EU AI Omnibus Regulation Takes Effect With Mixed Timeline For Compliance Obligations

corporate lawyer attorney US legal bankruptcy contract case

The European Union has adopted its first substantive amendment to the AI Act, marking a significant moment in the bloc’s evolving artificial intelligence regulatory framework.

Regulation (EU) 2026/1744, commonly known as the AI Omnibus, was published in the Official Journal on 24 July 2026 and entered into force just three days later on 27 July 2026.

While the legislation postpones certain aspects of the AI Act’s compliance timetable, it would be a mistake for organisations to view the Omnibus as a broad pause on AI regulation in Europe.

The most significant change introduced by the Omnibus is the deferral of obligations applying to many high-risk AI systems across several sectors.

The application date for stand-alone high-risk systems under Annex III, including AI used in employment, education, credit assessment, law enforcement and critical infrastructure, moves from 2 August 2026 to 2 December 2027.

For AI systems embedded in products already subject to EU product safety legislation, such as medical devices, machinery and toys, compliance is deferred further, until 2 August 2028.

Despite those deferrals, provisions governing general-purpose AI models continue to apply as planned, including transparency, reporting and systemic risk obligations for the largest models.

The Omnibus also introduces two new prohibited AI practices, targeting systems designed to generate or manipulate realistic intimate imagery or child sexual abuse material, with those prohibitions applying from 2 December 2026.

The legislation significantly strengthens the role of the European AI Office, granting it exclusive supervisory responsibility for certain AI systems built on general-purpose AI models and for systems integrated into very large online platforms and search engines regulated under the Digital Services Act.

The AI Office now holds powers closely resembling those exercised by European competition regulators, including the ability to launch investigations, compel the production of information, carry out inspections, accept binding commitments and impose periodic penalty payments of up to 5% of average daily turnover for continuing infringements.

Organisations should not be misled by headlines that say “delayed,” as delay does not extend to most of the AI Act’s transparency obligations, which remain firmly on track from 2 August 2026.

Businesses must continue to comply with requirements relating to disclosure that users are interacting with an AI system, labelling of deepfakes and certain AI-generated content, and notification obligations for emotion recognition and biometric categorisation systems.

A limited four-month grace period applies only to certain machine-readable marking requirements for generative AI systems already on the market before 2 August 2026.

The AI Omnibus provides welcome additional time for many organisations developing or deploying high-risk AI systems, though it is far from a regulatory pause, with key compliance obligations remaining imminent for many businesses.