Skip to main content

Digital Omnibus on Artificial Intelligence

What is the Digital Omnibus for Artificial Intelligence?

The Digital Omnibus for Artificial Intelligence is part of the so-called Digital Package, which was presented by the European Commission (EC) in November 2025. The Digital Package encompasses several concurrent regulatory changes to European legislation governing data processing, cyber security and artificial intelligence systems within the EU. By reducing administrative burdens and simplifying certain procedures in the field of digital technologies, the EC aims to make it easier for businesses to ensure compliance and to reduce their administrative burdens by simplifying rules and streamlining procedures, thereby making the EU more competitive in the technology sector. It has proposed numerous amendments to existing European legal acts, including several amendments to the Artificial Intelligence Act.

The Digital Omnibus for Artificial Intelligence was adopted by the co-legislators on 8 July 2026, and the Regulation will enter into force on 27 July 2026.

You can read more about the Digital Omnibus on the European Commission’s website, under the heading ‘General Questions’: https://digital-strategy.ec.europa.eu/en/faqs/digital-package.

 

What key changes does the Digital Omnibus bring to artificial intelligence?

Some of the key changes to the AI Act introduced by the Digital Omnibus for AI are as follows:

New prohibited practices: Two new paragraphs have been added to Article 5 of the AI Act, prohibiting the placing on the market, the putting into service and the use of AI systems that generate intimate images of individuals without their explicit consent, and of AI systems that generate material depicting child sexual abuse. The prohibitions will come into force on 2 December 2026.

Change to the timetable for the entry into force of the provisions concerning obligations for high-risk AI systems: The entry into force of the provisions defining the legal framework for high-risk AI systems is postponed to 2027 or 2028. The rules for high-risk AI systems listed in Annex III will apply from 2 December 2027, whilst the rules for high-risk AI systems that are covered, as products or parts of products, by the sector-specific legislation set out in Annex I will now not apply until 2 August 2028.

Legal basis for the processing of sensitive data to address bias: The new Article 4a provides a legal basis for the processing of sensitive data for the purpose of addressing bias, provided that such processing is strictly necessary to address bias and that this objective cannot be achieved by processing anonymised or synthetic data, and subject to strict conditions.

Mechanism to limit the application of the AI Act in certain sectors: A legal mechanism has been introduced which will enable the Commission in certain cases, through implementing acts, to limit the scope of application of the AI Act in areas governed by sectoral legislation listed in Section A of Annex I. The mechanism is intended to eliminate overlaps in obligations where existing sectoral legislation already provides for specific rules for certain AI systems.

Amendment concerning machinery: Directive 2006/42/EC on machinery has been moved from Section A of Annex I to Section B of Annex I. Among other things, this means that for products covered by this Directive, certain obligations under the Artificial Intelligence Act will no longer apply. The European Commission will have to adopt delegated acts in this regard, which will separately supplement the level of protection for the safety and health of individuals.

Division of competences between the AI Office and national market surveillance authorities: The powers of the AI Office to supervise AI systems based on general-purpose AI models, where the same provider has developed both the system and the AI model on which the AI system is based, have been delimited. The AI Office will no longer be responsible for the AI systems listed in Annex I, AI systems used in the administration of justice; and AI systems used by authorities responsible for the prevention, detection and investigation of criminal offences, state border control authorities and financial institutions within the meaning of Article 74(6) of the AI Act. In the case of the exceptions listed, supervision will be carried out by the competent national authorities instead of the Office.

Labelling of synthetically generated content: Providers of AI systems, including general-purpose AI systems, which generate synthetic audio, visual, video or text content and were placed on the market before 2 August 2026, will be required to comply with the transparency obligations set out in Article 50(2) of the AI Act. However, this deferral does not apply to other transparency obligations (providers of AI systems that interact directly with natural persons, operators of AI systems that generate deepfakes, etc.)

The text of the Digital Omnibus for AI is available here.

 

What are the new key dates for the entry into force of the obligations under the Artificial Intelligence Act?

2 December 2026:

  • the new prohibitions in Articles 5(ba) and 5(bb) of the AI Act come into force;

  • providers of AI systems, including general-purpose AI systems, which generate synthetic audio, visual, video or text content and were placed on the market before 2 August 2026, must comply with the transparency obligations set out in Article 50(2) of the AI Act.

2 December 2027 – the obligations for high-risk AI systems listed in Annex III shall apply.

2 August 2028 – the obligations for high-risk AI systems covered by the sectoral legislation listed in Annex I shall apply.