EU AI Omnibus takes effect: new AI Act deadlines
The EU AI Omnibus took effect on 27 July 2026. We explain new high-risk deadlines, deepfake rules, sandboxes, business duties and a compliance plan.
- AUTHOR
- Karol Rapacz / CEO of Breachroad · OSCP · PNPT
- PUBLISHED
- 27 July 2026
- READING TIME
- 19 min read
- TOPIC
- AI Security
The EU AI Omnibus entered into force on 27 July 2026. Regulation (EU) 2026/1744 changes parts of the AI Act timetable and operating mechanisms, extends support to smaller companies, establishes a basis for an EU-level regulatory sandbox and clarifies oversight of high-risk systems and general-purpose models. It also introduces provisions addressing non-consensual intimate material and child sexual abuse material generated or manipulated with AI.
The essential point for a business is that entry into force does not mean every new provision applies in full today. Some deadlines move to 2027 and 2028, while certain new prohibitions begin to apply on 2 December 2026. A compliance team needs a provision-specific timeline, not the broad claim that “the AI Act has been postponed”.
This analysis is based on the European Commission announcement and the text of Regulation 2026/1744 in EUR-Lex. It is information about technical and organisational consequences, not legal advice for a specific system.
What changed on 27 July
The Commission presents the AI Omnibus as administrative simplification that preserves protections for safety and fundamental rights. Its most visible changes concern five areas:
- revised dates for high-risk AI requirements;
- proportionate treatment extended to small mid-cap companies, not only SMEs;
- broader access to supervised testing and regulatory sandboxes;
- clearer prohibited uses of generative AI;
- changes to oversight, registration, AI literacy and post-market monitoring.
This is not a repeal of the AI Act. Elements already applicable remain part of the regime, while the Omnibus amends defined articles, dates and mechanisms. A company must still determine its role—provider, deployer, importer, distributor or product manufacturer—and classify each use case.
New dates for high-risk systems
Requirements in Chapter III, Sections 1–3 will apply on the revised timetable:
- 2 December 2027 for systems classified as high-risk under Article 6(2) and Annex III;
- 2 August 2028 for high-risk systems under Article 6(1) and Annex I, which are tied to regulated products.
The first group includes function- and use-based categories such as defined biometric, employment, education, essential-service and justice systems. Exact scope always requires the current annex and the facts of the application. The second group covers AI that is a product or safety component governed by listed Union harmonisation legislation.
A delayed deadline is not permission to start a project without controls. Data documentation, risk management, logging, human oversight, resilience and cybersecurity are architectural features. Adding them immediately before conformity assessment can require changes to the model, pipeline and user interface.
AI literacy: simplification is not the absence of competence
The Commission says the prior corporate AI-literacy requirement has been simplified, with the Commission and Member States taking a stronger role in promotion. That should not be interpreted as evidence that user training is unnecessary.
When an employee can submit personal data, approve a high-risk decision or run an agent with tools, documented competence is a practical risk control. Training should be role-specific:
- an ordinary user understands data policy and output limitations;
- a reviewer understands error criteria, bias and required evidence;
- an administrator controls access, logs, models and integrations;
- a business owner owns purpose, metrics and escalation;
- security teams test abuse, prompt injection and tool boundaries.
Evidence does not have to be a mass certificate for an identical course. A register of roles, materials, knowledge checks and permissions granted after meeting criteria is more useful.
SMC support and the regulatory sandbox
The Omnibus extends some proportionate mechanisms from SMEs to small mid-cap companies. The intention is to reduce burdens for growing businesses that have crossed the SME threshold without gaining the resources of the largest providers.
The Regulation also expands access to regulatory sandboxes and creates an EU-level sandbox. A sandbox is not a law-free zone. It is supervised testing with a defined objective, data scope, exit criterion and safeguards for affected people.
A strong technical submission should include:
- the model, version and supplier;
- a data-flow map and basis for processing;
- risk classification and misuse scenarios;
- evaluation, red-team and human-oversight plans;
- incident response and shutdown arrangements;
- criteria for moving from test to production.
Without that package, both regulatory discussion and safe deployment become harder.
New prohibitions covering intimate material and CSAM
The Omnibus adds provisions covering systems that generate or manipulate non-consensual intimate material and child sexual abuse material, including synthetic content. Under the amended timeline, the new Article 5 elements apply from 2 December 2026.
The legislative text is more precise than the shorthand “nudification-app ban”. On the provider side, it covers systems intended for that purpose and cases where the output is a reasonably foreseeable and reproducible result without reasonable, adequate safeguards. Examples in the text include data cleaning, refusal training, safe prompt design, output controls, content classification, usage restrictions, abuse detection and notice-and-action mechanisms.
