Core amendments to the EU AI Act (2026) - Digital Omnibus on AI

After being approved by the Council on June 29, the Regulation of the European Parliament and of the Council amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI) was finally adopted. The Regulation will be published in the EU’s official journal shortly and will enter into force on the third day after this publication.

The delayed application of rules on high-risk AI systems

As announced, the new regulation postponed the application of certain provisions of the AI Act, which had set the general date of application as 2 August 2026. This mainly refers to the obligations related to high-risk AI systems, and for the reason that the delayed availability of standards, common specifications, and alternative guidance and the delayed establishment of national competent authorities have led to challenges that jeopardize the effective entry into application of those obligations and to the risk of a significant increase in implementation costs. After the entry into force of the new regulation, the following AI Act application agenda is relevant.

  • Chapters I and II of the AI Act have been applied from 2 February 2025, with the exception of Article 5(1), first subparagraph, as added provisions introducing new prohibited AI practices shall apply from 2 December 2026.
  • The application of the high-risk AI systems rules, which was due to start on 2 August 2026, has been delayed, so that Chapter III, Sections 1, 2, and 3 of the AI Act, with the exception of Article 6(5), shall apply from:
    • 2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III; and
    • 2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I.

At the same time, this means that obligations laid down by the AI ​​​​Act will not apply to operators of high-risk AI systems that have been placed on the market or put into service before these new dates of Chapter III application, unless, from these dates, those systems are subject to significant changes in their designs (new Article 111 of the AI Act).

  • All other provisions of the AI Act shall apply from 2 August 2026.
  • The following provisions of the AI Act are already applicable as of August 2, 2025: Chapter III Section 4, Chapter V, Chapter VII, Chapter XII, and Article 78, with the exception of Article 101. T
  • This means that on August 2, 2026, the application of the following provisions of the AI Act begins: Chapter III Section 5, Chapters IV, VI, VIII, IX, X, XI and XIII.
  • For providers of generative AI systems, including general-purpose AI systems (generating synthetic audio, image, video or text content) that were placed on the market before August 2, 2026, a transitional period of four months is introduced, requiring them to harmonize their practices with the marking obligation under Article 50(2) of the AI Act by December 2, 2026.

                                                                      Extending the prohibitions of certain AI practices                                                          Article 5 of the AI ​​Act prohibits certain AI practices that are particularly harmful and abusive, contrary to certain Union values ​​and fundamental human rights. Therefore, Article 5 is subject to an assessment of the need for amendment (Article 112(1)) that follows societal and technological development. After the adoption of the AI Act, widespread use of AI systems generating non-consensual intimate images, videos, audio and similar material (‘non-consensual intimate material’) has created a severe risk to health, safety and fundamental rights, including victims’ human dignity, personal autonomy, integrity and private life, with potentially serious lasting psychological and other harms. Also, child sexual abuse material (CSAM), including wholly or partially synthetic material, constitutes a grave threat to the safety and fundamental rights of children, as well as a risk of normalising, amplifying and perpetuating sexual violence against children. Accordingly, the new regulation introduces an explicit regulatory prohibition of the following AI practices:

„the placing on the market, the putting into service or the use of an AI system

– that generates or manipulates realistic images, videos, audio or similar material of an identifiable natural person’s intimate parts, or of an identifiable natural person engaged in sexually explicit activities, without that person’s freely-given, specific, informed, unambiguous and explicit consent for that generation or manipulation;

– that generates or manipulates material or performance within the meaning of Article 2, points (c) and (e), of Directive 2011/93/EU on combating the sexual abuse and sexual exploitation of children and child pornography, except where a “without right” defence applies under national law.“

The placing on the market or putting into service of an AI system that generates or manipulates this material is only prohibited where: i) that generation or manipulation is the intended purpose of the AI system; or ii) the system’s design, training, architecture, capabilities or user-facing functionalities make that generation or manipulation a reasonably foreseeable and reproducible outcome, without requiring significant technical modification, and the system does not have reasonable and adequate technical safety measures and other safeguards to reliably prevent that generation or manipulation, taking into account reasonably foreseeable misuse, and to correct observed or reported misuse. The use of an AI system that generates or manipulates this material is only prohibited where the deployer uses the system for the purpose of generating or manipulating such material or performance.

