Is the AI Act Being Watered Down? What the Digital Omnibus on AI Really Means for Businesses

The Digital Omnibus on AI is now in effect. It postpones key deadlines, simplifies implementation—especially for small and medium-sized businesses—and modifies certain requirements of the AI Act. However, this does not constitute a deregulation of AI. Here’s what businesses need to know now.

The Digital Omnibus Is Here—But the AI Act Remains

The amendment to the AI Act, commonly referred to as the ‘Digital Omnibus on AI’, was published in the Official Journal of the EU on July 24, 2026, and entered into force on July 27, 2026. This marks the end of a legislative process that the European Commission had initiated in November 2025 to make the implementation of the AI Act more practical, reduce bureaucracy, and strengthen the competitiveness of European companies.

However, this is precisely where the biggest misconception currently circulating in the discussion stems from: “The AI Act has been completely postponed”—that is incorrect.

The Digital Omnibus primarily postpones the implementation deadlines for obligations related to so-called high-risk AI. In addition, it makes implementation easier, particularly for smaller companies, and adjusts individual regulations. The risk-based core concept of the AI Act, however, remains in place. Nor is the category of high-risk AI being abolished.

As a result, companies gain some breathing room in certain areas and are actually relieved of some burdens in others. However, the Omnibus does not provide a reason to put AI compliance on hold altogether.

The Most Important Change: More Time for High-Risk AI

The most significant point in practical terms concerns the effective date of the obligations for high-risk AI systems. According to the original version of the AI Act, the relevant requirements were largely set to take effect on August 2, 2026. This deadline is now being split up and significantly postponed.

For so-called stand-alone high-risk systems, the relevant requirements will now take effect on December 2, 2027. These include, for example, certain AI systems used for recruiting and human resources management, education, or creditworthiness assessment.

For high-risk AI integrated as a safety component into already regulated products—such as certain medical devices or machines—a longer deadline applies, extending to August 2, 2028.

The rationale behind this is primarily pragmatic. In particular, the harmonized technical standards that companies are expected to follow during implementation were not available in time . Regulatory and certification structures are also still being established in some cases.

For companies, the postponement is therefore good news for now: They have more time to inventory and classify AI applications, define responsibilities, engage suppliers, and establish the necessary governance, risk, and documentation structures.

However, the extra time is merely a breather, not a free pass. More time does not mean less responsibility.

What Was Not Postponed

That is precisely why it’s worth taking a look at what the Digital Omnibus has not changed.

The existing bans on certain AI practices remain in effect. Likewise, the requirements for providers of general-purpose AI models (GPAI) will not be postponed to 2027 or 2028.

Likewise, the transparency requirements of the AI Act for certain AI systems and synthetic content will generally apply as planned starting August 2, 2026. So, for example, anyone who generates AI-generated or manipulated content or offers corresponding systems cannot simply invoke the new transition periods across the board.

In addition, there is a point that is occasionally overlooked in the discussion surrounding the AI Act: AI is not regulated exclusively by the AI Act. The GDPR, labor law, the German anti-discrimination law (AGG), copyright law, and general duties of care under civil law continue to apply regardless of the AI Act’s transition periods.

This is evident, for example, in the use of AI in human resources. The specific high-risk requirements of the AI Act may take effect later. However, risks of discriminatory applicant selection or unlawful processing of personal data already exist today.

AI Literacy: Less Stringent Training Requirements

An interesting change concerns so-called AI literacy.

The original version of Article 4 of the AI Act required providers and deployers of AI systems to take measures to ensure a sufficient level of AI literacy among their staff and other persons dealing with the operation and use of AI systems. The Digital Omnibus weakens this direct corporate obligation and shifts the focus more toward supporting and promoting AI literacy.

However, this should not lead to the conclusion that employee training will be unnecessary in the future.

Particularly for high-risk systems, competence requirements continue to arise from the rules on human oversight. If a human is expected to oversee an AI-supported process, that person must also be capable of recognizing the system’s errors and limitations and intervening where necessary.

Even outside of high-risk applications, it will be nearly impossible to establish robust AI governance if employees are unaware of both the capabilities and limitations of the systems in use. Training and awareness-raising measures therefore remain essential from a compliance, data protection, and risk perspective—even if the AI Act itself becomes less stringent in this regard.

