EU AI Act
What did the Digital Omnibus change in the EU AI Act?

Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026. It moved the AI Act's high-risk dates by more than a year, added two prohibitions, rewrote the AI literacy duty, and extended relief for smaller companies. This page lists every change that matters for a compliance program, read from the Official Journal text.
Sources: Regulation (EU) 2026/1744, OJ L, 24 July 2026, and the consolidated AI Act dated 27 July 2026, both read on 2 October 2026 through the EU Publications Office. The consolidated text is a documentation tool with no legal effect; the Official Journal texts are authentic. This is not legal advice.
How did the Digital Omnibus become law?
The Commission proposed it on 19 November 2025 as COM(2025) 836. The European Parliament adopted its position on 16 June 2026 and the Council its decision on 29 June 2026. The Regulation was signed on 8 July 2026, published in the Official Journal on 24 July 2026, and entered into force "on the third day following that of its publication", which was 27 July 2026. It amends the AI Act, Regulation (EU) 2018/1139 on civil aviation safety, and Regulation (EU) 2023/1230 on machinery.
Which changes matter most?
| Provision | What changed | Applies |
|---|---|---|
| Article 113 | High-risk rules (Chapter III, Sections 1 to 3) moved to two dates set by classification route | 2 Dec 2027 (Annex III); 2 Aug 2028 (Annex I) |
| Article 5(1)(ba), (bb), 1a, 1b | Two new prohibitions, with limits | 2 Dec 2026 |
| Article 4 | AI literacy duty rewritten: "support the development", no specific level | Since 2 Feb 2025; new wording from 27 Jul 2026 |
| Article 4a (new) | A legal basis, with strict conditions, to process special categories of personal data to detect and correct bias | 27 Jul 2026 |
| Articles 3(14) and 6(1a) to (1c) | Narrower meaning of "safety component" for the Annex I route | With the high-risk rules |
| Article 2(2), 2(13) and Annex I | Machinery moved from Section A to Section B of Annex I; possible limits for Section A products | Delegated acts due by 2 Aug 2027 |
| Articles 11(1), 63(1), 99(6a) | Simplified documentation and lower fine caps reach small mid-caps (SMCs); simplified QMS for SMEs | With the relevant rules |
| Article 25(2), (4) | More detail on what an original provider owes a new provider; breaches now in the Article 99(4) fine tier | With the high-risk rules |
| Article 27(4), (5) | A fundamental rights impact assessment can cross-refer to, or include, the DPIA | With the high-risk rules |
| Article 111(4) | Generative systems already on the market before 2 Aug 2026 must mark outputs under Article 50(2) | By 2 Dec 2026 |
What happened to the high-risk deadlines?
They moved. The original Article 113 applied most of the Act from 2 August 2026, and pushed Article 6(1) and its corresponding obligations to 2 August 2027. The amended point (c) applies Chapter III, Sections 1, 2 and 3, the classification rules, the requirements and the obligations of providers and deployers, from:
- 2 December 2027 for AI systems that are high risk under Article 6(2) and Annex III, such as systems used in recruitment or credit scoring, and
- 2 August 2028 for AI systems that are high risk under Article 6(1) and Annex I, the product route.
The general date, 2 August 2026, is unchanged for the rest of the Act, including the Article 50 transparency duties and Chapter III, Section 5 on standards, conformity assessment and registration. Article 111(2) now ties the treatment of high-risk systems already on the market to the new Chapter III dates, and keeps 2 August 2030 for systems used by public authorities. Our guide to every AI Act date and fine tier has the full table.
What are the two new prohibitions?
From 2 December 2026, Article 5(1) prohibits AI systems that generate or manipulate realistic images, video or audio of an identifiable person's intimate parts or sexually explicit activity without that person's explicit consent (point (ba)), and AI systems that generate child sexual abuse material as defined in Directive 2011/93/EU (point (bb)). For providers, paragraph 1a limits the ban to systems where that output is the intended purpose, or a reasonably foreseeable and reproducible outcome that the system has no adequate safeguards to prevent. Our guide to the Article 5 prohibitions sets out the conditions.
What happened to AI literacy?
The duty survived, in a softer form. The Commission had proposed turning Article 4 into a duty on the Commission and the Member States to encourage organizations. The adopted text keeps the obligation on providers and deployers: they "shall take measures to support the development of AI literacy" of their staff, and the duty "does not require providers or deployers to guarantee any specific level of AI literacy of any individual". The Commission must publish practical examples, and the AI Board must adopt recommendations. Our Article 4 guide for learning and development teams covers what to do.
What changed for product makers?
Three things. First, Article 6(1a) says AI systems "solely used for non-safety related aspects of user assistance, performance optimisation, service efficiency, automation or convenience or quality control shall not qualify as safety components", unless their failure would endanger health and safety, and Article 6(1c) excludes products that need third-party assessment only for non-safety risks such as radio spectrum. Second, machinery moved from Section A of Annex I, where the AI Act's high-risk requirements apply directly, to Section B, where Article 2(2) limits the Act to Article 6(1), Article 60a and Articles 102 to 112. Third, new Article 2(13) lets the Commission limit some requirements for Section A products where sector law already gives equal or higher protection, by delegated acts due by 2 August 2027. New Article 60a lets Member States allow real-world testing of Section B products outside regulatory sandboxes.
Training obligation register
