The EU AI Act Omnibus Explained: What Businesses in Europe, the UK and the US Need to Know

 

On 7 May 2026, the European Parliament and the Council of the EU reached a provisional political agreement on the AI Omnibus — a targeted recalibration of the EU AI Act (Regulation (EU) 2024/1689). The reforms delay key deadlines, simplify obligations for smaller businesses, clarify how the AI Act interacts with sector-specific product law, and introduce a powerful new prohibition on AI-generated non-consensual intimate imagery. Here is what every organisation operating in or selling into the EU needs to understand — and act on — now.

The EU AI Act Omnibus Explained: What Businesses Need to Know

✅ AI Act timeline extended: The AI Act Omnibus postpones many obligations for high-risk AI systems, while leaving the overall AI Act framework unchanged.

🌍 Extra-territorial scope remains: The EU AI Act continues to apply to organisations both within and outside the European Union where its territorial scope is triggered.

🛡️ New prohibited AI practices: The Omnibus introduces new prohibitions covering AI-generated non-consensual intimate imagery (NCII) and child sexual abuse material (CSAM).

🤝 Greater support for SMEs: Small and medium-sized enterprises (SMEs) and small mid-cap businesses benefit from simplified compliance requirements and additional regulatory support.

📈 Time to prepare: Organisations should use the extended implementation period to strengthen AI governance, risk management, and compliance processes rather than delaying preparations.

What is the EU AI Act Omnibus?

EU AI ACT standards icons

Harmonised Standards Were Not Ready

Many of the technical standards needed to demonstrate compliance with the AI Act had not yet been finalised. Without these standards, providers of high-risk AI systems faced significant uncertainty when preparing technical documentation and conformity assessments.

EU AI ACT icon supervisory structures

National Supervisory Structures Were Still Developing

 

Many Member States had not yet designated competent authorities, notified bodies or supervisory structures responsible for enforcing the AI Act. Businesses therefore lacked clear national guidance.

EU AI ACT compliance certainty icon

Smaller Organisations Raised Compliance Concerns

SMEs, start-ups and growing technology companies argued that some compliance obligations were disproportionately complex and resource-intensive. The Omnibus responds by extending several simplification measures to small mid-cap enterprises (SMCs) in addition to SMEs.

EU AI ACT legal certainty icon

Businesses Requested Greater Legal Certainty

 

Manufacturers of products such as medical devices, machinery, toys and connected products highlighted uncertainty about how the AI Act interacted with existing product safety legislation. The Omnibus seeks to reduce unnecessary duplication.

EU AI ACT ai risk icon

New AI Risks Emerged

Since the AI Act was originally adopted, regulators have become increasingly concerned about the misuse of generative AI to create:

  • non-consensual intimate imagery;
  • synthetic child sexual abuse material;
  • harmful deepfakes; and
  • other forms of AI-generated abusive content.

The Omnibus responds by strengthening the prohibited AI practices under Article 5.

Does the AI Act Omnibus Replace the EU AI Act?

No. One of the most common misconceptions is that the Omnibus replaces or significantly weakens the AI Act.

This is not the case. The Omnibus is best understood as an implementation update rather than a new regulatory framework. The AI Act remains the world’s first comprehensive legislation governing artificial intelligence, and its core principles remain unchanged.

Businesses must still:

  • identify where they use AI;
  • classify AI systems according to risk;
  • implement appropriate governance measures;
  • comply with transparency obligations where required;
  • maintain technical documentation for high-risk AI systems; and
  • establish appropriate human oversight and risk management processes.

The additional implementation time should be viewed as an opportunity to build stronger compliance programmes rather than delaying preparation.

Key Point: The Omnibus changes deadlines and simplifies selected obligations, but it does not remove the AI Act’s fundamental compliance requirements.

What Does the AI Act Omnibus Change?

 

The Omnibus introduces five significant reforms designed to make implementation more practical while preserving the AI Act’s overall regulatory framework.

