TL;DR (for those of us running low on dopamine 😅)
If you've opened this post but your brain is already begging you to scroll, here's the pre-chewed version:
- The EU has just published Regulation (EU) 2026/1744, the "AI Digital Omnibus", which tweaks the AI Act rather than reinventing it.
- Good news: the obligations for high-risk systems are postponed to December 2027 and August 2028. Breathe.
- Watch out: new prohibitions are coming (intimate deepfakes and child abuse material) that already apply on 2 December 2026.
- Compliance is simplified and — this one interests me especially — it is officially connected to cybersecurity (CRA): presumption of conformity and less duplication.
- Translation: you have room to breathe, but the good work starts today. There's a checklist at the end.
If you have five more minutes, let me walk you through it. 👇
On 24 July 2026, Regulation (EU) 2026/1744 — better known as the "AI Digital Omnibus" — was published in the Official Journal of the European Union. And no, it isn't yet another rule built from scratch to send us all spinning again (which wouldn't be that surprising): it amends the Artificial Intelligence Regulation (Regulation (EU) 2024/1689), the Machinery Regulation (2023/1230) and the aviation one (2018/1139). The intention? To simplify the application of the AI framework without lowering the bar on protecting health, safety and fundamental rights.
From the point of view of whoever has to comply, it's bittersweet: on the one hand, more time to get ready; on the other, new obligations worth noting right away. Let's get to what matters.
1. High-risk system obligations are postponed
That's the headline. The application of much of the Chapter III obligations (sections 1, 2 and 3) of the AI Act — risk management, documentation, human oversight, data quality, and so on — is deferred: it isn't a freeze on the chapter, but a change to the specific application dates, which will no longer be 2 August 2026. The new timetable distinguishes by type of system:
- 2 December 2027 for high-risk systems under Article 6(2) and Annex III (the "standalone" use cases: employment, education, essential services, biometrics, etc.).
- 2 August 2028 for those under Article 6(1) and Annex I (AI systems that are a safety component of already regulated products).
The reason: delays in standards, common specifications and in getting national authorities up and running made compliance on time unworkable (we'll see how we manage in Spain). For companies this is not an excuse to relax, but a realistic window to do things properly.
2. New prohibitions: non-consensual intimate material and child sexual abuse
Article 5 broadens the prohibited practices to include AI systems that generate or manipulate non-consensual intimate material (so-called nudification apps) and child sexual abuse material, including synthetic material. These prohibitions will apply from 2 December 2026.
The rule is nuanced: it does not prohibit developing technical image-generation capabilities, but rather placing on the market or deploying systems intended for that purpose, or that allow it in a "reasonably foreseeable" way without adequate technical safeguards (content filtering, prompt controls, abuse detection mechanisms, etc.). In fact, the Regulation devotes a surprising level of detail — nearly three pages — to delimiting what is prohibited and which legitimate uses remain possible: consent, medical applications, artistic works, or red teaming by the authorities themselves. If your organisation develops or integrates generative AI, this is a design and red teaming point that needs to enter your risk analysis now.
3. AI literacy: from a strict obligation to a duty to promote
Article 4 has been softened. Instead of requiring you to guarantee a level of AI literacy among staff, it now requires adopting measures to support its development. It's a change of tone, not an exemption. And here I'll insist, with good reason: training remains a strategic priority and, in practice, the best defence against misuse of these tools.
Most AI scares don't come from the regulation — they come from people using it without knowing what they're doing. Whoever has already invested in upskilling their team starts ahead.
4. SMEs and small mid-cap companies
The regulation introduces definitions of SME and of small mid-cap company and extends to the latter several proportionality measures designed for smaller operators. The idea is that the jump from SME to mid-sized company shouldn't mean slamming straight into the requirements built for the big players.
5. Less duplication: the link with cybersecurity
This is the point that, coming from cybersecurity, interests me most. The regulation makes explicit the interaction with the Cyber Resilience Act (CRA, EU 2024/2847): where a high-risk AI system meets the CRA's essential cybersecurity requirements, it will be presumed to conform with the cybersecurity requirements of Article 15 of the AI Act, to the extent they are covered by the EU declaration of conformity. Mind the nuance, because it matters: the CRA does not replace AI Act compliance, it grants a presumption of conformity in respect of certain requirements. In practice, that lets companies reuse part of the evidence and avoid duplicating audits, testing and documentation.
Curiously, this rule already lived in the CRA itself (its Article 12); the Omnibus also brings it into the AI Act to make that interaction visible. A small detail with a real impact on day-to-day compliance.
This is exactly what we were discussing on LinkedIn a few months ago: unifying reporting mechanisms and evidence across regulations.
Less red tape with notified bodies
Another piece that deserves more attention than it usually gets. The Regulation establishes a single application and a unified assessment procedure for designating notified bodies that already operate under other sectoral rules (medical devices, for example). Translated: instead of repeating procedures before different authorities, the same body submits a single application and goes through a single assessment.
Why does it matter to a company? Because fewer bottlenecks in designating notified bodies means, sooner or later, more certification capacity available and less waiting when your turn comes to assess your system's conformity. It's one of those measures that never makes the headline, but if it weren't there everyone would be tearing their hair out.
And a note for those working with data and bias
The Regulation also broadens the legal basis for processing, exceptionally and under strict safeguards, special categories of personal data where the goal is to detect and correct bias — now not only for high-risk providers, but also for deployers and other systems.
6. Reinforced regulatory sandboxes
This is one of the longest blocks in the Regulation, and not by chance. European cooperation between sandboxes is strengthened, the door is opened to a Union-scale sandbox, testing in real-world conditions is expanded (also outside the sandbox, for Annex I high-risk systems), and that real-world testing is better integrated into the sandbox itself. Each Member State must have a national sandbox operational by 2 August 2027 at the latest. For anyone innovating with high-risk AI, it's a genuine route to validate compliance with regulatory support before going to market.
What to do now (compliance checklist)
Even though the big deadlines shift to 2027-2028, the useful work starts today:
- Inventory your AI systems and classify them: high-risk under Annex III or Annex I? The new timetable depends on it.
- Review the definition of "safety component" (Article 3(14)), now more tightly drawn, because some systems previously treated as high-risk might no longer be.
- If you develop generative AI, build in safeguards against the generation of prohibited content before December 2026.
- Align AI and cybersecurity: use the CRA's presumption of conformity so you don't duplicate effort.
- Invest in training your team: it remains the compliance lever with the best return.
- Keep an eye on the guidance, harmonised standards and codes of practice the Commission is due to publish in 2027; they'll set out the "how".
The 2026-2028 window isn't for procrastinating (we know ourselves too well 😉) — it's for turning compliance into a capability of your organisation rather than a last-minute race against the clock.
Hope this helped you get across the changes, Friday-style.
Regulation (EU) 2026/1744 of the European Parliament and of the Council, of 8 July 2026 (OJ L of 24.7.2026). Official text on EUR-Lex (PDF).