Regulation (EU) 2026/1744: What the Omnibus Defers and What It Does NOT

TL;DR

What exactly is Regulation (EU) 2026/1744?

It is a regulation that amends three others. Its official title: regulation "amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 as regards the simplification of the application of harmonised standards on artificial intelligence (Digital AI Omnibus)". It touches the AI Act, the aviation safety regulation and the Machinery Regulation. It does not replace any of them: it changes specific articles and amends dates.

Recital 2 explains the rationale: delays in drawing up technical standards and in establishing national governance frameworks "have given rise to a greater regulatory burden than expected". This is not a political U-turn, but an acknowledgement that the compliance infrastructure did not arrive in time.

It was adopted in Strasbourg on 8 July 2026. Article 4 provides that it "shall enter into force three days after its publication in the Official Journal of the European Union": published on 24 July, in force on 27 July 2026.

Is it true that the AI Act "is deferred to 2027"?

No. This is the most frequently repeated reading and it is false.

The deferral has a precise scope. The Omnibus replaces point (c) of the third paragraph of Article 113 of the AI Act, and the new wording states it applies to "Chapter III, Sections 1, 2 and 3, with the exception of Article 6(5)". Nothing more.

That block covers high-risk systems: classification rules (Articles 6 and 7), technical requirements (Articles 8 to 15) and obligations of providers and deployers (Articles 16 to 27). This is the most costly part to comply with, and it is what moves. Everything else keeps its original schedule — which is precisely what affects the average Spanish SME (small and medium-sized enterprise).

What is the canonical timeline after the Omnibus?

AI Act blockApplicable fromLegal basis
Chapters I and II (definitions, AI literacy, prohibited practices)2 February 2025Art. 113, para. 3, point (a)
Article 5(1), points (b bis) and (b ter), and paragraphs 1a and 1b (new prohibitions)2 December 2026Art. 113, para. 3, point (a), new wording
Ch. III Section 4; Ch. V (general purpose); Ch. VII (governance); Ch. XII (sanctions); Art. 782 August 2025 (except Art. 101)Art. 113, para. 3, point (b), unchanged
Articles 102–110 (amendments to sectoral legislation)27 July 2026Art. 113, para. 3, point (d), new
General rule: remainder of the Regulation, including Article 50 and Article 1012 August 2026Art. 113, para. 2
Marking of synthetic content in already-marketed systems2 December 2026Art. 111.4, new
Chapter III, Sections 1, 2 and 3 — high risk under Art. 6(2) and Annex III2 December 2027Art. 113, para. 3, point (c)(i)
Chapter III, Sections 1, 2 and 3 — high risk under Art. 6(1) and Annex I2 August 2028Art. 113, para. 3, point (c)(ii)
Designation of notified bodies28 January 2028Art. 43.3
Legacy systems of public authorities2 August 2030Art. 111.2

Two nuances. First: the deferral covers Sections 1, 2 and 3 of Chapter III, but does not mention Sections 4 and 5 (notified bodies, harmonised standards, conformity assessment, CE marking and registration). Second: Article 6(5) — the Commission guidelines with practical examples of what is and is not high risk — is expressly excluded from the deferral.

Which obligations entered into force on 2 August 2026 regardless?

The one most people will notice is Article 50, transparency obligations. Paragraph 1 requires that systems intended to interact with people be designed "in such a way that the natural persons concerned are informed that they are interacting with an AI system". Paragraph 2 requires providers of systems that generate synthetic audio, image, video or text output to ensure outputs "are marked in a machine-readable format". Paragraph 4 requires the deployer to disclose publicly when content is a deepfake.

That article is not deferred, and non-compliance is expressly listed in Article 99(4)(g), with fines of up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher. The Omnibus does touch it, but only in paragraph 7: it transfers to the Commission — rather than the AI Office — the promotion of codes of practice and the power to adopt common standards by implementing act if those codes are deemed inadequate.

It is also worth recalling what was already binding: Article 5 prohibited practices have applied since February 2025, and the sanctions regime in Chapter XII since August 2025. For details on specific prohibited uses, see prohibited AI practices in Europe.

What new prohibitions does the Omnibus add?

This is the part that almost nobody is reporting and the most relevant for anyone deploying image or video generation.

Point 7 of Article 1 of the Omnibus inserts two new points into Article 5(1), first subparagraph:

Paragraphs 1a and 1b are also added, delimiting when the infringement is deemed committed. For providers, the prohibition only operates when that generation is the system's intended purpose, or when it is "a reasonably foreseeable and reproducible outcome, without requiring substantial technical modifications" and the system lacks reasonable technical safety measures. For deployers, only when they use the system with that intent. Recital 84 names the phenomenon without euphemism: "The proliferation of these technologies, often described as 'nudification' applications, has generated an urgent need for an explicit regulatory prohibition".

Date of application: 2 December 2026.

Article 5 prohibitions are no longer eight: they are ten. Infringement is penalised under Article 99(3) with up to €35,000,000 or 7% of worldwide annual turnover.

What happens to generative systems already on the market?

