Back to AI Act Guide
    Omnibus UpdateFor founders, CTOs, and compliance leads

    EU AI Act Omnibus – What Changed for SMEs | ActNavigator

    10 min read

    Written by ActNavigator Team. Last reviewed July 2026.

    The Digital Omnibus on AI is no longer a proposal. It was adopted as Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force since 27 July 2026. It is the first amendment to the EU AI Act (Regulation (EU) 2024/1689) since the Act was adopted.

    The short version: high-risk obligations moved, transparency did not. Most stand-alone high-risk requirements now apply from 2 December 2027 instead of 2 August 2026, while the Article 50 transparency duties apply from 2 August 2026 exactly as originally scheduled.

    Two companion reads: what actually takes effect on 2 August 2026 and what the high-risk delay means in practice.

    The new AI Act calendar

    EU AI Act application dates after the Digital Omnibus on AI (Regulation (EU) 2026/1744).

    DateWhat appliesStatus
    2 February 2025Prohibited AI practices are banned (Art. 5)Unchanged
    2 February 2025AI literacy obligation applies (supervision from 3 August 2026) (Art. 4)Unchanged
    2 August 2025General-purpose AI model rules and governance apply (Art. 51–55)Unchanged
    2 August 2026Transparency duties apply — not deferred by the Omnibus (Art. 50)Unchanged
    2 December 2026Machine-readable marking of synthetic output for generative systems placed on the market before 2 August 2026 (Art. 50(2))New
    2 December 2026Two new prohibitions apply (non-consensual intimate imagery, AI-generated CSAM) (Art. 5)New
    2 August 2027National AI regulatory sandboxes must be operational (Art. 57)Previously 2 August 2026Deferred
    2 December 2027Stand-alone high-risk AI obligations (Annex III) apply (Annex III)Previously 2 August 2026Deferred
    2 August 2028High-risk AI embedded in regulated products (Annex I) applies (Annex I)Previously 2 August 2027Deferred

    How the Omnibus became law

    The European Commission proposed the package in November 2025, after sustained concern that the high-risk regime would start applying before the harmonised standards needed to comply with it existed. Parliament and Council reached a provisional agreement in May 2026, Parliament adopted the text in June, the Council approved it at the end of June, and the final act was signed in July and entered into force three days after publication.

    One detail matters for planning: the Commission originally proposed conditional start dates tied to a decision confirming that standards were ready. Parliament and Council rejected that and converted the backstops into fixed application dates. You now have a hard calendar, not a floating one.

    Key changes companies should understand

    1. High-risk obligations move to December 2027 and August 2028

    Stand-alone high-risk systems listed in Annex III — AI used in employment and worker management, education, credit scoring, insurance pricing, essential services, law enforcement and migration — now apply from 2 December 2027 instead of 2 August 2026.

    High-risk AI embedded as a safety component in products already covered by Annex I sectoral law (machinery, medical devices, lifts, toys, vehicles) moves from 2 August 2027 to 2 August 2028.

    The obligations themselves are unchanged: risk management, data governance, technical documentation, logging, human oversight, accuracy and robustness, conformity assessment. They arrive later; they do not arrive smaller.

    2. Nothing about 2 August 2026 moved

    This is the part that gets lost in headlines. Article 50 transparency applies from 2 August 2026: tell people they are interacting with AI, label deepfakes and AI-generated content published on matters of public interest, and mark synthetic output in machine-readable form. On the same date the AI Office gains its full enforcement powers over general-purpose AI model providers.

    The one relief added: generative AI systems already placed on the EU market before 2 August 2026 have until 2 December 2026 to meet the machine-readable marking requirement. Systems launched on or after 2 August 2026 comply from day one.

    3. Two new prohibitions arrive on 2 December 2026

    The Omnibus is a simplification package that made the Act stricter in one place. Article 5 gains two entries, both prohibited from 2 December 2026: AI systems that generate or manipulate non-consensual intimate imagery of real people, and AI systems that generate or manipulate child sexual abuse material. Article 5 breaches sit in the top penalty tier — up to €35 million or 7% of worldwide annual turnover.

