The Digital Omnibus on AI: What the 7 May 2026 Deal Actually Changes — and What It Doesn’t

A close reading of the finally adopted amending regulation, with a direct comparison to the AI Act as enacted, and an examination of what it means for organizations that treat Responsible AI as more than a compliance exercise.

The 90-second version

In the early hours of Thursday, 7 May 2026, after roughly nine hours of negotiations in the third political trilogue, the European Parliament and the Council of the EU reached political agreement on the Digital Omnibus on AI — the Commission’s targeted reform package (COM(2025) 836) for Regulation (EU) 2024/1689. That agreement has since been formally adopted by both co-legislators: the European Parliament on 16 June 2026, and the Council on 29 June 2026. What remains before the new rules take legal effect is publication in the Official Journal, expected within weeks, followed by the standard three-day entry into force. The deal replaces the original 2 August 2026 wall for high-risk obligations with new fixed dates in late 2027 and mid-2028.

For organisations preparing for the AI Act, three things matter operationally:

  • High-risk obligations are postponed, but to fixed dates — not the open-ended “when standards are ready” model the Commission originally proposed. Annex III (stand-alone high-risk systems: biometrics, employment, education, critical infrastructure, law enforcement, migration, justice) now applies from 2 December 2027. Annex I (AI as a safety component in regulated products: machinery, medical devices, toys, lifts, etc.) applies from 2 August 2028.
  • A new prohibition lands in Article 5: AI systems generating child sexual abuse material (CSAM) or non-consensual intimate imagery — the “nudifier” category — are added to the list of prohibited practices, with compliance by 2 December 2026.
  • The Article 50(2) watermarking date remains 2 August 2026, but a four-month transitional grace period sets the practical compliance date at 2 December 2026 for systems already on the market.

The agreement has now been formally endorsed by both the European Parliament (16 June 2026) and the Council (29 June 2026). What remains is legal-linguistic finalization and publication in the Official Journal, expected before the original 2 August 2026 deadline takes effect. Until that publication — and the three-day entry-into-force period that follows it — the original AI Act technically remains the law on the books. But with both co-legislators’ adoption complete, this is now a matter of administrative process, not political uncertainty. As a planning baseline, the new dates should be treated as settled.

How we got here

The reform did not arrive out of nowhere. The Commission tabled the Digital Omnibus on AI on 19 November 2025 as part of the EU’s seventh “Omnibus” simplification package, building on the Draghi competitiveness agenda and reflecting industry feedback about implementation readiness. The political path was unusually compressed:

  • Council position: 13 March 2026
  • Joint IMCO/LIBE report: 18 March 2026
  • Parliament plenary vote: 26 March 2026 (569 in favour, 45 against, 23 abstentions)
  • First trilogue: immediately after the plenary
  • Second trilogue: 28 April 2026 — collapsed after twelve hours, with the conformity-assessment architecture for Annex I products as the unresolved file
  • Third trilogue: 6–7 May 2026 — agreement reached at approximately 4:30 a.m. CEST

The co-rapporteurs are Arba Kokalari (EPP, Sweden) for the IMCO committee and Michael McNamara (Renew, Ireland) for the LIBE committee. The deal has been framed by the Cypriot Presidency as the first deliverable under the “One Europe, One Market” roadmap.

It is worth pausing on this point. The negotiation that had nearly failed nine days earlier ultimately closed because France and Italy moved toward Germany’s position on Annex I, and because Parliament’s left wing chose to spend its political capital on the new Article 5 prohibition rather than on resisting the broader thrust toward simplification. The text we now have is a political compromise — not a structural rethink of the Act.

A direct comparison of what changed

The Omnibus does not rewrite the AI Act. It preserves the risk-based architecture, the prohibited-practices core, the high-risk requirements (Articles 9–15), the GPAI regime (Articles 50–55), the fundamental-rights orientation, and the AI Office. What it changes are: timelines, scope at the margins, one new prohibition, the bias-detection legal basis, the SME perimeter, and the supervisory map for GPAI-derived systems.

The following table sets the AI Act as enacted against the political text agreed on 7 May.

