The Digital Omnibus on AI: What's Proposed, What's Law, and What You Must Do by 2 August 2026

The short answer: a provisional political agreement exists, but it is not yet law. On 7 May 2026, EU negotiators reached a deal - the "Digital Omnibus on AI" - that would postpone the Annex III high-risk compliance deadline from 2 August 2026 to 2 December 2027. Until that deal clears a Parliament plenary vote, formal Council adoption, and publication in the Official Journal, the original 2 August 2026 date remains the binding legal default. Plan to it. Treat any relief as upside.
This post is informational, not legal advice. For advice specific to your organisation, consult qualified legal counsel.
What Is the Digital Omnibus on AI?
The AI Omnibus is part of a broader Digital Omnibus legislative package published by the European Commission on 19 November 2025, which aims to simplify the EU's digital regulatory framework. The AI-specific slice targets the EU AI Act directly, proposing targeted amendments to timelines, scope, and prohibited practices.
On 7 May 2026, the European Parliament and the Council of the European Union reached a provisional political agreement under the European Commission's "Digital Omnibus" package to amend and streamline aspects of the EU AI Act. The relatively quick process reflects mounting pressure to avoid legal uncertainty ahead of 2 August 2026, which is the current implementation deadline for high-risk AI systems.
PROPOSED — NOT YET LAW. The provisional agreement of 7 May 2026 still requires a European Parliament plenary vote, formal Council adoption, and publication in the Official Journal before it takes legal effect. Until that happens, every obligation due on 2 August 2026 remains fully binding.
What the Omnibus Would Change
1. Annex III high-risk deadline: 16-month extension
For providers of stand-alone Annex III high-risk AI systems, the agreement extends the runway to substantive compliance by sixteen months, from 2 August 2026 to 2 December 2027. Annex III covers a wide range of systems - including recruitment, credit scoring, law enforcement, education, and border control tools.
2. Annex I product-safety-component rules: pushed to 2 August 2028
The obligations that apply to high-risk AI systems that are embedded in regulated products in Annex I are deferred until August 2, 2028. This covers AI built into medical devices, machinery, and other CE-marked products. The Omnibus does considerably less on the architectural questions concerning AI systems embedded in products already governed by EU sectoral product safety legislation, which had broken the previous trilogue at the end of April and which remain only partially resolved.
3. Article 50 transparency: grace period shortened, not removed
The Article 50 transparency obligations for AI systems largely remain on the original schedule. Businesses subject to those obligations must stay ready for 2 August 2026 regardless of the Omnibus.
The one targeted change concerns the watermarking obligation under Article 50(2). The Commission's November 2025 proposal would have postponed the application of that obligation by six months. The Parliament's negotiating mandate sought a three-month postponement. The compromise reached in the trilogue sets the deadline at four months, meaning that providers placing generative AI systems on the EU market will be required to comply with Article 50(2) marking obligations from 2 December 2026.
Systems entering the EU market on or after 2 August 2026 must comply from the date they are placed into service - there is no grace period for new market entrants.
4. A new 9th prohibition under Article 5: AI "nudifiers" and CSAM
The co-legislators have agreed to include a new prohibited practice under Article 5 of the AI Act, which bans AI systems that are capable of generating non-consensual sexual and intimate content or CSAM. The drafting reaches beyond purpose-built nudifier tools to systems whose functionality renders such misuse reasonably foreseeable. As a prohibited practice under Article 5, violations carry the maximum penalty: up to €35 million or 7% of global annual turnover.
The new Article 5 nudifier/CSAM prohibition, if adopted, would apply from 2 December 2026.
Original vs. Proposed Dates at a Glance
| Obligation | Original Date | Proposed Date (if Omnibus adopted) | Status |
|---|---|---|---|
| Article 5 prohibitions + Article 4 AI literacy | 2 Feb 2025 | Unchanged | ✅ IN FORCE |
| GPAI rules, AI Office governance, penalties | 2 Aug 2025 | Unchanged | ✅ IN FORCE |
| Article 50 transparency (general) | 2 Aug 2026 | Unchanged — 2 Aug 2026 | ⚠️ BINDING — plan now |
| Article 50(2) watermarking (existing systems) | 2 Aug 2026 | 2 Dec 2026 (4-month grace) | 🔶 PROPOSED |
| Annex III high-risk AI obligations | 2 Aug 2026 | 2 Dec 2027 | 🔶 PROPOSED |