Relief for SMEs—and Now Also for Small Mid-Caps

A second focus of the Digital Omnibus is introducing meaningful simplifications for smaller companies.

A notable new development is the introduction of an additional category of companies: alongside traditional small and medium-sized enterprises (SMEs), there are now so-called small mid-caps (SMCs). This category generally covers companies with fewer than 750 employees and an annual turnover of no more than 150 million euros or an annual balance sheet total of no more than 129 million euros.

This means that in the future, numerous companies that have already outgrown the traditional SME definition will also be able to benefit from these simplified requirements. This can be particularly relevant for growing technology companies.

The preferential treatment includes, among other things, simplified requirements for technical documentation, more proportionate requirements for quality management systems, preferential access to AI regulatory sandboxes, and adjusted upper limits on fines.

This represents an important difference from the extension of high-risk deadlines: The deadline extension primarily gives companies more time. The SME and SMC regulations, on the other hand, can actually reduce the regulatory burden.

Companies that fall below the relevant thresholds should therefore review which relief measures are specifically available to them.

A Quick Overview of Other Changes

In addition, the Digital Omnibus contains several other changes that will not be equally relevant for every company.

Notably, new prohibitions have been introduced regarding AI-generated child sexual abuse material and certain non-consensual sexualized deepfakes. The Omnibus also provides for a transitional provision for existing systems for labeling synthetic content.

Another point of interest in practice is bias detection: the ability to process special categories of personal data—under strict conditions—for the purpose of detecting and correcting biases is being extended to certain non-high-risk systems.

With regard to post-market monitoring, the obligation to continuously monitor high-risk systems remains in place, but the specific implementation is to become more flexible. The deadline for establishing national AI regulatory sandboxes is also being postponed.

Finally, the role of the European AI Office is being strengthened. Particularly in the area of general-purpose AI models, the European supervisory authority is being granted broader powers to request information, investigate risks, and enforce measures as necessary.

What does this mean for companies now?

In my view, the most important practical implication of the Digital Omnibus is not to “wait and see,” but to reprioritize.

Immediately

Companies should first dispel the myth internally that the AI Act has been postponed entirely. Otherwise, requirements that are already in effect or will apply in the near future can easily be overlooked.

Those who do not yet have a robust AI inventory should also establish transparency regarding actual AI usage: Which systems are being used? For what purpose? With what data? Who is responsible? And which risk category applies?

In addition, existing AI policies and internal guidelines should be reviewed. Particular attention should be paid to the often-underestimated “shadow AI”—that is, the use of unauthorized AI services by employees.

Prepare

For high-risk applications, the time gained should be actively utilized. Risk management, human oversight, responsibilities, and documentation can now be established in a structured manner, rather than later under time pressure.

SMEs and larger mid-sized companies should also check whether they fall under the SME or the new SMC category and what specific relief measures apply to them as a result.

Monitor

The practical implementation of numerous requirements has not yet been finalized. In particular, the harmonized technical standards will have a significant impact on how high-risk obligations can be implemented.

Companies should also keep an eye on further guidelines from the European Commission and the AI Office—for example, regarding documentation or post-market monitoring.

For management and the legal department, a pragmatic approach is therefore recommended: Not every detailed requirement needs to be implemented today. However, the company should know what AI it uses, what risks are associated with it, who is responsible for it, and which regulatory requirements will become relevant and when.

Conclusion: Make Use of the Extra Time

The Digital Omnibus is not a green light, but it does provide companies with one key thing: time. The core obligations for high-risk AI will take effect later. SMEs and small mid-caps also benefit from genuine regulatory relief.

However, this does not mean a departure from European AI regulation. The risk-based framework of the AI Act remains in place—as do numerous obligations that are already in effect or will apply in the near future. And even outside the scope of the AI Act, data protection, anti-discrimination laws, copyright, and general due diligence requirements remain relevant.

Companies can therefore now plan and prioritize their AI compliance more realistically. On the other hand, those who use the newly gained time buffer as an excuse to put governance, AI inventory, and risk classification on hold for the time being are likely to face the same tasks by the end of 2027—only this time under time pressure.

WEITERE ARTIKEL ZU DIESEM THEMA