Regulatory  ·  2026-07-30

EU 'Digital Omnibus on AI' (Regulation 2026/1744) enters into force — high-risk AI Act deadlines postponed, new CSAM/nudification ban added

RegulatoryHigh impactEuropean Union
Regulation (EU) 2026/1744, the 'Digital Omnibus on AI,' was signed 8 July 2026, published in the Official Journal on 24 July 2026, and entered into force on 27 July 2026 (three days after publication, per Article 4). It amends the AI Act (2024/1689), the aviation safety regulation, and the machinery regulation. It postpones compliance for standalone high-risk AI systems (Annex III — biometrics, employment, credit scoring, law enforcement, education) from 2 August 2026 to 2 December 2027, and for high-risk AI embedded in regulated products (Annex I) from 2 August 2027 to 2 August 2028. It also adds a new Article 5 prohibited practice — AI systems that generate non-consensual intimate imagery/CSAM ('nudifier' apps) — with a compliance deadline of 2 December 2026, carrying the AI Act's top penalty tier (€35M or 7% global turnover). Machine-readable watermarking obligations for generative AI already on the market are also extended to 2 December 2026. Widely analyzed in governance/compliance press through 27-29 July 2026 as the most consequential AI Act development of the window.
This is a binding amendment to the EU AI Act — the world's most influential comprehensive AI law — materially delaying core high-risk compliance obligations for up to 16 months while simultaneously creating a new, immediately-consequential prohibited practice with the harshest penalty tier in the Act. Every organization deploying high-risk AI systems in the EU, and every generative AI provider marketing in the EU, must recalibrate compliance timelines and address the new CSAM/nudification prohibition by December 2026.
Organizations providing or deploying standalone high-risk AI systems (Annex III) should recalibrate compliance planning to the new 2 December 2027 deadline; providers of AI systems capable of generating non-consensual intimate imagery must implement refusal training/output controls or cease EU offering by 2 December 2026; generative AI providers must implement machine-readable watermarking by 2 December 2026.
EUR-Lex — Regulation (EU) 2026/1744Future of Privacy Forum — AI Act Implementation Timeline: What Changes Under the AI Omnibus
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →