AI Omnibus has entered into force: what changed in the AI Act and what businesses should do now

AI Omnibus has entered into force: what changed in the AI Act and what businesses should do now

On 27 July 2026, the AI Omnibus came into force in the European Union — the first major package of amendments to the EU AI Act. It postpones deadlines for high-risk AI systems, simplifies some documentation and expands testing opportunities.

But this is not a repeal of the AI Act or a blanket delay. As early as 2 August 2026, transparency requirements will start to apply to chatbots, AI assistants and certain types of generated content.

In short. Developers of high-risk systems have been given more time. Ordinary businesses using chatbots, AI agents, content generation and automation should not relax yet: transparency, AI literacy, GDPR and control over system actions remain relevant.

Publication and review date: 28 July 2026 | CenterAI Editorial Team

What happened

The AI Omnibus was proposed by the European Commission on 19 November 2025 as part of a package to simplify digital legislation. The final document — Regulation (EU) 2026/1744 — was adopted on 8 July, published on 24 July and entered into force on 27 July 2026.

According to the European Commission, the amendments aim to reduce the administrative burden, give businesses greater legal certainty and avoid requiring companies to meet complex requirements before the necessary standards and tools are available.

At the same time, the core logic of the AI Act remains unchanged: the greater the potential harm an AI system may cause to a person, the stricter the requirements for its development and use.

Key AI Omnibus changes

Change What it means for business
Postponement of requirements for high-risk AI For systems in Annex III, the rules apply from 2 December 2027; for AI in regulated physical products, from 2 August 2028.
Simplification of AI literacy A company must take reasonable measures to develop employees' AI literacy, but is not required to guarantee a specific level of knowledge for every person.
Benefits for growing companies Some simplifications available to small and medium-sized businesses are extended to small mid-cap companies.
Regulatory sandboxes Companies have more opportunities to test AI under regulatory supervision.
Less registration burden The process is simplified for systems operating in sensitive areas but not classified as high-risk.
Bias testing Limited processing of special categories of personal data is allowed to identify and correct bias.
New prohibitions AI systems for creating intimate images without a person's consent and child sexual abuse material are prohibited.
Strengthening of the AI Office The European AI Office receives additional powers regarding GPAI models and certain large platforms.

An official overview of the changes is published on the European Commission website.

New deadlines for high-risk AI systems

The most notable change is the postponement of requirements for high-risk systems.

AI systems in Annex III — from 2 December 2027

Annex III covers stand-alone AI systems capable of significantly affecting a person's rights and opportunities. These may include solutions for:

  • recruiting and assessing workers;
  • determining access to education;
  • credit scoring;
  • providing essential private and public services;
  • migration and border control;
  • law enforcement;
  • certain types of biometric identification.

Previously, the main requirements for such systems were due to start applying on 2 August 2026. The AI Omnibus postponed the deadline to 2 December 2027.

AI in regulated physical products — from 2 August 2028

A separate deadline has been set for high-risk AI systems embedded in products regulated under EU law. These may include medical devices, machinery and equipment, lifts, toys, transport systems and other products from Annex I.

For them, the relevant AI Act requirements will start to apply on 2 August 2028.

Current dates are collected in the official AI Act Service Desk calendar.

What the postponement means in practice

Suppose a company develops a system that automatically evaluates CVs and ranks candidates. Such a project may fall into the high-risk AI category because it affects a person's access to employment.

The formal deadline for meeting the full set of requirements — risk management, technical documentation, logging, human oversight and conformity assessment — will now be 2 December 2027.

But the postponement does not mean that until then you can collect any data, make non-transparent decisions and not test the system. GDPR, employment, anti-discrimination and consumer protection laws continue to apply independently of the AI Act.

In addition, documentation is much easier to compile during development than to reconstruct retrospectively before launch or an inspection.

AI literacy has not been abolished

The original version of Article 4 required AI providers and professional users to ensure a sufficient level of AI literacy among employees.

