Blogs / 

Digital Omnibus on AI: Key Changes to the AI Act

IT, Privacy & Cybersecurity

6 August 2026

Written by

Hieke van Druten

Blog Image

The AI Act has only just entered into application, yet the European legislator has already stepped in. The Digital Omnibus Regulation, published on 24 July 2026, introduces a range of amendments. The aim is to make the rules clearer, more workable and future-proof, without compromising innovation or fundamental rights. Below, we highlight the most significant changes.

When Will the Rules for High-Risk AI Actually Apply?

Organisations working with so-called high-risk AI systems – such as systems used in recruitment, credit assessment or critical infrastructure – will no longer have to work towards a single fixed deadline. The Digital Omnibus Regulation splits the application dates into two stages. For most high-risk systems covered by Article 6(2) and Annex III of the AI Act, 2 December 2027 is the target date. For systems covered by Annex I, the deadline is 2 August 2028.

Will New Prohibited Practices Be Introduced?

Yes. In response to recent developments involving AI systems capable of generating sexually harmful material, two new practices will be added to the list of prohibited AI practices as of 2 December 2026. These include a prohibition on AI systems capable of generating realistic intimate images, videos, audio or similar material of identifiable individuals without their explicit consent (so-called non-consensual intimate material), as well as a prohibition on systems capable of generating child sexual abuse material (CSAM).

What Will Change Regarding the Transparency Obligations?

The AI Act requires providers and deployers of certain AI systems – such as chatbots or systems generating synthetic content – to inform users that they are interacting with or viewing AI-generated content. The original application date was 2 August 2026. For systems already placed on the market before that date, a four-month transition period applies. These systems must comply with the marking requirements under Article 50 by 2 December 2026 at the latest.

How Much AI Knowledge Must Employees Have?

Initially, the AI Act required organisations to ensure an adequate level of AI literacy among their staff. This obligation to achieve a specific result has been removed. The revised text provides that providers and deployers must take measures to support the development of AI literacy among their employees, but they are no longer required to actually guarantee a particular level of knowledge. The obligation therefore more closely resembles a best-efforts obligation than an obligation to achieve a specific result.

This may appear to reduce the regulatory burden, but there is a real risk that AI training will receive less attention within organisations. Organisations that deploy AI systems without ensuring that employees understand how these systems work and what risks they entail may face misuse or fail to identify errors in AI-generated outcomes.

Can Special Categories of Personal Data Be Used to Detect Bias?

Yes, subject to strict conditions. The Digital Omnibus Regulation introduces a new provision (Article 4a) allowing special categories of personal data to be processed for the purpose of detecting and correcting bias in AI systems. A key change is that this will no longer be limited to providers of high-risk AI systems. It will also apply to providers of other AI systems, such as general-purpose AI, as well as to deployers of high-risk AI systems. This means that organisations using a high-risk AI system in their own operations can also assess whether the system produces discriminatory outcomes.

The conditions are strict. Among other things, the processing must be strictly necessary, the data may not be shared, the data must be deleted after use, and robust security measures must be in place. Continued attention to privacy safeguards therefore remains essential.

What Does This Mean for Your Organisation?

The Digital Omnibus Regulation gives organisations more time and flexibility, but it does not necessarily make compliance any easier. The already complex rules have become more complex, with obligations applying at different times to different types of AI systems. Organisations using AI would therefore be well advised to establish or update their AI policy and reassess their compliance strategy.

Questions?

Do you have any questions? Please feel free to contact one of our specialists within our IT, Privacy & Cybersecurity team.

Newsletter

Would you like to receive a monthly overview of our latest legal updates and blog articles? Subscribe to our newsletter.