EU AI Act 2026/1744 Digital Omnibus on AI 24 July 2026: Key changes and what leaders must do now

Market UpdatesJuly 24, 2026 DocsOrb
EU AI Act 2026/1744 Digital Omnibus on AI 24 July 2026: Key changes and what leaders must do now

The EU AI Act has been amended, introducing stricter deadlines, new prohibited practices, and a more powerful AI Office. High-risk AI compliance now starts December 2027, with bans on non-consensual intimate material and child sexual abuse AI effective December 2026. Smaller players gain simplified requirements, but accountability remains unchanged. Leaders must act now—this is the window to build robust AI governance before enforcement begins.

eu ai act 2026 amendmentsai governance compliance deadlineshigh-risk ai regulation changeseu ai office enforcement powersai prohibited practices 2026ai literacy requirements euai compliance for smesgenerative ai marking obligations

Key Points

  • The EU AI Act has been amended via Regulation (EU) 2026/1744, the Digital Omnibus on AI, published on 24 July 2026 and effective from 27 July 2026.
  • New deadlines for high-risk AI compliance: 2 December 2027 for standalone Annex III systems and 2 August 2028 for AI embedded in Annex I products.
  • Two new prohibited practices: AI systems generating non-consensual intimate material ("nudification" apps) and child sexual abuse material, effective 2 December 2026.
  • Providers remain liable if misuse is a reasonably foreseeable outcome, even if unintended, unless adequate safeguards are in place.
  • The definition of "safety component" has narrowed, excluding AI used for user assistance, performance optimization, or convenience.
  • AI literacy requirements are relaxed but still require providers and deployers to support literacy without guaranteeing specific outcomes.
  • The AI Office gains expanded powers, including exclusive competence over AI systems built on general-purpose models and those integrated into VLOPs/VLOSEs.
  • Simplified compliance for smaller players: Small mid-cap enterprises (SMCs) are now included, with streamlined documentation and registration.
  • Generative AI systems already on the market before 2 August 2026 must comply with Article 50(2) marking obligations by 2 December 2026.
  • The amendments simplify compliance but do not reduce accountability—organizations must use the extended timeline to build robust AI governance.
  • Leaders should act now to align policies, governance frameworks, and employee practices before enforcement deadlines.

The EU AI Act amendments are here: what senior leaders must do before enforcement begins

The European Union has just published the Digital Omnibus on AI—Regulation (EU) 2026/1744—in the Official Journal. It enters into force on 27 July 2026, reshaping the compliance landscape for high-risk AI, prohibited practices, and governance oversight. For HR, compliance, risk, and operations leaders, these changes are not just updates; they are a signal to accelerate AI governance programs before enforcement deadlines arrive.

Here’s what changed, why it matters, and what your organization must do now.

New deadlines: fixed dates, no more waiting for standards

The most immediate impact is the shift from conditional to fixed compliance deadlines. High-risk AI systems under Chapter III, Sections 1–3 now face two clear dates:

  • 2 December 2027: Compliance required for standalone AI systems listed in Annex III (e.g., biometric identification, critical infrastructure, employment management).
  • 2 August 2028: Compliance required for AI systems embedded in products covered by Annex I (e.g., machinery, medical devices, toys).

These dates are no longer tied to the availability of harmonised standards. That means organizations can no longer delay preparation while waiting for technical guidance. The clock is now running—and regulators expect readiness by the deadline, not after.

For leaders, this is a strategic opportunity: the extended timeline is not a reason to pause. It’s the window to build governance frameworks, align policies, and train teams before enforcement begins. Read our guide on preparing for the EU AI Act to understand the exact steps your team should take now.

Two new prohibited practices: liability where misuse is foreseeable

The amendments introduce two new prohibited AI practices, effective 2 December 2026:

  • AI systems that generate or manipulate non-consensual intimate material (commonly referred to as “nudification” apps).
  • AI systems that generate or manipulate child sexual abuse material.

These prohibitions are not limited to intentional misuse. Providers are liable if the prohibited output is a reasonably foreseeable and reproducible outcome—even if the misuse was unintended. The only defense is demonstrating that the system includes reasonable and adequate technical safeguards to prevent such outcomes.

This is a significant shift in accountability. It means that deploying AI without robust guardrails—such as content filters, misuse detection, and real-time monitoring—exposes organizations to legal and reputational risk. The adequacy of those safeguards will be the battleground in enforcement actions. For HR and compliance leaders, this underscores the need for enterprise-grade AI safety frameworks that go beyond basic compliance.

