✨ New — try Standpoint free for 14 days: full access to all 15 frameworks. A card is required, but you won’t be charged. Start your free trial →
Standpointby AI Service Pro
Security Intelligence / EU AI Act
Guide

The EU AI Act "Digital Omnibus," Explained in Plain English

M
Mohammad
Founder, AI Service Pro · 8 min read

Quotable definition: The Digital Omnibus is a 2026 amendment package that simplifies and delays parts of the EU AI Act — most importantly pushing the high-risk obligations from August 2026 to late 2027 and 2028 — while leaving the August 2, 2026 transparency and general-purpose AI rules fully in force.

If you have read one thing about the EU AI Act this year, it was probably a headline saying it got "delayed." If you read a second thing, it probably said the deadline is still coming in August. Both are true, and that is exactly the problem the Digital Omnibus created: a single change package that moved some deadlines back by more than a year and left others exactly where they were.

This guide translates the Omnibus out of legal-firm-PDF language and into what a founder or a first security hire actually needs to decide: does anything change for us, and by when?

Note: This is educational information, not legal advice. Standpoint is a self-assessment and readiness tool — it helps you know where you stand, not a substitute for counsel on your specific obligations.

What is the EU AI Act Digital Omnibus?

The Digital Omnibus (formally the "Digital Omnibus on AI") is a package of targeted amendments to the EU AI Act that EU institutions agreed in 2026 to simplify and streamline the rules. The Council gave its final green light on June 29, 2026, following the political agreement reached earlier that spring (Consilium).

An "omnibus" in EU lawmaking is simply one legal instrument that amends several existing rules at once — think of it as a batch of edits rather than a brand-new law. It does not replace the AI Act. It reaches into the existing text and changes specific dates, definitions, and a handful of obligations.

The single most consequential edit: it postpones the AI Act's high-risk obligations, which had been scheduled to bite in August 2026, to late 2027 and 2028.

What did the Omnibus actually delay?

Here is the part almost everyone gets wrong. The Omnibus did not delay "the EU AI Act." It delayed one specific — though large — chunk of it: the obligations attached to high-risk AI systems.

Stand-alone high-risk systems (Annex III) — the ones used for things like recruitment, credit scoring, education, law enforcement, and border control — now have until December 2, 2027 to comply, instead of August 2026 (Gibson Dunn).

High-risk AI embedded in regulated products (Annex I) — AI inside medical devices, machinery, and vehicles — moves further still, to August 2, 2028 (aiactblog.nl).

The Omnibus also pushes the deadline for member states to stand up their national regulatory sandboxes — supervised environments where companies can test AI against the rules — by a year, to August 2, 2027.

If your product is high-risk under the AI Act, this is real breathing room: more than a year of it. The catch is knowing whether you are actually high-risk, which most companies assume they are not and some are wrong about.

What did the Omnibus NOT delay — and what still lands August 2, 2026?

This is the half that gets lost in the "it's delayed" headlines. Two sets of obligations were not touched and still take effect on August 2, 2026:

1. Article 50 transparency obligations. These apply to AI systems that interact with people, generate synthetic content, detect emotions, or biometrically categorize users. In practice that means labeling AI chatbots as AI, marking AI-generated content, and disclosing deepfakes. Critically, Article 50 is not limited to high-risk systems — it covers the vast majority of ordinary AI products, including the customer-facing chatbot on your site (DigitalApplied).

2. General-purpose AI (GPAI) obligations and enforcement powers. From August 2, 2026 the European Commission's enforcement powers over GPAI model providers "enter into application" — meaning the AI Office can move from persuasion to compulsion: request documentation, evaluate models, order corrective measures, and impose fines (artificialintelligenceact.eu).

So the honest one-sentence summary is: the paperwork-heavy high-risk regime moved to 2027–2028, but the transparency rules that touch almost every AI product, plus GPAI enforcement, still start August 2, 2026.

What new rules did the Omnibus ADD?

A delay package that only delays would be easy. The Omnibus also added obligations, which is why "it got weaker" is not quite right either. It introduces a new prohibition into Article 5 (the banned-practices list) covering AI-generated non-consensual intimate imagery ("nudifiers") and child sexual abuse material (Gibson Dunn). These are hard prohibitions, not risk-managed categories.

