Regulation (EU) 2026/1744, the Digital Omnibus on AI
The first amendment to the EU AI Act since 2024. It is narrower than the headlines suggested and broader than the deadline change everyone reported: alongside the deferral it added two prohibitions, rebuilt the supervisory architecture around the AI Office, and left the general-purpose AI regime untouched.
The legislative record
| Commission proposal | 19 November 2025, as part of the wider Digital Omnibus simplification package |
| First trilogue | 28 April 2026, ended without agreement |
| Provisional political agreement | 7 May 2026; confirmed by member state representatives in Council 13 May 2026 |
| European Parliament adoption | 16 June 2026 |
| Council approval | 29 June 2026 |
| Signature | 8 July 2026 |
| Official Journal publication | 24 July 2026, L series |
| Entry into force | 27 July 2026: third day following publication, expedited given the proximity of 2 August |
| Instruments amended | Reg. (EU) 2024/1689 (AI Act); Reg. (EU) 2018/1139 (civil aviation); Reg. (EU) 2023/1230 (machinery) |
Entry into force is not the same as application
The amendments became part of the AI Act text on 27 July 2026. That does not make every amended provision enforceable from that date: the new Article 5 prohibitions apply from 2 December 2026, and the deferred high-risk obligations from 2 December 2027. Expert analysis: public commentary has repeatedly presented the new prohibitions as immediately operative. They are not.
Where this usually goes next
Three situations account for most people reading this page. Each has a different answer.
A deal is blocked on an AI questionnaire
Legal will not sign until you can evidence how AI is governed. HumanAudit’s AI Trust Package is a fixed $3,500 over five business days: a public trust page, a pre-filled SIG Lite / CAIQ / SSPA Section K questionnaire bank, and your AI inventory and classification.
You need ISO/IEC 42001 documentation
23 clause-mapped AIMS documents with all 38 Annex A controls pre-populated, editable and yours to keep, from $199. Or score your gaps first: 18 questions, free, no signup to begin.
You are not sure what reaches you
Twenty minutes with the founder. No prep, no deck, straight to the person accountable for the work. If none of this applies to you, you get told that on the call.
This reference is published by HumanAudit Inc. Not a law firm, not an accredited certification body, not a registered auditor. We build documentation, your counsel interprets it, and an accredited body of your choosing certifies you. How this is funded →
What changed
| Area | Before | After |
|---|---|---|
| Annex III high-risk | 2 August 2026 | 2 December 2027: a fixed date, replacing the proposed standards-conditional trigger |
| Annex I embedded high-risk | 2 August 2027 | 2 August 2028 |
| Art. 50(2) marking | 2 August 2026 for all | 2 August 2026 for new systems; 2 December 2026 for generative systems already on the market |
| Article 5 | Eight prohibitions | Plus two new prohibitions, NCII/NCIM and CSAM generation, from 2 December 2026 |
| AI Office | GPAI model supervision | Exclusive competence over AI systems built on a GPAI model by the same provider or group, and over AI systems in DSA-designated VLOPs/VLOSEs; consolidated investigative and enforcement powers |
| Regulatory sandboxes | 2 August 2026 | 2 August 2027 |
| SMEs / small mid-caps | Lower-of fine rule; simplified documentation power | Additional relief reported to include reduced fine caps, proportionate QMS and priority sandbox access |
What deliberately did not change
- The Article 5 prohibitions in force since 2 February 2025: unchanged, and now joined by two more.
- Chapter V general-purpose AI, Articles 51–55: systemic-risk thresholds and model provider obligations untouched in substance.
- Article 50 transparency: on its original schedule.
- Article 49 registration: on its original schedule.
- Penalty ceilings: €35M/7%, €15M/3%, €7.5M/1%.
- Article 2 territorial scope: the extra-territorial hooks are intact.
- Annex III itself: the same high-risk use cases. The obligations arrive later; they do not arrive smaller.
Article 4 AI literacy — resolved
Article 1, point 5 of Reg. (EU) 2026/1744 replaced Article 4 in full. The duty changed from ensuring a sufficient level of AI literacy to taking measures to support its development, with an express statement that no particular level need be guaranteed. It was not deferred and still binds every provider and deployer at every tier. A new Article 4a was also inserted. Article 4 as amended →
Status labels on this page
Verified fact: The legislative record dates, the deferral scope, the two new prohibitions and their 2 December 2026 date, the AI Office competence changes, and the unchanged provisions listed above.
Expert analysis: The observation that entry into force has been conflated with application in public commentary.
Unsettled: The precise content of the SME relief and the status of Article 4 / any new Article 4a. Read the consolidated text.
Re-check anything written before 27 July 2026
Any compliance plan, board paper, vendor questionnaire response or published guide dated before 27 July 2026 describes a version of the AI Act that no longer exists. The cheapest audit you can run this month is a date check on your own documents.
Not sure where you sit?
The classifier maps your system against Articles 5, 6, 50 and Annex III. Twelve questions, no email.
Frequently asked
What is Regulation (EU) 2026/1744?
Regulation (EU) 2026/1744 is the Digital Omnibus on AI, the first set of amendments to the EU AI Act since its adoption in 2024. It amends Regulation (EU) 2024/1689 together with Regulation (EU) 2018/1139 on civil aviation and Regulation (EU) 2023/1230 on machinery. It was adopted by the European Parliament on 16 June 2026, approved by the Council on 29 June 2026, signed on 8 July 2026, published in the Official Journal on 24 July 2026, and entered into force on 27 July 2026, the third day following publication.
What did the Digital Omnibus on AI change?
Five things principally. It deferred Chapter III Sections 1 to 3 high-risk obligations to 2 December 2027 for stand-alone Annex III systems and 2 August 2028 for Annex I embedded systems, replacing the proposed standards-conditional trigger with fixed calendar dates. It added two Article 5 prohibitions covering non-consensual intimate imagery and CSAM generation, applying from 2 December 2026.
It gave the AI Office expanded and in some cases exclusive supervisory competence. It deferred national regulatory sandboxes to 2 August 2027. And it introduced relief for SMEs and small mid-caps. It did not change the GPAI regime in substance or the penalty ceilings.
Did the Digital Omnibus change the general-purpose AI rules?
Not in substance. Articles 51 to 55, covering systemic risk thresholds and model provider obligations, have applied since 2 August 2025 and were left as they were. What changed is supervision: the AI Office gained a consolidated set of supervisory and enforcement powers, including exclusive competence over AI systems based on a general-purpose AI model developed by the same provider or group, and over AI systems integrated into services designated as very large online platforms or search engines under the Digital Services Act.
Is the EU AI Act now final?
The Digital Omnibus on AI is final and in force. Other work continues: harmonised standards under CEN-CENELEC JTC 21 are still in development, Commission guidance and implementing acts are being issued, and a separate data and cybersecurity omnibus package remains under negotiation. The AI Act itself will keep moving through guidance and standards rather than through further amendment in the near term.