Regulation (EU) 2026/1744: What the Omnibus Defers and What It Does NOT
TL;DR
- Regulation (EU) 2026/1744, of 8 July 2026 ("Digital AI Omnibus"), was published in the OJEU Series L on 24 July 2026 and entered into force on 27 July 2026.
- It does not defer the AI Act. It defers Chapter III, Sections 1, 2 and 3 (high risk): to 2 December 2027 for Annex III and to 2 August 2028 for Annex I.
- 2 August 2026 still stands: among other things, the transparency obligations of Article 50 and Article 101.
- What was already binding remains binding: prohibited practices and AI literacy since 2 February 2025; Chapters V, VII and XII since 2 August 2025.
- The two new Article 5 prohibitions — non-consensual intimate material and child sexual abuse material — apply from 2 December 2026: all ten prohibitions now apply as a block.
- The transitional marking period under Article 111.4 expired on 2 December 2026: generative systems predating 2 August 2026 have no further grace period.
- The Omnibus left six duties with deadlines ranging from 1 August 2027 to 2 August 2030.
What exactly is Regulation (EU) 2026/1744?
It is a regulation that amends three others. Its official title: regulation "amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 as regards the simplification of the application of harmonised standards on artificial intelligence (Digital AI Omnibus)". It touches the AI Act, the aviation safety regulation and the Machinery Regulation. It does not replace any of them: it changes specific articles and amends dates.
Recital 2 explains the rationale: delays in drawing up technical standards and in establishing national governance frameworks "have given rise to a greater regulatory burden than expected". This is not a political U-turn, but an acknowledgement that the compliance infrastructure did not arrive in time.
It was adopted in Strasbourg on 8 July 2026. Article 4 provides that it "shall enter into force three days after its publication in the Official Journal of the European Union": published on 24 July, in force on 27 July 2026.
Is it true that the AI Act "is deferred to 2027"?
No. This is the most frequently repeated reading and it is false.
The deferral has a precise scope. The Omnibus replaces point (c) of the third paragraph of Article 113 of the AI Act, and the new wording states it applies to "Chapter III, Sections 1, 2 and 3, with the exception of Article 6(5)". Nothing more.
That block covers high-risk systems: classification rules (Articles 6 and 7), technical requirements (Articles 8 to 15) and obligations of providers and deployers (Articles 16 to 27). This is the most costly part to comply with, and it is what moves. Everything else keeps its original schedule — which is precisely what affects the average Spanish SME (small and medium-sized enterprise).
What is the canonical timeline after the Omnibus?
| AI Act block | Applicable from | Legal basis |
|---|---|---|
| Chapters I and II (definitions, AI literacy, prohibited practices) | 2 February 2025 | Art. 113, para. 3, point (a) |
| Article 5(1), points (b bis) and (b ter), and paragraphs 1a and 1b (new prohibitions) | 2 December 2026 | Art. 113, para. 3, point (a), new wording |
| Ch. III Section 4; Ch. V (general purpose); Ch. VII (governance); Ch. XII (sanctions); Art. 78 | 2 August 2025 (except Art. 101) | Art. 113, para. 3, point (b), unchanged |
| Articles 102–110 (amendments to sectoral legislation) | 27 July 2026 | Art. 113, para. 3, point (d), new |
| General rule: remainder of the Regulation, including Article 50 and Article 101 | 2 August 2026 | Art. 113, para. 2 |
| Marking of synthetic content in already-marketed systems | 2 December 2026 | Art. 111.4, new |
| Chapter III, Sections 1, 2 and 3 — high risk under Art. 6(2) and Annex III | 2 December 2027 | Art. 113, para. 3, point (c)(i) |
| Chapter III, Sections 1, 2 and 3 — high risk under Art. 6(1) and Annex I | 2 August 2028 | Art. 113, para. 3, point (c)(ii) |
| Designation of notified bodies | 28 January 2028 | Art. 43.3 |
| Legacy systems of public authorities | 2 August 2030 | Art. 111.2 |
Two nuances. First: the deferral covers Sections 1, 2 and 3 of Chapter III, but does not mention Sections 4 and 5 (notified bodies, harmonised standards, conformity assessment, CE marking and registration). Second: Article 6(5) — the Commission guidelines with practical examples of what is and is not high risk — is expressly excluded from the deferral.
Which obligations entered into force on 2 August 2026 regardless?
The one most people will notice is Article 50, transparency obligations. Paragraph 1 requires that systems intended to interact with people be designed "in such a way that the natural persons concerned are informed that they are interacting with an AI system". Paragraph 2 requires providers of systems that generate synthetic audio, image, video or text output to ensure outputs "are marked in a machine-readable format". Paragraph 4 requires the deployer to disclose publicly when content is a deepfake.
