The European Parliament and the Council approve the Digital Omnibus Package on AI
Regulation (EU) 2026/1744, known as the ‘Digital Omnibus’, was published in the Official Journal of the European Union on 24 July 2026 and entered into force three days later, on 27 July 2026. It amends the Artificial Intelligence Regulation (AIR) to simplify its application, ease compliance burdens – particularly for SMEs and small mid-cap companies – and extend certain deadlines, whilst at the same time strengthening supervision.
Key new provisions include:
- New AI prohibitions (Article 5 of the AI Regulation): the use of AI systems to generate non-consensual intimate material of identifiable individuals, as well as child sexual abuse material, is prohibited. These will apply from 2 December 2026.
- Clarification of the concept of ‘safety component’: it is specified that an AI system is only considered a safety component when its intended purpose is to prevent risks to health and safety; functions such as user assistance or performance optimisation are excluded.
- More flexible AI literacy (Article 4): organisations are no longer required to “guarantee” a level of literacy, but rather to “take measures to support its promotion” amongst staff.
- New legal basis for correcting bias (Article 4a): the possibility of processing special categories of data to detect and correct bias is extended to more providers and those responsible for deployment, subject to strict safeguards.
- Greater support for SMEs: simplified technical documentation, quality management systems proportionate to the size of the business, more moderate fines and priority access to the AI Office’s sandboxes.
- Simpler conformity assessment: a single procedure for bodies wishing to be designated under both the AI Act and other EU harmonisation standards.
The Omnibus Directive also strengthens the supervisory framework and provides greater scope for innovation:
- Sandboxes and real-world testing (Articles 57, 58, 60 and 60a): Member States must have a national sandbox operational by August 2027, and the scope for testing AI systems in real-world conditions is expanded, including for high-risk systems.
- The European AI Office gains exclusive powers over the most significant AI systems — general-purpose models and very large platforms or search engines — with the authority to inspect, investigate on its own initiative and impose fines of up to €35 million or 7 per cent of global turnover.
- Transitional period for content labelling (Article 50): providers who were already marketing synthetic content generation systems before August 2026 have until 2 December 2026 to comply with the labelling obligations.
- Alignments with sector-specific regulations: the Machinery Regulation will now be governed by a sector-specific approach within the RIA, and coordination with the Cyber Resilience Regulation is strengthened.
- Other changes: simplification of registration procedures, a voluntary model for post-market surveillance, clarifications regarding the grace period for systems already on the market, and an expanded penalty regime with more favourable caps for small businesses.
- Key deadlines to watch: the new prohibitions come into force on 2 December 2026; high-risk systems listed in Annex III have until 2 December 2027 to comply, and those in Annex I until August 2028.
The TMT team at ECIJA recommends reviewing how these changes affect ongoing AI projects and keeping an eye on the guidelines the Commission will publish in the coming months on sectoral complementarity (August 2027) and post-market surveillance (September 2027).