. They took effect on 2 August 2026 and are in force today, independent of whether the underlying system is classified as high-risk.
The one narrow exception is the watermarking sub-obligation in Article 50(2): for AI systems that were already on the market before 2 August 2026, the deadline to implement machine-readable marking of synthetic content was extended by four months, to 2 December 2026. Everything else under Article 50 was not extended.
Article 4 (AI literacy) also stayed on its original schedule: in force since 2 February 2025, with national authorities gaining formal enforcement powers on 2 August 2026.
What this means for your compliance timeline
If your AI systems are chatbots, content generators, or use emotion/biometric recognition, and don’t fall into an Annex III high-risk category, nothing changed for you: Article 50 obligations are due now, and the Omnibus is irrelevant to your timeline.
If you have (or suspect you have) an Annex III high-risk system, you effectively got 16 extra months. That is time to build the required risk management system, technical documentation, and conformity assessment process properly, not a reason to stop tracking it. The obligation didn’t disappear, it moved to 2 December 2027.
Either way, the practical first step is unchanged: you cannot know which deadline applies to you until you have an inventory of your AI systems and a risk-tier classification for each one. See the risk tier guide below.
Questions
Is the Digital Omnibus final law, or still a proposal?
It is adopted and in force. Regulation (EU) 2026/1744 entered into force on 27 July 2026. The new high-risk dates are binding, not a draft proposal.
Does the Digital Omnibus delay apply to me if I’m not sure my system is "high-risk"?
Only Annex III and Annex I high-risk obligations were delayed. If your system isn’t high-risk, this delay doesn’t apply to your timeline at all, though you still need Article 50 and Article 4 in place if they’re relevant. See the risk tier guide to work out which category you’re in.
Want this tracked automatically, not read about?
The EU AI Act Governance Cockpit is a Notion + n8n workspace that logs your AI systems, runs this exact risk classification, tracks the required actions, and keeps the evidence. One-time payment from €49.