That article is not deferred, and non-compliance is expressly listed in Article 99(4)(g), with fines of up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher. The Omnibus does touch it, but only in paragraph 7: it transfers to the Commission — rather than the AI Office — the promotion of codes of practice and the power to adopt common standards by implementing act if those codes are deemed inadequate.
It is also worth recalling what was already binding: Article 5 prohibited practices have applied since February 2025, and the sanctions regime in Chapter XII since August 2025. For details on specific prohibited uses, see prohibited AI practices in Europe.
What new prohibitions does the Omnibus add?
This is the part that almost nobody is reporting and the most relevant for anyone deploying image or video generation.
Point 7 of Article 1 of the Omnibus inserts two new points into Article 5(1), first subparagraph:
- (b bis): prohibits "the placing on the market, putting into service or use of an AI system that generates or manipulates realistic images, videos or audio or similar material of the intimate parts of an identifiable natural person, or of an identifiable natural person engaged in sexually explicit activities, without the free, specific, informed and unambiguous explicit consent of that person for such generation or manipulation".
- (b ter): prohibits the generation or manipulation of "material or performances within the meaning of Article 2(c) and (e) of Directive 2011/93/EU" — i.e., child sexual abuse material — "except where an 'unlawful conduct' defence applies under national law".
Paragraphs 1a and 1b are also added, delimiting when the infringement is deemed committed. For providers, the prohibition only operates when that generation is the system's intended purpose, or when it is "a reasonably foreseeable and reproducible outcome, without requiring substantial technical modifications" and the system lacks reasonable technical safety measures. For deployers, only when they use the system with that intent. Recital 84 names the phenomenon without euphemism: "The proliferation of these technologies, often described as 'nudification' applications, has generated an urgent need for an explicit regulatory prohibition".
Date of application: 2 December 2026.
Article 5 prohibitions are no longer eight: they are ten. Infringement is penalised under Article 99(3) with up to €35,000,000 or 7% of worldwide annual turnover.
What happens to generative systems already on the market?
There is a date being overlooked. The Omnibus adds paragraph 4 to Article 111:
"4. Providers of AI systems, including general-purpose AI systems, that generate synthetic audio, image, video or text content and have been placed on the market before 2 August 2026 shall take the necessary measures to comply with Article 50(2) by no later than 2 December 2026."
If your product is already on the market and generates synthetic content, your deadline for machine-readable marking is not 2 August 2026 but 2 December. A four-month extension, not an exemption.
What does the Omnibus change in favour of SMEs?
| Change | Before | After the Omnibus |
|---|---|---|
| Simplified quality management (Art. 63.1) | Microenterprises only | All SMEs, where they have no associated or linked enterprises |
| Technical documentation (Art. 11.1) | Full Annex IV | Simplified form that notified bodies must accept |
| Proportionality (Art. 17.2) | Generic reference to size | Explicit mention of SMEs and small mid-cap companies |
| Fines (Art. 99, new 6a) | Reduced cap only for SMEs | Extended to small mid-cap companies |
| Definitions (Art. 3) | No standalone SME definition | New points 14a (SME) and 14b (small mid-cap company) |
Article 4 (AI literacy) is also rewritten with a new sentence that reduces pressure: "This obligation does not require providers or deployers to ensure a specific level of AI literacy of any particular person." The training duty has been live since February 2025; what is clarified is that there is no certifiable bar per employee.
Other novelties the Omnibus brings that almost nobody is reporting
New Article 4a. Allows "exceptionally" processing special categories of personal data to detect and correct bias, subject to six cumulative conditions: synthetic or anonymised data being insufficient; pseudonymisation and technical re-use limits; access controls and documentation; prohibition on transfer to third parties; deletion once bias is corrected; and a record of why it was strictly necessary.
New Annex XIV. The AI Act goes from thirteen annexes to fourteen. The new one contains the designation codes for notified bodies: AIP for Annex I systems, AIB for Annex III biometrics and AIH by technology. Worth reading code AIH 0401: "AI systems based on other emerging AI technologies not covered by other codes, including agentic AI". This is the first time an official EU list names agentic AI.
Article 6, new paragraphs 1a, 1b and 1c. Clarify what is not a safety component: systems used "solely for aspects not related to safety in the domains of user assistance, performance optimisation, service efficiency, automation, comfort or quality control". Except, says paragraph 1b, where their failure could endanger health and safety.
