Comparison · the AI Act after the omnibus
The changes Regulation (EU) 2026/1744 made to the Artificial Intelligence Act with effect from 27 July 2026 — article by article, including what stayed the same.
The full title reads: Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI). English-language material calls it the Digital Omnibus on AI; in Czech the shorthand AI omnibus has taken hold.
The regulation was adopted in Strasbourg on 8 July 2026; the position of the European Parliament dates from 16 June 2026 and the decision of the Council from 29 June 2026. The legal basis is Article 114 of the Treaty on the Functioning of the European Union. It was published in the Official Journal on 24 July 2026 and, under its Article 4, entered into force on the third day following publication, that is on 27 July 2026. Memorise that date — it comes back more often than any other on this page.
The scope is narrower than the coverage of the package suggested. The omnibus amends three regulations and nothing else: Article 1 amends the Artificial Intelligence Act, Regulation (EU) 2024/1689, in 43 amending points; Article 2 amends Regulation (EU) 2018/1139, the aviation basic regulation, in seven points; and Article 3 amends Regulation (EU) 2023/1230 on machinery in three points. This regulation does not amend the General Data Protection Regulation, the ePrivacy Directive or the Data Act. Anyone who comes across a claim that the digital omnibus also changed the GDPR is reading about a different document, and it has to be verified separately.
The most convenient way to read the changes is the consolidated text of the AI Act with the consolidation date of 27 July 2026, where the changes made carry the M1 marker. It is, however, a Publications Office tool, not a legally binding text — in the documentation you will rely on during an inspection, cite the authentic texts from the Official Journal.
One last note on how to navigate. This page goes article by article and is written for readers whose documentation is drafted against the older wording. The practical reading for companies that merely use AI is a separate page in this category — the Deployer checklist.
A methodological note on how to read this page: where it says that something did not change, that statement is derived from the fact that the article in question is not among the amending points of Article 1 of the omnibus and that it carries no change marker in the consolidated text. For the most important cases — Article 26 and Article 5(1), point (f) — this is stated expressly, because those are exactly where third-party summaries go wrong most often.
This is the change with the greatest practical impact in the whole omnibus and, at the same time, the one that short summaries distort most often. Point 40 of Article 1 of the omnibus rewrote the third subparagraph of Article 113 of the AI Act, the provision on the dates of application.
The new point (c) defers the application of Chapter III, Sections 1, 2 and 3, with the exception of Article 6(5), to 2 December 2027 for systems that are high-risk under Article 6(2) and Annex III, and to 2 August 2028 for systems that are high-risk under Article 6(1) and Annex I. The starting position differed between the two branches, which is why the length of the deferral differs as well. For Annex III there was no special date and the general date of application, 2 August 2026, applied, so the deferral is sixteen months. For Annex I the original point (c) of Article 113 set 2 August 2027 for Article 6(1) and the related obligations, so the deferral is twelve months. Summaries that quote only 2 December 2027 and omit the second date are inaccurate — for Annex I the period is eight months longer.
The deferral has precisely drawn boundaries, and that is where most of the misunderstandings arise. It does not cover Chapter IV, that is the transparency obligations under Article 50. It does not cover Chapter III, Section 5, that is harmonised standards, conformity assessment, certificates and registration under Articles 40 to 49 — for those the general date of application of 2 August 2026 under the second subparagraph of Article 113 stands. And it does not cover Article 6(5) either, which is expressly carved out of the deferral and which requires the Commission, after consulting the Board, to provide guidelines on the practical implementation of Article 6 together with a comprehensive list of practical examples of use cases that are high-risk and use cases that are not.
The reason for the deferral is set out in recital 40 of the omnibus: the delayed availability of standards, common specifications and alternative guidance and the delayed establishment of the competent national authorities create problems that do not justify keeping the original date of application of 2 August 2026.