| New Art. 5 prohibition (nudifiers / CSAM) | N/A (new) | 2 Dec 2026 | 🔶 PROPOSED |
| Annex I product-safety-component AI | 2 Aug 2027 | 2 Aug 2028 | 🔶 PROPOSED |
What Is Already in Force - and Unaffected
Two layers of the AI Act are already live and the Omnibus does not touch them.
Article 5 prohibitions and Article 4 AI literacy (since 2 February 2025). The Article 5 prohibited practices - including bans on social scoring, real-time remote biometric identification in public spaces (with narrow exceptions), and subliminal manipulation - have applied since 2 February 2025. The Article 4 duty to ensure AI literacy across your workforce applies from the same date. These are not deferred.
GPAI model rules, governance, and penalties (since 2 August 2025). The General-Purpose AI obligations under Articles 50 to 55 of the AI Act, which have been in force since 2 August 2025, are not amended by the Omnibus and continue to apply on their existing terms. If you develop or deploy a GPAI model - think large language models, foundation image generators - those rules are live now.
What Still Needs to Happen Before the Omnibus Becomes Law
The provisional agreement requires endorsement by the Council and the European Parliament, then legal-linguistic revision, then publication in the Official Journal. Formal adoption and publication in the Official Journal are expected in the coming weeks, in advance of the 2 August 2026 deadline.
Should the Omnibus not be formally adopted prior to 2 August 2026, the provisions of the original Act, including the high-risk obligations and their initially envisaged timeline, will take effect from that date as originally drafted.
That is not a theoretical risk. It is the legal default.
How to Plan Right Now
Although the Omnibus delays the high-risk obligations, it does not remove the need to build system inventories, risk-classification logic, supplier due diligence, and evidence packs. The additional time will likely raise the bar for what regulators consider reasonable preparedness.
Here is the practical framework:
1. Plan to 2 August 2026 - not to December 2027. The Omnibus is not law yet. Any organisation that pauses its compliance programme on the basis of a provisional deal is taking a legal risk it does not need to take.
2. Treat the proposed extension as upside, not a plan. If the Omnibus is formally adopted before 2 August 2026 - as expected - the extended dates become your new runway. Use that runway to build a more robust programme, not to start later.
3. Article 50 transparency is not deferred for most systems. The broader Article 50 transparency obligations, including the requirement to disclose to users when they are interacting with AI systems, remain on the original schedule. The Article 50 transparency obligations are largely unaffected by the Omnibus. Businesses subject to those obligations should continue preparing for that date.
4. Watch for formal adoption. The agreement must still be formally endorsed and adopted by the co-legislators before it becomes law. Given the proximity of the original August 2026 deadline, the legislative process is expected to proceed on an accelerated timeline in the coming weeks.
5. Audit for nudifier exposure now. If you provide a general-purpose image generation model, the safe-harbour design needs to be part of your risk management documentation. There is no "we'll add it later" path. If you build downstream apps on top of someone else's generative model, the prohibition still applies to you.
Use the Compliance Planner
Not sure which deadlines apply to your organisation? Use the interactive planner below to map your AI systems against the binding and proposed dates.
Stay current. The Omnibus is moving fast — formal adoption could come any week before 2 August 2026. Bookmark our live AI Act timeline for date-by-date updates as each legislative step completes, and subscribe to The AI Act Brief for plain-English analysis delivered to your inbox the moment anything changes.
Related reading

Harmonised Standards and Presumption of Conformity Under the EU AI Act: A Plain-English Guide to Articles 40 and 41
What "presumption of conformity" actually buys you under Articles 40 and 41, why the CEN-CENELEC standards are delayed, and what high-risk AI providers must do right now.

EU AI Act Article 9: A Plain-English Guide to the Risk Management System for High-Risk AI
Article 9 of the EU AI Act requires a continuous, lifecycle-wide risk management system for every high-risk AI system. Here's exactly what that means and how to build one.

Article 22 EU AI Act: The Plain-English Guide to Authorised Representatives for Non-EU Providers
If you build high-risk AI outside the EU and want to sell into the EU market, Article 22 requires you to appoint an EU authorised representative by written mandate - before you go live. Here's exactly what that means.