After the amendments, the wording became softer. Organisations must now take measures that support the development of AI literacy, taking into account:

  • the employee's role;
  • their experience and training;
  • the type of AI system used;
  • the people who may be affected by its output;
  • the likelihood and severity of potential errors.

In other words, businesses do not need to conduct an exam or guarantee that every employee reaches the same level of knowledge. But training cannot be ignored entirely either.

Practical minimum for a small company:

  1. Explain to employees where AI is used.
  2. Show typical errors and system limitations.
  3. Set rules for handling personal and confidential data.
  4. Identify decisions that cannot be made without human review.
  5. Document the training provided.

For high-risk projects, requirements for staff training and human oversight remain stricter.

Small and medium-sized businesses received more relief

Some simplifications previously available only to small and medium-sized enterprises are extended to small mid-cap companies — companies that have outgrown the SME category but have not yet become large businesses.

In general, these are companies that are not SMEs, have fewer than 750 employees and meet the established financial thresholds: turnover of up to €150 million or a balance sheet total of up to €129 million.

They may benefit from:

  • more proportionate requirements;
  • simplified technical documentation;
  • reduced administrative burden;
  • consideration of company size when applying requirements and penalties.

Important: SMC status does not exempt a company from the AI Act. It affects how complex and costly the process of meeting certain requirements needs to be.

More opportunities for AI testing

AI Omnibus expands access to regulatory sandboxes — controlled environments where AI systems can be tested together with competent authorities.

By 2 August 2027, at least one national AI sandbox must be operational in every EU Member State. An EU-level sandbox is also planned.

This is especially useful for startups and companies developing solutions in healthcare, finance, HR, education and other regulated areas. A sandbox makes it possible to discuss the system's classification, data, risks and required control measures in advance.

It is not a way to circumvent the law. But it helps avoid building an expensive product based on an incorrect understanding of its legal status.

Registration and monitoring become easier

Previously, a provider of a system used in an Annex III area but not classified as high-risk could have been required to register it in the European database.

AI Omnibus reduces this burden. Companies will still need to carry out and retain an assessment explaining why the system is not high-risk. However, in some cases, additional public registration will no longer be required.

Post-market monitoring is also simplified. Instead of a mandatory single format, businesses have more freedom in choosing the structure of their system monitoring plan.

This does not mean that errors can stop being tracked after launch. The company must understand:

  • how often AI makes errors;
  • which users or groups may be affected;
  • what incidents occur;
  • how changes to the model and workflow are recorded;
  • when the system needs to be restricted or stopped.

Bias testing and special categories of data

AI Omnibus allows providers and deploying companies, under certain conditions, to process special categories of personal data where necessary to identify and correct bias in an AI system.

For example, without analysing results for individual groups, it can sometimes be impossible to determine whether an HR system is unfairly lowering ratings for candidates of a certain background or gender.

However, this is not a blanket permission to collect sensitive data “just in case”. Processing must be necessary, limited to the stated purpose and protected by technical and organisational measures. GDPR requirements continue to apply.

New prohibited practices have been introduced

AI Omnibus adds a ban on AI systems intended to create:

  • sexually explicit or intimate images of a person without their consent;
  • child sexual abuse material.

This category includes so-called nudification services that digitally “undress” a person in a photograph.

The new bans start applying 2 December 2026. The restriction applies not only to publishing the result, but also to the systems themselves intended to create such materials.

Which requirements have not been postponed

The main mistake is to assume that the entire AI Act has been postponed until 2027 or 2028. That is not the case.

Date What applies
2 February 2025 Core prohibited practices and AI literacy requirements.
2 August 2025 Obligations for providers of general-purpose AI models.
2 August 2026 Article 50 on transparency, measures to support innovation and the start of full enforcement of already applicable provisions.
2 December 2026 New bans and a transitional period for content labelling by certain previously released generative systems.
2 August 2027 National regulatory sandboxes.
2 December 2027 High-risk AI under Annex III.
2 August 2028 High-risk AI in regulated products under Annex I.

