Skip to content
All articles
EU AI Act 8 min read· by Lars Zimmermann

The Digital Omnibus: New AI Bans, More Time, and Targeted Relief

The Digital Omnibus amending the EU AI Act is final. It does not just push deadlines: it bans new practices and gives manufacturers targeted relief.

In short

The Digital Omnibus, the regulation amending the EU AI Act, was formally adopted on 29 June 2026. It is not a simple deadline extension: it bans new AI practices from 2 December 2026, extends relief to small mid-cap companies, and eases embedded AI through product law. Read only "later" and you miss half of it.

Auf Deutsch lesen: deutsche Fassung

On 29 June 2026 the so-called Digital Omnibus was formally adopted, the regulation that amends the EU AI Act. In many companies only one message has stuck: the high-risk obligations are postponed, so we have more time. That is true, but it is only half the story. The Omnibus is not a blanket deferral and certainly not an all-clear. It bans new things, it grants targeted relief, and it still requires you to classify every single AI system. This is my read as an auditor, not legal advice.

What is actually postponed, and what is not

The high-risk part is postponed: stand-alone high-risk systems under Annex III, such as AI for CV screening, now apply from 2 December 2027. High-risk AI embedded in a product as a safety component applies from 2 August 2028. Everything else stays: the transparency obligations under Article 50 have applied since 2 August 2026, and the prohibited practices (Article 5) and the AI literacy duty (Article 4) since 2 February 2025. The full timeline, class by class, is covered in a separate article.

One detail that often gets lost: even for systems already on the market, the relevant date is no longer a blanket 2 August 2026 but the new deadline for that system type. Existing systems generally only have to meet the high-risk requirements once they are substantially changed after that date. That retrofit point moves with the deadline. Real relief for running systems, but no reason to leave classification undone: a substantial change is quickly triggered, for example by a larger update or a change of purpose.

Newly banned: AI for intimate fakes and abuse material

The Omnibus adds to the list of prohibited practices in Article 5. Newly banned is AI that generates or manipulates non-consensual intimate imagery of an identifiable person, and AI that generates or manipulates child sexual abuse material. These bans apply from 2 December 2026.

The scope matters: it covers not only systems whose main purpose is this, but also systems where such outputs are reproducibly possible under intended or foreseeable use and where no adequate, state-of-the-art safeguards are in place. In practice: anyone offering or integrating a generative image or video model now has a new checkpoint. If the system can be misused to create such content, filters, moderation and technical limits must demonstrably prevent or minimise it, accounting for foreseeable misuse.

Do not underestimate the weight of this. A prohibited practice is the strictest category of the AI Act, carrying the highest penalty ceiling of up to 35 million euros or 7 percent of worldwide annual turnover. Unlike high-risk obligations, there is no generous transition here: what is banned is banned. For providers of generative systems, whether the system can be misused to create such content becomes a checkpoint you should be able to evidence before 2 December 2026.

Relief many mid-sized firms miss: small mid-caps

Until now the AI Act's simplifications mainly applied to small and medium-sized enterprises (under 250 employees, up to 50 million euros turnover). The Omnibus extends part of these privileges to a new group: small mid-cap enterprises. Under the underlying Commission recommendation, these are companies with fewer than 750 employees and no more than 150 million euros in turnover or 129 million euros in balance-sheet total.

Concretely, SMEs and small mid-caps may keep the technical documentation for high-risk AI in simplified form, scale their quality management to size and risk, get priority access to regulatory sandboxes, and have their economic capacity taken into account when fines are set. For many industrial and engineering firms this is relevant, because they sit exactly in this bracket. If you assumed the relief was only for micro-businesses, check your own classification deliberately.

A practical note on classification: the thresholds for SMEs and small mid-caps follow the Commission definitions, and a one-off overshoot or undershoot does not change your status. Only when the limits are crossed over two consecutive financial years does the category change. It pays to document your classification cleanly, because it decides which relief you may use.

The Digital Omnibus postpones the high-risk part and grants targeted relief. It abolishes neither the labelling duty nor the literacy duty, and it even bans new things. Read only "later" and you build yourself a compliance risk.

One clear limit is written into the text: these simplifications target the high-risk area, that is documentation, quality management and oversight. The transparency and labelling obligations under Article 50 are untouched, including for small mid-caps. A chatbot notice does not become dispensable just because a company is small.