However, an AI system that manipulates material in a way that does not increase the exposure of any depicted intimate parts or alter the nature of any depicted sexually explicit activities shall not constitute manipulation.

Simplified compliance with rules on high-risk AI systems and reducing regulatory overlaps

AI systems classified as high-risk pursuant to Article 6, paragraph 1 of the AI Act

According to the first classification rule of the AI Act (Article 6 (1)), certain AI systems shall be considered to be high-risk where both of the following conditions are fulfilled: (a) the AI system is intended to be used as a safety component of a product, or the AI system is itself a product, covered by the Union harmonization legislation listed in Annex I (e.g. medical devices, in vitro diagnostic medical devices, lifts, toys, radio equipment…); (b) the product whose safety component pursuant to point (a) is the AI system, or the AI system itself as a product, is required to undergo a third-party conformity assessment, with a view to the placing on the market or the putting into service of that product pursuant to the Union harmonization legislation listed in Annex I.

1. The new regulation has specified the meaning of the key term safety component in this rule, which is defined by Article 3 (14) of the AI Act as ” a component of a product or an AI system that fulfils a safety function for that product or AI system, or the failure or malfunction of which endangers the health and safety of persons or property“, by adding the further clarification that „for the purposes of this definition, a component fulfills a safety function where its intended purpose is to prevent or mitigate risks to health and safety of persons or property“.

Consistently, the amended Article 6 of the AI Act clarifies that for the purposes of this Regulation, including Article 6 (1), AI systems that are solely used for non-safety-related aspects of user assistance, performance optimisation, service efficiency, automation or convenience or quality control shall not qualify as safety components.

Notwithstanding this clarification, the amended Article 6 also retains part of the definition that “AI systems the failure or malfunctioning of which would endanger health and safety shall qualify as safety components”.

Still, it shall not be considered as fulfilling this condition: a product that is required to undergo a third-party conformity assessment solely due to risks other than risks to health and safety, in particular risks relating to the distribution of radio spectrum or electromagnetic interference that do not affect health and safety.

2. For these categories of high-risk AI systems (determined in Article 6(1) of the AI Act), the new Regulation prescribes the possibility of limited application of specific requirements and their providers’ obligations (laid down in Articles 9 to 15 and 17 to 25 of the AI Act) where and to the extent that:

(a) the corresponding Union harmonisation legislation listed in Section A of Annex I lays down requirements or obligations providing an equivalent or higher level of protection of health, safety or fundamental rights as the requirement or obligation concerned; and

(b) such limitation does not reduce the overall level of protection provided for by AI Act.

The goal of this change in Article 2. of the AI Act is to facilitate compliance, minimize administrative burden and duplication, while the Commission is empowered to adopt delegated acts to identify such cases and specify the products concerned, the requirements or obligations that may be limited, and the conditions and scope of any limitation.

3. The amended Article 43, paragraph 3 of the AI Act prescribes that for the categories of AI systems classified as high-risk pursuant to Article 6, paragraph 1 and covered by the Union harmonization legislation listed in Section A of Annex I, the provider of the system shall follow the relevant conformity assessment procedure as required in accordance with the relevant Union harmonization legislation. In addition, the requirements set out in the AI Act (Section 2 of Chapter III) shall apply to those high-risk AI systems and shall be part of that assessment. Assessment of the quality management system set out in Article 17 of the AI Act shall also be undertaken.

For the purposes of that conformity assessment, notified bodies which have been notified under the Union harmonisation legislation listed in Section A of Annex I shall have the power to assess the conformity of high-risk AI systems with the requirements set out in the AI Act (Section 2 of Chapter III).