The date is particularly important 2 August 2026. From this point, the requirements of Article 50 start to apply:

  • a chatbot must inform a person that they are interacting with AI;
  • providers of generative systems must ensure the detectability of artificially generated or altered content;
  • deepfakes must be clearly labelled;
  • certain AI-generated texts on matters of public interest require disclosure of AI use;
  • people must be informed when emotion recognition and biometric categorisation are used.

We covered these rules in detail in the article “Labelling AI content in the EU from 2 August 2026”.

Three examples for businesses

Chatbot on a company website

The company has connected an AI assistant to respond to customers. This is a standard, not high-risk scenario.

The deadline extension does not fundamentally change anything. From 2 August 2026, the user must understand that they are receiving a response from AI. Personal data processing, handover to an employee and error logging should also be reviewed.

AI agent in n8n

The agent reads requests, fills in the CRM and prepares responses for customers. If it does not make decisions about credit, hiring or access to essential services, such a workflow is usually not high-risk.

Nevertheless, it is worth setting up:

  • action and error logs;
  • minimum access rights;
  • confirmation before sending emails and changing important data;
  • API key protection;
  • handling repeated actions;
  • an emergency stop.

AI for candidate screening

The system evaluates CVs and recommends whom to invite for an interview. Such a project may fall under Annex III.

The full high-risk regime has been postponed until 2 December 2027. But companies already need to review the lawfulness of data processing, the risk of discrimination, the human role and the ability to explain the decision made.

What businesses should do after AI Omnibus enters into force

The deadline extension should be used not as a pause, but as time for careful preparation.

A short action plan

  1. Create an inventory of AI systems. Include chatbots, content generators, AI features in SaaS, internal assistants and automations.
  2. Determine your role. A company may be a provider, deployer or perform both roles at the same time.
  3. Check the classification. Separately identify systems affecting hiring, lending, education, healthcare, biometrics and essential services.
  4. Meet transparency requirements. Add notices to chatbots and content labelling rules.
  5. Organise AI literacy. Provide a short briefing and retain confirmation.
  6. Review the data. Determine what is passed to the model, where it is stored, and who can access it.
  7. Set up action controls. Risky operations should require human confirmation.
  8. Start keeping documentation. A system passport, data schema, risk register, and change log will be useful even for a standard AI project.

You can conduct this initial assessment using our guide “How to prepare an AI project for EU requirements in one day”.

Frequently asked questions

Has the AI Act been postponed until 2027?

No. The postponement mainly affects requirements for high-risk systems under Annex III and AI embedded in regulated products. Transparency, AI literacy, GPAI rules, and some prohibited practices follow separate timelines.

Do I need to label every text created with ChatGPT?

No. Mandatory visible labeling depends on the content, publication method, and whether there is meaningful human review. Editorial oversight is especially important for content of public significance.

Can I hold off on documenting a high-risk project?

The formal deadline has been postponed, but this is a poor practical strategy. Development history, data sources, tests, and system changes are much harder to reconstruct later.

Has the AI Omnibus eliminated employee training?

No. The requirement has become more flexible: companies must take reasonable measures to develop AI literacy, taking into account employees' roles and the system's risk.

Conclusion

The AI Omnibus does make the AI Act less stringent in terms of deadlines and administrative procedures. This is especially important for developers of high-risk systems, manufacturers of regulated products, and growing European companies.

But businesses' core obligations have not disappeared. If a company uses an AI chat, AI agent, content generation, or automated processing of customer data, it already needs transparency, human oversight, clear data rules, and minimal documentation.

CenterAI helps conduct a technical audit of an AI project, identify obvious risks, and implement notifications, logging, human approval, access management, and other practical measures.

Discuss an AI project with CenterAI

This material is for informational purposes and does not replace a legal assessment of a specific AI system.

Leave a Reply

Your email address will not be published. Required fields are marked *