On 27 July 2026, a package of amendments to the EU Artificial Intelligence Act, commonly referred to as the “AI Omnibus”, entered into force across the European Union. The reform does not rewrite the AI Act’s core structure, but it resets several of its implementation deadlines and simplifies a number of administrative obligations, following more than a year of debate about whether Europe’s flagship AI law was ready to apply as originally scheduled.
Background: from proposal to law
The AI Omnibus originated as part of a broader “Digital Omnibus” package that the European Commission published on 19 November 2025. That package covered two separate legislative proposals: one amending EU data protection and cybersecurity rules, and a second, the Digital Omnibus on AI, amending the AI Act (Regulation (EU) 2024/1689) itself, along with a related update to the EU’s civil aviation rules.
The Commission’s stated rationale was that a public consultation and ongoing implementation work had revealed practical obstacles to applying parts of the AI Act on schedule, among them, delays in finalising the harmonised technical standards that companies need to demonstrate compliance, and delays by member states in designating the national authorities responsible for market surveillance and conformity assessment. The Commission framed the Omnibus as a way to protect the AI Act’s underlying safeguards while giving companies and regulators more realistic timelines and lighter administrative requirements, particularly for smaller businesses. The proposal then went through the EU’s ordinary legislative procedure. The Council of the EU agreed its negotiating position in March 2026, and the European Parliament adopted its own position before the two institutions entered trilogue negotiations with the Commission. After a first round of talks failed to produce agreement in April 2026, negotiators reached a political deal in the following weeks. The European Parliament gave its formal endorsement in mid-June 2026, the Council gave final approval on 29 June 2026, and the text was published in the EU’s Official Journal shortly afterward, entering into force on 27 July 2026, three days after publication, as is standard for EU legislation of this kind.
What the reform changes
According to the European Commission’s own summary, the AI Omnibus introduces changes across four broad areas.
Support for innovation: Several compliance simplifications previously available only to small and medium-sized enterprises (SMEs) are extended to “small mid-cap” companies (SMCs), a category generally understood to cover firms with several hundred employees that sit just above the SME threshold. The reform also broadens access to regulatory sandboxes, supervised environments in which companies can test AI systems under regulatory oversight, and creates a new EU-level sandbox in addition to the national ones already provided for under the Act.
Extended compliance timelines: This is the most consequential change in practical terms, obligations for high-risk AI systems listed in Annex III of the AI Act, covering uses such as employment, credit scoring, law enforcement, and access to essential services, will now apply from 2 December 2027, rather than the original date of 2 August 2026. Obligations for high-risk AI embedded in regulated physical products, such as machinery, toys, and lifts (Annex I of the Act), are pushed back further, to 2 August 2028.
Reduced administrative burden: The reform simplifies the AI literacy obligation that the Act placed on organisations deploying AI systems, shifting more responsibility for promoting AI literacy onto the Commission and member states. It also streamlines the process for registering certain exempted AI systems in the EU’s central database.
Safety and fundamental rights provisions: Alongside the simplification measures, the Omnibus adds an explicit prohibition on AI systems that generate non-consensual sexually explicit or intimate imagery, so-called “nudification” tools.
Governance alignment: The EU AI Office’s oversight powers are extended to cover certain AI systems built on general-purpose AI models and embedded in large online platforms and search engines, and the reform clarifies how the AI Act interacts with other pieces of EU law, along with simplifying procedures for the bodies responsible for conformity assessment.
A contested process
The path to adoption was not uncontroversial. Because the Digital Omnibus package touched core elements of both the AI Act and EU data protection law, it drew sustained criticism from digital rights organisations, some data protection authorities, and parts of academia. Critics, including coalitions of civil society groups such as European Digital Rights (EDRi), argued at various points in the process that the Commission had not conducted a full impact assessment of the proposal’s effects on fundamental rights, and that some of the originally proposed changes, such as a plan to loosen registration requirements for AI systems that providers self-declared as not high-risk, would have weakened transparency and accountability under the Act. Some of the most contested elements were ultimately dropped or narrowed during negotiations between the Parliament, the Council and the Commission, though advocacy groups continued to argue that the final deal still reduces oversight in some areas, including changes affecting how AI embedded in machinery is classified.
Supporters of the reform, including the Commission and a majority of member states in the Council, argued that the changes were necessary to avoid a situation in which companies faced binding high-risk obligations before the technical standards and national enforcement infrastructure needed to comply with them were actually in place, and that a delay of this kind reduces legal uncertainty rather than reducing protection for individuals.
What happens next
With the Omnibus now in force, the practical effect for organisations developing or deploying AI in the EU is a later compliance horizon for high-risk obligations, rather than a change to whether those obligations will eventually apply. Businesses that had been preparing for the original 2 August 2026 deadline for Annex III systems now have until December 2027, and until August 2028 for AI embedded in regulated physical products. The Commission and member states are expected to continue work on the underlying technical standards and national enforcement structures during the extended transition period, and further implementing guidance is likely as the new deadlines approach.
Background Reading and Additional Sources:
European Commission, Futurium – Apply AI Alliance, “AI Omnibus enters into force”: https://futurium.ec.europa.eu/en/apply-ai-alliance/news/ai-omnibus-enters-force
Official Journal text of the adopted regulation: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ:L_202601744
AI Act Service Desk, implementation timeline: https://ai-act-service-desk.ec.europa.eu/en/ai-act/timeline/timeline-implementation-eu-ai-act
European Commission, original Digital Omnibus on AI proposal, COM(2025) 836 final: https://ec.europa.eu/newsroom/dae/redirection/document/121744
European Commission press release on the Digital Omnibus package: https://ec.europa.eu/commission/presscorner/detail/en/ip_25_2718
Council of the EU, “Artificial Intelligence: Council and Parliament agree to simplify and streamline rules”: https://www.consilium.europa.eu/en/press/press-releases/2026/05/07/artificial-intelligence-council-and-parliament-agree-to-simplify-and-streamline-rules/
European Parliament, Legislative Train Schedule, “Digital Omnibus on AI”: https://www.europarl.europa.eu/legislative-train/package-digital-package/file-digital-omnibus-on-ai