At a high level, the Omnibus:

✅ Postpones implementation dates for many high-risk AI obligations

✅ Expands support for SMEs and small mid-cap enterprises

✅ Clarifies interactions with existing EU product legislation

✅ Introduces a new prohibition on certain forms of AI-generated abusive content

✅ Refines specific compliance obligations without altering the overall regulatory structure

These changes are intended to make implementation more practical while maintaining the high level of protection established by the AI Act. The following sections examine each reform in detail.

 

What Does the AI Act Omnibus NOT Change?

While much attention has focused on the delayed deadlines, organisations should understand that the AI Act’s core architecture remains intact.

The Omnibus does not change the AI Act’s core architecture.

✅ The four-tier risk classification model

✅ The distinction between providers and deployers

✅ Obligations relating to prohibited AI practices

✅ The governance framework for general-purpose AI (GPAI) models

✅ The requirement to manage risks proportionately

✅ Documentation, transparency and human oversight requirements

✅ The AI Act’s extraterritorial application to organisations outside the EU

In practical terms, organisations should continue building AI governance programmes, conducting AI inventories and preparing documentation even if formal compliance deadlines have moved.

Businesses that delay preparation until the new deadlines risk compressed implementation programmes, increased compliance costs and greater regulatory exposure.

Why Businesses Should Continue Preparing Now

The Omnibus creates additional time, but it does not eliminate compliance obligations.

Forward-looking organisations should use this period to strengthen AI governance and prepare for the revised implementation deadlines.

Organisations should continue to:

Identify AI systems across the business
Assess whether any systems fall within the AI Act’s high-risk categories
Establish AI governance structures
Review contracts with AI vendors
Integrate AI governance with existing GDPR and information security processes
Improve AI literacy across the organisation

Practical advice

Treat the extended timeline as an opportunity to build a stronger AI governance programme—not as a reason to delay compliance.
Your Content Goes Here

The New AI Act Timeline: What Has Changed?

 

One of the most significant changes introduced by the AI Act Omnibus is the postponement of several compliance deadlines for high-risk AI systems.

The revised timetable is intended to give businesses, national regulators and conformity assessment bodies sufficient time to prepare for implementation, particularly while harmonised technical standards are still being developed.

However, organisations should remember one important point:

Until the Omnibus is formally adopted, the original AI Act implementation dates remain legally applicable. Businesses should therefore continue planning for compliance while monitoring the legislative process

What Happens on 2 December 2026?

Although much attention has focused on delayed obligations, December 2026 remains a critical compliance milestone.

  • From this date:
  • Article 50 transparency obligations apply.
  • Providers must comply with transparency requirements for certain AI-generated content.
  • The new prohibition on AI systems that generate non-consensual intimate imagery (NCII) enters into force.
  • New prohibitions relating to AI-generated child sexual abuse material also apply.

For organisations developing or deploying generative AI systems, these obligations should already form part of compliance planning.

What Happens on 2 December 2027?

This is the new proposed implementation date for stand-alone high-risk AI systems listed in Annex III.

Examples include AI systems used in:

  • recruitment and employment;
  • education;
  • biometric identification;
  • critical infrastructure;
  • migration and border management;
  • law enforcement;
  • access to essential public services.

Providers and deployers of these systems should use the additional implementation period to complete:

  • AI inventories;
  • risk assessments;
  • technical documentation;
  • governance procedures;
  • human oversight measures;
  • post-market monitoring processes.

The additional time should not be viewed as an opportunity to postpone compliance activities.

What Happens on 2 August 2028?

The Omnibus also postpones obligations for AI systems that form part of regulated products covered by Annex I.

These include AI integrated into products such as:

  • medical devices;
  • machinery;
  • lifts;
  • toys;
  • watercraft;
  • radio equipment;
  • connected consumer products.

The delayed implementation allows alignment between the AI Act and existing EU product safety legislation.

The Five Most Important Changes Introduced by the AI Act Omnibus

Although the Omnibus contains numerous technical amendments, five reforms are likely to have the greatest practical impact on businesses.

The headline change is the postponement of obligations for many high-risk AI systems.
This reflects concerns that organisations could not realistically demonstrate compliance before:
• harmonised standards were available;
• notified bodies had been designated;
• national supervisory authorities became operational.
The delay gives businesses additional time to establish governance programmes while reducing implementation risk.
Importantly, the obligations themselves remain largely unchanged.

