EU AI Omnibus takes effect with revised implementation deadlines

Europe just bought itself more runway — and sharpened one ban. On 27 July 2026, the AI Omnibus entered into force across the EU. High-risk AI Act duties that were barreling toward an earlier cliff now sit on later calendars, while systems that generate non-consensual intimate imagery move firmly into the prohibited pile.
This is simplification with teeth, not a quiet repeal of the AI Act.
New Annex III and Annex I compliance dates
The Commission’s notice is blunt on timing. Rules for Annex III high-risk systems — biometrics, critical infrastructure, education, employment, migration, justice, and the rest of that sensitive list — apply from 2 December 2027. High-risk AI embedded in physical products covered by Annex I (machinery, toys, lifts, and similar) applies from 2 August 2028.
That is the headline for product and compliance teams who were staring at 2026 as the hard wall. GPAI obligations and earlier prohibitions already on the books stay in the picture; the Omnibus is a targeted delay-and-simplify package, born from the November 2025 digital omnibus proposal and the May 2026 political agreement. If you build Annex III tooling, the deadline moved. If you were hoping the whole Act would evaporate, it did not.
Sandbox access and SME simplifications
Brussels is also widening the on-ramp. Measures once reserved for SMEs now reach small mid-cap companies (SMCs), including simplified documentation paths. Access to regulatory sandboxes expands, and an EU-level sandbox joins the national ones so firms can test under supervision instead of guessing in the dark.
Other burden cuts: AI literacy duties get simplified, with the Commission and Member States taking a stronger promotion role; registration of certain exempted systems in the EU central database gets lighter. Bias-detection work can process special categories of personal data when the point is detecting and correcting bias. The package is pitched as innovation support without shredding fundamental-rights guardrails. Read it as permission to test and grow under proportionate rules — still rules.
Expanded AI Office oversight
Governance shifts toward the center. The AI Office gains extended oversight of certain AI systems, including those built on general-purpose models and embedded in large online platforms and search engines. The Omnibus also clarifies how the AI Act sits beside other EU product and safety laws and simplifies procedures for conformity assessment bodies.
That matters for platforms that thought GPAI model rules and product-level duties would stay cleanly separated forever. If your system is a GPAI stack inside a mega-platform surface, expect the AI Office’s file on you to get thicker, not thinner. Fragmented national supervision was already a complaint; centralizing pieces of it is the Commission’s answer.
New bans on non-consensual intimate imagery systems
The rights side is not all delay. The Omnibus prohibits AI systems that generate non-consensual sexually explicit and intimate content or child sexual abuse material — the “nudification app” ban called out in the Commission’s own summary. On the Commission’s AI Act explainer, that prohibition is sequenced to apply from December 2026, separate from the high-risk compliance pushout.
Analysis: the Omnibus is a political bargain in one statute. Industry gets calendar relief and SMC-friendly paperwork. Platforms get a sharper Brussels overseer. Victims of non-consensual intimate deepfakes get a clearer ban. For builders, the actionable split is simple: high-risk Annex clocks moved to late 2027 and mid-2028; intimate-image generators do not get that mercy. Watch the implementing guidance and sandbox intake windows next — that is where the delay either becomes usable time or just a longer scramble.