Article 42, new paragraph 3. If a high-risk system falls within the scope of Regulation (EU) 2024/2847 (Cyber Resilience Act) and complies with its Article 12(1), compliance with the cybersecurity requirements of Article 15 is presumed.
Article 75. The AI Office acquires "exclusive competence" over systems based on general-purpose models developed by the same provider and over those integrated in very large online platforms and search engines designated under Regulation (EU) 2022/2065. And Article 57.1: each Member State must have an operational national testing sandbox "by no later than 2 August 2027".
What happened on 2 December 2026
That day two distinct things occurred, with different addressees and consequences.
First: points (b bis) and (b ter) of Article 5(1) and paragraphs 1a and 1b became applicable, by virtue of the new wording of Article 113, third paragraph, point (a). Since then all ten Article 5 prohibitions apply as a block.
Second: the deadline in Article 111(4), added by point 39 of the Omnibus, expired. Providers of AI systems — including general-purpose ones — generating synthetic audio, image, video or text content placed on the market before 2 August 2026 had until 2 December to comply with Article 50(2). From 3 December 2026 the machine-readable marking requirement applies equally to new and legacy systems.
The Omnibus is applicable law, but part of its relief has not yet bitten
All the Omnibus amendments are applicable law since 27 July 2026: nothing in the text remains pending "entry into force". Quite another question is when they have practical effect, because several relieve obligations that are not yet enforceable.
| Omnibus change | Where it lives in the AI Act | When it actually starts operating |
|---|---|---|
| Simplified technical documentation (Art. 11.1) | Chapter III, Section 2 | With Chapter III: 2 Dec 2027 (Annex III) or 2 Aug 2028 (Annex I) |
| Proportionality for SMEs and mid-caps (Art. 17.2) | Chapter III, Section 3 | With Chapter III, same dates |
| Simplified quality management for all SMEs (Art. 63.1) | Chapter VI | Applicable now, but exempts from an Art. 17 not yet enforceable |
| Presumption of conformity in cybersecurity (Art. 42.3) | Chapter III, Section 5 | Applicable from 2 Aug 2026: Section 5 was not deferred |
| Extended fine cap to mid-caps (Art. 99, new 6a) | Chapter XII | Applicable from 2 Aug 2025 |
| Exclusive competence of the AI Office (Art. 75) | Chapter IX | Applicable from 2 Aug 2026 |
The counterintuitive consequence: much of the relief the Omnibus granted to SMEs rests on Chapter III requirements not enforceable until late 2027, so it does not relieve any real burden today. What does operate now is the sanctions block, governance, and Sections 4 and 5 of Chapter III, which fell outside the deferral.
The six duties the Omnibus left with deadlines
| Pending duty | Who it binds | Deadline | Legal basis |
|---|---|---|---|
| Guidelines on practical application of Arts. 8(2), 9(10) and 17(3) to avoid duplication with Annex I, Section A | European Commission | 1 August 2027 | Art. 96.1, new point (g) |
| At least one national AI testing sandbox, operational | Each Member State | 2 August 2027 | Art. 57.1, 1st para. |
| Guidance, including a template, on the post-market monitoring plan | European Commission | 2 September 2027 | Art. 72.3 |
| Apply for designation under Chapter III, Section 4 | Notified bodies already notified under Annex I, Section A | 28 January 2028 | Art. 43.3 |
| Delegated acts adding AI health and safety requirements to Machinery Regulation Annex III | European Commission | By 2 August 2028 | Art. 3, pt. 1 of the Omnibus, on Art. 8 of Reg. (EU) 2023/1230 |
| Comply with requirements and obligations for legacy high-risk systems intended for public authorities | Providers and deployers | 2 August 2030 | Art. 111.2 |
What to review in early 2027
- Close the marking file. For each generative system the company provides, document when the output marking was deployed and by what method. If the system predates 2 August 2026, the file must show marking was operational before 2 December 2026.
- Ask your notified body in writing whether it will apply for Chapter III, Section 4 designation before 28 January 2028 and keep the reply. If not, there is a year and a half to find an alternative.
- Reclassify the system inventory between Annex III (Chapter III from 2 December 2027) and Annex I (from 2 August 2028): the documentary relief of Articles 11.1 and 17.2 activates with those dates, not before.
- Note the three 2027 dates — 1 August, 2 August and 2 September — as review points, not your own deliverables: they are duties of the Commission and of the Member State in which you operate whose delay does not exempt anyone but does change what material is available to work with.
- Follow the marking codes of practice that are published. Adhering is not mandatory, but a code evaluated as adequate is today the most solid route to demonstrating compliance with Article 50(2).
