Yes. Since July 27, 2026, it has been Regulation (EU) 2026/1744, the digital omnibus package on AI, has entered into force, and it shifts the high-risk obligations from the AI Act to December 2, 2027, and August 2, 2028. However, the general effective date of August 2, 2026, remains in place, as do the transparency rules. As part of the same changes, two new prohibited practices will be added, the AI literacy requirement will be scaled back, and the AI Agency will be granted powers derived directly from competition law.
What Happened Beforehand
The European Commission proposed the Digital Omnibus on AI on November 19, 2025. The European Parliament adopted its position on June 16, 2026; the Council adopted its decision on June 29, 2026; the regulation was adopted on July 8, 2026; and it was published on July 24, 2026. Since the general date of application of the AI Act fell on August 2, 2026, the legislature explicitly opted for urgent entry into force: the third day after publication, i.e., July 27, 2026.
In Recital 2, the legislator itself explains the reason for the intervention. Because the standards that providers are required to meet were introduced too late, and because the national governance and conformity assessment frameworks were established too late, the regulatory burden turned out to be heavier than expected.
What the Omnibus Regulation Changes
New dates for high-risk obligations
Article 113 of the AI Act has been amended. The Requirements for High-Risk AI Systems The provisions of Chapter III, Sections 1 through 3, shall now apply as of December 2, 2027, to systems designated as high-risk pursuant to Article 6(2) and Annex III, and as of August 2, 2028, for systems designated as such pursuant to Article 6(1) and Annex I. One provision is expressly excluded from this deferral, namely Article 6(5), concerning the guidelines for classification.
What remains unchanged is at least as important. The general effective date of August 2, 2026, remains in effect; the prohibited practices that have been in effect since February 2, 2025, remain in effect; and the rules for general-purpose AI models remain in effect. Articles 102 through 110 will take effect on July 27, 2026.
Two related deadlines follow. Member States are not required to have at least one AI regulatory sandbox operational until August 2, 2027, and the grace period under Article 111(2) for systems already on the market has been realigned with the new dates set out in Chapter III.
Two New Prohibited Practices
Article 5, paragraph 1, is amended to include two new subparagraphs, effective as of December 2, 2026. Subparagraph (b-a) prohibits the placing on the market, putting into service, and use of an AI system that generates or manipulates realistic images, videos, audio, or similar material depicting the intimate parts of an identifiable natural person, or of an identifiable natural person engaging in explicit sexual acts, without that person’s freely given, specific, informed, unambiguous, and explicit consent.
Subparagraph (b)(ter) does the same for systems that generate or manipulate material or a representation within the meaning of Article 2, subparagraphs (c) and (e), of Directive 2011/93/EU on combating the sexual abuse and sexual exploitation of children and child pornography, except when the act is not considered unlawful under national law. Recital 13 refers in this context to government action in criminal proceedings and the evaluation of a system through red teaming.
The scope is adjusted in two new paragraphs. The prohibition applies to the provider only if that output is the intended purpose of the system, or if the system’s design, training, architecture, capabilities, or user-oriented functionalities make that output a reasonably foreseeable and reproducible result without requiring significant technical modifications, while the system does not include reasonable and adequate technical safeguards. For the person responsible for use, the prohibition applies only if they use the system specifically for that purpose. Anyone who edits existing material without increasing the exposure of depicted intimate body parts or altering the nature of the depicted behavior is not considered to be manipulating within the meaning of this provision.
Obligations That Are Becoming Less Burdensome
Article 4 on AI literacy has been rewritten. Providers and those responsible for use are no longer required to ensure that an adequate level exists, but must take measures that support the development of AI literacy, and the text explicitly adds that they are not required to guarantee a specific level for individuals.
The criteria for high-risk classification have also been tightened. The definition of “safety component” in Article 3, point 14, links the safety function to the purpose intended by the provider, and the new Article 6(1a) excludes systems used exclusively for non-safety-related user assistance, performance optimization, service efficiency, automation, convenience, or quality control. However, if the system fails in a way that endangers health or safety, it remains a safety component.
