The AI Omnibus introduced changes that may affect how organisations assess, govern and use AI systems.
- Updated application dates: The application of several AI Act obligations has been postponed. The rules applicable to stand-alone high-risk AI systems will now apply from 2 December 2027, while the rules for high-risk AI systems embedded in products or constituting safety components of products will apply from 2 August 2028. The deadline for Member States to establish AI Regulatory Sandboxes has also been postponed to 2 August 2027.
- Transparency obligations: The application of the providers' marking and detection obligations relating to AI-generated content and deepfakes has been postponed until 2 December 2026. However, the transparency obligations applicable to deployers of AI-generated content, deepfakes, emotion recognition and biometric categorisation systems, as well as the obligations applicable to providers of AI systems that interact directly with natural persons, continue to apply from 2 August 2026.
- New prohibited AI practice: The AI Omnibus expressly prohibits AI practices involving the generation of non-consensual intimate content and AI-generated child sexual abuse material (CSAM).
- Bias detection: The requirement of strict necessity for the processing of special categories of personal data for the purposes of detecting and correcting bias in AI systems has been reinstated.
- Sector-specific legislation: Explicit reference to guidance on the interaction between the AI Act and harmonised sectoral legislation, including legislation on medical devices, machinery and toys, helping to avoid duplicative compliance requirements.
- AI Regulatory Sandboxes: The deadline for Member States to establish AI Regulatory Sandboxes has been extended until 2 August 2027, providing additional time to develop controlled testing environments for innovative AI systems.
- AI Office competences: The supervisory role of the AI Office over AI systems based on general-purpose AI models has been clarified, while confirming the areas that remain within the competence of national authorities.
- European Commission guidance: The European Commission is required to publish guidance to support providers and deployers of high-risk AI systems subject to harmonised sectoral legislation, promoting a more consistent and practical application of the AI Act across sectors.
Explore the changes and consult our updated User-Friendly Version of the EU AI Act.