For manufacturers: relief through product law

I come from precision engineering, so this point matters to me. The Omnibus first sharpens the definition of a safety component: an AI system only counts as safety-relevant if its intended purpose is to perform a safety function, that is, to prevent or reduce risks to health or safety. Pure comfort or optimisation AI in a product does not automatically fall under it, even if the product itself is safety-regulated.

Beyond that, the Omnibus introduces a mechanism for sectoral relief: individual AI Act obligations can be limited in favour of sector-specific product rules where those provide an equivalent or higher level of protection. For AI related to machinery, implementation moves closer to the Machinery Regulation that these firms already know, so double, contradictory requirements are meant to fall away. It does not happen automatically, though: the relief only applies where the Commission spells it out in a delegated act.

What stays the same: labelling and the literacy duty

On labelling, look closely, because the Omnibus cleanly separates two duties. The machine-readable marking of AI output (a provider duty under Article 50(2)) gets a transition period until 2 December 2026, but only for systems placed on the market before 2 August 2026. New systems must mark immediately. The duty of deployers to disclose deepfakes and certain AI-generated content (Article 50(4)) stays at 2 August 2026 and is not postponed.

And the AI literacy duty under Article 4? It is softened in wording, not abolished. It becomes an explicit organisational duty of measures and support, not a guarantee of a specific literacy level for each individual. In practice this changes little: if you use AI, you have to enable your team anyway, or the expensive mistakes happen.

What you should do now

  • Determine the role and risk class of each AI system. That decides the deadline and the obligations, and the Omnibus makes this classification more important, not less.
  • Check your own size class: are you an SME or a small mid-cap? Then use the new relief deliberately, instead of doing work that is not required.
  • For generative AI, add the new Article 5 checkpoint: can the system produce intimate fakes or abuse material, and are safeguards in place against it?
  • Do not forget the Article 50 labelling. It is exempt from the postponement and largely applies already.
  • Document everything. A management system to ISO/IEC 42001 keeps classification, evidence and deadlines in one place, no matter how often the legislator adjusts.

My clear line: the Omnibus is a smart recalibration, not a free pass. It takes pressure off the high-risk timeline, and precisely for that reason it demands a clean classification. If you do not know which risk and size class you fall into, you can neither use the relief nor meet the new obligations. Order things now and you win. Wait, and you mistake postponement for completion.

Share: LinkedIn E-Mail

Frequently asked questions

Is the Digital Omnibus already binding law?+

It was formally adopted on 29 June 2026. The amending regulation is published in the Official Journal after signature; entry into force is expected on or before 2 August 2026. The amended dates and rules are therefore settled, no longer a mere proposal.

Does the postponement mean we can do nothing?+

No. Only the high-risk part is postponed (Annex III to 2 December 2027, embedded systems to 2 August 2028). The prohibited practices (Article 5), the transparency duties (Article 50) and the AI literacy duty (Article 4) still apply, and new bans are added from 2 December 2026.

What is newly banned by the Omnibus?+

AI that generates or manipulates non-consensual intimate imagery, and AI that generates or manipulates child sexual abuse material. The ban applies from 2 December 2026 and also covers generative systems that make such outputs possible under foreseeable use without adequate safeguards.

What changes for small and medium-sized companies?+

High-risk simplifications are extended from SMEs to small mid-cap enterprises (under 750 employees, up to 150 million euros turnover or 129 million euros balance-sheet total): simplified technical documentation, quality management scaled to size and risk, priority sandbox access, proportionate fines. The Article 50 transparency duties are unchanged.

Do manufacturers benefit in particular?+

The Omnibus sharpens the safety-component definition and creates a mechanism to implement AI obligations through machinery law, avoiding double regulation. This only provides relief once the Commission issues the corresponding delegated acts.

Author & expert review: Lars Zimmermann · ISO/IEC 42001 Senior Lead Auditor & Senior Lead Implementer · ISO/IEC 27001 Lead Auditor & Lead Implementer (PECB)

Last updated: 21 July 2026. Researched and reviewed to the best of our knowledge; not a substitute for individual legal advice.

Sources & further reading

Questions about your own case?

In a free 15-minute intro call we assess where you stand on ISO 42001, ISO 27001 and the EU AI Act, honestly and without a sales pitch.

Continue reading