In addition, SMEs and the new category of small mid-cap companies will benefit from simplified technical documentation and a more proportionate quality management system; the impact assessment regarding fundamental rights may cross-reference the data protection impact assessment under the General Data Protection Regulation (GDPR), and systems that comply with Regulation (EU) 2024/2847 are deemed to comply with the cybersecurity requirements of Article 15 of the AI Act. The legal basis for processing special categories of personal data for the purpose of detecting and correcting bias has been moved from Article 10, paragraph 5 to a new Article 4 bis, and now also applies to controllers of high-risk systems and to providers and controllers of other AI systems and models.
An AI agency with powers under competition law
The European Artificial Intelligence Office, or the AI Office for short, is established pursuant to amended Article 75, paragraph 1, has exclusive jurisdiction over AI systems built on a general-purpose AI model when the model and the system come from the same provider or from providers within the same company, and over AI systems that constitute a very large online platform or a very large online search engine within the meaning of the Digital Services Act (DSA) are part of or integrated into those systems. There are, however, four exceptions to that exclusivity for the first category, including systems related to Annex I products and the systems of law enforcement agencies, border control authorities, and financial institutions.
The new Articles 75 bis through 75 quinquies supplement this with a set of tools that competition lawyers will immediately recognize: requests for information by simple request or by decision; inspections involving entry into premises, copying of documents, and the sealing of premises or documents; the ability to make commitments binding and close the case, and the authority to determine noncompliance on its own and impose the penalties set forth in Article 99. In addition, there are daily penalty payments of up to 5 % of the average daily income or the average global annual revenue in the preceding fiscal year, per day. Furthermore, the AI agency can fully recover all its supervision and enforcement costs from the operator in question.
There are limits to this. The statute of limitations is three years; the Court of Justice of the European Union has full jurisdiction to review decisions imposing fines and periodic penalty payments and may annul, reduce, or increase them, and Article 75d enshrines the rights of the defense and access to the case file subject to negotiated disclosure.
Legal analysis and interpretation
The ban now also applies to those who build the instrument
Under Belgian sexual criminal law, two acts are punishable in connection with intimate visual material. The act of creating the image falls under voyeurism, Article 417/8 of the Criminal Code (Sw.), and share the image with the non-consensual distribution of sexually explicit content, Articles 417/9 and 417/10 of the Sw. As of September 1, 2026, these will become Articles 135, 136, and 137 of the New Penal Code. Neither provision mentions the offering of the application.
The person who builds the application is not beyond reach, but remains at a distance. They may be an accomplice if they provide a means knowing that it will be used to commit the crime (Article 67 of the Penal Code), and as of September, they are considered a participant and will be punished as a perpetrator (Article 19 of the new Penal Code). This requires, in each case, a specific crime committed by a user, plus proof that the developer knew what his tool would be used for.
This is the scope of Article 5(1), first subparagraph, point (b-a). Not only is the use prohibited, but also the placing on the market and the putting into service. Within the limits of paragraph 1a, the mere offering of the device thus constitutes the prohibited conduct, without the need for a user to have first acted upon it.
Moreover, in the case of fully generated images, there is already a problem with their creation. During the debate on the Act of March 21, 2022, Professor Catherine Van de Heyning and Professor Liesbet Stevens called for the criminalization to be extended to realistic fake nudes. The minister then read a memorandum from the Commission on Criminal Law Reform: in the case of fully manipulated images, voyeurism does not appear to be a factor, because that criminalization—unlike that for images of sexual abuse of minors—is linked to the consent of a specific person (Report, House of Representatives, 2021-22, December 23, 2021, No. 55-2141/006, 65–66). The proposals for expansion were not implemented.
There is a tension in that response. Both professors described deepnudes as images of a recognizable person, created from existing photos of that person. The minister took the opposite view: in a full deepnude, the real person is not recognizable, so no one can give or withhold consent. The European ban adopts the first interpretation and sets the standard based on realism, because according to Recital 12, it concerns the depiction of a face, voice, or body in a credible, lifelike manner, even if it does not fully correspond to the person’s actual appearance.
Where the discussion will take place
The provider’s liability depends on two open-ended criteria: whether the output is reasonably foreseeable and reproducible without significant technical modifications, and whether the security measures are reasonable and adequate. Recital 12 provides a series of examples, ranging from data cleaning and refusal training to prompt filters, content classification, usage restrictions, abuse detection, and a reporting and action mechanism.
