The Digital Omnibus on AI: What Regulation (EU) 2026/1744 Changed
The first amendment to the EU AI Act deferred the high-risk regime to 2 December 2027 and 2 August 2028 — but left the 2 August 2026 general application date intact. What moved, what did not, and what your compliance programme should do about it.
Most coverage of the first amendment to the EU AI Act reduces it to four words: the AI Act was delayed. That summary is wrong, and for a compliance team it is actively dangerous, because it invites an organisation to stand down work on obligations that are already enforceable and already carry penalties.
The accurate picture has two sides. The high-risk regime in Chapter III, Sections 1 to 3 was deferred, by sixteen months for stand-alone systems and by twelve months for product-embedded ones. Everything else held. The general application date of 2 August 2026 was not amended, enforcement began on that day, and the Article 5 prohibitions have been in force since 2 February 2025 regardless.
This article sets out what the amending regulation actually changed, what it deliberately left alone, and how to reallocate compliance effort in response.
What the Instrument Is
Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026 amends Regulation (EU) 2024/1689 as regards the simplification of the implementation of harmonised rules on artificial intelligence. It is commonly called the "Digital Omnibus on AI". It also amends Regulation (EU) 2018/1139 (civil aviation) and Regulation (EU) 2023/1230 (machinery).
It was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026, the third day after publication. It is the first amendment to the AI Act. EUR-Lex now carries a consolidated AI Act text dated 27 July 2026, which is the version to work from.
What Moved
Three deadlines changed. All three sit on the high-risk track.
| Obligation | Was | Now |
|---|---|---|
| Chapter III, Sections 1–3, for systems high-risk under Article 6(2) and Annex III (stand-alone use cases) | 2 August 2026 | 2 December 2027 |
| Chapter III, Sections 1–3, for systems high-risk under Article 6(1) and Annex I (products and safety components) | 2 August 2027 | 2 August 2028 |
| Article 57 national regulatory sandboxes operational | 2 August 2026 | 2 August 2027 |
The legal mechanism is Article 1(40)(b) of the amending regulation, which replaces point (c) of the third paragraph of Article 113. The replaced provision applies Chapter III, Sections 1, 2 and 3 — with the express exception of Article 6(5) — from 2 December 2027 for Article 6(2) and Annex III systems, and from 2 August 2028 for Article 6(1) and Annex I systems.
That covers the substantive requirements in Articles 8 to 15 and the provider and deployer obligations in Articles 16 to 27. It is a meaningful deferral for anyone building a high-risk compliance programme. It is not a deferral of the AI Act.
The Deferral Is Unconditional
This point is widely misreported. The Commission's original proposal, COM(2025) 836, would have tied the new application dates to a Commission decision confirming that harmonised standards were available — a "stop-the-clock" mechanism that could have extended the deferral further. The co-legislators dropped it.
There is no standards-readiness trigger in the adopted text and no further automatic delay. Commentary that describes the deferral as conditional, or that suggests the dates may slip again if CEN-CENELEC deliverables are late, is describing a proposal that was rejected, not the law. Plan against 2 December 2027 and 2 August 2028 as fixed dates.
What Did Not Move
This is the half of the story that goes missing, and it is where the enforcement exposure sits.
- 2 August 2026 remained the general application date. The second paragraph of Article 113 was not amended. The Commission's AI Office and national authorities began enforcing the AI Act on that date.
- Article 50 transparency obligations apply from 2 August 2026. Article 50 sits in Chapter IV, outside the Chapter III deferral. Chatbot disclosure, deepfake labelling and machine-readable marking of synthetic content are live.
- Article 49 registration is not deferred. It sits in Chapter III, Section 5, outside the Sections 1 to 3 deferral, and applies from 2 August 2026.
- Article 6(5) is expressly carved out of the deferral.
- Article 5 prohibitions have applied since 2 February 2025, unchanged.
- Article 99 fines are unchanged: up to EUR 35 000 000 or 7% of total worldwide annual turnover for Article 5 breaches; EUR 15 000 000 or 3% for other operator obligations, including Article 50; EUR 7 500 000 or 1% for incorrect or misleading information. The Article 99(6) rule applying the lower of the two figures to SMEs is unchanged.
- Chapter V on general-purpose AI was not substantively amended. Articles 51 to 55 and Annexes XI to XIII are untouched; the only change is the removal of the implementing-act approval power in Article 56(6). The Article 51(2) systemic-risk threshold remains 10^25 cumulative training FLOP, and GPAI models placed on the market before 2 August 2025 still have until 2 August 2027 under Article 111(3).
- Annex III itself was not amended. The eight use-case headings stand as enacted, and no Article 7 delegated act has been adopted.
- Article 6(3), the high-risk filter, was not substantively amended. The rule that an Annex III system performing profiling of natural persons is always high-risk survives.
- 2 August 2030, the legacy deadline for public-authority systems, is unchanged.
An organisation that read "the AI Act was delayed" and paused its Article 50 or Article 49 work is out of compliance today, not in 2027. Those obligations sit outside the deferral and carry the 3% penalty tier.
Need auditable AI for compliance?
Ctrl AI provides full execution traces, expert verification, and trust-tagged outputs for every AI decision.