The transitional provisions in Article 111 were changed as well. In paragraph 2 the fixed date of 2 August 2026 was replaced by a moving reference to the date of application of Chapter III under Article 113, so the grandfathering of high-risk systems already placed on the market moves together with the deferral. The hard deadline is unchanged: providers and deployers of high-risk AI systems intended to be used by public authorities have to achieve compliance by 2 August 2030 in any event. Recital 39 clarifies that if at least one individual unit of a high-risk AI system was lawfully placed on the market before the relevant date, the deferral also covers further units of the same type and model, which may continue to be placed on the market without further obligations and without additional certification, provided the design of the system does not change; what counts is the date on which the first unit of that type and model was first placed on the Union market.
The new Article 111(4) then introduces the only time relief transparency gets: providers of AI systems, including general-purpose AI systems, that generate synthetic audio, image, video or text content and that were placed on the market before 2 August 2026 have to take the measures necessary to comply with Article 50(2) by 2 December 2026. Recital 38 describes this as a four-month transitional period.
The practical consequence for documentation in progress: a sentence such as “obligations for high-risk systems start on 2 August 2026” has been wrong since 27 July 2026, but the sentence “the transparency obligations under Article 50 start on 2 August 2026” is still correct. Anyone who corrects dates across a document in bulk will also correct what should have been left alone.
Point 4 of Article 1 of the omnibus reached into the definitions in Article 3 and point 8 into the classification rules in Article 6. Together they narrow the range of systems that end up high-risk through Annex I and introduce two new categories of undertaking for the purposes of relief.
The definition of a safety component in Article 3, point (14), was narrowed, and the same narrowing is reflected in the new paragraphs 1a to 1c of Article 6. Under the new Article 6(1a), AI systems used solely for user assistance, performance optimisation, service efficiency, automation, convenience or quality control not related to safety are not considered safety components. Under the new Article 6(1b), systems whose failure or malfunctioning would endanger health and safety are, on the contrary, considered safety components. The new Article 6(1c) then targets the second condition of classification through Annex I: a product for which third-party conformity assessment is required solely because of risks other than risks to health and safety does not meet the condition in Article 6(1).
The practical significance is obvious for industrial and product manufacturers: a system that merely increases efficiency or operator convenience does not become high-risk through Annex I just because it is built into a regulated product. What decides is the link to health and safety, not the position inside the product.
The second group of changes in Article 3 introduces two new definitions that impose nothing in themselves but are referred to in the relief provisions. The new point (14a) defines a small and medium-sized enterprise by reference to Commission Recommendation 2003/361/EC; the new point (14b) defines a small mid-cap enterprise by reference to Commission Recommendation (EU) 2025/1099. Both definitions feed into the penalty regime and into the support measures.
Anyone with a product classification drafted against the older wording has a reason to go through it again — not because of the change of dates, but because the boundary itself has moved. A system classified as a safety component merely because of where it sits in the product may end up somewhere else once the narrowed definition is applied.
Point 5 of Article 1 of the omnibus replaced Article 4 in its entirety. It is a change that concerns absolutely everyone who provides or uses AI, because Article 4 has no threshold and no risk condition attached to it.
The original wording required providers and deployers to take measures to ensure, to their best extent, a sufficient level of AI literacy. The new Article 4(1) speaks of measures to promote the improvement of AI literacy and adds a sentence that decides how the whole provision is to be read: this obligation does not require providers or deployers to guarantee any specific level of AI literacy of any individual. What is assessed are the measures, not the outcome.
The personal scope is unchanged. The obligation covers staff as well as any other persons dealing with the operation and use of AI systems on behalf of the provider or the deployer, and account is to be taken of the technical knowledge, experience, education and training of those persons, the context in which the systems are to be used, and the persons or groups of persons on whom the systems are to be used.
The new Article 4(2) requires the Commission and the Member States to support and facilitate the efforts of providers and deployers, in particular SMEs, and the Commission is to publish practical examples of compliance on the single information platform under Article 62(3), point (b). The new Article 4(3) requires the European Artificial Intelligence Board to adopt a recommendation setting out, among other things, common objectives.
Point 6 of Article 1 of the omnibus then inserted an entirely new Article 4a on the processing of special categories of personal data for the purpose of bias detection and correction, while point 9 deleted Article 10(5), which until then governed this question only for providers of high-risk systems. The new Article 4a(2) extends the legal basis to deployers of high-risk AI systems and to providers and deployers of other AI systems and AI models, and expressly adds that this paragraph does not create an obligation to carry out such bias detection and correction.