That same recital sets the standard that will determine the dispute: the measures are adequate if they are consistent with the most advanced measures and, in each specific case, demonstrably prevent or sufficiently reduce the risk of such material, including any reasonably foreseeable circumvention. The regulation does not further define these concepts, even though the ban takes effect as early as December 2, 2026. The first cases will therefore revolve around a technical expert’s assessment of what was standard practice at a given time.
From the perspective of the person responsible for the system’s use, the provision is notably limited. Only those who use the system for the purpose of creating this material are subject to the prohibition; unintentional generation is not. For the victim, this means that the quickest route is usually still national law, because Article 5 is enforced by market regulators, not by the victim themselves.
A postponement is not an exemption
The postponement applies only to Chapter III, Sections 1 through 3. The transparency requirements of Article 50 remain in effect as of August 2, 2026, and the new Article 111, paragraph 4, grants only providers of AI systems that were placed on the market before August 2, 2026, and that generate synthetic audio, image, video, or text content, until December 2, 2026, to comply with Article 50, paragraph 2. Anyone releasing a new system must comply by August 2, 2026. Unlike the grace period for high-risk systems in Article 111, paragraph 2, this transitional provision does not include a threshold for a significant change: anyone who thoroughly updates their existing system will not lose the four additional months.
There is also a contradiction within the regulation itself. The reason for the postponement is that the standards and national structures are not yet in place, but the same text already grants the AI Agency the authority to enter and seal premises, and to have pre-market conformity assessments conducted at the provider’s expense. Article 64(3), on the other hand, stipulates—without prejudice to the budgetary procedure—that the AI agency will receive sufficient resources. Whether enforcement will follow is therefore no longer a legal question but a matter of capacity.
One constitutional safeguard deserves attention. If national law requires a judicial authorization for an on-site inspection, the national court reviews only whether the coercive measures are arbitrary or excessive. The court may not review the necessity of the investigation or request the AI agency’s file; the legality of the decision remains the exclusive purview of the Court of Justice.
Specifically, what does this mean?
For providers of generative AI systems. The relevant date is December 2, 2026, not 2027. Now document which technical measures you have implemented, why they align with the most advanced measures, and how you follow up on and correct reported abuses, as the latter is part of the assessment. Explicitly test whether your security can be circumvented without significant technical changes.
For providers of high-risk systems. Extra time does not constitute a break. The grace period applies per type and model, and a significant change to the design after the new date brings the system into full compliance, including the conformity assessment. Re-evaluate the qualification: the more restrictive definition of a safety component may exclude a system from the scope of application, but you must document that assessment and provide it upon request.
For those responsible for use. The impact assessment regarding fundamental rights may cross-reference your data protection impact assessment, which makes it worthwhile to align the two documents. If you wish to conduct your own bias testing using special categories of personal data, you may do so under Article 4 bis, but only within the strict conditions of that article and the rules of the data protection law. It is a privilege, not an obligation.
For government agencies. For high-risk systems intended for use by government agencies, the deadline remains August 2, 2030. This deadline will not be extended and should already be included in the multi-year planning.
Frequently asked questions (FAQ)
Do I need to have my AI system assessed against the high-risk rules of the AI Act right now?
Not necessarily. The obligations set forth in Chapter III will apply as of December 2, 2027, for stand-alone high-risk systems, and as of August 2, 2028, for systems that are incorporated as safety components in a regulated product. However, the qualification assessment and technical documentation may already be underway.
Are apps that digitally undress people now banned?
Effective December 2, 2026, the AI Act prohibits the placing on the market, putting into service, and use of AI systems that generate or manipulate realistic intimate imagery of an identifiable person without explicit consent. Under Belgian law, the creation and distribution of such material may already be punishable as a criminal offense.
Will the requirement to label AI-generated content remain in effect as of August 2, 2026?
Yes. The extension does not affect the transparency requirements. Only providers of systems that generate synthetic audio, image, video, or text content and that were placed on the market before August 2, 2026, have until December 2, 2026, to comply with the labeling requirement set forth in Article 50(2).
Conclusion
The digital omnibus bill postpones the high-risk obligations to December 2, 2027, and August 2, 2028, weakens the AI literacy requirement and narrows the definition of a safety component, but at the same time adds two new prohibited practices and grants the AI agency powers of inspection, compliance enforcement, fines, and coercive measures. The resulting agenda is twofold: in the short term, the transparency and prohibition rules of August 2 and December 2, 2026; in the longer term, the high-risk issues.