A narrower definition of “safety component” reshapes the high-risk perimeter

The amendments clarify that AI systems used solely for user assistance, performance optimization, service efficiency, automation, convenience, or quality control do not qualify as “safety components” under Article 6(1). This narrows the scope of what is considered high-risk AI, particularly in workplace and operational contexts.

For example, AI tools used for scheduling, productivity tracking, or internal process automation may no longer be classified as high-risk—provided they do not directly influence safety-critical decisions. However, this does not mean these systems are risk-free. They still require governance, transparency, and oversight to prevent bias, privacy violations, or unintended consequences.

Leaders should conduct a fresh risk assessment to determine which AI systems in their organization now fall outside the high-risk category—and ensure that governance frameworks still apply. Use our AI harms taxonomy to identify and mitigate risks across all AI use cases, not just those classified as high-risk.

AI literacy: softer in form, no less strategic

Article 4 has been amended to require providers and deployers to take measures to support AI literacy—without mandating a specific level of literacy or outcome. While the language is more flexible, the obligation remains: organizations must ensure that employees, users, and stakeholders understand how AI systems work, their limitations, and their potential impacts.

For HR leaders, this is an opportunity to integrate AI literacy into onboarding, training, and change management programs. Compliance teams should document these efforts as part of their governance records. Risk leaders should ensure that literacy initiatives address not just technical understanding, but also ethical considerations, bias awareness, and accountability.

AI literacy is not just about compliance—it’s about building trust. When employees understand how AI decisions are made, they are more likely to engage with the technology responsibly and report concerns early. Learn how to build AI literacy into your governance framework.

The AI Office gains teeth: exclusive competence and enforcement powers

The AI Office has been granted exclusive competence over two critical categories of AI systems:

  • AI systems built on general-purpose AI models by the same provider or undertaking.
  • AI systems that constitute or are integrated into Very Large Online Platforms (VLOPs) and Very Large Online Search Engines (VLOSEs).

This expansion of authority is backed by new enforcement tools, including:

  • Inspection powers to audit AI systems and governance frameworks.
  • Authority to issue binding commitments and corrective measures.
  • Fines and periodic penalty payments for non-compliance.

For organizations deploying AI at scale—particularly those using foundation models or operating in digital markets—this means the AI Office is now a key regulator to engage with proactively. Compliance leaders should prepare for audits, document governance decisions, and ensure that AI systems are transparent, auditable, and aligned with regulatory expectations.

This shift also signals a broader trend: AI governance is no longer a niche concern. It is now a board-level priority, with regulators empowered to act decisively. Discover what happens when regulators find your AI governance gaps—and how to close them before it’s too late.

Simplification for smaller players: streamlined compliance, but no less accountability

The amendments introduce several measures to reduce regulatory friction for smaller organizations:

  • Small mid-cap enterprises (SMCs) are now explicitly included in the AI Act, with tailored compliance pathways.
  • A dedicated simplified technical documentation form is available for SMEs, reducing administrative burden.
  • The quality management system shortcut is extended to all SMEs, allowing for lighter-weight governance frameworks.
  • EU database registration is streamlined, with fewer mandatory fields and faster processing.

These changes reflect a recognition that one-size-fits-all regulation can stifle innovation. However, simplification does not mean deregulation. Smaller organizations are still accountable for the risks their AI systems create—and regulators will expect evidence of responsible deployment.

For leaders in mid-sized and growing companies, this is an opportunity to adopt governance frameworks that scale with the business. Start with lightweight but robust policies, document decisions, and use tools that automate compliance tracking. ISO 42001 certification is one way to demonstrate commitment to AI governance without overburdening teams.

One deadline that isn’t moving: generative AI marking obligations

While most deadlines have been extended, one remains fixed: providers of generative AI systems already on the market before 2 August 2026 must comply with Article 50(2) marking obligations by 2 December 2026. This includes requirements to:

  • Clearly label AI-generated content.
  • Disclose the use of AI in decision-making processes.
  • Provide transparency about data sources and model limitations.

For HR and operations leaders, this means auditing all generative AI tools in use—including those embedded in third-party platforms—and ensuring they meet transparency requirements. Failure to comply risks fines, reputational damage, and loss of stakeholder trust.

This is not just a technical requirement; it’s a cultural shift. Employees and users need to know when they are interacting with AI-generated content. Learn how to secure and govern data in AI-driven environments while meeting transparency obligations.