There is a date being overlooked. The Omnibus adds paragraph 4 to Article 111:

"4. Providers of AI systems, including general-purpose AI systems, that generate synthetic audio, image, video or text content and have been placed on the market before 2 August 2026 shall take the necessary measures to comply with Article 50(2) by no later than 2 December 2026."

If your product is already on the market and generates synthetic content, your deadline for machine-readable marking is not 2 August 2026 but 2 December. A four-month extension, not an exemption.

What does the Omnibus change in favour of SMEs?

ChangeBeforeAfter the Omnibus
Simplified quality management (Art. 63.1)Microenterprises onlyAll SMEs, where they have no associated or linked enterprises
Technical documentation (Art. 11.1)Full Annex IVSimplified form that notified bodies must accept
Proportionality (Art. 17.2)Generic reference to sizeExplicit mention of SMEs and small mid-cap companies
Fines (Art. 99, new 6a)Reduced cap only for SMEsExtended to small mid-cap companies
Definitions (Art. 3)No standalone SME definitionNew points 14a (SME) and 14b (small mid-cap company)

Article 4 (AI literacy) is also rewritten with a new sentence that reduces pressure: "This obligation does not require providers or deployers to ensure a specific level of AI literacy of any particular person." The training duty has been live since February 2025; what is clarified is that there is no certifiable bar per employee.

Other novelties the Omnibus brings that almost nobody is reporting

New Article 4a. Allows "exceptionally" processing special categories of personal data to detect and correct bias, subject to six cumulative conditions: synthetic or anonymised data being insufficient; pseudonymisation and technical re-use limits; access controls and documentation; prohibition on transfer to third parties; deletion once bias is corrected; and a record of why it was strictly necessary.

New Annex XIV. The AI Act goes from thirteen annexes to fourteen. The new one contains the designation codes for notified bodies: AIP for Annex I systems, AIB for Annex III biometrics and AIH by technology. Worth reading code AIH 0401: "AI systems based on other emerging AI technologies not covered by other codes, including agentic AI". This is the first time an official EU list names agentic AI.

Article 6, new paragraphs 1a, 1b and 1c. Clarify what is not a safety component: systems used "solely for aspects not related to safety in the domains of user assistance, performance optimisation, service efficiency, automation, comfort or quality control". Except, says paragraph 1b, where their failure could endanger health and safety.

Article 42, new paragraph 3. If a high-risk system falls within the scope of Regulation (EU) 2024/2847 (Cyber Resilience Act) and complies with its Article 12(1), compliance with the cybersecurity requirements of Article 15 is presumed.

Article 75. The AI Office acquires "exclusive competence" over systems based on general-purpose models developed by the same provider and over those integrated in very large online platforms and search engines designated under Regulation (EU) 2022/2065. And Article 57.1: each Member State must have an operational national testing sandbox "by no later than 2 August 2027".

What happened on 2 December 2026

That day two distinct things occurred, with different addressees and consequences.

First: points (b bis) and (b ter) of Article 5(1) and paragraphs 1a and 1b became applicable, by virtue of the new wording of Article 113, third paragraph, point (a). Since then all ten Article 5 prohibitions apply as a block.

Second: the deadline in Article 111(4), added by point 39 of the Omnibus, expired. Providers of AI systems — including general-purpose ones — generating synthetic audio, image, video or text content placed on the market before 2 August 2026 had until 2 December to comply with Article 50(2). From 3 December 2026 the machine-readable marking requirement applies equally to new and legacy systems.

The Omnibus is applicable law, but part of its relief has not yet bitten

All the Omnibus amendments are applicable law since 27 July 2026: nothing in the text remains pending "entry into force". Quite another question is when they have practical effect, because several relieve obligations that are not yet enforceable.

Omnibus changeWhere it lives in the AI ActWhen it actually starts operating
Simplified technical documentation (Art. 11.1)Chapter III, Section 2With Chapter III: 2 Dec 2027 (Annex III) or 2 Aug 2028 (Annex I)
Proportionality for SMEs and mid-caps (Art. 17.2)Chapter III, Section 3With Chapter III, same dates
Simplified quality management for all SMEs (Art. 63.1)Chapter VIApplicable now, but exempts from an Art. 17 not yet enforceable
Presumption of conformity in cybersecurity (Art. 42.3)Chapter III, Section 5Applicable from 2 Aug 2026: Section 5 was not deferred
Extended fine cap to mid-caps (Art. 99, new 6a)Chapter XIIApplicable from 2 Aug 2025
Exclusive competence of the AI Office (Art. 75)Chapter IXApplicable from 2 Aug 2026

The counterintuitive consequence: much of the relief the Omnibus granted to SMEs rests on Chapter III requirements not enforceable until late 2027, so it does not relieve any real burden today. What does operate now is the sanctions block, governance, and Sections 4 and 5 of Chapter III, which fell outside the deferral.

