From the journal

EU AI Omnibus Enters Into Force on 27 July 2026, Amending AI Act Timelines and SME Obligations

Regulation (EU) 2026/1744, the AI Omnibus, entered into force on 27 July 2026, amending the EU AI Act to extend compliance deadlines, expand regulatory sandbox access, and reduce administrative burdens for SMEs and small mid-cap companies. Annex III high-risk AI obligations shift to 2 December 2027; Annex I product-embedded systems to 2 August 2028. Core prohibitions and GPAI model rules are unchanged.

2 min read

Regulation (EU) 2026/1744, the AI Omnibus, entered into force on 27 July 2026. The Council and European Parliament adopted it on 19 November 2025, and the political agreement was reached on 7 May 2026. The Omnibus amends the EU Artificial Intelligence Act (Regulation (EU) 2024/1689) through the Commission's Digital Omnibus simplification agenda. It adjusts timelines and administrative requirements without altering the Act's risk-based structure, prohibitions on unacceptable-risk AI under Article 5, or GPAI model obligations under Chapter V.

The amendments modify Articles 9, 17, 18, 28, 43, and 50 of the AI Act, among others. Compliance obligations for high-risk AI systems listed in Annex III now apply from 2 December 2027. For high-risk AI systems embedded in regulated products under Annex I Union harmonisation legislation, including machinery, medical devices, and toys, the obligations apply from 2 August 2028. The machine-readable marking requirement under Article 50(2) carries a transitional period to 2 December 2026 for systems on the market before 7 May 2026.

SMEs and small mid-cap companies developing or deploying high-risk AI systems in the EU are the primary beneficiaries of the changes. The Omnibus extends to small mid-cap companies compliance reliefs previously reserved for micro and small enterprises, including lighter conformity assessment documentation and expanded sandbox access. A new EU-level regulatory sandbox provides a direct testing route for smaller AI developers before market release. Larger companies developing Annex III high-risk systems should use the extended timeline for compliance preparation rather than treat it as a deferral.

AI systems prohibited under Article 5 are unaffected by the Omnibus amendments. GPAI model obligations under Chapter V remain on their original schedule, with AI Office enforcement commencing on 2 August 2026. The Article 50(1) duty to disclose AI interaction to users took effect on 2 August 2026 with no grace period.

Licentium tracks EU AI Act and AI Omnibus developments for clients operating AI systems in the EU. Contact us to align your compliance roadmap with the revised deadlines. Work we undertake includes EU AI Act compliance roadmaps, regulatory sandbox applications, SME and small mid-cap compliance adaptation assessments, and GPAI model documentation support.

Source: European Commission, AI Omnibus enters into force, digital-strategy.ec.europa.eu, 27 July 2026

More from the journal

See all

UKJT Publishes Final Legal Statement on AI Liability Under English Private Law on 7 July 2026

The UK Jurisdiction Taskforce published its final Legal Statement on Liability for AI Harms under the private law of England and Wales on 7 July 2026, providing authoritative analysis of when English common law imposes liability for non-deliberate loss caused by AI systems. The statement covers negligence, product liability, contract, and strict liability doctrines as applied to increasingly autonomous AI deployments.

Senate Majority Leader Files Cloture on Digital Asset Market Clarity Act on 7 August 2026

On 7 August 2026, Senate Majority Leader John Thune filed a cloture motion on the motion to proceed to H.R. 3633, the Digital Asset Market Clarity Act (CLARITY Act), advancing the bill toward a Senate floor vote. The CLARITY Act passed the Senate Banking Committee 15-9 in May 2026 and would create a joint SEC-CFTC structure assigning CFTC jurisdiction over digital commodities and SEC jurisdiction over digital securities.

CNIL and CIANum Publish Exploratory Note on Agentic AI and Personal Data on 20 July 2026

On 20 July 2026, France's CNIL and the Conseil de l'IA et du Numerique (CIANum) jointly published an exploratory note on the GDPR risks raised by agentic AI systems. The note identifies how AI agents' autonomous cross-service data access, persistent memory retention, and capacity to act on users' behalf create tensions with GDPR purpose limitation, data minimisation, and controller identification rules under Articles 5, 24, and 28.