    4. AI literacy became an obligation of effort

    Article 4 was rewritten from a duty to ensure a sufficient level of AI literacy into a duty to take measures to support the development of it. It still applies to every deployer, regardless of size or sector, and national authorities begin supervising it from 3 August 2026. Softer wording, live supervision — keep an AI use inventory, an internal policy, and dated training records.

    5. Registration of Article 6(3) self-assessments survived

    The Commission proposed removing the requirement to register systems that a provider self-assesses as not high-risk under Article 6(3). Parliament and Council refused. Registration stays, with a streamlined set of information. If you intend to rely on the Article 6(3) filter, plan for a documented, reasoned assessment that goes into a public database — not an internal memo.

    6. Real relief for SMEs and small mid-caps

    The most underrated part of the package: SME and small mid-cap (SMC) definitions are written into the AI Act with concrete accommodations attached.

    • a simplified technical documentation form for high-risk systems
    • proportionate quality management system requirements, extended across the SME category
    • reduced caps on administrative fines
    • priority access to AI regulatory sandboxes

    7. National sandboxes slip to August 2027

    Member states were required to have at least one national AI regulatory sandbox operational by 2 August 2026. Almost none were on track, and the obligation is deferred to 2 August 2027. Fewer sandboxes in 2026 means fewer supervised places to test a borderline high-risk product.

    What the Omnibus did not touch

    • The prohibitions. Article 5 has applied since 2 February 2025 and just got longer, not shorter.
    • The general-purpose AI regime. Articles 51–55 are unchanged in substance and have applied since 2 August 2025.
    • The penalty ceilings. Up to €35M or 7% for prohibited practices, €15M or 3% for most other infringements including transparency, €7.5M or 1% for supplying incorrect information.
    • The risk-based architecture. Annex III still lists the same high-risk use cases.
    • Territorial scope. Article 2 was not narrowed, so non-EU companies placing AI on the EU market, or whose AI output is used in the EU, remain in scope.

    What this means for different types of companies

    Startups and SaaS companies

    The extended high-risk deadlines reduce the urgency of a full compliance program, but the core work is unchanged: map your AI systems, understand your role, classify risk. If your product is user-facing or generative, your nearest deadline is 2 August 2026, not 2027.

    HR and hiring companies

    Hiring AI remains one of the clearest Annex III categories. HR companies now have until 2 December 2027 for the high-risk technical file — which, for a defensible data-lineage, bias-testing and oversight package, is a project start date rather than a reprieve.

    Consulting and advisory firms

    Clients need help separating what moved from what did not. Consulting firms that can explain the December 2027 / August 2026 split precisely will give better advice than those repeating the old calendar.

    Practical steps to take now

    1. Handle transparency first. Chatbot disclosure, content labelling and synthetic-output marking are due 2 August 2026, and they are cheap to fix.
    2. Check whether you are SME or SMC. The accommodations materially change what a high-risk technical file costs you.
    3. Treat December 2027 as a project start date. Building an Annex III technical file typically takes two to three quarters.
    4. Keep Article 4 evidence. Softer wording, but supervision begins 3 August 2026.
    5. Re-check your classification. The dates moved; the Annex III categories did not.

    For a complete overview, return to the EU AI Act Guide. Start with the EU AI Act checklist if you need a quick overview, or see the full EU AI Act timeline. Run a free AI Act scan to check your exposure, or return to the ActNavigator homepage.

    Next step

    Run a free AI Act scan

    Get a fast, practical view of your potential AI Act exposure. No legal expertise needed.

    ActNavigator provides guidance and does not replace legal advice.

    Indicative assessment only — not legal advice.

    ActNavigator provides preliminary compliance guidance based on the EU AI Act (Regulation 2024/1689) and publicly available regulatory frameworks. Assessments are based solely on user-provided answers and do not constitute legal advice, legal opinion, or a guarantee of regulatory compliance.

    The EU AI Act is subject to ongoing implementation and potential amendment. Organizations remain solely responsible for their regulatory obligations. ActNavigator accepts no liability for decisions made on the basis of this assessment. For a formal review, consult a qualified legal professional.

    Some content and outputs in this service may be generated or assisted by artificial intelligence. While we strive to ensure accuracy and relevance, the information provided should not be considered legal advice.

    © 2026 actNavigator. All rights reserved.