22 July 2026

The EU AI Omnibus: Where Are We Now and What Should Businesses Do Next?

On 29 June 2026, the Council of the European Union formally adopted the AI Omnibus (“AI Omnibus”) which makes amendments to the EU Artificial Intelligence Act (“AI Act”).

In a previous blog titled “Biggest EU digital shake-up since GDPR: what businesses need to know”, we explored the European Commission’s proposed “Digital Omnibus” package (“the Package“) unveiled in November 2025, which is a legislative package aiming to simplify an increasingly complex set of EU digital rules. The AI Omnibus forms a part of this Package.

The amendments to the AI Act made by the AI Omnibus do not alter the overall structure or ambition of the AI Act. Instead, the changes focus on improving how the regime will operate in practice, particularly around timing, compliance and the continuing use of data and risk.

If you are a UK business and you serve EU customers, monitor EU users, provide cloud or SaaS services to EU‑based clients, deploy AI systems affecting EU individuals, or place AI systems on the EU market, you remain potentially in scope of the AI Act (as well as the other digital omnibus reforms set out in the Package), regardless of UK regulatory divergence.

Timing update:

The most significant development is a reset of the AI Act’s implementation timeline. The AI Omnibus adjusts the AI Act’s application timeline to align with technical standards, delaying ‘high-risk’ AI systems compliance deadlines originally set for 2 August 2026. The AI Omnibus formally delays compliance for Annex III systems to 2 December 2027 (i.e., stand-alone ‘high risk’ AI systems), and Annex I product-integrated AI systems to 2 August 2028, aiming for a more realistic, phased implementation for businesses.

This is a practical adjustment, not a policy shift. The EU co-legislators recognised that businesses cannot effectively comply until technical standards are in place and have pushed back the timetable accordingly.

Article 50 watermarking obligations (i.e., the obligations to mark AI-generated content) have also been delayed for AI systems already on the market before 2 August 2026, which will now benefit from an extended application deadline of 2 December 2026. A draft ‘Code of Practice’ has already been published to guide labelling, watermarking and detection approaches, which developers and AI system providers will need to get familiar with in respect of their AI-generated and manipulated content to ensure compliance.

Despite the pushback of the above implementation dates, for all other systems the 2 August 2026 deadline has not been changed. From 2 August 2026, certain provisions of the AI Act will apply, including transparency requirements and the activation of regulators’ enforcement powers. The result is a phased rollout, rather than a single ‘go-live’ date. Therefore, despite the delayed application of some parts of the AI Act, businesses should be preparing now, not waiting for 2027 to ensure compliance across the AI Act’s various obligations.

Importantly, the postponement only affects certain high-risk AI obligations. Existing obligations concerning prohibited AI practices, AI literacy and, where applicable, general-purpose AI systems remain in force according to the AI Act’s phased implementation timetable.

Key updates to the AI Act set out in the revised AI Omnibus are as follows:

Ban on certain AI practices:

The AI Omnibus now explicitly bans AI systems designed to generate non-consensual sexual or intimate content, as well as AI-generated child sexual abuse material. The ban is broad and encompasses both providers of such AI systems as well as persons deploying such systems for these purposes.

The ban will apply from 2 December 2026.

Registration obligations:

The Council reinstated a simplified and proportionate registration obligation for certain non-high-risk AI systems. This is a material change, as previously only ‘high risk’ AI systems were required to register via an EU central database. This means that certain providers of non-high risk AI systems will once again be subject to registration requirements, albeit under a simplified and proportionate framework.

A more workable framework:

The new proposals provide welcome additional relief and additional privileges for small mid-cap companies. In particular, the proposals introduce a more proportionate approach with regards to compliance obligations for small mid-cap companies by extending the special regime applied to SMEs and seeking to reduce unnecessary administrative burdens, while maintaining the core risk-based structure. In particular, sandbox access privileges originally granted to SMEs, as well as simplified documentation and special consideration in the application of penalties originally only granted to SMEs, are extended to small mid-caps.

The role of the EU AI Office is also strengthened, signalling a move towards more centralised oversight and, potentially, more consistent enforcement across Member States. Taken together, these changes reflect a shift towards a regime that is not only robust, but also capable of being applied in real-world business environments.

Data use and risk:

The interaction between AI and data protection continues to be a central issue. The Council reinstated the standard of ‘strict necessity’ for processing of special category personal data (i.e., sensitive personal data) and maintained that the processing of special category personal data for bias detection, mitigation and correction remains subject to strict safeguards and a strict necessity threshold.

While having a clear standard is helpful for businesses, this does not reduce the compliance challenge. Organisations will still need to ensure that their data governance, training datasets and testing processes can withstand regulatory scrutiny, particularly where sensitive data is involved.

What does this mean for your business?

The amendments introduced by the AI Omnibus do not reduce AI regulation. Instead, they aim to make the pathway to compliance more streamlined. Whether the streamlined processes will assist AI system developers, providers and deployers in practice is yet to be seen. The message, however, is simple: while there is more time to prepare for some compliance deadlines, other compliance deadlines are fast approaching and regulatory expectations are crystallising quickly.

AI system developers, providers and deployers that use this extended implementation period to build robust AI governance frameworks will be best placed to manage risk and adapt as the regime and guidance beds in.

Navigating the evolving requirements of the AI Act can be complex, particularly as deadlines approach at different stages and obligations vary depending on the nature of your AI systems. Get in touch with Caroline Sheldon from our Corporate, Commercial and Finance team to find out how we can support your business.

About the authors

Caroline Sheldon is an associate who specialises in advising on commercial matters. She advises entrepreneurs, startups and established businesses across a variety of sectors, with a focus on those in the technology sector.

Bethany Hall is a trainee solicitor currently in her fourth seat with the Corporate, Commercial and Finance team.

Contact_us

Let us take it from here

Whatever your legal needs, we’re here to help.

Contact us