Skip to content

Type a term, e.g. API, Shopware or SEO.

    ← All posts

    Written with AI, reviewed by René Mattis · vona

    Digital Omnibus on AI: What Changes in the EU AI Act – and What Doesn't

    New deadlines for high-risk AI, two new prohibitions, a softer AI literacy obligation: what Regulation (EU) 2026/1744 means for companies and what you should do now.

    In July 2026 the EU amended its AI regulation (the EU AI Act) for the first time. The amending Regulation (EU) 2026/1744 is called the “Digital Omnibus on AI” and is meant to simplify implementation. Headlines often made it sound like “the EU is backing down”. That is only partly true: some deadlines have been postponed and some obligations softened, but at the same time there are new prohibitions. Here we explain what actually changes for companies. Our basis is the official text in the Official Journal of the EU; we link to the current version of the regulation on our EU AI Act page. This article is not legal advice.

    The key points

    • High-risk AI comes later: The requirements apply to the areas in Annex III (such as recruitment, education, creditworthiness) from 2 December 2027 instead of 2 August 2026, and to AI in regulated products (Annex I) from 2 August 2028 instead of 2 August 2027.
    • Two new prohibitions from 2 December 2026: AI systems that generate sexualised images, videos or audio of identifiable people without their consent, and AI systems that generate child sexual abuse material.
    • More time for marking: Generative AI systems already on the market before 2 August 2026 must mark their output in a machine-readable way by 2 December 2026.
    • AI literacy remains an obligation, but softer: Companies must take measures to support the AI literacy of their people. They no longer have to guarantee a particular level.
    • Relief for mid-sized companies: Relief that previously applied only to small and medium-sized enterprises, such as simplified technical documentation, now also applies to small mid-cap enterprises.
    • Unchanged: The prohibitions in force since February 2025, the transparency obligations of Art. 50 and the obligations for providers of general-purpose AI models continue to apply.

    Why the EU made changes

    The EU states its reasons openly: the technical standards that providers of high-risk AI are supposed to follow were not ready in time, and many member states had not yet set up their supervisory authorities. According to the legislator, sticking to the original date would mainly have caused costs and legal uncertainty. The order stays the same: as before, the rules for Annex III apply before those for Annex I.

    What changes in detail

    New deadlines for high-risk AI

    High-risk AI is the area with the strictest obligations: risk management, requirements for training data, technical documentation, logging, human oversight and a conformity assessment. Two groups are affected:

    Area Examples previously now
    Annex III recruitment and employment, education, creditworthiness, access to essential services 2 August 2026 2 December 2027
    Annex I AI as a safety component of products such as machinery or medical devices 2 August 2027 2 August 2028

    Systems already in use before these dates are still covered by a grandfathering rule: the requirements only apply once the system’s design is significantly changed afterwards. Systems intended for use by public authorities must comply by 2 August 2030 at the latest.

    The regulation also now clarifies what is not a safety component: AI used exclusively for user assistance, performance optimisation, automation, ease of use or quality control, as long as it is not safety-relevant. This takes many everyday functions in products out of the high-risk area.

    Two new prohibitions

    The list of prohibited practices in Art. 5 is growing. From 2 December 2026 it is prohibited to place on the market, put into service or use AI systems that

    • generate or manipulate realistic images, videos, audio or similar material of an identifiable person’s intimate parts or of an identifiable person engaged in sexual activity without that person’s explicit consent, or
    • generate or manipulate child sexual abuse material.

    For providers, the prohibition applies if this is the purpose of the system, or if the system foreseeably produces such material without major technical changes and lacks appropriate safeguards against it. For deployers, it applies if they use a system for this purpose. The legislator explicitly responds to the widespread use of AI systems that generate such material. For companies using reputable image generators, practically nothing changes. Anyone offering generative image or video systems themselves, however, needs effective safeguards against misuse and must be able to stop reported misuse.

    AI literacy: less strict, not abolished

    Previously, Art. 4 required providers and deployers to ensure “to their best extent” that their staff have “a sufficient level of AI literacy”. Now it says: they take measures to support the development of AI literacy and do not have to guarantee a particular level. The Commission publishes practical examples, and member states are to support small companies in particular.

    That is relief, but not a free pass. Anyone using AI in their company still has to do something so that staff know what the tools can do, where they make mistakes and which data must not go into them.

    More time for marking AI-generated content

    Art. 50 has applied since 2 August 2026: providers of generative AI must mark generated images, audio, video and text in a machine-readable way as artificially generated. For systems already on the market before that date, there is now a transition period until 2 December 2026. The other transparency obligations remain unchanged: people must be able to tell that they are talking to an AI, and anyone publishing deepfakes must disclose them as such.

    Further changes

    • Bias correction with sensitive data: Providers of high-risk AI may, by way of exception, process special categories of personal data (such as health or ethnic origin) where strictly necessary to detect and correct bias. Strict conditions and safeguards apply.
    • Small mid-cap enterprises: The relief for SMEs, such as simplified technical documentation, priority access to AI regulatory sandboxes and lower caps on fines, now also applies to small mid-cap enterprises.
    • AI regulatory sandboxes: Every member state must set up at least one AI regulatory sandbox by 2 August 2027, where companies can test new systems under supervision.
    • Central supervision: The European Commission’s AI Office supervises AI systems built on a general-purpose AI model where model and system come from the same provider, as well as AI systems that are part of very large online platforms or search engines.

    What this means for your company

    Most companies use AI as deployers: they use chatbots, assistants, translation or image tools developed by someone else. For them, the Omnibus changes less than the headlines suggest. These are the points to tackle now:

    1. Take stock: Which AI tools do you use, for what and with which data? Without this list, none of the other questions can be answered.
    2. Determine the risk class: Most everyday office applications fall into the “minimal” or “transparency” categories. But if AI is used for job applications, performance reviews or credit decisions, you are in the high-risk area, and December 2027 is not far away.
    3. Keep promoting AI literacy: Short training sessions, clear usage rules and a contact person for questions are often enough. This protects you not only from trouble with the authorities but above all from costly mistakes.
    4. Build in transparency: When customers talk to a chatbot, they should know it. Mark AI-generated images or videos that look real.
    5. Keep data protection in mind: The GDPR applies regardless of the AI Act. Under Art. 22 GDPR, decisions with significant effects on people must not be left to AI alone anyway. More on this in our article AI and Data Privacy.

    Our view

    We think postponing the high-risk deadlines is understandable: obligations without finished standards and without competent authorities would mainly have created uncertainty. The new prohibitions against sexualised deepfakes are long overdue. And relief for smaller companies helps exactly the mid-sized businesses we work with.

    Still, we advise against treating the postponement as a break. The principles of the regulation – transparency, human oversight and clean data – make AI solutions better, regardless of the deadline. Planning them in from the start means nothing has to be retrofitted later. That is why at vona we classify every AI project under the EU AI Act during the analysis phase. Our position on the regulation and the current official version are on our EU AI Act page.

    As of October 2026, consolidated version of Regulation (EU) 2024/1689 of 27 July 2026. Source: Regulation (EU) 2026/1744 of 8 July 2026 in the Official Journal of the EU, available via EUR-Lex (opens in a new tab).

    ← Back to overview

    Newsletter

    News from the vona workshop.

    AI tools we actually use, our weekly AI review & insights from our projects – short, practical and without spam.