:AI Act as enacted (2024/1689)Digital Omnibus on AI — Agreement of 7 May 2026
Annex III high-risk obligations (stand-alone)Apply from 2 August 2026Apply from 2 December 2027 (fixed date, not conditional)
Annex I high-risk obligations (safety components)Apply from 2 August 2027Apply from 2 August 2028 (fixed date)
Article 50(2) — watermarking of synthetic contentApply from 2 August 2026 with no transition for legacy systemsApplication date unchanged (2 Aug 2026), but providers with systems already on the market get until 2 December 2026 (4-month grace — the trilogue compromise, between the Commission’s proposed 6 months / 2 February 2027 and the Parliament’s 3 months)
Article 5 prohibited practicesEight categories (manipulation, exploitation of vulnerabilities, social scoring, predictive policing in certain forms, untargeted facial-recognition scraping, emotion recognition in workplace/education with exceptions, biometric categorisation, real-time RBI in public spaces)+ New prohibition: AI systems that generate CSAM or non-consensual intimate imagery (the “nudifier” category). Covers placing such systems on the market for that purpose, placing them without reasonable safety measures, and deployer use for that purpose. Applies to images, video, audio. Compliance by 2 December 2026.
“Safety component” concept (Annex I)Broad — AI features in regulated products can be pulled into the high-risk regime even where the AI is non-criticalNarrowed: AI functions that merely assist users or optimise performance and whose failure would not create health or safety risks are no longer automatically high-risk
Machinery products (Annex I, Section A)Subject to combined AI Act + Machinery Regulation conformity assessmentCarved out to Section B: AI-related health and safety requirements to be set by delegated acts under the Machinery Regulation. Note: Medical Devices Regulation, IVDR, Radio Equipment Directive remain in the combined regime — only machinery was moved
Equivalence clauseNoneNew mechanism: where sectoral safety legislation contains AI-specific requirements equivalent to the AI Act’s, the Commission may, by implementing act, limit the AI Act’s direct application accordingly
Bias detection — processing of special-category dataArticle 10(5) permits processing of special-category personal data for bias detection/correction, but limited to providers of high-risk AI systemsExtended to providers and deployers of AI systems and models, regardless of risk classification, subject to a strict necessity standard. For high-risk systems without model training, the derogation is limited to dataset testing
SME perimeter for proportionate complianceReduced obligations for SMEs; simplified QMS only for microenterprises (Art. 63)Small mid-cap enterprises (SMCs) introduced into the AI Act (up to 750 employees and meeting either €150 M turnover or €129 M balance-sheet threshold). SMCs get simplified technical documentation, proportionate QMS, and modulated penalties. Simplified QMS extended from microenterprises to all SMEs
AI Office competence (GPAI-derived systems)National authorities supervise AI systems regardless of the underlying modelAI Office gets exclusive competence over AI systems based on GPAI models where the same provider develops both the model and the system, plus systems integrated into VLOPs / VLOSEs under the DSA. Exceptions (national authorities remain competent): law enforcement, border management, judicial authorities, financial institutions
Registration of self-assessed non-high-risk AIRequired in EU database under Article 6(4)Commission proposed deletion; both co-legislators rejected that. Registration retained, but with streamlined content requirements (simplified Section B of Annex VIII)
National AI regulatory sandboxesMember States required to establish by 2 August 2026Deadline pushed back to 2 August 2027
Real-world testing (Article 60)Available primarily to Annex III (purpose-based) high-risk systemsExtended to Annex I (product-based) high-risk systems, with safeguards. New Article 60a creates a voluntary testing-agreement basis for Annex I, Section B (aviation, road, rail, agricultural, maritime)
AI literacy (Article 4)Providers and deployers obliged to ensure AI literacy of staffCommission had proposed softening this to an encouragement model. Parliament and Council kept the obligation — this one is unchanged in substance
Risk-based architectureFour tiers (unacceptable, high, limited, minimal)Unchanged
GPAI obligations (Articles 50–55)In force since 2 August 2025Unchanged and not on the table
Article 4 AI literacy & Article 5 prohibitionsIn force since 2 February 2025Unchanged (except for the new nudifier/CSAM addition to Article 5)

A few of those rows deserve unpacking.

Fixed dates, not a conditional timeline

The Commission’s original proposal tied the application of high-risk obligations to a Commission decision confirming that standards and support tools were in place, with backstop dates of 2 December 2027 and 2 August 2028 if no decision was adopted. Both co-legislators stripped that flexibility out. The new dates are fixed, removing the Commission’s discretion to bring application forward (or push it later than the backstop). For compliance planning this is genuinely useful: organisations now have a hard date to plan against, not a moving target.