What leaders must do now: a 6-point action plan

The message from Brussels is clear: this is simplification, not deregulation. Less regulatory friction does not mean less accountability. The extended timeline is not a reason to delay—it’s the window to build AI governance properly. Here’s what senior leaders should do in the next 90 days:

  1. Conduct a fresh AI inventory.
    • Identify all AI systems in use, including shadow AI and third-party tools.
    • Classify them under the new definitions (high-risk, prohibited, limited-risk, minimal-risk).
    • Update your risk register to reflect the amended scope of “safety components.”
  2. Align governance frameworks with the new deadlines.
    • Map compliance milestones to the fixed dates (2 December 2027 and 2 August 2028).
    • Ensure technical documentation, risk assessments, and quality management systems are ready for audit.
    • For generative AI, meet the 2 December 2026 marking obligations without delay.
  3. Strengthen safeguards against prohibited practices.
    • Audit AI systems for reasonably foreseeable misuse, particularly in content generation.
    • Implement technical guardrails (e.g., content filters, misuse detection, real-time monitoring).
    • Document the adequacy of these safeguards to defend against liability claims.
  4. Build AI literacy into employee training.
    • Integrate AI literacy into onboarding, upskilling, and change management programs.
    • Focus on ethical considerations, bias awareness, and accountability—not just technical skills.
    • Document training efforts as part of your governance records.
  5. Prepare for AI Office scrutiny.
    • Ensure AI systems built on general-purpose models or integrated into VLOPs/VLOSEs are auditable and transparent.
    • Document governance decisions, risk assessments, and corrective actions.
    • Engage with the AI Office proactively, particularly if your organization operates at scale.
  6. Leverage simplification for smaller players.
    • If your organization qualifies as an SMC or SME, adopt the simplified technical documentation and quality management shortcuts.
    • Use streamlined registration processes to reduce administrative burden.
    • Ensure governance frameworks are lightweight but robust, scaling with your business.

For a deeper dive into how to execute these steps, explore our step-by-step guide to AI governance.

The bottom line: act now, or risk falling behind

The EU AI Act amendments are not just regulatory updates—they are a call to action. The extended deadlines provide a rare opportunity to build AI governance frameworks that are robust, scalable, and aligned with global standards. But this window will close quickly. Organizations that wait until enforcement begins will face fines, operational disruptions, and reputational damage.

For HR, compliance, risk, and operations leaders, the path forward is clear:

  • Audit your AI systems under the new rules.
  • Align your policies, governance frameworks, and employee practices with the amended requirements.
  • Act now to build trust, mitigate risk, and future-proof your organization.

The time to prepare is not after the deadlines—it’s now. Don’t let regulators find your gaps before you do.

More stories

DocsOrb and OpenAI partner to deploy AI safely with Guardrails expertise
Product UpdatesJuly 14, 2026

DocsOrb and OpenAI partner to deploy AI safely with Guardrails expertise

DocsOrb’s new OpenAI partnership brings enterprise-grade AI safety to HR, compliance, and risk leaders. With direct access to OpenAI’s expertise and DocsOrb Guardrails, organizations can now deploy AI models confidently—balancing innovation with governance, policy enforcement, and real-time risk mitigation before regulators demand proof.

openai partnership for ai governanceai guardrails for compliancesafe ai deployment in hr
Mapping AI harms: a taxonomy for HR, compliance, and risk leaders
Market UpdatesJuly 11, 2026

Mapping AI harms: a taxonomy for HR, compliance, and risk leaders

AI’s rapid adoption brings transformative potential—but also risks like bias, privacy violations, and environmental harm. For HR, compliance, and risk leaders, a structured harms taxonomy is essential to identify, assess, and mitigate these threats. From individual discrimination to societal erosion of trust, understanding AI’s impact across dimensions ensures governance keeps pace with innovation while safeguarding people and organizations.

ai governance risks and harmsai harms taxonomy for complianceprivacy and ai risk frameworks
How to secure and govern data in the age of AI-driven risks
Product UpdatesJune 12, 2026

How to secure and govern data in the age of AI-driven risks

Generative AI and agentic workspaces are accelerating data risks—shadow tools, unvetted copilots, and AI agents now routinely handle sensitive information. Without proactive governance, organizations face $4.5M+ breach costs, regulatory penalties, and operational chaos. Discover how to secure AI applications, enforce policies, and prevent data loss before it triggers a crisis.

ai governance frameworkai-driven data security riskspreventing ai data breaches