Law,Article,Does it apply to us? (yes or no and why),Who must be trained,What the text requires (summary),Applies since,Our measure,Owner,Evidence kept (where),Review date,Notes EU AI Act (Regulation (EU) 2024/1689),Article 4 as amended by Regulation (EU) 2026/1744,,Staff and other persons dealing with AI systems on our behalf,Take measures to support the development of AI literacy; no specific level required,2 February 2025,,,,,The Commission's Q&A says no certificate is needed; keep an internal record. EU AI Act (Regulation (EU) 2024/1689),Article 26(2),,People assigned to human oversight of high-risk AI systems,"Necessary competence, training and authority, and support",2 December 2027 (Annex III) or 2 August 2028 (Annex I),,,,,Only for deployers of high-risk AI systems. NIS2 (Directive (EU) 2022/2555),Article 20(2),,Members of the management body; employees (encouraged),Management body members required to follow training; entities encouraged to offer similar training to employees regularly,National transposing law (Member States to apply measures from 18 October 2024),,,,,A directive: check your national law for the exact duty. DORA (Regulation (EU) 2022/2554),Article 13(6),,All employees and senior management staff; ICT third-party service providers where appropriate,ICT security awareness programs and digital operational resilience training as compulsory modules,17 January 2025,,,,,Article 5(2)(g): the management body allocates and reviews the budget for this training. GDPR (Regulation (EU) 2016/679),Article 39(1)(b),,Staff involved in processing operations,The DPO monitors compliance including awareness-raising and training of staff,25 May 2018,,,,,A task of the DPO; not a free-standing duty to train all staff. ,,,,,,,,,, "Read from the Official Journal texts on 2 October 2026. Template from credentialpress.com/guides/eu-laws-that-require-staff-training. Not legal advice.",,,,,,,,,,
What changed for smaller companies?
Article 3 now defines both SMEs and small mid-cap enterprises (SMCs), the latter by reference to Commission Recommendation (EU) 2025/1099. SMCs join SMEs in being allowed to use a simplified form for the Annex IV technical documentation under Article 11(1). The simplified quality management system in Article 63(1), which recital 28 says was previously open to microenterprises, now covers SMEs without partner or linked enterprises. And new Article 99(6a) caps SMC fines under Article 99(4) and (5) at the lower of the fixed amount and the percentage; the Article 5 tier is not covered.
What else changed?
- Bias data. New Article 4a lets providers of high-risk systems process special categories of personal data where strictly necessary to detect and correct bias, under six conditions, including pseudonymization, no transfer to other parties and deletion once the bias is corrected.
- Value chain. Article 25(2) now lists what an initial provider must give a new provider: technical documentation, known limitations and failure modes, and targeted technical access. Article 99(4)(da) puts breaches of Article 25(2) and (4) in the EUR 15 million tier.
- Impact assessments. Article 27(4) lets a deployer's fundamental rights impact assessment cross-refer to, or include parts of, its DPIA. Our guide to AI impact assessments compares the documents.
- Enforcement. New Article 75a gives the AI Office the powers of a market surveillance authority for the AI systems Article 75(1) assigns to it, including inspections.
- Labeling. Article 50(7) now has the Commission assess whether codes of practice are adequate for the marking and labeling duties, with implementing acts as a fallback.
What should you do this week?
Re-date your high-risk work plan to 2 December 2027 or 2 August 2028, depending on the route, and check whether any product AI still counts as a safety component under the narrower definition. If you supply image, video or audio generation, check your safeguards against Article 5(1a) before 2 December 2026. Books and courses written before July 2026, including the AI Governance Framework handbook, follow the original text, so read them alongside these changes. Credential Press is independent of the EU institutions.
Frequently asked questions
What is the EU AI Act Digital Omnibus?
Regulation (EU) 2026/1744, the Digital Omnibus on AI, which amends the AI Act and two product laws. It was signed on 8 July 2026, published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026.
Did the Digital Omnibus delay the AI Act's high-risk rules?
Yes. The rules in Chapter III, Sections 1 to 3, now apply from 2 December 2027 for high-risk systems under Annex III and from 2 August 2028 for those under Annex I. Before the amendment, most applied from 2 August 2026, and those for Annex I systems from 2 August 2027.
Did the Digital Omnibus remove the AI literacy obligation?
No. The Commission had proposed moving the duty onto the Commission and the Member States, but the adopted text keeps it on providers and deployers. Article 4 now requires them to take measures to support the development of AI literacy, without any specific level.
What new prohibitions did the Digital Omnibus add?
Two, from 2 December 2026: AI systems that generate or manipulate realistic intimate or sexually explicit material of an identifiable person without consent, and AI systems that generate child sexual abuse material as defined in Directive 2011/93/EU.
What is an SMC under the AI Act?
A small mid-cap enterprise as defined in Commission Recommendation (EU) 2025/1099. The amendment extends some SME relief to SMCs, including the simplified technical documentation form and a lower fine cap for the Article 99(4) and (5) fines.
Did the GDPR, NIS2 or DORA change too?
Not through this Regulation. A separate Digital Omnibus proposal, COM(2025) 837, would amend the GDPR and NIS2; on 2 October 2026 it had not been adopted.
EU AI Act: test yourself in five minutes
Which books cover the EU AI Act?

Building one that survives the EU AI Act. 22 chapters, 384 pages.

Artificial Intelligence Governance Professional. 21 chapters, 385 pages.
Sources
Every provision above was read on 2 October 2026 from the Official Journal text through the EU Publications Office.
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), OJ L, 24 July 2026, recitals 8, 28 and 40, Articles 1 and 4
- Regulation (EU) 2024/1689 (AI Act), OJ L, 12 July 2024
- Regulation (EU) 2024/1689, consolidated text dated 27 July 2026 (no legal effect)
Credential Press is independent of the European Commission and every exam board. This is not legal advice.