The conditions for the processing in Article 4a(1) are cumulative and they are strict. The processing cannot be effectively carried out by processing other data, including synthetic or anonymised data; technical limitations on re-use and state-of-the-art security measures, including pseudonymisation, apply; strict controls and documentation of access apply; the data are not transmitted or made accessible to other parties; they are deleted once the bias has been corrected or the retention period expires, whichever comes first; and the reason is justified in the records of processing activities.
On the applicability of the new Article 4a: the omnibus inserted it into Chapter I, which is covered by point (a) of the third subparagraph of Article 113 with the date of 2 February 2025 — the amended point (a) carves out only the new prohibitions in Article 5, and no special date is laid down for Article 4a. So the rule is not missing. One question stays open: from when a provision inserted with effect from 27 July 2026 actually applies, since it cannot operate retroactively. Anyone building a specific processing operation on Article 4a should have the conclusion confirmed rather than derive it from this material.
Point 7 of Article 1 of the omnibus amends Article 5 by inserting the new points (ba) and (bb) into paragraph 1 and adding the new paragraphs 1a and 1b. Nothing that was already in Article 5 changes — and that has to be said before the list of novelties, because this is exactly where third-party summaries go wrong most often.
The new point (ba) prohibits the placing on the market, the putting into service or the use of AI systems that generate realistic image, film, audio or similar material depicting the intimate parts of an identifiable natural person, or that person engaged in sexually explicit activities, or that manipulate such material, without the freely given, specific, informed, unambiguous and explicit consent of the person concerned.
The new point (bb) prohibits the placing on the market, the putting into service or the use of AI systems that generate or manipulate material or performances within the meaning of Article 2, points (c) and (e), of Directive 2011/93/EU, except in cases where a ground excluding unlawfulness applies under national law.
The new paragraph 1a substantially limits the reach of both new prohibitions and splits it by role. Placing on the market or putting into service is prohibited only where the generation of such material is the intended purpose of the system, or where such generation is, in view of the design, training, architecture, capabilities or functionalities, a reasonably foreseeable and reproducible outcome without significant technical modification and the system lacks reasonable and adequate technical safety measures and safeguards. Use is prohibited only where the deployer uses the system precisely for the purpose of generating or manipulating such material.
The new paragraph 1b contains a carve-out from the notion of manipulation: it is not manipulation within the meaning of point (ba) where an AI system manipulates material in a way that does not increase the exposure of the intimate parts depicted and does not alter the nature of the sexually explicit activities shown.
Both new points and both new paragraphs apply only from 2 December 2026 under the amended point (a) of the third subparagraph of Article 113. The rest of Article 5 applies unchanged from 2 February 2025.
The most important sentence in this section is about what did not change: Article 5(1), point (f), the prohibition on using AI systems to infer emotions of a natural person in the workplace and in education institutions, was not opened by the omnibus at all. Both the wording and the date of application of 2 February 2025 stand. Anyone who expected the deferral for high-risk systems to reach this as well has an error in their documentation.
Point 12 of Article 1 of the omnibus amends Article 25 in two places, point 13 amends Article 27 in paragraphs 4 and 5. Both changes target practical obstacles that companies in the middle of the value chain kept running into.
What matters first is what did not change in Article 25. Paragraph 1, that is the three circumstances in which a distributor, importer, deployer or other third party is considered a provider of a high-risk AI system for the purposes of the regulation, is unchanged: putting their own name or trademark on a high-risk system already placed on the market; making a substantial modification to a high-risk system already placed on the market in such a way that it remains high-risk; and modifying the intended purpose of an AI system, including a general-purpose AI system, that has not been classified as high-risk in such a way that it becomes high-risk under Article 6. The consequence is still that the obligations of the provider under Article 16 apply to the actor concerned.
The amended paragraph 2 still provides that the initial provider is no longer considered the provider of that system for the purposes of the regulation, and it now spells its duty of cooperation out into a concrete list: make available technical documentation sufficient to assess compliance with Article 16, inform the new providers of known limitations and failure modes, and provide targeted technical access, including access for testing and validation. For the new provider that is a tangible improvement in bargaining position.
