Rewriting the rules of AI: Targeted EU AI Act amendments in the Digital Omnibus on AI

The Digital Omnibus on AI introduces changes aimed at improving legal certainty, proportionality and AI Act implementation.

Contributors:
Müge Fazlioglu
CIPP/E, CIPP/US
Principal Researcher, Privacy Law and Policy
IAPP
On 7 May 2026, the European Parliament and the Council of the EU reached a political agreement on the Commission's proposal for a Digital Omnibus on AI, less than six months after the proposal was introduced on 19 Nov. 2025. While the AI Act's overall structure and its risk-based approach remain intact, the agreement includes numerous targeted and significant amendments to the EU's landmark AI law. Changes brought about by the Digital Omnibus on AI, which entered into force on 27 July 2026, will affect providers and deployers as well as regulators and public-sector bodies in various ways.
Changes affecting AI providers and deployers
AI providers and deployers will be directly impacted by numerous provisions of the Digital Omnibus on AI, namely, its delayed deadlines for entry into application of rules around high-risk AI systems and watermarking AI-generated content, an extended legal basis for the processing of sensitive personal data when strictly necessary for bias detection and mitigation, and the banning of AI systems that generate nonconsensual intimate material or child sexual abuse material. Other significant reforms include softened AI literacy requirements, relief for small "mid-cap" enterprises, reduced overlap between EU product safety laws and the AI Act that lessens the "double burden" on businesses, and greater allowances for fundamental rights impacts assessments with Article 27.
Delayed deadlines for high-risk AI systems and for watermarking AI-generated content
While the AI Act came into force on 1 Aug. 2024, its provisions have entered into application on a staggered timeline. Originally, all of its rules were planned to be enforceable by 2 Aug. 2027.
Contributors:
Müge Fazlioglu
CIPP/E, CIPP/US
Principal Researcher, Privacy Law and Policy
IAPP