On 24 July 2026, the European Union’s Digital Omnibus on AI was published in the Official Journal of the EU (the “AI Digital Omnibus”).[1] The agreed text makes targeted amendments to the EU AI Act (the “AI Act”) to streamline certain requirements and provide a further grace period for compliance with certain obligations. The final text of the AI Digital Omnibus has also coincided with new draft guidelines from the European Commission (the “Commission”) on the classification of high-risk AI systems under Article 6 of the AI Act (the “Classification Guidelines”)[2] and the transparency obligations applicable under Article 50 of the AI Act (the “Transparency Guidelines”).[3]

This alert summarises the main changes agreed in the AI Digital Omnibus compared to the Commission’s original November 2025 proposal[4] and highlights key practical considerations for businesses developing or deploying AI.

Key Takeaways

  1. New timelines for high-risk AI systems. The compliance deadline for compliance with obligations relating to high-risk AI systems has been pushed back to 2 December 2027 for Annex III systems (i.e., high risk sectoral activities) and 2 August 2028 for AI systems that are, or are safety components of, Annex I regulated products. The intention is now for the Classification Guidelines and additional standards to be finalised to enable the AI value chain to be able to properly implement high-risk compliance obligations.
  2. New prohibitions on child sexual abuse material and non-consensual intimate material. From 2 December 2026, a new Article 5 prohibition will apply to AI systems generating child sexual abuse material (“CSAM”) or non-consensual intimate material. The prohibition extends beyond purpose-built “nudifier” applications to providers of general-purpose generative AI that fail to put in place reasonable safeguards. Providers of generative image, video and audio models should prioritise training data filtering, input and output classifiers and content moderation.
  3. Classification is about substance, not presentation. Pursuant to the draft guidance, providers of multi-purpose AI systems, including for example LLM APIs and agentic platforms, should ensure that technical documentation, marketing materials and contractual terms consistently exclude high-risk use cases, otherwise their systems will be in scope of the higher high-risk duties under the AI Act. For AI systems that are, or are safety components of, regulated products, realistic failure modes (not just their stated purpose) can also trigger high-risk classification – providers of these AI systems should consider how to implement guardrails against those failure modes.

