The EU AI Act Omnibus: Quiet Changes And Hidden Risks?
On July 24, 2026, only nine days before the EU AI Act’s initial high-risk compliance deadline, EU authorities introduced a series of changes to key measures and timeframes through the Digital Omnibus on AI. This shift has seen a re-evaluation of compliance deadlines and an expansion of powers, causing a twofold impact on affected firms. First, thousands of in-scope organizations will need to revisit their exposure to double-check compliance, given that the Omnibus’s edits apply unevenly. Second, the late timing of the report increases the risk of organizations misinterpreting their own compliance requirements. In short, there are new and highly specific regulatory details that will likely catch many firms out.
The first major area where the agenda has changed is that high-risk deadlines have been pushed back significantly:
- Standalone high-risk areas of AI use – such as HR, credit and law enforcement – have moved from compliance by August 2, 2026 to December 2, 2027.
- For those embedded in regulated products, such as medical devices, the deadline is now August 2, 2028, a 12-month extension from the original August 2027 application date for embedded systems.
- The immediate result is that organizations building or deploying standalone high-risk systems gain over a year of extra runway to complete compliance assessments and technical documentation – but, importantly, the new runway does not extend to every obligation in the Act.
A possible compliance trap lies in the fact that risk leaders across the EU may read these changes as uniform relief – but, in reality, the Act’s conditions for ‘transparency’ remain entirely unchanged and will not be postponed. This includes transparency duties such as chatbot and deepfake disclosure and public-interest text labelling, which will still go live from August 2, 2026. This also applies to high-stakes AI use cases such as emotion and biometric data disclosures.
Moreover, the Omnibus has re-established the limits of grace periods for watermarking AI-generated content, meaning that relief applies narrowly – by system and by date – rather than universally. Providers of generative AI systems already on the market before August 2, 2026 receive a four-month grace period to achieve full compliance. However, any system entering the market on or after August 2 will not benefit from a grace period and must mark its outputs immediately with no phase-in. For vendors mid-launch or planning a release around the deadline, the Omnibus has not eased but rather front-loaded the compliance burden. Providers should therefore factor their launch dates directly into go-to-market planning, as this will now determine whether they get a grace period at all.
The Omnibus also includes a consolidation of oversight by expanding and clarifying the powers of the AI Office. Specifically, vendors should now be aware that the AI Office has new powers to conduct on-site and remote inspections and, crucially, to impose fines directly. For AI systems built on general-purpose AI (GPAI) in particular, where the model and the system are from the same provider, vendors must now be prepared for the AI Office to hold largely exclusive oversight over supervision and enforcement.
Another important change is that the Omnibus now names ‘agentic AI’ for the first time in EU law. While this is currently little more than an administrative classification code for notified bodies, the presence of the phrase nevertheless serves as an early warning signal for the next update cycle of the regulation. As such, it is imperative for risk leaders to:
- Map every generative AI system against its market-entry date, as well as risk classification, to identify which face December's deadline and which require compliance immediately.
- Treat transparency and high-risk workstreams as separate tracks with separate clocks, rather than a single unified programme.
- Flag vendor launch schedules as a compliance variable in procurement and contract review.
- Monitor for how 'agentic AI' becomes defined and redefined ahead of the next EU AI Act amendment cycle.
- Prepare for more direct engagements with the AI Office, particularly for GPAI systems where the model and system share a provider.
The most effective reading of the EU Digital Omnibus on AI is one that acknowledges a shift in some near-term pressures, while also maintaining a good view over obligations that have changed future compliance dynamics. The organizations that come out ahead will be the ones tracking each obligation against its own date, rather than treating the Omnibus as a single, uniform delay.
For more risk management content, check out Verdantix Insights.
About The Author

Tom Murphy
Analyst

-prc-issues-new-expansion-of-its-compliance-architecture_main-image.jpg?sfvrsn=d101cbd3_1)
.jpg?sfvrsn=b397b971_1)