At the same time the exception was widened, and in the opposite direction. It does not apply where the initial provider has clearly specified that its AI system is not to be changed into a high-risk AI system — in that case it is bound neither to cooperate with new providers nor to hand over documentation. The original wording mentioned only the duty to hand over documentation. That single sentence in supplier terms therefore now carries more weight.
The first subparagraph of Article 25(4) was replaced so that an AI model was added to the list of what a third party supplies and what has to be covered by a written agreement, alongside AI systems, tools, services, components and processes. The exemption was retained for third parties that make tools, services, processes or components other than general-purpose AI models accessible to the public under a free and open-source licence.
For Article 27, that is the fundamental rights impact assessment, the change concerns working with documents. A deployer may now include in the assessment cross-references to the relevant sections of the data protection impact assessment under Article 35 of Regulation (EU) 2016/679 or Article 27 of Directive (EU) 2016/680, or incorporate the relevant parts of it. The AI Office is to draw up a template questionnaire that makes this possible.
For a buyer of AI, the most practical item in this whole section is the last one on the exception in paragraph 2. Before signing, it pays to go through the supplier terms looking for a statement that the system is not to be changed into a high-risk one — after the omnibus, such a statement means the supplier owes you neither cooperation nor the documentation you would need in the role of the new provider.
Four changes belong in this group. At first sight they have nothing to do with each other, but they aim at the same thing — to cut duplication against other legislation and to give time where the infrastructure is not keeping up.
The new Article 2(13) allows the application of specific requirements or obligations under Articles 9 to 15 and 17 to 25 to be limited for high-risk systems under Article 6(1) where the Union harmonisation legislation listed in Section A of Annex I provides an equivalent or higher level of protection and where the limitation does not reduce the overall level of protection. The Commission is to specify the cases in delegated acts by 2 August 2027.
The new Article 42(3) introduces a presumption of conformity for cybersecurity: where high-risk AI systems fall within the scope of Regulation (EU) 2024/2847, the Cyber Resilience Act, and the conditions in its Article 12(1) are met, they are presumed to comply with the cybersecurity requirements under Article 15 of the AI Act. For manufacturers of products with digital elements this is one of the most useful changes in the whole omnibus, because it removes having to prove the same thing twice.
Article 50 was amended in paragraph 7 only. The power of the Commission to approve codes of practice by an implementing act is removed; the Commission, taking utmost account of the opinion of the Board, now only assesses whether adherence to the codes is sufficient to ensure compliance with the obligations under paragraphs 2 and 4, and only where it does not consider a code to be adequate may it adopt an implementing act laying down common rules. Recital 41 explains this by pointing out that codes of practice have limited legal effect and, in particular, do not provide a presumption of conformity. Paragraphs 1 to 6 keep their original wording.
And finally Article 57: the deadline for getting regulatory sandboxes running was extended. Under the amended paragraph 1, Member States have to ensure at least one operational national sandbox by 2 August 2027, whereas the original wording set 2 August 2026. The new paragraph 3a additionally allows the AI Office to establish a sandbox at Union level with priority access for SMEs, including start-ups, and for small mid-cap enterprises.
The link between the AI Act and the Cyber Resilience Act deserves separate attention if you supply a product with digital elements. The new Article 42(3) does not mean that complying with one act gets you compliance with the other — it concerns solely the cybersecurity requirements under Article 15 of the AI Act, not the rest of Chapter III. What the Cyber Resilience Act requires of a manufacturer is covered by a separate CRA category in the resources.
Points 31 and 32 of Article 1 of the omnibus amend Article 75 and insert the entirely new Articles 75a to 75d. The change is institutional in nature but has very practical consequences, because it introduces direct enforcement at Union level where enforcement so far ran mainly through national authorities.
Under the amended Article 75(1), the AI Office has exclusive competence for, among other things, AI systems based on general-purpose AI models where both the model and the system were developed by the same provider or by providers that are part of the same undertaking, and for AI systems integrated into very large online platforms and very large online search engines under Regulation (EU) 2022/2065. The new Articles 75a to 75d then equip the AI Office with supervisory and enforcement powers of its own: investigations, on-site and remote inspections, sealing of premises, requests for information, acceptance of commitments under Article 75b, non-compliance decisions, fines and periodic penalty payments of up to 5 % of average daily income or turnover per day, with a limitation period of five years.