What should a Spanish SME do heading into 2027?
- Inventory what AI systems the company uses and in what role it acts in each: provider, deployer or both. The obligations regime changes by role.
- Review Article 5. It has been in force for over a year and carries the heaviest penalties. Also review the two new points if you generate or manipulate images of people.
- Article 50 transparency was covered on 2 August 2026 — interaction notices, synthetic content marking and deepfake disclosure — and Article 50(2) marking expired on 2 December 2026: check it against the marking section above.
- Document AI literacy for staff who operate AI systems. Obligation live since February 2025.
- Do not relax on high risk. December 2027 seems far away, but the conformity assessment of an Annex III system cannot be improvised in a quarter.
Frequently asked questions
Does the Omnibus defer the entire AI Act to 2027?
No. Only Chapter III, Sections 1 to 3, with two dates: 2 December 2027 (Annex III) and 2 August 2028 (Annex I). The general rule of 2 August 2026 remains intact.
Is the obligation to disclose that a chatbot is an AI deferred?
No. It is in Article 50(1), Chapter IV, which enters into force on 2 August 2026 under the general rule.
Do the prohibited practices still apply?
Yes, since 2 February 2025, and since 2 December 2026 two new ones have been added. Full catalogue at prohibited AI practices in Europe.
My image generation tool was already on the market in 2025. When must I mark outputs?
By no later than 2 December 2026, under the new Article 111(4). If the system is introduced from 2 August 2026 onwards, Article 50(2) applies from that date.
Who enforces this in Spain?
The market surveillance authorities designated under Article 70, with Chapter XII applicable since 2 August 2025. The actual state of Spanish supervision is covered in AI sandbox in Spain: how your company can participate.
Do I need a notified body if my system is not high risk?
No. Third-party conformity assessment only arises for certain high-risk systems. Most AI uses in an SME fall outside Chapter III and only carry transparency and literacy obligations.
Is anything in the Omnibus still to enter into force?
No. Regulation (EU) 2026/1744 entered into force on 27 July 2026 and all its provisions are applicable law from that date. What is pending is not entry into force but the deferred effects — the last being the new prohibitions, which activated on 2 December 2026 — and the timed mandates it created for the Commission, Member States and notified bodies, running until 2 August 2030.
Does the high-risk deferral still stand after 2 December?
Yes. 2 December only affected Article 5 and the Article 111(4) transitional period. The deferral of Chapter III, Sections 1, 2 and 3 keeps its two dates: 2 December 2027 for Article 6(2) and Annex III, and 2 August 2028 for Article 6(1) and Annex I. Sections 4 and 5 and Article 6(5) are outside the deferral and applicable from 2 August 2026.
Is there an official standard yet for marking synthetic content?
As of 16 December 2026, none. The new wording of Article 50(7) commissions codes of practice first and only foresees an implementing act with common standards if the Commission deems the code inadequate. Until that happens there is no single mandatory format or official list of compliant software: each provider chooses its method and documents it.
What if a generative system missed the 2 December deadline?
Article 111(4) provides no further grace or transitional period: past that date, non-compliance with Article 50(2) is sanctionable under Article 99(4)(g). The prudent course is to document when marking was implemented, why it was late and what was done about it: when setting the amount, Article 99(7) requires all relevant circumstances to be taken into account, including the duration of the infringement (point (a)) and actions taken to mitigate harm (point (j)).
Sources
- Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 (Digital AI Omnibus). OJEU Series L, 24 July 2026. CELEX 32026R1744.
- Regulation (EU) 2024/1689 (AI Act) of 13 June 2024. OJEU L, 12 July 2024. ELI: https://eur-lex.europa.eu/eli/reg/2024/1689/oj. Articles 5, 6, 11, 17, 50, 63, 99, 111 and 113; Annexes I, III and IV.
- Directive 2011/93/EU of 13 December 2011 on combating the sexual abuse and sexual exploitation of children. ELI: http://data.europa.eu/eli/dir/2011/93/oj.
- Regulation (EU) 2023/1230 of 14 June 2023 on machinery. ELI: http://data.europa.eu/eli/reg/2023/1230/oj.
- Regulation (EU) 2024/2847 (Cyber Resilience Act), cited by the new Article 42(3) of the AI Act.
- Recommendation 2003/361/EC (SME definition) and Recommendation (EU) 2025/1099 (small mid-cap companies), incorporated as points 14a and 14b of Article 3.
Citations verified against the Spanish-language OJEU text. Informational content; not a substitute for legal advice.