Update on 30 July 2026: this article records the political agreement as it stood in May. The process has since been completed. Regulation (EU) 2026/1744 was published on 24 July 2026 and entered into force on 27 July 2026.
In May 2026, the Digital Omnibus was no longer just a Commission proposal because the Council and European Parliament had reached a political deal. This article records that stage. The current legal basis is Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744.
The current legal baseline is Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744. Do not treat the remainder of this historical update as the current legal status.
Short status
| Date | Status | Meaning |
|---|---|---|
| 19 November 2025 | Commission proposal COM(2025)836 | Start of the Digital Omnibus on AI legislative track |
| 13 March 2026 | Council position | Member States support simplification and deferral |
| 26 March 2026 | European Parliament position | Parliament supports deferral and tightens several points |
| 7 May 2026 | Provisional political agreement | Council and Parliament reach a deal |
| 24 July 2026 | Publication in the Official Journal | Regulation (EU) 2026/1744 published |
| 27 July 2026 | Entry into force | Amended AI Act becomes binding |
For ongoing background, we keep the Digital Omnibus guide as the central reference.
What changes under the deal?
The most concrete change is the timeline for high-risk AI systems. For systems listed in Annex III, the main obligations move to 2 December 2027. This affects AI in areas such as biometrics, education, employment, essential services, law enforcement, migration and justice.
For high-risk AI systems embedded in products covered by existing EU sectoral safety legislation, such as medical devices or machinery, 2 August 2028 becomes the relevant date.
That is not a free pass. An organisation that starts classification, data governance, technical documentation, human oversight and supplier assurance only at the end of 2027 will be too late. The extra time is mainly valuable if it is used well.
New practical planning
Annex III high-risk AI: core obligations under the agreement from 2 December 2027.
Product-based high-risk AI under sectoral EU law: under the agreement from 2 August 2028.
Article 50 transparency: generally applies from 2 August 2026. Only Article 50(2) marking for synthetic content systems already on the market before that date has a transition until 2 December 2026.
Current status: Regulation (EU) 2026/1744 is in force.
Article 4 AI literacy: the final outcome
The original Commission proposal sought to weaken Article 4 AI literacy: less direct obligation for organisations, more encouragement by the Commission and Member States. The EDPB and EDPS strongly advised against that move.
The final Article 4 keeps a direct duty for providers and deployers. Since 27 July 2026, they must take measures that support the development of AI literacy, considering knowledge, experience, education, context of use and affected persons. They do not have to guarantee a specific individual level. The law prescribes no standard course or certificate.
For organisations that want to make this demonstrable, the route is clear: start with a baseline assessment, train by role, record results and refresh periodically. You can start with the LearnWize AI literacy assessment.
Watermarking and nudifier apps
Article 50 generally applies from 2 August 2026. Providers of synthetic content systems already on the market before that date have until 2 December 2026 for the machine-readable marking required by Article 50(2).
The deal also introduces an explicit ban on AI systems that generate or manipulate child sexual abuse material or non-consensual intimate images. This is not an abstract compliance point. Providers of generative image, video or multimodal systems need demonstrable safety controls, filters, logging and misuse prevention.
Registration: more transparency after all
One important difference from the original proposal is now confirmed: registration under Article 49(2) remains, but the required registration information is simplified.
That makes sense. If a provider says: "this is in a sensitive domain, but it does not fall under the high-risk obligations", that assessment needs to be reviewable. For compliance teams, this means risk classification cannot be a loose spreadsheet. It needs to become a traceable decision with reasoning, version control and a link to the AI inventory.
What should organisations do now?
- Update the AI Act roadmap. Use 2 December 2027 for Annex III and 2 August 2028 for Annex I as fixed legal dates.
- Classify systems now. You need to know which AI systems you use or provide before you can sequence the work.
- Keep Article 4 alive. Continue training, testing and documenting AI literacy. It is legally prudent and operationally necessary.
- Sharpen vendor assurance. Ask suppliers about classification, data use, bias controls, logging, human oversight, incident handling and their future AI Act roadmap.
- Use the extra time for evidence. The organisations that move fastest later will not be the ones that waited. They will be the ones that already built the basics.
If you want to translate this into a concrete roadmap for your organisation, an AI Act readiness track with Embed AI fits that need. If your main gap is demonstrable AI literacy, start with the LearnWize assessment.
Conclusion
The Digital Omnibus gives organisations more time for high-risk AI, but not a reason to lean back. The core remains the same: know which AI you use, know the risks, train people, hold suppliers to account and collect evidence.
The best use of the political agreement is not delay. The best use is to turn the extra months into better governance.
Frequently asked questions
The most important questions and answers about the Digital Omnibus and the AI Act.
Sources
Newsletter
Every Tuesday, the AI Act week ahead in 5 minutes
A practical briefing on deadlines, new guidance and enforcement, so you know what matters this week. No spam and you can unsubscribe in one click.
Practical and short · No spam · One-click unsubscribe