In Article 99 on penalties the omnibus made three changes, and it is worth knowing all three precisely, because the fine brackets themselves are unchanged. The first is the rewritten paragraph 1: Member States still lay down the rules on penalties, but enforcement measures other than fines are now expressly contemplated — warnings and non-monetary measures — and the economic viability of SMEs and small mid-cap enterprises is to be taken into account. The second is the new point (da) in paragraph 4, which added the obligations of providers and operators under Article 25(2) and (4) to the bracket of up to EUR 15 000 000 or up to 3 % of total worldwide annual turnover. The third is the new paragraph 6a, under which, for small mid-cap enterprises, the fine under paragraphs 4 and 5 is capped at the lower of the two values, that is either the percentage or the amount.
What did not change: the top bracket in Article 99(3) for infringements of the prohibitions in Article 5, that is up to EUR 35 000 000 or up to 7 % of total worldwide annual turnover for the preceding financial year, whichever is higher. Nor did point (e) of paragraph 4 change, that is the bracket of up to EUR 15 000 000 or up to 3 % of turnover for infringements of the obligations of deployers under Article 26.
For companies operating in the Czech Republic, the question of national supervision sits outside the text of both regulations — it is a matter for Czech implementing legislation, not for the omnibus. This page therefore takes no position on it; its status is something to verify at the source at the time you need it.
This section is unusual in a piece about an amending act, but it is the most useful part of the page. Most of the errors we come across in documentation in progress did not arise because someone missed a change — they arose because someone assumed a change that never happened.
The most prominent case is Article 26, the obligations of deployers of high-risk AI systems. The omnibus did not open it at all: the list of 43 amending points in Article 1 goes straight from Article 25 to Article 27, and in the consolidated text the wording of Article 26 carries no change marker whatsoever. What changed is solely its date of application, and that indirectly, through Article 113. Wording about “the new version of Article 26” therefore describes something that does not exist.
The second case is the prohibition on inferring emotions in the workplace. The omnibus did not change Article 5(1), point (f), by a single word, nor did it change its date of application — it has applied since 2 February 2025. Point 7 of Article 1 of the omnibus only added points (ba) and (bb) and paragraphs 1a and 1b to Article 5.
The third case is transparency. Article 50 changed in paragraph 7 only, and paragraphs 1 to 6 keep their original wording. And because Article 50 makes up the whole of Chapter IV, which is not mentioned in any of the points of the third subparagraph of Article 113, the general date of application of 2 August 2026 applies to it. The transparency obligations were not deferred.
The changes to the annexes deserve a mention too, because summaries usually lose them entirely. The omnibus deleted point 1 of Section A of Annex I, that is the Machinery Regulation, and moved Regulation (EU) 2023/1230 into Section B of Annex I as a new point 21. It also added an entirely new Annex XIV with a list of codes, categories and types of AI systems for the purposes of the notification of notified bodies under Article 30 — it includes, for instance, code AIB 0203 for AI systems for emotion recognition and code AIH 0401 for emerging AI technologies, including agentic AI.
A suggested order for revising documentation in progress: start with the dates, because they took the brunt of the change and because a bulk correction does the most damage there; then the sentence on AI literacy under Article 4, where the wording of the obligation changed; then the supplier terms because of Article 25(2). And note in the text which version of the law it was written against — for a regulation that has changed this much in two years, the validity date of the material is its single most important piece of information.
The first three entries are legislative milestones of Regulation (EU) 2026/1744, the rest are dates of application of the AI Act as it stands after the omnibus. Dates the omnibus did not change are marked as such in the text of the entries.
Every statement about the changes on this page comes from the primary sources below, as they stood on 9 August 2026. This material does not replace the text of the legislation — what is binding is what is in the Official Journal.
Documentation written against the old wording
An introductory consultation on what in your draft AI Act documentation still holds after 27 July 2026, what needs rewriting and what should be left alone. The output is a list of places to revise, in order of urgency. Tell us what you already have.