Skip to main content
← All articles
EU AI ActDigital OmnibusGDPR

The AI Act's dates just changed. Here is what moved and what did not.

The Digital Omnibus on AI is in force. It pushes the high-risk deadlines back, adds a ban on non-consensual deepfakes, and gives existing generative systems until December 2026 to add watermarks.

The EuroCompliant team·

The AI Act changed more than people realised when it was published. On 27 July 2026 the Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force. It rewrites the application timeline and adds a new prohibited practice, so the dates you see on compliance checklists in 2026 are not the dates from the original 2024 text.

What moved, and when

The original AI Act said most high-risk obligations would bite from 2 August 2026. The Omnibus pushed that back, and the delay is bigger than a few months:

  • Standalone high-risk AI systems, the ones caught by Annex III like employment tools and law enforcement, now have until 2 December 2027.
  • High-risk AI that is a safety component of a physical product, the Annex I category covering things like medical devices and machinery, now has until 2 August 2028.
  • National AI regulatory sandboxes, which Member States were due to stand up by 2 August 2026, moved to 2 August 2027.

None of this touches the rules that were already live. The prohibitions in Article 5, the general-purpose AI obligations and the AI literacy duty have applied since February and August 2025 respectively, and the transparency rules in Article 50 applied from 2 August 2026.

A genuinely new prohibition

The Omnibus also added a fifth prohibited practice: AI systems that generate child sexual abuse material, or that create or alter images, audio or video of a real person in sexually explicit or intimate scenes without their consent. The ban starts 2 December 2026. The deadline matters because these systems can be built and sold today, and a provider that does not put safeguards in place is exposed from that date.

The watermarking grace period

If your generative AI system was already on the market before 2 August 2026 and it produces synthetic content, Article 50(2) gives you until 2 December 2026 to add machine-readable marking and detection mechanisms. New systems face the requirement from 2 August 2026 with no grace period.

The GDPR omnibus is still a proposal

The Commission's parallel proposal to simplify GDPR, COM(2025) 837, has not been adopted. It is a proposal. Nothing in it is law yet, and we have not changed any GDPR obligations in the platform to reflect it. If you read coverage claiming GDPR record-keeping or privacy-notice requirements have changed, treat it as commentary about a draft, not a rule you owe.

High-risk classification guidance

The Commission has also published draft guidelines on classifying high-risk AI systems, with worked examples of what is in and out of Annex III. The public consultation closed on 23 July 2026 and the text has not been formally adopted. We are tracking it because the guidance affects how Annex III should be read in practice. When it is final we will fold it into the classification questionnaire and reference it from the relevant obligations.

What this means on the platform

We have checked every date in the obligations engine against the adopted text and the Commission's own implementation timeline. The checklist deadlines now reflect the Omnibus, the new prohibited practice appears in the Article 5 obligations, and the deepfake and synthetic content items carry the correct grace-period date. If a date in your plan looks further out than you remembered, this is why.

Ready to get compliant?

Register your AI systems, classify risk, and generate audit-ready evidence.

Start free trial