On the deployer side, using an AI system for that purpose—including circumventing safeguards—is prohibited. The Regulation also distinguishes consent, medical uses, realistic depiction and the manipulation of existing content. A concrete product in this area requires specialist legal analysis.
Technically, providers need evidence of more than the presence of a filter. They should demonstrate effectiveness against known and reasonably foreseeable bypasses through red-team testing, privacy-compliant abuse monitoring, reporting mechanisms and updates after circumvention is found.
Special-category data and bias detection
The amendment broadens the legal basis that may permit processing special categories of personal data, under strict conditions and safeguards, for bias detection and correction. It is not a general authorisation to collect more data.
Teams should document necessity, minimisation, access, retention, dataset separation and the evaluation method. Data used for a fairness audit should not automatically become production-model features. Review must determine whether correcting one bias creates a privacy violation or another discriminatory effect.
Useful technical measures include pseudonymisation, an isolated environment, export controls, minimum cohort-size statistics and interdisciplinary review.
Marking synthetic content
The Regulation clarifies a transition for providers of systems generating synthetic text, image, audio or video. Systems placed on the market before 2 August 2026 must take the necessary steps to comply with Article 50(2) by 2 December 2026.
A company should treat marking as an end-to-end chain rather than a single watermark:
- metadata needs to survive ordinary export and publication;
- the mechanism should be machine-readable;
- generation logs should support abuse investigations;
- the interface must explain limitations;
- integrations and intermediaries should not strip the signal;
- tests should cover compression, cropping, transcoding and republication.
If a marker disappears during the first routine transformation, the formal presence of a feature does not create meaningful traceability.
Registration, oversight and technology codes
The Commission highlights simplified registration for systems found to be exempt from the high-risk category. A company still needs evidence supporting the exemption. A bare “not high-risk” label without an assessment of purpose, users and effects is difficult to defend.
The AI Office receives broader authority over certain systems, including those based on general-purpose models and embedded in large platforms or search engines. For providers, this increases the importance of a coherent evidence package: a model card, data description, evaluation results, incidents, limitations and post-market monitoring.
A new Annex XIV introduces codes defining the notification scope of conformity-assessment bodies. The technology codes cover generative AI and systems based on GPAI, and a separate emerging-technology category expressly includes Agentic AI. The code does not itself classify every agent as high-risk; it structures the competence scope of assessment bodies and signals that agentic systems are treated as a distinct assessment problem.
What a European business should do now
The best outcome from 27 July is not moving every task into a 2027 backlog. It is updating the system register and delivery roadmap. A minimum programme includes:
- Inventorying all models, agents and AI features, including those purchased inside SaaS.
- Mapping the legal role for every use case and supplier agreement.
- Reclassifying risk against the amended text and current annexes.
- Updating the timeline for 2 December 2026, 2 December 2027 and 2 August 2028.
- Defining evidence for data, evaluation, logs, oversight and cybersecurity.
- Reviewing content generation for consent, safeguards, CSAM and non-consensual intimate material.
- Testing synthetic-content marking throughout the publication pipeline.
- Reviewing contracts for model changes, incidents, audit and deletion.
- Building post-market monitoring around real metrics rather than an annual checkbox.
- Creating an exit path that can disable AI without stopping the core business process.
Our earlier practical guide to EU AI Act business obligations remains useful for roles and controls, but its timetable should now be read together with today’s binding Omnibus text.
Cybersecurity remains a design requirement
A delayed compliance date does not prevent an AI system from being attacked beforehand. Prompt injection, poisoned retrieval, agent-token compromise, data leakage and model manipulation are operational risks today.
The compliance programme should use the same evidence as the security programme: threat models, penetration tests, logs, vulnerability management, access controls and incident exercises. Documentation written only for an auditor quickly diverges from production.
For agentic systems, separate identities, least-privilege tools, action limits and approval of high-impact operations are especially important. The appearance of Agentic AI in the new annex shows regulatory direction, but technical accountability remains with the organisation granting the agent access.
Bottom line
The AI Omnibus entered into force on 27 July 2026 and materially changes the AI Act implementation plan. It provides more time for parts of the high-risk regime and proportionate support for smaller organisations. It also adds prohibitions, clarifies oversight and creates preparation work for deadlines as early as 2 December 2026.
A business should not confuse postponement with cancellation. The advantage of additional time is the ability to produce technical evidence: a system register, evaluations, data controls, agent security, monitoring and an exit plan. Those features cannot credibly be bolted on one week before assessment.
Primary sources: European Commission — AI Omnibus enters into force, EUR-Lex — Regulation (EU) 2026/1744, AI Act Service Desk — implementation timeline.