However, where Union harmonisation legislation listed in Section A of Annex I provides the product manufacturer with an option to rely on a conformity assessment that does not involve a third-party, provided that that manufacturer has applied harmonised standards to ensure compliance with all the relevant requirements, that manufacturer may use that option only if it has also applied harmonised standards or, where applicable, common specifications, covering all requirements set out in Section 2 of Chapter III of the AI Act.

Also, where a high-risk AI system is both covered by the Union harmonisation legislation listed in Section A of Annex I and it falls within one of the categories listed in Annex III (Article 6(2)), the provider of that system shall follow the relevant conformity assessment procedure as required pursuant to the relevant Union harmonisation legislation listed in Section A of Annex I.

4. Given the specific nature of machinery and the machinery sector, and in order to simplify the regulatory framework and avoid overlapping application of different legislation for machines with embedded AI, the Machinery Regulation (EU) 2023/1230 has been moved from Section A to Section B of the Annex to the AI Act. The Commission is empowered to adopt secondary legislation under the Machinery Regulation (EU) 2023/1230, which will add health and safety requirements in respect of AI systems classified as high-risk pursuant to Article 6(1) of the AI Act. 

AI systems classified as high-risk pursuant to Article 6, paragraph 2

The conformity assessment of categories of AI systems classified as high-risk pursuant to Article 6, paragraph 2 and referred to in Annex III of the AI Act (eight specific areas) is carried out, as a general rule, by the provider under its own responsibility, with the only exception of AI systems intended to be used for biometrics. This means that for high-risk AI systems referred to in points 2 to 8 of Annex III, providers shall follow the conformity assessment procedure based on internal control as referred to in Annex VI, which does not provide for the involvement of a notified body (Article 43 (2) of the AI Act).

Harmonised standards

High-risk AI systems which are in conformity with harmonised standards or parts thereof shall be presumed to be in conformity with the requirements set out in Section 2 of Chapter III of the AI Act, to the extent that those standards cover those requirements or obligations (Article 40 (1) of the AI Act). In accordance with Article 40(2) of the AI Act, the Commission is already authorized to issue, without undue delay, standardization requests covering all requirements set out in Section 2 of Chapter III. In order to support and simplify the process of compliance with regulations, the new Regulation restated and supplemented this provision by Commission authorization to request, without undue delay, the European standardization organizations to develop standardization deliverables, including, as appropriate, harmonized standards, to facilitate the joint compliance and presumption of conformity with the requirements or obligations set out in Chapter III, Sections 2 and 3 of the AI Act and the relevant requirements and obligations laid down in the Union harmonization legislation listed in Annex I to this Regulation.

Amendments to provisions relating to transparency obligations

for providers and deployers of certain AI systems generating or manipulating content

In order to ensure compliance with transparency obligations by providers and deployers of certain AI systems generating or manipulating content, the new Regulation redefines the responsibility and authorization of the Commission. According to the amended provision of Article 50 (7) of the AI Act, the Commission shall encourage and facilitate the drawing up of codes of practice at Union level to facilitate the effective implementation of the obligations regarding the detection, marking and labelling of artificially generated or manipulated content. The Commission, taking utmost account of the opinion of the Board, shall assess whether adherence to those codes of practice is adequate to ensure compliance with the transparency obligations, in accordance with the procedure of regularly monitoring and evaluation. If it deems the code of practice to be inadequate, the Commission may adopt an implementing act specifying common rules for the implementation of those obligations in accordance with the examination procedure.

Extending support measures and simplification of compliance requirements to ‘small mid-cap enterprises’ (SMCs)

The AI Act provides for more support measures and simplification of compliance requirements for micro, small and medium-sized enterprises (SMEs), including startups. The new regulation extends the application of these benefits to the category of companies that have outgrown SMEs, but are smaller than large companies (they have fewer than 750 employees and an annual turnover that does not exceed 150 million euros), the so-called small mid-cap enterprises (SMCs) (Article 3), which also face similar challenges as SMEs in terms of administrative burden. Due to the need for proportionality in the implementation of the AI Act and targeted support, for example, SMEs and SMCs can draw up technical documentation in a simplified manner (Article 11); the obligation of the quality management system must be proportional to the size of the provider’s organization, especially if the provider is an SME, including a startup, or an SMC (Article 17).