Learn About Ctrl AITwo New Prohibitions from 2 December 2026
The amending regulation inserts two new points into Article 5, both applying from 2 December 2026:
- Article 5(1)(ba) prohibits AI systems that generate or manipulate realistic intimate imagery of an identifiable person without that person's consent.
- Article 5(1)(bb) prohibits AI systems that generate or manipulate child sexual abuse material.
Scoping for both sits in the new Article 5(1a) and 5(1b). Because these are Article 5 provisions, breaches fall in the highest penalty tier. The Commission guidelines on prohibited practices of 4 February 2025 remain the operative Article 5 guidance and do not yet address either addition.
The Article 111(4) Marking Grace Period
A new Article 111(4) gives generative AI systems that were placed on the market before 2 August 2026 until 2 December 2026 to meet the machine-readable marking duty in Article 50(2).
The scope of this grace period is narrow. It covers Article 50(2) marking only, and only for pre-existing systems. Systems placed on the market on or after 2 August 2026 had to meet Article 50(2) from day one, and the other Article 50 duties — interaction disclosure under Article 50(1), deepfake disclosure under Article 50(4) — were not given any grace period at all.
Other Changes
Article 4 on AI literacy was rewritten and softened. It is now best read as a proportionate expectation calibrated to the risk and complexity of the use, rather than a hard, audited duty. Training programmes remain sensible practice, but the amended text no longer frames literacy as a prescriptive obligation.
Machinery moved within Annex I, from Section A to Section B. Annex III, by contrast, was not amended.
A new Article 43(3) deadline of 28 January 2028 requires bodies already notified under the sectoral legislation listed in Annex I, Section A to apply for designation under Chapter III, Section 4 of the AI Act by that date. This matters to anyone planning a third-party conformity assessment route for a product-embedded system.
Articles 102 to 110 of the AI Act were pulled forward to apply from 27 July 2026.
One drafting mismatch is known and worth recording. Article 111(1), on large-scale IT systems listed in Annex X, was not realigned with the new dates. It still refers internally to 2 August 2027, with a compliance date of 31 December 2030.
The Dates That Now Matter
What This Means for Your Compliance Programme
Keep doing now what was already due. Article 50 disclosure and marking, Article 49 registration and Article 5 screening are all enforceable, and none of them were deferred. If the amendment prompted a review, the correct output of that review is a confirmation that these three workstreams are staffed, not a pause.
Add 2 December 2026 to the near-term plan. Two things land on that date: the two new Article 5 prohibitions, and the expiry of the Article 111(4) marking grace period for pre-existing generative systems. The second requires engineering work on output marking, which is not a task to start in November.
Treat the extra sixteen months on the high-risk track as capacity, not slack. The obvious use is the work that has to happen sequentially: classification under Article 6 across the portfolio, the Article 9 risk management system, data governance under Article 10, the Annex IV technical documentation, logging, human oversight design, and — where a third-party route applies — the notified body engagement that now has its own 28 January 2028 marker.
No harmonised standard has been cited in the Official Journal. No CEN-CENELEC JTC 21 deliverable yet confers a presumption of conformity under Article 40, and standardisation request M/613 runs to 28 February 2027. Documentation and risk management work therefore cannot simply wait for standards to arrive: an organisation that defers everything until a citable standard exists may have very little time left when one appears.
What Remains Unsettled
Two things are frequently cited as though they were law and are not.
The data strand of the Digital Omnibus, COM(2025) 837 — which would amend the GDPR, the ePrivacy rules, the Data Act, NIS2 and DORA — remains a proposal. Only the AI strand became Regulation (EU) 2026/1744. Nothing in the data proposal is binding.
The Commission guidelines on high-risk classification under Article 6(5), published on 19 May 2026 in three documents, are draft. The consultation closed on 23 July 2026, and the statutory deadline of 2 February 2026 for these guidelines was missed. Positions taken from them should be recorded internally as draft interpretations, not settled guidance.
For the full sequence of application dates across the regulation, see the EU AI Act timeline; for the structure of the regulation as a whole, see the EU AI Act overview.
Frequently Asked Questions
What is Regulation (EU) 2026/1744?
Was the EU AI Act delayed?
Which EU AI Act obligations are enforceable now?
Is the high-risk deferral conditional on harmonised standards being ready?
What new prohibitions did the Digital Omnibus on AI add?
Make Your AI Auditable and Compliant
Ctrl AI provides expert-verified reasoning units with full execution traces — the infrastructure you need for EU AI Act compliance.
Explore Ctrl AIRelated Articles
Annex I Explained: AI in Regulated Products Under the EU AI Act
How Annex I of the EU AI Act classifies AI systems embedded in regulated products — medical devices, machinery, toys, vehicles, aviation, marine, and more. Conformity assessment, deadlines, and the MDR/IVDR interaction.
Annex III Explained: Standalone High-Risk AI Systems Under the EU AI Act
Detailed breakdown of all eight categories of standalone high-risk AI systems in Annex III of the EU AI Act — biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, and justice.
High-Risk AI Systems: Complete Requirements Under the EU AI Act
Detailed guide to the requirements for high-risk AI systems under the EU AI Act — risk management, data governance, documentation, human oversight, accuracy, and cybersecurity.