Agreed Amendments to the AI Act Under the AI Digital Omnibus

  1. Fixed timelines for compliance with high-risk AI obligations. The AI Digital Omnibus confirms new, but fixed, application dates of 2 December 2027 for compliance for Annex III high-risk AI systems (e.g., recruitment, emotion recognition, credit scoring) and 2 August 2028 for Annex I products, or safety components of products, that are regulated under certain EU product safety laws (e.g., toys, medical devices, machinery, vehicles). The Commission’s standards-linked conditional mechanism has been dropped in favour of fixed dates, giving businesses greater certainty but leaving deadlines to apply regardless of whether harmonised standards are ready.
  2. New prohibitions on AI systems generating CSAM and non-consensual intimate material. The AI Digital Omnibus also introduces a new prohibited practice for AI systems where generation of CSAM or non-consensual sexual or intimate material is the intended purpose (i.e., “nudifier” applications), as well, systems where such generation is a reasonably foreseeable and reproducible outcome and for which the provider has not implemented reasonable and adequate safety measures will be prohibited. These practices must have ceased by 2 December 2026. The amendment comes during a period of acute regulatory and enforcement focus, with the Commission, the UK ICO, Ofcom and the Irish DPC each opening formal investigations in connection with AI-generated sexualised images such as those generated by X’s Grok tool. Providers of generative image, video and audio models should revisit safeguards, including those discussed in the Recitals to the AI Digital Omnibus, such as training data filtering, refusal training, input and output classifiers, prompt moderation and output-stage content review.
  3. No delay to transparency obligations. The Article 50 transparency obligations will come into effect on 2 August 2026 as planned, subject only to a limited deferral for the machine-readable watermarking obligations until 2 December 2026 for providers of generative AI systems already on the market before 2 August 2026. Organisations running chatbots or generating AI content at scale should prioritise Article 50 compliance now. The Commission’s voluntary Code of Practice on Transparency of AI-Generated Content was published on 10 June 2026[5] and the Transparency Guidelines were published on 20 July 2026.[6]
  4. Reduced overlap between the AI Act and sectoral product safety legislation. The AI Act will not apply directly to machinery, instead the Commission will adopt delegated acts adding health and safety requirements for high-risk AI systems that are machinery (or safety components of machinery) by 2 August 2028. The Commission will also adopt delegated acts (by 2 August 2027) to disapply AI Act high-risk requirements where equivalent AI-specific obligations already apply at an equivalent or higher level under sectoral laws. Businesses should reassess AI Act compliance workstreams against sectoral programmes once the delegated acts are adopted.
  5. Expanded bias detection for processing special-category data. In line with the Commission’s original proposal, deployers of AI systems will now be able to take advantage of the permission currently reserved solely for providers to process special-category personal data for bias detection and correction, subject to strict conditions. Processing must be strictly necessary and must not be achievable by other means, including through synthetic or anonymised data. The data must not be transmitted, transferred or otherwise accessed by third parties, appropriate technical and organisational security and access controls must be in place, and records must explain why processing was strictly necessary and why the objective could not be achieved otherwise.
  6. Registration requirements retained for all AI systems. The Council and Parliament have retained simplified registration requirements for non-high-risk AI systems. This reverses the Commission’s proposal to remove that obligation for non-high-risk AI systems (for example, used for narrow procedural or preparatory tasks) following pushback from the European Data Protection Board and European Data Protection Supervisor.
  7. AI literacy. Contrary to the Commission’s original proposal, providers and deployers of AI systems remain subject to a softer, means-based duty to support AI literacy. Businesses should document the measures taken, maintain training records and link literacy initiatives to the AI systems used by the business.
  8. Other simplification and pro-innovation measures. In line with the Commission’s original proposal, the final agreed amendments also include: (i) removal of the requirement to rely on Commission templates for the preparation of post-market monitoring plans; (ii) expansion of the regulatory sandbox regime to provide for EU-level regulatory sandboxes for certain AI systems and extending the regulatory sandbox regime to cover high-risk systems covered by Annex I, section A of the AI Act; and (iii) extending regulatory simplifications (e.g., simplified technical documentation requirements and special consideration regarding penalties) to small mid-caps that were previously available only to SMEs.