It also carries forward the earlier simplification aimed at smaller companies: the SME simplified regime was widened so that lighter documentation and reporting expectations reach mid-sized companies, not just the smallest — a meaningful reduction in paperwork for the exact startups this most affects.

When does the Omnibus actually take legal effect?

It already has. The Omnibus was published in the Official Journal as Regulation (EU) 2026/1744 — published in the Official Journal on 24 July 2026 and in force since 27 July 2026. The delays described above are law, not a proposal, and you can plan against them. (Earlier coverage written before 24 July still says publication is 'expected' — that is now out of date.) The two new Article 5 prohibitions it adds apply from 2 December 2026 (Consilium). Until that publication happens, the delays are politically agreed but not yet formally in force. For planning purposes you can rely on them; for legal certainty, watch for the Official Journal publication.

What are the penalties if you get this wrong?

The penalty tiers were not softened by the Omnibus. For GPAI non-compliance and for Article 50 transparency violations, the maximum penalty is the greater of €15 million or 3% of total worldwide annual turnover under Article 99 (ComplianceHub). The most serious prohibited-practice violations carry a higher ceiling still. These numbers are the reason "we'll deal with it later" is a poor strategy for the transparency obligations specifically — those are the ones that did not move.

Does the Omnibus change anything for a US company?

Not the fundamentals. The AI Act's reach is based on whether your AI system is placed on the market or used in the EU, not on where your company is headquartered. If you ship an AI feature to EU users, the same August 2, 2026 transparency obligations apply to you as to an EU company, and the same high-risk delays benefit you if you are high-risk. The Omnibus is a timing and simplification change, not a change to who is in scope.

So what should you actually do before August 2, 2026?

For most companies reading this, the honest answer is narrower than the panic suggests. You are unlikely to be a GPAI model provider. You may or may not be high-risk — and if you are, you now have until December 2027. But if you have any AI that talks to users or generates content, Article 50 transparency is your live deadline.

A sensible short list:

  1. Confirm whether you are high-risk at all. Most SaaS companies are not, but recruitment, credit, education, and biometric use cases are. If you are, your deadline is December 2, 2027 — plan, don't panic.
  2. Inventory every place your product uses AI to talk to a person or make content. Chatbots, AI-written emails, generated images, voice. Those are your Article 50 surfaces, due August 2, 2026.
  3. Add the disclosures. Label AI chat as AI, mark AI-generated content, disclose deepfakes. This is usually a copy-and-UI change, not an engineering project.
  4. Write down your reasoning. Keeping a short record of why you concluded you are or aren't high-risk is the single most useful artifact when a customer's security team — or a regulator — asks.

Where Standpoint fits

Standpoint's EU AI Act self-assessment walks you through the scope questions above and shows you where you stand against the obligations that actually apply to you — the transparency rules due now, and the high-risk rules due later — without a sales call and without claiming to certify anything. It is a readiness check, not an audit: it tells you where your gaps are so you can close them before someone else finds them.

FAQ

Did the EU AI Act get delayed?

Partly. The Digital Omnibus delayed the high-risk obligations to December 2, 2027 (stand-alone Annex III systems) and August 2, 2028 (AI embedded in regulated products). It did not delay the Article 50 transparency obligations or GPAI enforcement, which still take effect August 2, 2026.

What is the Digital Omnibus in one sentence?

It is a 2026 amendment package that simplifies the EU AI Act and postpones its high-risk deadlines, while leaving the August 2026 transparency and general-purpose AI rules in force.

What still applies on August 2, 2026?

Article 50 transparency obligations (labeling AI chatbots, marking AI-generated content, disclosing deepfakes) and the Commission's enforcement powers over general-purpose AI model providers, including the ability to impose fines.

When did the Omnibus become official?

The Council gave final approval on June 29, 2026, and the amendment was published in the Official Journal on 24 July 2026 as Regulation (EU) 2026/1744, entering into force on 27 July 2026. The changes are in force now.

Does the Omnibus reduce the fines?

No. The maximum penalty for GPAI and Article 50 transparency violations remains the greater of €15 million or 3% of worldwide annual turnover.

See where you stand — free
2-minute check · no card · runs in your browser
Run your free check →
Newsletter
Practical AI-governance & security tips, monthly

No fluff, no fear-selling. Unsubscribe anytime.

// Keep reading