EU AI Act Omnibus Measures Are Now in Force: Key Changes Explained
On 27th July 2026, a package of amendments known as the Digital Omnibus on AI entered into force, altering several of the Act's timelines and easing some of its administrative demands. The good news for most businesses is that these changes buy you more time and reduce some of the paperwork, rather than adding new burdens.
Why the Omnibus Happened
The AI Act was always going to be implemented in stages, but the European Commission recognised that some of those stages were arriving faster than the practical tools needed to comply with them. National authorities had not finished designating the bodies responsible for conformity assessments, and harmonised technical standards for high-risk systems were still being developed. The Omnibus, first proposed in November 2025, was designed to close that gap between what the law expected and what businesses and regulators could actually deliver on time.
High-Risk AI Systems Now Have Longer to Comply
The most significant practical change is a delay to the obligations for high-risk AI systems. Rules for standalone high-risk systems listed in Annex III of the Act, which cover areas such as employment, education and access to essential services, now apply from 2nd December 2027 rather than the original date. For AI embedded in physical products already regulated under EU safety law, such as machinery, toys and lifts, the deadline moves further still, to 2nd August 2028. If your business had been working towards an earlier deadline for one of these systems, you now have meaningfully more runway, though it is worth using that time to clarify and develop your compliance and processes rather than assuming the requirement has gone away.
Easier Rules for Growing Businesses
Some simplified obligations that previously applied only to small and medium sized enterprises are now extended to small mid-cap companies too, giving a wider group of growing businesses a more proportionate compliance path. The Omnibus also expands access to regulatory sandboxes, including a new EU-level sandbox, which gives businesses more room to test AI systems under regulatory supervision before full rules apply.
Less Paperwork Around Registration and AI Literacy
The obligation to register certain exempted AI systems in the EU's central database has been simplified, cutting down on administrative work for systems that were never intended to carry the full weight of high-risk obligations. The previous AI literacy requirement placed on individual companies has also been eased, with the Commission and member states taking a larger role in promoting AI literacy more broadly rather than leaving it entirely to businesses to demonstrate.
New Safeguards Have Also Been Added
The changes are not entirely about relaxing rules. The Omnibus introduces a ban on AI systems that generate non-consensual sexually explicit or intimate content, closing a gap that had allowed so-called nudification apps to operate in a grey area. It also allows limited processing of special category personal data specifically for the purpose of detecting and correcting bias in AI systems, which had previously been a source of uncertainty for developers trying to test their systems for fairness.
The EU AI Office Now Has Wider Oversight
Enforcement powers have also shifted. The AI Office now has extended oversight over certain AI systems, including those built on general-purpose AI models and those embedded within large online platforms and search engines. If your business relies on foundation models from major providers, this is worth being aware of, as it changes who is watching that layer of the AI supply chain.
What You Should Do Next
If your business had a high-risk AI system on its roadmap for compliance this year, check the revised timeline against your own plans rather than assuming the original date still applies. The full legislative text and implementation timeline are available through the European Commission's AI Omnibus announcement, which also links to the AI Act's official implementation timeline. Delayed deadlines are not the same as removed obligations, and the underlying expectation that high-risk AI systems will eventually need to meet the Act's safety and transparency requirements has not changed. If you are uncertain how these changes affect a specific AI system your business uses or provides, it is worth getting tailored advice before you recalibrate your own internal deadlines.
How Can Gerrish Legal Help?
Gerrish Legal is a dynamic digital law firm. We pride ourselves on giving high-quality and expert legal advice to our valued clients. We specialise in many aspects of digital law such as GDPR, data privacy, digital and technology law, commercial law, and intellectual property.
We give companies the support they need to successfully and confidently run their businesses whilst complying with legal regulations without the burdens of keeping up with ever-changing digital requirements.
We are here to help you, get in contact with us today for more information.