The six duties the Omnibus left with deadlines

Pending dutyWho it bindsDeadlineLegal basis
Guidelines on practical application of Arts. 8(2), 9(10) and 17(3) to avoid duplication with Annex I, Section AEuropean Commission1 August 2027Art. 96.1, new point (g)
At least one national AI testing sandbox, operationalEach Member State2 August 2027Art. 57.1, 1st para.
Guidance, including a template, on the post-market monitoring planEuropean Commission2 September 2027Art. 72.3
Apply for designation under Chapter III, Section 4Notified bodies already notified under Annex I, Section A28 January 2028Art. 43.3
Delegated acts adding AI health and safety requirements to Machinery Regulation Annex IIIEuropean CommissionBy 2 August 2028Art. 3, pt. 1 of the Omnibus, on Art. 8 of Reg. (EU) 2023/1230
Comply with requirements and obligations for legacy high-risk systems intended for public authoritiesProviders and deployers2 August 2030Art. 111.2

What to review in early 2027

  1. Close the marking file. For each generative system the company provides, document when the output marking was deployed and by what method. If the system predates 2 August 2026, the file must show marking was operational before 2 December 2026.
  2. Ask your notified body in writing whether it will apply for Chapter III, Section 4 designation before 28 January 2028 and keep the reply. If not, there is a year and a half to find an alternative.
  3. Reclassify the system inventory between Annex III (Chapter III from 2 December 2027) and Annex I (from 2 August 2028): the documentary relief of Articles 11.1 and 17.2 activates with those dates, not before.
  4. Note the three 2027 dates — 1 August, 2 August and 2 September — as review points, not your own deliverables: they are duties of the Commission and of the Member State in which you operate whose delay does not exempt anyone but does change what material is available to work with.
  5. Follow the marking codes of practice that are published. Adhering is not mandatory, but a code evaluated as adequate is today the most solid route to demonstrating compliance with Article 50(2).

What should a Spanish SME do heading into 2027?

  1. Inventory what AI systems the company uses and in what role it acts in each: provider, deployer or both. The obligations regime changes by role.
  2. Review Article 5. It has been in force for over a year and carries the heaviest penalties. Also review the two new points if you generate or manipulate images of people.
  3. Article 50 transparency was covered on 2 August 2026 — interaction notices, synthetic content marking and deepfake disclosure — and Article 50(2) marking expired on 2 December 2026: check it against the marking section above.
  4. Document AI literacy for staff who operate AI systems. Obligation live since February 2025.
  5. Do not relax on high risk. December 2027 seems far away, but the conformity assessment of an Annex III system cannot be improvised in a quarter.

Frequently asked questions

Does the Omnibus defer the entire AI Act to 2027?

No. Only Chapter III, Sections 1 to 3, with two dates: 2 December 2027 (Annex III) and 2 August 2028 (Annex I). The general rule of 2 August 2026 remains intact.

Is the obligation to disclose that a chatbot is an AI deferred?

No. It is in Article 50(1), Chapter IV, which enters into force on 2 August 2026 under the general rule.

Do the prohibited practices still apply?

Yes, since 2 February 2025, and since 2 December 2026 two new ones have been added. Full catalogue at prohibited AI practices in Europe.

My image generation tool was already on the market in 2025. When must I mark outputs?

By no later than 2 December 2026, under the new Article 111(4). If the system is introduced from 2 August 2026 onwards, Article 50(2) applies from that date.

Who enforces this in Spain?

The market surveillance authorities designated under Article 70, with Chapter XII applicable since 2 August 2025. The actual state of Spanish supervision is covered in AI sandbox in Spain: how your company can participate.

Do I need a notified body if my system is not high risk?

No. Third-party conformity assessment only arises for certain high-risk systems. Most AI uses in an SME fall outside Chapter III and only carry transparency and literacy obligations.

Is anything in the Omnibus still to enter into force?

No. Regulation (EU) 2026/1744 entered into force on 27 July 2026 and all its provisions are applicable law from that date. What is pending is not entry into force but the deferred effects — the last being the new prohibitions, which activated on 2 December 2026 — and the timed mandates it created for the Commission, Member States and notified bodies, running until 2 August 2030.

Does the high-risk deferral still stand after 2 December?

Yes. 2 December only affected Article 5 and the Article 111(4) transitional period. The deferral of Chapter III, Sections 1, 2 and 3 keeps its two dates: 2 December 2027 for Article 6(2) and Annex III, and 2 August 2028 for Article 6(1) and Annex I. Sections 4 and 5 and Article 6(5) are outside the deferral and applicable from 2 August 2026.

Is there an official standard yet for marking synthetic content?

As of 16 December 2026, none. The new wording of Article 50(7) commissions codes of practice first and only foresees an implementing act with common standards if the Commission deems the code inadequate. Until that happens there is no single mandatory format or official list of compliant software: each provider chooses its method and documents it.

What if a generative system missed the 2 December deadline?

Article 111(4) provides no further grace or transitional period: past that date, non-compliance with Article 50(2) is sanctionable under Article 99(4)(g). The prudent course is to document when marking was implemented, why it was late and what was done about it: when setting the amount, Article 99(7) requires all relevant circumstances to be taken into account, including the duration of the infringement (point (a)) and actions taken to mitigate harm (point (j)).

Sources

Citations verified against the Spanish-language OJEU text. Informational content; not a substitute for legal advice.