There is a particular kind of exhaustion that comes from trying to keep up with a regulation that keeps moving.
If you have been following the EU AI Act since it entered into force in August 2024, you know that feeling. Deadlines shifted. Proposals appeared. Trilogues collapsed. Then finally, in the span of a few weeks this spring, something settled.
On 29 June 2026, the Council of the European Union gave its final green light to the Digital Omnibus on AI — the first formal amendment to the EU AI Act since it was adopted. After months of uncertainty, the calendar is clear again.
This post is here to hand you that clarity. No legal jargon. No spin in either direction. Just the corrected picture, and what it means for the people and organisations trying to do this right.
—
### What the Digital Omnibus actually is
The Digital Omnibus on AI is not a new regulation. It is a targeted amendment to the existing AI Act, proposed by the European Commission in November 2025 as part of a broader simplification package.
The headline change: the timeline for high-risk AI compliance was linked to the availability of harmonised standards and support tools. In plain language — the EU acknowledged that companies could not reasonably comply with rules for which the technical standards had not yet been published. So it adjusted the clock.
The Omnibus reached provisional political agreement on 7 May 2026. The European Parliament formally adopted it on 16 June. The Council confirmed it on 29 June. Official publication in the EU Official Journal is expected before 2 August 2026 — after which the changes take legal effect.
—
### The corrected timeline — what you are actually working to
Here is the full picture, updated for where things stand today.
| Date | Obligation | Status |
|——|———–|——–|
| 2 February 2025 | Prohibited AI practices + AI literacy obligations | ✅ In force |
| 2 August 2025 | GPAI model rules + EU governance bodies | ✅ In force |
| **22 July 2026** | **Code of Practice signatory deadline (18:00 CEST)** | **⏳ Open now** |
| **2 August 2026** | **Article 50 transparency obligations** | **🔴 Unchanged — still due** |
| **2 December 2026** | **GenAI watermarking + new NCII/CSAM prohibition** | **🆕 New requirement** |
| 2 December 2027 | Annex III standalone high-risk AI obligations | ⬆️ Deferred from Aug 2026 |
| 2 August 2028 | Annex I product-embedded high-risk AI obligations | ⬆️ Deferred from Aug 2027 |
Read that table slowly. Because the most important line is not the one most people are talking about.
—
### What did not move — and why it matters more than the delay
The deferral of Annex III obligations is real. If your company deploys AI in credit scoring, hiring, education, biometric identification, or law enforcement, you now have until December 2027 to complete your full risk management system, technical documentation, human oversight architecture, and conformity assessment.
That is sixteen months of genuine breathing room, and it deserves to be used deliberately.
But Article 50 — the transparency obligations — was not deferred. Not by a day.
What does Article 50 require, as of 2 August 2026?
Every chatbot interacting with EU users must disclose it is an AI. Emotion recognition systems must notify the people they are scanning. AI-generated content — images, video, audio, text — on matters of public interest must be labeled as AI-generated. Deep fakes require explicit disclosure.
If your product talks to, scans, or generates content for EU users, these rules apply to you in less than a month.
This is the part of the “delay” news that got lost in the celebration. The delay is real. But it is not universal.
—
### The window that is still open — until July 22
There is one more deadline worth knowing about, and it closes before August even arrives.
On 10 June 2026, the EU AI Office published the final **Code of Practice on Transparency of AI-Generated Content**. It is a voluntary framework that sets out practical ways to meet Article 50 obligations on marking and labeling AI-generated output.
Sign it by **22 July 2026 at 18:00 CEST**, and your organisation receives a **presumption of conformity** with Article 50(2) and Article 50(4). That means when a national authority investigates your compliance, they carry the burden of proving you are wrong — not you.
That is not a small thing. For a company that has taken the Code seriously and implemented its requirements, this is meaningful legal protection.
The signatory form is available at digital-strategy.ec.europa.eu. The deadline is 22 July. This is still open as of this writing.
—
### What was added — the part no one is celebrating
Simplification packages are rarely only about making things easier. The Digital Omnibus was no exception.
Effective 2 December 2026, the AI Act adds two new explicit prohibitions. AI systems used to generate non-consensual intimate imagery — sometimes called “nudifier” tools — and AI systems used to produce child sexual abuse material are now banned under the Act. The penalty for violation: up to **€35 million or 7% of global annual turnover**, whichever is higher. That is the maximum enforcement tier in the entire regulation.
If you build or deploy generative models capable of producing images or audio, this line arrives in December, and it applies regardless of whether users claim consent.
—
### What the delay actually means — a different way to think about it
There is a temptation to read sixteen more months as permission to pause. It is not.
It is an acknowledgement that the hard work of complying with Annex III obligations takes time to do properly — and that rushing it without the right standards and tools in place would produce compliance theatre rather than genuine governance.
The companies that will come out of December 2027 in the strongest position are not the ones who stopped working. They are the ones who used this runway to build something that will actually hold up: a real risk management system, documentation that reflects how the AI genuinely behaves, oversight mechanisms that function rather than just exist on paper.
The regulation has not softened. The standards are coming. The enforcement starts the moment those standards land.
—
### Where to begin if you are starting now
You do not need to solve everything at once. Here is what matters most in the next few weeks:
**First:** Audit your Article 50 exposure before 2 August. If you have a chatbot, an emotion recognition tool, or a generative content system touching EU users, map what disclosure you need and build it now.
**Second:** Consider the Code of Practice before 22 July. If signing it is feasible for your organisation, the presumption of conformity is worth having.
**Third:** Rebaseline your Annex III roadmap. You have until December 2027. Use a portion of that time to do the foundation work properly — classification, risk documentation, human oversight design — rather than treating it as a pause.
**Fourth:** Mark 2 December 2026 for your content and generative AI controls. New watermarking requirements and the new prohibitions both arrive on that date.
**Fifth:** Keep watching the Official Journal. The Omnibus amendments do not become binding until published. Publication is expected before 2 August — but until it appears, treat the changes as a strong signal to plan to, not yet final law.
—
### A final thought
The EU AI Act is not going away. It is not being diluted into irrelevance. What has happened is that the EU has done something regulators rarely do — looked honestly at the gap between what it asked and what the market could deliver, and adjusted the timeline rather than pretending the problem did not exist.
That is not weakness. That is how durable regulation gets built.
The window is open. The tools are arriving. The obligations — some of them — are already here.
This is a good time to start, or to continue.
—
*If you are building your AI compliance framework and want a practical starting point, the [EU AI Act Starter Kit](https://frelih.gumroad.com/l/rxpuu) gives you the audit checklist and documentation templates to begin. For a plain-language walkthrough of the full regulation, [AI_4_Act_Simple](https://frelih.gumroad.com/l/pzqly) covers everything from prohibited practices to Annex III obligations in accessible language.*

Leave a comment