
The delay to the European Union's toughest AI rules is now law. The EU's "Digital Omnibus on AI", Regulation (EU) 2026/1744, entered into force on 27 July 2026, three days after it was published in the Official Journal. It moves the start of the EU AI Act's high-risk obligations to 2 December 2027 for stand-alone systems and to 2 August 2028 for AI built into regulated products. It also adds a new ban, widens the relief available to smaller companies and gives the EU's AI Office more power. It does not switch the AI Act off, and the transparency rules still begin this August. This article is general information, not legal advice.
What happened
The European Commission announced the change in a news item, AI Omnibus enters into force, dated 27 July 2026. It says the amendments were proposed on 19 November 2025 as part of the Commission's digital omnibus package, and describes them as a targeted simplification of the AI rulebook.
The European Parliament's Legislative Observatory procedure file records the steps in between. Parliament approved the agreed text in plenary on 16 June 2026, by 423 votes to 57 with 174 abstentions according to its summary of the vote. The Council adopted the act on 29 June. The final act was signed on 8 July and published in the Official Journal on 24 July 2026 as Regulation 2026/1744.
Key details
| Area | Position after the Digital Omnibus on AI |
|---|---|
| Stand-alone high-risk AI systems: the areas in Annex III of the Act, which include biometrics, critical infrastructure, education, employment, and migration, asylum and border control | Rules apply from 2 December 2027 |
| High-risk AI embedded in physical products, such as machinery, toys and lifts (Annex I) | Rules apply from 2 August 2028 |
| Transparency rules (Article 50 of the Act) | Still start to apply on 2 August 2026 |
| Article 50(2) for certain providers of systems that generate synthetic content and were already on the market before 2 August 2026 | Transitional deadline of 2 December 2026 |
| New prohibition: AI systems that generate non-consensual sexually explicit or intimate content, or child sexual abuse material, which the Commission describes as a ban on nudification apps | Applies from 2 December 2026 |
| Smaller companies | Some measures previously reserved for small and medium-sized enterprises are extended to small mid-cap companies |
| Supervision | The AI Office gets extended oversight of certain AI systems, including those built on general-purpose models and those embedded in large online platforms and search engines |
The dates are set out in the Commission's AI Act implementation timeline. Parliament's Legislative Observatory summary of the adopted text adds several points that matter to software makers:
- Each member state must have at least one national AI regulatory sandbox operating by 2 August 2027, the AI Office may set up an EU-level sandbox, and small and medium-sized enterprises, including start-ups, get priority access to the AI Office's sandboxes. A sandbox is a supervised setting where a company can test a product with a regulator before full launch.
- Personal data may be processed where strictly necessary to detect and correct bias, under strict safeguards, for both high-risk and other AI systems.
- The AI Office gets exclusive competence over AI systems built on a general-purpose AI model where the system and the model come from the same provider, or from providers in the same undertaking.
- Overlapping AI requirements for machinery products are removed: they only need to comply with the sector's own safety rules.
Why it matters
The change buys time, and it is tempting to read it as a reprieve. It is better read as a timetable. The rules for high-risk uses of AI, including software used in employment and education, have a firm start date. The parts of the Act that are already running are untouched: the Commission's timeline shows that the prohibitions have applied since 2 February 2025 and the obligations for providers of general-purpose AI models since 2 August 2025.
The new ban is a reminder that the Act can tighten as well as loosen. Parliament's summary says suppliers may not place such systems on the European market unless they have adequate technical safeguards to prevent the creation of that material, so any business offering image or video generation to European users has a design question to answer.
The reach of the law has not narrowed. Article 2 of the Act says it applies to providers that place AI systems on the market or put them into service in the EU, "irrespective of whether those providers are established or located within the Union or in a third country". It also covers providers and deployers located outside the EU where the output of the AI system is used in the EU. Whether that describes a particular Australian company is a question to put to a legal adviser.
What this means for businesses
The Act is concerned with AI systems placed on the market, put into service or used in the EU. If you sell software with AI features into Europe, or use AI tools on people there, ask an adviser how the Act applies to you and treat the new dates as a planning window.
- Map your exposure. List each AI feature or tool that touches EU customers, and note whether you built it or bought it.
- Check for high-risk uses. Analysing and filtering job applications, evaluating candidates and evaluating students' learning outcomes are among the uses listed in Annex III. If one applies to you, 2 December 2027 is the date to plan for.
- Do not pause transparency work. The Article 50 transparency rules still start to apply on 2 August 2026. For certain providers of systems that generate synthetic content and were already on the EU market before that date, the deadline to comply with Article 50(2) is 2 December 2026.
- Rule out the banned use. Confirm that any image or video generation feature has safeguards against non-consensual intimate content before 2 December 2026.
- Ask suppliers for their plan in writing. Ask which of these dates they are working to and what documentation they will give you.
- Ask whether the relief for smaller companies applies. Some measures reserved for small and medium-sized enterprises now extend to small mid-cap companies; an adviser can tell you whether your business qualifies.
- Put the dates in the calendar. 2 August 2026, 2 December 2026, 2 December 2027 and 2 August 2028.
Much of this is ordinary good engineering: knowing what your product does, keeping records, and designing features so a person can check an important result. Those habits are easier to build into custom software from the start than to add later. If your systems have grown over time and nobody is sure where AI features sit, an IT consulting review can produce the map, and a digital transformation plan can schedule the changes alongside other work. To talk through a product that sells into Europe, send us an enquiry.
Key takeaways
- Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026.
- High-risk rules now apply from 2 December 2027 for stand-alone systems and 2 August 2028 for AI embedded in regulated products.
- The Article 50 transparency rules still start to apply on 2 August 2026, with a transitional deadline of 2 December 2026 for certain synthetic-content systems already on the market.
- A new prohibition on AI that generates non-consensual intimate content or child sexual abuse material applies from 2 December 2026.
- Some measures reserved for small and medium-sized enterprises now extend to small mid-cap companies, and the Act still reaches providers outside the EU.
Frequently asked questions
What is the Digital Omnibus on AI?
It is Regulation (EU) 2026/1744, a set of amendments to the EU AI Act proposed by the European Commission on 19 November 2025 and in force since 27 July 2026. The Commission describes it as a targeted simplification of the AI rulebook.
When do the EU AI Act high-risk rules apply now?
From 2 December 2027 for the stand-alone high-risk systems listed in Annex III, in areas such as employment, education and biometrics, and from 2 August 2028 for high-risk AI embedded in physical products such as machinery, toys and lifts.
Did the delay change the transparency rules?
Only at the edges. The Article 50 transparency rules still start to apply on 2 August 2026. Certain providers of systems that generate synthetic content, where those systems were already on the market before that date, have until 2 December 2026 to comply with Article 50(2).
Does the EU AI Act apply to an Australian business?
It can reach businesses outside the EU. Article 2 applies the Act to providers that place AI systems on the EU market or put them into service there, wherever they are established, and to providers and deployers outside the EU where the system's output is used in the EU. Whether it applies to your business is a question for a legal adviser.
What relief do smaller companies get?
Some measures and simplified obligations previously reserved for small and medium-sized enterprises now extend to small mid-cap companies. Small and medium-sized enterprises, including start-ups, also get priority access to the AI Office's regulatory sandboxes.