The Annex I compromise was narrower than the Parliament had wanted

The Parliament’s pre-trilogue position would have moved all Section A products (machinery, medical devices, IVDR products, lifts, radio equipment) out of the combined AI Act + sectoral conformity assessment regime. In the end, only machinery moved. Manufacturers of AI-enabled medical devices, IVDR products, lifts, and radio equipment remain in the combined regime, although the new equivalence clause and the narrowed “safety component” concept will reduce the regulatory drag at the edges.

The nudifier prohibition is broader than it looks

The new Article 5 prohibition is not only about apps marketed for that purpose. It also captures general-purpose generative AI providers who place such systems on the EU market without reasonable safety measures to prevent their use for generating non-consensual intimate imagery or CSAM. For providers of large generative models, this lands real obligations: trust-and-safety architecture, content-moderation guardrails, red-teaming for these specific harms. Compliance by 2 December 2026. (The precise scope of the prohibition is one of the details still being settled in the final text.)

Bias detection: the most consequential RAI change

This is the change most relevant to a Responsible AI program. The old Article 10(5) allowed providers of high-risk AI to process special-category personal data — race, ethnicity, health data, biometric data, sexual orientation, political opinions — only for bias detection and correction in high-risk systems. The Omnibus extends that legal basis to all providers and deployers of AI systems and models, regardless of risk classification, subject to a strict-necessity test.

This is technically a simplification, but it has substantive RAI consequences. It removes a long-standing tension between Article 10’s bias-mitigation duties and the GDPR’s Article 9 prohibition on special-category processing. It allows organisations running non-high-risk systems — which is most systems — to actually measure and correct demographic bias without retreating into proxy variables. For any organisation that has been doing fairness assessments under a fragile legal basis, this provides a much cleaner footing. The strict-necessity standard is the constraint that keeps it from being a back door.

What didn’t change, and why that matters

It is tempting to read “delay” and conclude that the AI Act has been weakened. It hasn’t. The political agreement preserves:

  • The risk-based architecture in full.
  • Article 5 prohibitions as the structural floor (now expanded, not contracted).
  • Articles 9–15 — the substantive high-risk requirements: risk management, data governance, technical documentation, record-keeping, transparency, human oversight, accuracy, robustness, cybersecurity. None of these requirements has been softened.
  • The GPAI regime (Articles 50–55), which was never in dispute.
  • AI literacy obligations under Article 4, which have applied since February 2025 and which the co-legislators explicitly kept.
  • Registration for self-assessed non-high-risk systems under Article 6(4), which both Parliament and Council reinstated against the Commission’s proposed deletion, reflecting EDPB/EDPS concerns about regulatory visibility.

The Omnibus is, in the words of one observer, complexity redistributed rather than reduced. The headline relief is the timeline. The substance of the Act, including the parts that matter most to a Responsible AI program — fairness, transparency, human oversight, documentation — is the same.

When does it actually apply?

This is where the lex lata / de lege ferenda distinction still matters, though less than it did in May. Both co-legislators have now formally adopted the text — the European Parliament on 16 June 2026, the Council on 29 June 2026. What remains outstanding is publication in the Official Journal and the three-day entry into force that follows. Until that publication, the AI Act technically remains in force in its original wording, meaning the 2 August 2026 application date for Annex III high-risk obligations is, for the moment, still on the books — but only as a formality awaiting a printing date, not as an open question of political will.

The confirmed and expected sequence:

  1. 16 June 2026 — European Parliament plenary approval. (Confirmed.)
  2. 29 June 2026 — Council final adoption, completing formal endorsement by both co-legislators. (Confirmed.)
  3. July 2026 — legal-linguistic revision, translation into all 24 official languages, and signing.
  4. Expected before 2 August 2026 — publication in the Official Journal of the European Union.
  5. Three days after publication — entry into force.
  6. 2 August 2026 — original Annex III date that the Omnibus is designed to supersede before it takes effect.

