The European Union published Regulation (EU) 2026/1744, the Digital Omnibus on AI, in the Official Journal on 24 July 2026, resetting the compliance calendar of the AI Act (Regulation (EU) 2024/1689). The measure defers the high-risk obligations, amends Regulations (EU) 2018/1139 and (EU) 2023/1230, and extends the Article 5 prohibitions to AI systems that generate intimate imagery produced against a person's consent and to child sexual abuse material. It binds every provider and deployer operating within the single market.
What the regulation changes
Regulation (EU) 2026/1744 carries the formal purpose of simplifying the harmonised rules on artificial intelligence. It rewrites the AI Act across several load-bearing provisions, and the headline shift concerns timing. Obligations for stand-alone high-risk systems listed in Annex III move from 2 August 2026 to 2 December 2027, a sixteen-month deferral. Obligations for high-risk systems embedded in regulated products under Annex I move from 2 August 2027 to 2 August 2028, a twelve-month extension. The Commission frames the recalibration as alignment with the maturity of harmonised standards and the readiness of conformity-assessment infrastructure across Member States. The Digital Omnibus bundles these AI Act revisions with parallel adjustments to aviation-safety Regulation (EU) 2018/1139 and machinery Regulation (EU) 2023/1230, aligning three product-safety regimes onto one coherent timeline.
The regulation adds a fresh prohibited practice to the top tier of the risk pyramid. The amended Article 5 bars AI systems that generate or manipulate intimate images, video, and audio depicting a person absent that person's consent, alongside child sexual abuse material. The prohibition reaches providers even where such output falls outside the declared intended purpose, provided generation represents a reasonably foreseeable and reproducible outcome achievable absent significant technical modification. This drafting captures general-purpose image and video generators, the "nudifier" applications that data-protection authorities across Europe have repeatedly flagged as an enforcement priority. The scope decision matters for foundation-model providers, whose systems can produce such content across a broad prompt space, placing the compliance burden at the model layer rather than downstream.
Who must act and by when
The deferral attaches to high-risk classification alone. Transparency duties advance on the original schedule. Article 50 obligations, disclosure of AI interaction, machine-generated content, deepfakes, and emotion-recognition or biometric-categorisation systems, take effect on 2 August 2026. Providers placing generative systems on the market before that date receive a four-month grace window for the Article 50(2) marking-and-detection requirement, a window that closes on 2 December 2026. This split creates a two-speed compliance reality: labelling and disclosure duties bind within weeks, while classification-driven engineering work gains breathing room.
The new Article 5 prohibition carries a transitional period ending 2 December 2026, granting providers a defined runway to withdraw or re-engineer capabilities that yield prohibited output. From that date, enforcement engages the AI Act's most severe sanction tier: administrative fines reaching €35 million or 7% of total worldwide annual turnover, whichever proves higher. National market-surveillance authorities and the European AI Office share jurisdiction over these penalties, and the ceiling applies per infringement. The elevated ceiling signals the co-legislators' treatment of synthetic sexual-abuse content as a red-line practice, on par with social scoring and untargeted facial-recognition scraping.
Affected entities span the full value chain. The obligations reach providers of general-purpose AI models, developers of high-risk classified systems, deployers integrating third-party models into regulated products, and distributors placing image and video generation tools on the European market. Importers channelling third-country models into the market inherit verification duties equivalent to those of domestic providers. The regulation also refines the Article 4 AI-literacy duty and the Article 57 regulatory-sandbox regime, and it permits processing of special-category personal data where necessary for detecting and mitigating bias in AI models, a targeted opening within the GDPR framework that unlocks fairness testing previously constrained by data-minimisation limits.
The board-level decision
Directors gain engineering runway alongside a sharper prohibition, and the two developments demand a single coordinated response. The governance milestone centres on a documented re-baselining of the AI compliance roadmap against the revised anchor dates. Boards should direct the general counsel and chief risk officer to reclassify every inventoried system, confirming which fall under Annex III (December 2027), Annex I (August 2028), or the transparency regime that binds from August 2026. The exercise carries a second mandate: an audit of every deployed or procured generative capability against the expanded Article 5 prohibition, completed ahead of the 2 December 2026 transitional deadline. Organisations that rely on third-party foundation models should secure contractual warranties confirming the model provider has assessed reasonably foreseeable prohibited outputs and has controls in place. The deferral converts into value where directors reinvest the recovered time in robust conformity documentation, treating it as an opportunity. The prohibition, by contrast, demands immediate legal attention. Both belong on the next board agenda as one dated, owner-assigned action item, with progress reported to the audit committee each quarter through 2027.
Article by ATLASGovernance & Compliance
ATLAS covers AI regulation from primary legal sources. Every obligation cited to the official document.