European Union flags displayed outdoors, representing legal and regulatory services across EU jurisdictions.

EU Digital Omnibus on AI: What Do Businesses Need to Know?

The EU Digital Omnibus on AI updates compliance deadlines, transparency rules and oversight responsibilities under the AI Act.


In brief

  • The EU Digital Omnibus on AI extends key compliance deadlines for high-risk AI systems and introduces a new prohibition on harmful synthetic content.
  • Providers of AI-generated content face a 2 December 2026 transparency deadline, requiring outputs to be clearly labelled or marked.
  • The regulation clarifies regulatory oversight and aims to reduce duplicative compliance requirements across sector-specific EU legislation.

On 29 June 2026, the Council of the European Union formally adopted a new regulation designed to simplify and streamline certain rules under the EU Artificial Intelligence Act (the AI Act).  Known as the Digital Omnibus on AI, the regulation is part of the EU's broader “Omnibus VII” legislative simplification package. It amends three existing EU laws: the AI Act itself (Regulation (EU) 2024/1689), the Aviation Safety Regulation (Regulation (EU) 2018/1139), and the Machinery Regulation (Regulation (EU) 2023/1230).

The Digital Omnibus on AI is one part of the wider Digital Omnibus (Omnibus VII) — the seventh in a series of EU simplification packages launched by the Commission since February 2025. Those packages followed the Draghi Report on EU competitiveness and the European Council’s October 2024 call for regulatory simplification. The full Digital Omnibus covers six legislative instruments across two tranches, spanning many areas of EU digital law: the AI Act, GDPR, the Data Act, NIS2, cybersecurity certification, and digital business identity. The other instruments in the package — still at various stages of the legislative process — include the Data and Platform Omnibus (amending GDPR, the Data Act, NIS2, and ePrivacy), the European Business Wallets Regulation, the Cybersecurity Act 2, and the NIS2 Amending Directive. Of these, only the Digital Omnibus on AI has been formally adopted.

The regulation is largely a practical response to experience since the AI Act entered into force in August 2024. Stakeholders have found that delayed standards, incomplete national governance frameworks, and overlapping sectoral compliance requirements have created a bigger compliance burden than expected. The Digital Omnibus on AI addresses this by adjusting key application dates, introducing new prohibited AI practices, clarifying supervisory responsibilities, and reducing duplication between the AI Act and sector-specific legislation. The changes are significant for organisations that develop, deploy, or use AI systems in the EU.

Application Dates 

One of the most significant near-term changes is the shift in compliance deadlines for high-risk AI systems. The original AI Act set two separate application dates for high-risk AI systems — reflecting the different compliance challenges for stand-alone systems versus those embedded in regulated products. Both deadlines have now been pushed back:

  • Stand-alone high-risk AI systems (Annex III) – Original date: 2 August 2026 → New application date: 2 December 2027.
  • High-risk AI systems embedded in products (Annex I) – Original date: 2 August 2027 → New application date: 2 August 2028.

Organisations that were preparing for the previous deadlines should update their compliance plans — but should continue preparing rather than deferring work.

New Prohibition; Non-Consensual Sexual Deepfakes and CSAM

The regulation adds a new prohibited AI practice to the AI Act, targeting AI systems that generate or manipulate non-consensual intimate images and child sexual abuse material (CSAM). This responds to the growing spread of so-called ‘nudification’ applications and other tools that can generate harmful synthetic content. AI systems that produce non-consensual realistic intimate depictions of real people and/or CSAM will be banned from 2 December 2026, when the new provisions take effect.

Accelerated Transparency Deadline for AI-Generated Content

The regulation sets a transitional transparency deadline for providers of AI systems — including general-purpose AI systems — that generate synthetic audio, image, video or text content and have already placed their systems on the market before 2 August 2026. Those providers must implement the AI Act’s transparency marking and labelling requirements (under Article 50(2)) by 2 December 2026. Providers bringing new systems to market after that date must comply with the standard AI Act obligations from day one. This means affected providers will need to ensure their outputs are clearly marked or labelled within a fairly short timeframe.

AI Regulatory Sandboxes

The regulation also extends the deadline for establishing AI regulatory sandboxes to 2 August 2027. This may delay opportunities for businesses that were planning to test new AI systems within the sandbox framework.

Clarification of Supervisory Competences

The regulation clarifies how supervisory responsibility is divided between the EU AI Office and national authorities. The AI Office remains responsible for overseeing AI systems based on general-purpose AI models where the same provider developed both the model and the system. National authorities remain responsible in certain areas, including:  

  • Law Enforcement;
  • Border management; 
  • Judicial authorities; and
  • Financial institutions. 

Interplay with Sectoral Legislation

The regulation introduces a mechanism to handle overlaps between the AI Act’s high-risk requirements and those in existing sectoral legislation — for example, the rules covering medical devices, toys, lifts, and watercraft.

Where sectoral legislation sets AI-specific requirements similar to those in the AI Act, the Commission may adopt implementing acts to limit the AI Act’s application in those specific cases, cutting down on duplicative compliance obligations.

Products covered by the Machinery Regulation are exempt from the AI Act's direct application. Instead, the Commission can adopt secondary legislation under the Machinery Regulation to add health and safety requirements for AI systems classified as high-risk under the AI Act. 

The Commission is also required to provide guidance to help businesses operating high-risk AI systems under sectoral harmonisation legislation comply with the AI Act in a way that minimises the compliance burden.

Next Steps

The regulation will be published in the EU’s Official Journal shortly. It will enter into force on the third day after publication, at which point it will apply automatically and in full across all EU Member States.

What Should Businesses Do Now?

  • Review your AI governance framework and update it to reflect the Digital Omnibus on AI’s new timelines and prohibitions.
  • Map and classify all AI systems your business uses — HR, recruitment, credit scoring, and generative AI tools carry specific obligations, including a labelling deadline of 2 December 2026.
  • Update compliance timelines: 2 December 2027 (stand-alone high-risk, Annex III) and 2 August 2028 (AI in regulated products, Annex I) — and keep preparing, not deferring.
  • Check exposure to the new prohibitions: AI systems generating non-consensual intimate images or CSAM must have adequate safeguards in place by 2 December 2026.
  • Regulated-sector businesses (medical devices, aviation, machinery, financial services) should assess the AI Act/sectoral overlap — the Digital Omnibus on AI offers mechanisms to reduce duplication.
  • Ensure AI-generated outputs are detectably labelled by 2 December 2026; deployers should confirm vendor compliance contractually.
  • Support AI literacy: ensure staff who work with AI understand how systems operate, their limits, and when human oversight is required.
  • Engage your regulator early — the AI Office supervises general-purpose AI providers; national authorities cover most other deployments.

For further information on how these changes may affect your business, please contact Rob Haniver at Robert.Haniver@ie.ey.com or Susan Walsh at Susan.Walsh@ie.ey.com

Summary

The EU Digital Omnibus on AI introduces important updates to the EU AI Act, including extended compliance deadlines for high-risk AI systems, new rules prohibiting AI-generated non-consensual intimate content and CSAM, and earlier transparency requirements for AI-generated content. It also clarifies regulatory oversight and reduces overlapping compliance obligations between the AI Act and sector-specific legislation, helping businesses prepare for implementation more efficiently.

About this article

Contributors

Related articles