One of the most significant policy developments is the expansion of prohibited AI practices.

The Omnibus introduces a specific prohibition covering AI systems that generate:

  • non-consensual intimate imagery (NCII);
  • child sexual abuse material (CSAM);
  • sexually explicit depictions of identifiable individuals created without consent.

The prohibition applies to providers placing these systems on the EU market and to deployers using them.

Potential administrative fines remain among the highest available under the AI Act.

For organisations developing generative AI technologies, this reinforces the importance of implementing appropriate safeguards, content moderation measures and acceptable-use controls.

Manufacturers have consistently expressed concern about overlapping regulatory obligations.

For example, AI integrated into medical devices or machinery may already be subject to comprehensive product safety legislation.

The Omnibus seeks to reduce unnecessary duplication by clarifying how the AI Act interacts with sector-specific legislation.

Implementing acts are expected to provide further guidance on:

  • machinery;
  • medical devices;
  • toys;
  • lifts;
  • recreational craft;
  • other regulated products.

This should make compliance more predictable while preserving product safety standards.

The AI Act originally contained several simplification measures designed for SMEs.

The Omnibus extends many of these benefits to small mid-cap enterprises (SMCs), recognising that many growing technology businesses face similar compliance challenges.

Potential support measures include:

  • simplified documentation templates;
  • proportionate quality management obligations;
  • easier access to AI regulatory sandboxes;
  • reduced administrative burdens;
  • more proportionate enforcement approaches.

The intention is to encourage innovation while maintaining robust safeguards for individuals affected by AI systems.

While the Omnibus simplifies certain compliance obligations, it also reinforces protections in areas considered particularly sensitive.

In particular, negotiators retained stricter safeguards relating to:

  • processing special category personal data;
  • bias detection activities;
  • registration of high-risk AI systems;
  • market surveillance.

This reflects the EU’s continued emphasis on protecting fundamental rights alongside technological innovation.

The message from legislators is clear:

Simplification should not come at the expense of accountability.

What Has Not Been Relaxed?

Some organisations assume the Omnibus significantly weakens the AI Act. That assumption is incorrect.

The following obligations remain central to the AI Act:

🛡️ Risk management

🛡️ Technical documentation

🛡️ Human oversight

🛡️ Transparency

🛡️ Post-market monitoring

🛡️ Record keeping

🛡️ Governance

🛡️ Accountability

Businesses should therefore continue investing in compliance programmes rather than waiting for the revised deadlines.

💡 Key Takeaway

 

The AI Act Omnibus gives organisations more time—but not fewer responsibilities.

Businesses that use the additional implementation period to strengthen governance, improve documentation and increase AI literacy will be significantly better positioned when the revised deadlines take effect.

In the next section, we examine what the Omnibus means for organisations in Ireland, Spain, the United Kingdom and the United States, before setting out a practical compliance roadmap for the next 12 months.

Official sources and further reading

 

European Commission — Digital Omnibus on AI Regulation Proposal (COM(2025) 836), 19 November 2025.

Council of the EU — Press release, “Artificial intelligence: Council and Parliament agree to simplify and streamline rules”, 7 May 2026.


European Parliament Legislative Train — Digital Omnibus on AI.


EU AI Act — Regulation (EU) 2024/1689, Official Journal of the European Union.


Department of Enterprise, Trade and Employment (Ireland) — EU Artificial Intelligence Act guidance.


AESIA — Agencia Española de Supervisión de la Inteligencia Artificial (Spain).

 

Disclaimer: This blog post is provided by Symmetry Compliance for general information purposes only. It reflects the state of the AI Act Omnibus as of May 2026, based on the provisional political agreement of 7 May 2026, and does not constitute legal advice. The Omnibus has not yet been formally adopted; the final text and its application dates may change. For advice on your specific situation, please contact us at info@symmetrycompliance.ie.

2026-07-22T08:41:19+01:00June 25th, 2026|AI, AI Act, Data Governance, Data Protection, DPIA, DPO, GDPR, Personal data, Privacy|