The Most Important Changes to the EU AI Act Under the Digital Omnibus
The EU’s Digital Omnibus on AI has changed several important parts of the EU AI Act. It is not merely a proposal: Regulation (EU) 2026/1744 entered into force on 27 July 2026.
These are the most important changes for organisations.
1. AI literacy remains mandatory—but the obligation is softer
Providers and deployers of AI systems must take measures to support the development of AI literacy among employees and other people using AI on their behalf.
However, organisations are no longer required to guarantee that every individual reaches a specific level of AI literacy.
Training should still reflect:
- The person’s knowledge, experience, education and training.
- The context in which the AI system is used.
- The people or groups affected by the AI system.
So, a generic AI course or participation certificate is still not automatically sufficient. Organisations need a role-based and risk-based AI-literacy approach.
2. Important high-risk AI deadlines have been postponed
The compliance dates for the main high-risk AI requirements have changed:
- High-risk AI systems listed in Annex III: 2 December 2027.
- High-risk AI systems connected to regulated products in Annex I: 2 August 2028.
This gives organisations more preparation time, but it does not remove the need to identify and classify their AI systems now.
3. The definition of a safety component is narrower
An AI system is not automatically a safety component simply because it is integrated into a regulated product.
Its intended purpose must be to prevent or reduce risks to people’s health and safety or to property—or its failure must create such risks. AI used only for convenience, automation, optimisation or efficiency will not necessarily qualify.
4. New prohibited AI practices have been added
The AI Act now explicitly prohibits certain AI systems used to generate or manipulate:
- Non-consensual intimate material.
- Child sexual abuse material, including synthetic material.
Providers must implement reasonable and adequate safeguards against foreseeable misuse. Deployers are prohibited from using AI systems for these purposes.
The new prohibitions apply from 2 December 2026.
5. Special personal data may be used to detect bias
Under strict conditions, providers and deployers may process special categories of personal data—such as data concerning ethnicity, health or religion—when this is strictly necessary to detect and correct AI bias.
This is not a general exemption from the GDPR. Strong privacy, security, access-control and documentation safeguards remain mandatory.
6. More support is provided to smaller businesses
Several benefits previously limited to microenterprises are extended to SMEs, start-ups and, in some cases, small mid-cap enterprises.
These include:
- Simplified quality-management requirements.
- Better access to AI regulatory sandboxes.
- More proportionate registration and compliance requirements.
- Greater consideration of company size when penalties are imposed.
7. Testing AI in real-world conditions becomes easier
The possibilities for testing high-risk AI systems outside regulatory sandboxes have been expanded. The AI Office may also establish an EU-level regulatory sandbox.
Testing remains subject to safeguards protecting health, safety, personal data and fundamental rights.
8. The European AI Office receives stronger powers
The AI Office receives broader supervisory and enforcement powers over:
- General-purpose AI models.
- Certain AI systems based on those models.
- AI systems operated by very large online platforms and search engines.
Its powers include requesting information, conducting investigations and inspections, requiring corrective action and imposing fines or periodic penalty payments.
What does this mean for organisations?
The Digital Omnibus simplifies and postpones parts of the EU AI Act, but it does not make organizational AI compliance optional.
Organisations should still:
- Maintain an inventory of the AI systems they provide or use.
- Determine their role as provider, deployer, importer or distributor.
- Classify their AI systems and related risks.
- Introduce role-based AI-literacy measures.
- Document training, decisions, safeguards and human oversight.
- Monitor the use and misuse of generative AI.
- Prepare for the revised high-risk AI deadlines.
The Omnibus provides more time and flexibility. It does not provide an excuse to wait to make sure everyone inside your organization has the right level of AI literacy to ensure Regulatory AI Compliance of your organization as a whole.
Reach Out
The EU AI Act requires role-based AI literacy education for people in different roles inside your organisation. Send me an email using this form. We can then plan a short online session to see if there is a match and how I can help with short practical online sessions tailored to specific roles, existing knowledge, use of AI systems and responsibilities under the EU AI Act.
Sincerely, Tony de Bree
P.S. Let’s connect on LinkedIn and follow me on Instagram and possibly on X @tonydebree.
