AI Omnibus enters into force: what it means for members

3–4 minutes

The AI Omnibus Regulation takes effect across the EU on 27 July 2026, introducing extended implementation timelines and a suite of measures designed to streamline and simplify administrative requirements for organisations working with artificial intelligence.

Originally proposed on 19 November 2025 as part of the wider Digital Omnibus package, the AI Omnibus provides a targeted refinement of the existing AI rulebook. It maintains strong protections for people’s safety and fundamental rights, while easing compliance burdens and improving legal clarity for businesses developing and deploying AI systems in Europe.

The proposed changes introduce a more innovation-friendly and proportionate regulatory framework, particularly for smaller organisations. Measures that were previously available only to small and medium-sized enterprises (SMEs) will now be extended to small mid-cap companies (SMCs), enabling a wider range of businesses to benefit from reduced regulatory burdens and tailored compliance requirements. In addition, companies will have broader access to regulatory sandboxes, including a new EU-level sandbox, providing valuable opportunities to develop, test and refine AI systems under regulatory supervision before deployment.

The proposals also allow for extended implementation timelines, giving organisations additional time to prepare for compliance.

Key dates to note:

  • Obligations relating to high-risk AI systems listed in Annex III (such as biometrics, critical infrastructure, HR systems) will now apply from 2 December 2027.
  • Obligations for high-risk AI embedded in physical products such as machinery, toys and lifts (Annex I) apply from 2 August 2028.

These revised deadlines are intended to support a smoother transition while maintaining regulatory certainty.

The former requirement for organisations to ensure AI literacy is also being streamlined, with the European Commission and Member States expected to play a more active role in promoting awareness and understanding of AI. Furthermore, obligations relating to the registration of exempted AI systems in the EU’s central database will be simplified.

The proposals strengthen protections for individuals and fundamental rights by introducing new safeguards against harmful uses of AI. In particular, AI systems that generate non-consensual sexually explicit or intimate content, including child sexual abuse material, will be prohibited. At the same time, organisations will be permitted to process special categories of personal data where necessary to identify, monitor and mitigate bias within AI systems, supporting fairness and accountability.

The reforms seek to improve consistency and clarity in AI governance across the EU. The EU AI Office will be granted expanded oversight powers in relation to certain AI systems, including those based on general-purpose AI models and systems integrated into major online platforms and search engines. The proposals also provide clearer guidance on the interaction between the AI Act and other EU legislation, while simplifying procedures for conformity assessment bodies responsible for evaluating compliance. Together, these measures aim to create a more coherent regulatory framework that balances innovation, competitiveness and protection of fundamental rights.

Finally, the package is intended to strengthen innovation and competitiveness by supporting smaller businesses, expanding opportunities for testing and experimentation, and providing greater clarity around the obligations applicable to high-risk AI systems. However, it should not be interpreted as a reduction in regulatory requirements. Its primary purpose is to adjust implementation timelines, while leaving the substance of the legislation unchanged. The package does not remove any existing obligations, introduce exemptions based on sector, industry or organisation size, or reduce the penalties for non-compliance. Once the revised deadlines take effect, organisations within scope will remain subject to the same enforcement regime and potential fines. Equally, the definition and scope of high-risk AI systems remain unchanged, with the criteria set out in Annex I and Annex III continuing to apply in full. The omnibus also has no impact on the rules governing General-Purpose AI (GPAI) models, the prohibitions on certain AI practices, or the transparency obligations imposed on organisations. In essence, the package provides additional time and greater clarity for compliance, but it does not alter the regulatory expectations, scope, or enforcement provisions established by the AI Act.

Resources

Discover more from Irish Computer Society

Subscribe now to keep reading and get access to the full archive.

Continue reading