Commission Guidelines on High-Risk AI Systems and Transparency

  1. Transparency Guidelines complement Code of Practice. The Transparency Guidelines were published on 20 July 2026 and seek to give practical guidance to: (i) providers of AI systems regarding their AI Act obligations to tell users when they are interacting directly with AI and to mark AI-generated or manipulated synthetic content; and (ii) deployers regarding their AI Act obligations to disclose emotion recognition, biometric categorisation, deepfake and AI-generated public-interest text systems. For AI interacting with people, the “obviousness” exception will be judged in context against the average consumer standard drawn from EU consumer protection law. Disclosures buried in terms and conditions, manuals or layered menu options are unlikely to suffice and sustained or sensitive interactions may need persistent reminders. For AI-generated content, no single technique is likely to satisfy all of the required marking criteria for verifying origin – as such, compliant solutions will need to combine a range of possible techniques (such as visible content labelling and machine-readable metadata).
  2. Two routes to high-risk classification. The Classification Guidelines provide guidance based on the two types of high-risk AI system identified in the AI Act.
    1. AI as a product or safety component. In relation to those AI systems that qualify as high-risk under the AI Act as Annex I products, or a safety component of an Annex I product, the Classification Guidelines clarify that: (i) a system may qualify as a safety component where it is intended to fulfil a safety function (i.e., to mitigate risks to health and safety of people or property) or where its failure or malfunction would in practice endanger health, safety or property, even if the intention of that component is not to act as a safety function; and (ii) labels such as “performance optimiser” or “user experience enhancement” will not avoid high-risk classification where a realistic failure mode creates a genuine physical hazard.
    2. Annex III use cases and the Article 6(3) filter. The Classification Guidelines provide further clarity on the scope of Annex III high-risk AI systems and provide examples of uses that may fall outside high-risk classification, such as administrative recruitment tools that do not limit access to employment opportunities or cause discrimination, and biometric use to confirm a person is who they claim to be (e.g., Face ID). This is a detailed assessment on a use-by-use case basis and more commentary will follow once the final guidelines are produced. However, the Classification Guidelines are clear that real-time identification of individuals in public spaces will generally remain high-risk. In relation to the Article 6(3) filter that allows providers to self-certify an Annex III system as not high-risk if it does not pose a significant risk of harm to health, safety or fundamental rights and meets one of the four filter conditions (performing only a narrow procedural task; improving the result of previously completed human activity; detecting decision-making patterns or deviations, provided the analysis does not replace or influence prior human assessment without proper review; or performing a preparatory task to an Annex III assessment), the Classification Guidelines confirm that the exception is narrow. Systems used for profiling cannot rely on that exception and agentic AI systems cannot use the benefit where the combined system does not meet the exception (even if individual elements do), because the agentic AI will be viewed as a whole. Providers relying on the filter must document the assessment and register the system in the EU database.
    3. Blanket prohibited-use clauses in T&Cs do not avoid high-risk classification. Intended purpose is central to classification and will be tested by reference to how the system is actually positioned, not only how the provider describes it. If product documentation, API examples or marketing materials make high-risk uses feasible and reasonably foreseeable, a blanket “prohibited-use clause” in terms of service will not be sufficient to avoid high-risk classification: high-risk uses must be “clearly, concretely and coherently” excluded across all materials. Businesses that configure or fine-tune a general-purpose AI model for an Annex III use case that effectively give the system a new intended purpose, or who own-brand a high-risk AI system, should also note that they may become the provider of a high-risk AI system, with the full set of obligations that follow. Separate Commission guidelines on responsibility along the AI value chain are expected in the second or third quarter of 2026.

Comment

The AI Digital Omnibus delivers welcome certainty on timing (and an additional grace period) for high-risk AI obligations under the AI Act. However, other than the new prohibited practice for nudifier-style applications (which comes as no surprise given the advancements in AI capabilities and regulatory scrutiny), the AI Digital Omnibus otherwise provides few meaningful amendments to the AI Act. Read alongside the draft Classification Guidelines and Transparency Guidelines, the amendments are more limited than some businesses may have hoped (including, for example, the Commission’s proposal to remove the obligation to register Annex III systems that providers self-assess as not high-risk under Article 6(3), which the co-legislators did not adopt) and indeed, the new prohibited practice and proposals under the draft guidelines for more scrutiny of agentic AI systems as a whole and proactive monitoring of terms and conditions and other public literature appear to push increased liability risk onto technology companies and their investors. For now, and pending the final text of the Classification Guidelines, AI developers and deployers should treat the package as a modest delay and clarification for high-risk activities, but not a relaxation of the road to full AI Act implementation.

* * *

[1]Available here: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ:L_202601744.

[2]Available here: https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems

[3]Available here: https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems

[4] The Commission’s original proposal is available here: https://digital-strategy.ec.europa.eu/en/library/digital-omnibus-ai-regulation-proposal. For Paul, Weiss commentary on the original proposal, see our client alert of 10 December 2025: An Uncertain Journey on the Digital Omnibus: European Commission Takes Business-Friendly Step for Digital Regulation, available here (which also covers separate amendments to other EU digital regulations such as the GDPR which is undergoing a separate legislative process): https://www.paulweiss.com/insights/client-memos/an-uncertain-journey-on-the-digital-omnibus-european-commission-takes-business-friendly-step-for-digital-regulation

[5] Available here: https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content.

[6] Available here: https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems.