Digital Omnibus on AI

Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI)

European Union

RAI-EU-NA-COM2025-2025

Regulation (EU) 2026/1744

Effective: July 27, 2026
In Force(In Force)
RegulationGovernance and OversightRisk Management
Export PDF

The EU Digital Omnibus simplifies the AI Act, easing burdens for businesses and enhancing innovation while maintaining high safety and ethical standards.

Summary

The EU Digital Omnibus on AI streamlines the landmark AI Act, reducing administrative burdens for businesses, especially SMEs, while upholding high safety and ethical standards. It clarifies governance, expands regulatory sandboxes, and adjusts application timelines for high-risk AI systems. This initiative aims to foster innovation and ensure consistent, human-centric AI implementation across the EU.

Full article

Read full text ↗

Overview

The Regulation on the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI) represents a pivotal legislative initiative by the European Union, designed to streamline and enhance the practical application of the landmark AI Act (Regulation (EU) 2024/1689). Proposed by the European Commission on November 19, 2025, as part of a broader Digital Simplification Package, this regulation aims to reduce the administrative burden on businesses, particularly small and medium-sized enterprises (SMEs) and small mid-cap companies (SMCs), while upholding the high standards for safety, fundamental rights, and ethical considerations established by the original AI Act. The initiative stems from a recognition that while the AI Act sets a global benchmark for AI regulation, its comprehensive nature could present implementation challenges, potentially hindering innovation and competitiveness within the EU market.

This Digital Omnibus on AI seeks to address identified challenges in the timely application and operationalisation of the AI Act, particularly concerning the designation of national competent authorities, the publication of harmonised standards, and the availability of compliance tools for high-risk AI requirements. Key objectives include fostering an innovation-friendly environment, ensuring legal certainty, and promoting a more harmonised implementation of AI rules across Member States. The regulation also introduces targeted amendments to facilitate the use of AI regulatory sandboxes, clarify governance structures, and adjust application timelines for certain high-risk AI systems to align with the readiness of supporting infrastructure and standards. Furthermore, it reinforces protections for citizens by prohibiting certain ethically problematic AI systems, such as those generating non-consensual explicit content. The political agreement on this regulation was reached on May 7, 2026, and it received the final green light from the Council on June 29, 2026, marking its adoption.

Definitions

For the purposes of this Regulation, several key terms are either explicitly defined or implicitly understood in the context of the overarching AI Act. A 'High-risk AI system' refers to AI systems identified under the AI Act as posing significant risks to health, safety, or fundamental rights, necessitating stringent requirements and conformity assessments. This category includes AI used in critical infrastructure, education, employment, and law enforcement, among others. The Digital Omnibus aims to simplify the compliance pathways for these systems, particularly for smaller entities, without compromising the inherent safety and ethical safeguards. The concept of 'Regulatory Sandboxes' is central to the innovation support mechanisms, denoting controlled environments where AI systems can be developed and tested under regulatory supervision, allowing innovators to iterate and refine their solutions in a real-world setting while ensuring compliance with evolving legal frameworks. The Regulation expands the scope and accessibility of these sandboxes, including the establishment of an EU-level sandbox.

The 'AI Office,' established within the European Commission, plays a crucial role as the central body responsible for overseeing the implementation and enforcement of the AI Act. Its powers are reinforced by this Digital Omnibus, particularly in supporting the oversight of AI systems built on general-purpose models and those embedded in very large online platforms. The regulation also extends specific considerations to 'SMEs and SMCs' (Small and Medium-sized Enterprises and Small Mid-Cap Companies), acknowledging their unique challenges in navigating complex regulatory landscapes. This includes simplified technical documentation requirements and proportionate monitoring activities and penalties. 'General-purpose AI models (GPAI)' are also addressed, with the regulation clarifying governance and oversight mechanisms for these foundational technologies that can be adapted for a multitude of tasks. The amendments ensure that the regulatory framework remains agile enough to address rapidly evolving AI technologies and their diverse applications, promoting both innovation and responsible deployment across the single market.

Governance and Institutional Framework

The Digital Omnibus on AI significantly refines and strengthens the governance and institutional framework established by the original AI Act, primarily by clarifying roles and enhancing coordination among various bodies. A central element of this framework is the European AI Office, whose enforcement powers are reinforced to centralise oversight of certain AI systems, including those built on general-purpose models and those integrated into very large online platforms and search engines. This centralisation aims to reduce governance fragmentation and ensure a consistent application of rules across the EU, addressing concerns about potential inconsistencies arising from multi-level governance where EU-wide rules are enforced by national authorities. The regulation also mandates Member States to strengthen cross-border cooperation among their national regulatory sandboxes, further fostering a cohesive European approach to AI innovation and regulation.

The regulation also addresses the practical challenges faced by national competent authorities in implementing the AI Act, particularly regarding the designation of these authorities and the timely publication of harmonised standards. By streamlining processes and providing clearer guidance, the Digital Omnibus facilitates the effective functioning of these national bodies, enabling them to better support businesses in compliance. Furthermore, the regulation extends certain simplified requirements and considerations, initially granted to SMEs, to SMCs, ensuring that monitoring activities and any penalties imposed by competent authorities remain proportionate to the size and capacity of these businesses. This strategic adjustment aims to alleviate administrative burdens and encourage innovation among a broader spectrum of European companies, aligning regulatory oversight with the economic realities of diverse market actors while maintaining robust protection for health, safety, and fundamental rights.

Key Focus Areas

The Digital Omnibus on AI zeroes in on several critical areas to achieve its overarching goal of simplification and enhanced implementation of the AI Act. A primary focus is the reduction of administrative burdens for businesses, particularly for SMEs and SMCs. This includes introducing binding definitions for these entities in the AI Act and permitting them to submit certain elements of technical documentation in a simplified manner, with the Commission committed to providing a simplified technical documentation form. These measures are designed to save businesses significant administrative costs and encourage broader participation in the AI market by making compliance more accessible for smaller innovators. The regulation acknowledges that the original AI Act's scope and technical requirements presented challenges for these companies, and the omnibus seeks to provide practical relief.

Another significant area of focus is the expansion and optimisation of AI regulatory sandboxes. The provisions on AI regulatory sandboxes in the AI Act are amended to create a legal basis for the AI Office to introduce an EU-level AI regulatory sandbox for certain AI systems under its exclusive supervisory competence. This expansion aims to give more innovators access to environments where they can test their AI solutions in real-world conditions, fostering innovation while ensuring regulatory compliance. Furthermore, the Digital Omnibus addresses specific ethical concerns by prohibiting AI systems that generate non-consensual sexually explicit and intimate content or child sexual abuse material, such as AI 'nudification' apps, thereby strengthening protection for citizens. The regulation also clarifies the interplay between the AI Act and existing EU product safety laws, like the Machinery Regulation, to avoid duplication and ensure coherence across the regulatory landscape.

Implementation Framework

The implementation framework outlined in the Digital Omnibus on AI is designed to ensure a smoother, more coherent, and innovation-friendly application of the harmonised rules on artificial intelligence across the European Union. A key aspect of this framework is the adjustment of application timelines for certain high-risk AI systems, linking their entry into application to the availability of essential support tools, including necessary technical standards. This strategic sequencing is crucial to ensure that businesses have the required technical standards and other support mechanisms in place before the rules become fully applicable, thereby mitigating potential delays and compliance costs. For instance, rules for systems used in certain high-risk areas like biometrics, critical infrastructure, education, employment, migration, asylum, and border control will apply from December 2, 2027, while rules for systems integrated into products like lifts or toys will apply from August 2, 2028.

Moreover, the Digital Omnibus facilitates the practical operationalisation of the AI Act by providing clearer guidance and targeted amendments to existing provisions. It aims to address challenges identified in integrating AI governance with existing data governance frameworks and embedding risk management throughout the entire AI lifecycle. The Commission is committed to issuing a series of guidelines to optimise compliance with the AI Act, complementing the legislative changes introduced by the Omnibus. The regulation also seeks to ensure that national authorities give special attention to SMEs and SMCs, ensuring that monitoring activities and any penalties and fines imposed remain proportionate. This comprehensive approach to the implementation framework seeks to strike a balance between robust regulation and the promotion of innovation, ensuring that Europe remains a leader in trustworthy AI development and deployment.

Monitoring and Evaluation

The Digital Omnibus on AI, while primarily focused on simplifying the implementation of existing rules, inherently establishes a framework for ongoing monitoring and evaluation of the AI Act's effectiveness and the impact of the introduced simplifications. The reinforcement of the AI Office's powers and its central role in overseeing certain AI systems, including those built on general-purpose models, positions it as a key institution for continuous monitoring of market developments and compliance trends. This centralised oversight will enable the Commission to gather comprehensive data on the deployment and performance of AI systems across the EU, facilitating a more informed assessment of the regulatory framework's practical effects and identifying any emerging challenges or areas requiring further adjustment. The requirement for Member States to strengthen cross-border cooperation of their regulatory sandboxes also contributes to a broader monitoring ecosystem, allowing for the sharing of best practices and insights gained from real-world testing of AI solutions.

Furthermore, the Commission's commitment to issuing a series of guidelines aimed at optimising compliance with the AI Act, alongside the legislative amendments, indicates a dynamic approach to regulation that includes continuous evaluation of the regulatory landscape. These guidelines can be updated based on feedback from stakeholders and observations from market surveillance activities, ensuring the framework remains relevant and effective in a rapidly evolving technological environment. The explicit extension of simplified requirements to SMEs and SMCs, coupled with the directive for national and EU authorities to ensure proportionate monitoring and penalties, implies a continuous assessment of the regulatory burden on these critical economic actors. This ongoing evaluation will be vital to confirm that the simplification efforts are indeed reducing administrative costs and fostering innovation without compromising the fundamental objectives of the AI Act, thereby ensuring that the EU's AI strategy remains competitive and human-centric.

Penalties, Liability, and Appeals

While the Digital Omnibus on AI primarily focuses on streamlining and simplifying the implementation of the AI Act, it also implicitly reinforces the principles of proportionate enforcement, particularly concerning penalties and liability. The regulation explicitly states that national and EU authorities are to give special attention to SMEs and SMCs, ensuring that monitoring activities and any penalties and fines imposed remain proportionate. This provision is crucial for fostering an innovation-friendly environment, as it aims to prevent overly burdensome sanctions from stifling smaller entities that may have fewer resources to navigate complex compliance requirements. The underlying penalties and liability frameworks for non-compliance with the AI Act remain in effect, but the Omnibus seeks to ensure their application is fair and balanced, reflecting the size and capacity of the regulated entities. The objective is to maintain a high level of protection for health, safety, and fundamental rights while avoiding disproportionate impacts on businesses.

The clarification of governance structures and the reinforcement of the AI Office's powers, as introduced by the Omnibus, also contribute to a more transparent and predictable enforcement landscape. A clearer understanding of supervisory responsibilities and compliance pathways can indirectly reduce instances of non-compliance, thereby mitigating the need for penalties. Furthermore, by expanding access to regulatory sandboxes, the regulation provides a mechanism for innovators to test and validate their AI systems in a controlled environment, reducing the risk of non-compliance before market deployment. This proactive approach to compliance, supported by the simplification measures, aims to minimise the likelihood of breaches that would trigger penalties. While the Omnibus itself does not introduce new appeal mechanisms, the existing avenues for appealing regulatory decisions and penalties under EU law and national administrative procedures would continue to apply, ensuring due process for affected parties. The emphasis on clear, practical, and innovation-friendly implementation ultimately aims to create a regulatory environment where compliance is achievable, and enforcement is both effective and equitable.

Relationship to Other Instruments

The Regulation on the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI) is intrinsically linked to and directly amends the foundational EU AI Act (Regulation (EU) 2024/1689), which entered into force on August 1, 2024. Its primary purpose is to address implementation challenges and lighten the regulatory burden identified since the AI Act's entry into force, making its provisions more practical and innovation-friendly. Beyond the AI Act, the Digital Omnibus also introduces minor amendments to Regulation (EU) 2018/1139, which pertains to common rules in the field of civil aviation. These specific amendments aim to ensure the consistent application of the AI Act's high-risk requirements within the civil aviation sector, thereby maintaining coherence across different regulatory domains. This demonstrates the EU's commitment to ensuring that AI regulation is integrated seamlessly into existing sectoral legal frameworks.

Furthermore, the Digital Omnibus on AI is an integral part of a broader European Commission initiative known as the Digital Simplification Package, or the 'Digital Omnibus' package, published on November 19, 2025. This comprehensive package includes not only the AI-focused regulation but also another digital omnibus proposal aimed at simplifying and consolidating parts of the EU's digital acquis, making targeted amendments to data, privacy, and cybersecurity laws. The package also encompasses a Data Union Strategy to unlock high-quality data for AI and proposals for European Business Wallets, which aim to offer companies a single digital identity to simplify paperwork. This holistic approach underscores the EU's strategic vision to streamline its digital regulatory framework across various interconnected domains, aiming to boost competitiveness, cut red tape, and save billions for businesses by making compliance simpler, less costly, and more efficient.

International Alignment

While the Digital Omnibus on AI is an internal European Union legislative instrument, its implications for international alignment are significant, given the EU's pioneering role in comprehensive AI regulation. The original AI Act has been widely recognised as the world's first comprehensive legal framework on AI, setting a global benchmark for trustworthy and human-centric artificial intelligence. By simplifying and clarifying the implementation of this landmark regulation, the Digital Omnibus aims to enhance the EU's position as a leader in responsible AI governance, potentially influencing regulatory approaches in other jurisdictions. The objective of fostering an innovation-friendly environment within the EU, while maintaining high standards of protection, demonstrates a model that balances technological advancement with ethical considerations, a balance keenly observed by international partners and competitors alike.

The regulation's efforts to streamline compliance for businesses, including SMEs and SMCs, and to expand regulatory sandboxes, could make the EU market more attractive for international AI developers and deployers seeking regulatory clarity and support. This could, in turn, promote greater international cooperation and potentially facilitate mutual recognition of conformity assessments or regulatory approaches in the future. Conversely, concerns about regulatory fragmentation and inconsistency across jurisdictions have been highlighted as challenges in implementing horizontal AI regulation, particularly for companies operating across multiple sectors. By ensuring a more harmonised and practical implementation within the EU, the Digital Omnibus indirectly addresses these concerns by providing a clearer and more predictable domestic landscape, which can serve as a more stable foundation for international engagement and dialogue on AI governance. The EU's commitment to a clear, practical, and innovation-friendly implementation of its AI framework reinforces its ambition to shape global norms for AI development and deployment.

Implementation Timeline

MilestoneDateNotes
Commission Proposal for Digital Omnibus on AI2025-11-19Part of the broader Digital Simplification Package.
European Parliament adopts negotiating position2026-03-26
Council adopts negotiating mandate2026-03-13
Political agreement reached between European Parliament and Council2026-05-07On simpler, innovation-friendly rules for AI.
European Parliament approves agreement2026-06-16
Council gives final green light (adoption)2026-06-29Final legislative step for adoption.
Prohibition of AI systems generating non-consensual explicit content applies2026-12-02Deadline for 'nudification' apps and similar prohibited AI practices.
Reduced grace period for transparency solutions for artificially generated content2026-12-02New deadline for providers (from 6 to 3 months).
Rules for high-risk AI systems (biometrics, critical infrastructure, etc.) apply2027-12-02Adjusted timeline for specific high-risk areas.
Deadline for establishment of national AI regulatory sandboxes2027-08-02Postponed deadline for Member States.
Rules for high-risk AI systems integrated into products (lifts, toys) apply2028-08-02Extended transition period for embedded systems.

Sources and References

SourceType
Proposal for a REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL amending Regulations (EU) 2024/1689 and (EU) 2018/1139 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI) - COM(2025) 836 finalofficial
EU agrees to simplify AI rules to boost innovation and ban 'nudification' apps to protect citizens - European Commission (May 6, 2026)government
Artificial Intelligence: Council gives final green light to simplify and streamline rules - Council of the European Union (June 29, 2026)government
Digital Omnibus on AI [EU Legislation in Progress] - European Parliament Think Tank (February 12, 2026)legal

Read this article-by-article

Plain-English breakdown of 11 key articles, with cross-jurisdiction equivalents where applicable.

Open breakdown →

Requirements for a company

What an organisation has to do under Digital Omnibus on AI, at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Must do

9
  • Classify your AI system into one of four risk tiers: unacceptable, high, limited, or minimal risk.Any provider or deployer placing an AI system on the EU market or whose output is used in the EU.
  • Stop using prohibited AI practices: social scoring, manipulative subliminal techniques, exploitation of vulnerabilities, and untargeted scraping of facial images.All providers and deployers of AI systems in the EU.
  • Register your high-risk AI system in the EU public database before placing it on the market.Providers of high-risk AI systems (Annex III).
  • Establish, document, and maintain a continuous risk management system across the AI system's lifecycle.Providers of high-risk AI systems.
  • Ensure training, validation, and test datasets are relevant, representative, free of errors, and complete for the system's intended purpose.Providers of high-risk AI systems that train models on data.
  • Prepare and keep up-to-date technical documentation demonstrating conformity with the Act's requirements.Providers of high-risk AI systems.
  • +3 more in the table below

Must not do

0

Nothing in this category.

Should do

0

Nothing in this category.

Should not do

0

Nothing in this category.

Who must do what

The obligations under Digital Omnibus on AI, most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Any provider or deployer placing an AI system on the EU market or whose output is used in the EU.Classify your AI system into one of four risk tiers: unacceptable, high, limited, or minimal risk.Feb 2, 2025Article 6 & Annex IIICritical
2All providers and deployers of AI systems in the EU.Stop using prohibited AI practices: social scoring, manipulative subliminal techniques, exploitation of vulnerabilities, and untargeted scraping of facial images.
AI practices listed in this Article are prohibited.
Feb 2, 2025Article 5Critical
3Providers of high-risk AI systems (Annex III).Register your high-risk AI system in the EU public database before placing it on the market.Aug 2, 2026Article 49 & 71Critical
4Providers of high-risk AI systems.Establish, document, and maintain a continuous risk management system across the AI system's lifecycle.
A risk management system shall be established, implemented, documented and maintained.
Aug 2, 2026Article 9Critical
5Providers of general-purpose AI models with systemic risk.If your general-purpose AI model exceeds 10^25 FLOPs of training compute, notify the Commission within 2 weeks and meet systemic-risk obligations (red-teaming, cybersecurity, incident reporting).Aug 2, 2025Articles 51-55Critical
6Providers of high-risk AI systems that train models on data.Ensure training, validation, and test datasets are relevant, representative, free of errors, and complete for the system's intended purpose.Aug 2, 2026Article 10Important
7Providers of high-risk AI systems.Prepare and keep up-to-date technical documentation demonstrating conformity with the Act's requirements.Aug 2, 2026Article 11 & Annex IVImportant
8Providers of chatbots, emotion recognition, biometric categorisation, and generative AI systems.Inform users when they interact with an AI system, and label AI-generated or manipulated content (deepfakes) as artificially generated.Aug 2, 2026Article 50Important
9Providers of high-risk AI systems.Set up a post-market monitoring system to track real-world performance and report serious incidents to authorities within 15 days.Aug 2, 2026Articles 72 & 73Important

Real enforcement actions

4 actions recorded · ~€15.0M in fines

Public enforcement actions where regulators cited Digital Omnibus on AI. Helps you see how the law is actually applied in practice.

  1. FineDec 20, 2024

    Italian Data Protection Authority (Garante) vs OpenAI

    Sector: Generative AI

    €15.0M
    Fine

    Closing its 2023 investigation, Garante fined OpenAI €15M for: (1) processing user data to train ChatGPT without an adequate legal basis, (2) failing to provide transparent information to users, (3) inadequate age-verification controls, and (4) not notifying the March 2023 breach within 72 hours. Garante also ordered OpenAI to run a six-month public awareness campaign explaining how ChatGPT works. Cited GDPR; substantively this is the closest thing to AI-Act-style enforcement of a generative AI service in the EU to date.

    Source ↗
  2. Enforcement orderMar 6, 2024

    Spanish Data Protection Agency (AEPD) vs Tools for Humanity (Worldcoin)

    Sector: Biometric AI / crypto

    AEPD issued a precautionary three-month order halting Worldcoin's iris-scanning operations in Spain after complaints that the project was collecting biometric data with inadequate consent (including from minors) and providing insufficient information about retention and rights. Cited GDPR's special-category data rules — but iris-scan for identity is precisely the kind of biometric categorisation that the EU AI Act prohibits or treats as high-risk under Articles 5 and Annex III §1.

    Source ↗
  3. OtherSep 20, 2023

    Polish Personal Data Protection Office (UODO) vs OpenAI

    Sector: Generative AI

    UODO opened a formal investigation into OpenAI after a complaint that ChatGPT generated false personal information about an individual and that OpenAI provided no mechanism for the data subject to correct or delete it. The complaint targets transparency, accuracy and data-subject rights under GDPR — issues that overlap with EU AI Act obligations on transparency to affected persons (Article 50) and provider risk-management duties for generative AI.

    Source ↗
  4. Service ban / suspensionMar 31, 2023

    Italian Data Protection Authority (Garante) vs OpenAI (ChatGPT)

    Sector: Generative AI

    Garante temporarily banned ChatGPT in Italy over: (1) no legal basis for processing personal data to train the model, (2) no age-verification despite obvious minor exposure, (3) inadequate transparency to users, and (4) a March 2023 data leak exposing other users' conversations. OpenAI restored service on 28 April 2023 after meeting Garante's interim requirements. Legal basis cited was GDPR — but the substance (training-data transparency, age-gating of a generative AI service, user-facing disclosure) is exactly what EU AI Act Articles 50 (transparency for generative AI) and 52 (deepfake labelling) now address.

    Source ↗

© Regulations.AI — created on 05-Feb-2026 using Gemini 2.5 Flash · updated on 26-Aug-2026