Five dates now matter for operational planning:

DateObligation
2 August 2026AI Office regulatory sandbox base date; Article 50(2) watermarking applicable date for new market entrants
2 December 2026Article 5 nudifier/CSAM prohibition compliance deadline; Article 50(2) watermarking compliance deadline for systems already on the market on 2 August 2026
2 August 2027New deadline for Member States to establish AI regulatory sandboxes
2 December 2027Annex III (stand-alone) high-risk obligations apply
2 August 2028Annex I (safety component) high-risk obligations apply

The tail risk that mattered in May has largely passed: formal adoption by both co-legislators is complete, and the text is locked in. What remains is a publication-timing risk, not a political one — if Official Journal publication were to slip past 2 August 2026 for purely administrative reasons, the original AI Act dates would remain legally binding for those few extra days. Professional prudence is to plan against the new dates as the baseline and to confirm the Official Journal publication date once it is on file, rather than to leave open the possibility that the original 2 August 2026 obligations resurface.

The implications for Responsible AI programs

Three strategic observations for organisations — particularly Mittelstand companies — that have been building toward AI Act readiness.

First, the delay is real but narrow, and it is almost certainly the only one. The political argument for postponement has now been used. The Cypriot Presidency framed the deal as a flagship deliverable. A second postponement would erode the Brussels-effect leverage that makes the AI Act globally relevant in the first place. Plan against the new dates as if they were binding.

Second, the delay is a change in timeline, not a change in values. The fundamental-rights orientation, the transparency requirements, the human-oversight obligation, the data-governance duties — these are all intact, just deferred. For organizations that have been treating Responsible AI as a competitive differentiator rather than as a deadline-driven compliance scramble, very little changes strategically. The case for fairness audits, documented model cards, lineage tracking, and oversight processes is the same case it was on 6 May. The legal basis for bias detection is now easier, not harder.

Third, the SMC perimeter genuinely matters for German and continental Mittelstand companies. Many Mittelstand firms sit precisely in the gap between SME and large enterprise — they have crossed the 250-employee threshold but remain well under 750. Until the Omnibus, they received no proportionate treatment under the AI Act. The new SMC category brings simplified documentation, proportionate QMS, and penalty modulation within reach for exactly the firms that have been hit hardest by AI Act readiness costs.

What I’d recommend operationally:

  1. Re-baseline the compliance calendar against the new dates, but keep the original dates visible in your program governance until Official Journal publication is confirmed.
  2. Treat the watermarking deadline as the nearest live obligation if you ship anything generative — UI labelling, machine-readable metadata embedding, detection capability. Seven months of engineering work, not a paperwork exercise. (The AI Office’s Code of Practice on Transparency of AI-Generated Content — the operational benchmark — is itself still in draft.)
  3. For generative providers, get a CSAM and NCII trust-and-safety review on the roadmap before December 2026.The new Article 5 prohibition captures providers who fail to implement reasonable safety measures, not just those who market nudifier apps.
  4. Use the extended bias-detection legal basis. If you have been deferring fairness assessments because of GDPR Article 9 friction, that friction is now substantially reduced for the special-category-data piece. Implement the strict-necessity governance now so the legal basis is defensible when used.
  5. Check the SMC perimeter. If your organisation qualifies, the documentation and QMS implications are material.
  6. Do not wind down the substantive readiness program. Risk management (Art. 9), data governance (Art. 10), technical documentation (Art. 11), record-keeping (Art. 12), transparency (Art. 13), human oversight (Art. 14), accuracy/robustness/cybersecurity (Art. 15) — all unchanged in substance. The clock just got 16 months longer.

A closing reflection

The Digital Omnibus is being sold as simplification. Read closely, it is something more ambiguous: a redistribution of complexity, a recalibration of timing, a narrow set of substantive changes (some genuinely simplifying, some — like the new Article 5 prohibition — adding new obligations), and a careful preservation of the AI Act’s structural architecture.

For organisations that have understood Responsible AI as a question of how to build trustworthy systems — not how to satisfy a regulator before a deadline — the 7 May agreement changes the calendar but not the work. The work remains: data governance, fairness measurement, documentation, human oversight, transparency, robustness. The reasons for doing that work — competitive differentiation, customer trust, employee confidence, fundamental-rights protection — are the same reasons they were on 6 May.

The deadline moved. The standard did not.

This article reflects the political agreement of 7 May 2026, as formally adopted by the European Parliament on 16 June 2026 and by the Council on 29 June 2026, and re-verified in early July 2026. The consolidated legal text is in its final legal-linguistic revision ahead of publication in the Official Journal; at this stage no further substantive changes are expected, though the exact publication date has not yet been confirmed. The article is for informational purposes and does not constitute legal advice.

Similar Posts