AI literacy

The previous obligation on all providers and deployers of AI systems to ensure AI literacy of their staff has been moderated and replaced with the requirement for providers and deployers to „take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used“ (Article 4). At the same time, the Commission and the Member States are responsible for supporting and facilitating the efforts of providers and deployers of AI systems, in particular SMEs, in fulfilling these obligations.

Extending the legal basis for the processing of special categories of personal data

To enable providers of high-risk AI systems to establish practices concerning the detection, prevention and correction of biases likely to affect the health and safety of persons, have a negative impact on fundamental rights or lead to discrimination (Article 10(2), points (f) and (g) of the AI Act), Regulation provides for a legal basis authorizing these providers to process special categories of personal data in certain exceptional cases and prescribes strict conditions and safeguards, in addition to these set out in Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680.

However, biases likely to have those effects could also result from the actions of the deployers ofhigh-risk AI systems, and they could also arise in the case of other AI systems or models (for example, biases in eligibility or risk-scoring tools used to assess applications for various types of public permits or licences can restrict rights or effectively prevent certain groups from accessing public services). Accordingly, the new Regulation extends this legal basis for the processing of special categories of personal data for the purposes of bias detection and correction, exceptionally and where strictly necessary, also to deployers of high-risk AI systems, as well as to providers and deployers of other AI systems and models. That legal basis is subject to the same limitations, conditions and safeguards.

Measures of support of innovation

Articles 57, 58 and 60 of the AI Act are amended to strengthen further cooperation at Union level of AI regulatory sandboxes, foster clarity and consistency in the governance of AI regulatory sandboxes, and to extend the scope of real-world testing outside AI regulatory sandboxes to high-risk AI systems covered by the Union harmonisation legislation listed in Annex I to that Regulation. In particular, to allow procedural simplification, where applicable, in the projects supervised in the AI regulatory sandboxes that also include real-world testing, the plan for real-world testing should be integrated into the sandbox plan, agreed by the providers or prospective providers and the competent authority. In addition, it is provided for the possibility of the AI Office to establish an AI regulatory sandbox at Union level for AI systems, the monitoring and supervision of which are within its competence.

Post-market monitoring

According to Article 72 (3) of the AI Act, the post-market monitoring system shall be based on an appropriate plan. The post-market monitoring plan shall be part of the technical documentation referred to in Annex IV. The new regulation prescribes authorisation of the Commission to adopt guidance, including a template, on the post-market monitoring plan by 2 September 2027.

Enforcement

Market surveillance, control of AI systems and mutual assistance

In order to strengthen the governance system for AI systems, new regulation clarifies the role of the AI Office in monitoring and supervising the compliance of AI systems. While the Commission has exclusive competence as regards general-purpose AI models, according to the amendment of Article 75 of the AI Act,  the AI Office shall be exclusively competent for the supervision and enforcement of the obligations in relation to:

(a) the AI systems based on general-purpose AI models where the model and the system are developed by the same provider, or by providers forming part of the same undertaking as that provider; Exceptions are within specific sectoral supervision, where responsibility remains with the relevant national competent authority, such as AI systems related to products covered by the Union harmonisation legislation listed in Annex I, Critical infrastructure, Administration of justice and democratic processes, AI systems provided by law enforcement authorities, border management authorities and financial institutions;

(b) AI systems that constitute or that are integrated into a very large online platform or very large online search engine designated in accordance with EU Digital Services Act .

The exclusive competence of AI Office shall apply to the providers of those systems. It shall apply to the deployers of those systems only when they are also the provider or form part of the same undertaking as the provider. In order to carry out the tasks assigned to it, the new Regulation provides the AI Office with a variety of powers, such as requesting information, conducting all necessary remote or on-site inspections.

Guidelines from the Commission on the implementation of this Regulation

and the power to adopt delegated acts

Amended articles 96 and 97 update and regulate in detail the power of the Commission to develop guidelines on the practical implementation of this Regulation, as well as to adopt delegated acts.