The European Union's rulebook for artificial intelligence changed on 27 July 2026, as the Digital Omnibus on AI — Regulation (EU) 2026/1744 — entered into force. Published in the Official Journal on 24 July and effective on the third day thereafter, the act amends the landmark AI Act just days before its most consequential enforcement milestone, deferring key high-risk obligations while adding new prohibitions and preserving the law's core architecture.

A Deliberately Urgent Timeline

The speed was intentional. The regulation's own text explains that it took effect on the third day after publication to ensure legal certainty without delay — in view of the AI Act's imminent general application on 2 August 2026. Brussels wanted the amended rules settled before that date arrived, rather than leaving companies to prepare against a text that was about to change.

As of 27 July, the AI Act is no longer the 2024 statute businesses first studied. It is that text as amended by the Omnibus, which also touches EU regulations on civil aviation and machinery. Legal teams that spent two years mapping compliance to the original wording now have a revised baseline to work from.

What Actually Changed

The most significant substantive shift is timing. High-risk AI obligations have been postponed by more than a year relative to the original schedule:

  • Standalone high-risk systems under Annex III — covering recruitment, credit scoring, law enforcement, education and border-control tools — now face a compliance deadline of 2 December 2027.
  • AI embedded in regulated products under Annex I — including medical devices, machinery and vehicles — must comply by 2 August 2028.

The rationale was pragmatic rather than political. The technical standards needed to assess conformity for high-risk AI were not ready, and penalising companies for failing against benchmarks that did not yet exist was legally incoherent. The institutions acknowledged as much and moved the deadlines to dates when the standards will actually be in place.

The Omnibus is not only a set of deferrals. Co-legislators added a new prohibition targeting AI-generated non-consensual sexual and intimate content — effectively banning "nudification" apps — and the creation of child sexual abuse material using AI systems. A grandfathering rule also gives generative AI systems placed on the market before 2 August 2026 until 2 December 2026 to meet watermarking requirements for synthetic content.

Why It Matters

For all the attention on the delay, this is a targeted reform, not a rollback. The AI Act's fundamental architecture — its risk-based approach, its governance structure under a strengthened AI Office, and its core obligations — remains intact. The high-risk deadlines moved; the framework did not.

That distinction matters for how businesses and other jurisdictions read the EU's intentions. A dismantling would have signalled retreat under industry pressure. A deferral tied explicitly to missing technical standards signals something narrower: a regulator adjusting its timeline to reality while holding its principles. Companies that assumed the high-risk rules were softening in substance are likely to be disappointed.

Crucially, 2 August 2026 remains the single most consequential date in the AI Act's remaining calendar. Despite the high-risk delay, several enforcement mechanisms still activate then — including the Article 50 transparency obligations and penalty powers over providers of general-purpose AI models. Organisations deploying chatbots, generative tools or GPAI-based systems cannot treat the Omnibus as breathing room; their obligations arrive on schedule next week.

A Signal Beyond Europe

The Omnibus lands amid a wider pattern of regulatory convergence. Across jurisdictions with very different legal traditions, the same building blocks keep recurring — risk-based frameworks, transparency requirements and accountability structures — and 2026 is the year that convergence turns into operational pressure. The OECD's policy observatory now tracks more than 1,000 AI policies across over 70 jurisdictions.

The contrast with the United States remains sharp. Washington's approach is defined by executive action rather than comprehensive legislation, with binding obligations sitting mostly in state law — California, Texas, Illinois and Utah duties already in force — while a federal preemption push plays out. Europe, by amending rather than pausing its statute, is reaffirming that its comprehensive, binding model is here to stay.

A practical thread runs through nearly every current and proposed AI rule, in Brussels and beyond: documentation. Whether an organisation is preparing for the AI Act's August transparency duties or a US state's requirements, the ability to show regulators what a system does, how it was evaluated and why it behaved as it did is becoming the common currency of compliance.

For companies operating in or selling into the EU, the immediate task is clear. Re-baseline against the amended AI Act, confirm which obligations still bite on 2 August, and treat the high-risk deferral as time to build robust conformity processes — not as permission to defer the work. The rulebook has been revised, but the direction of European AI governance is unchanged.

Sources