The European regulatory framework for AI continues to evolve. With the new AI Omnibus, organisations are being granted additional time to prepare for certain obligations under the AI Act. While most obligations remain unchanged, a number of deadlines have been postponed or clarified. In this newsletter, we explain what AI rules are changing and what these developments mean for your organisation.
The EU AI Act entered into force on 1 August 2024. However, its provisions were designed to become applicable in different phases, with all obligations originally intended to apply by 2 August 2027.
The AI regulatory framework nevertheless remains under development. On 19 November 2025, the European legislator published a proposal for an AI Omnibus Regulation (the “AI Omnibus”). The purpose of this proposal is to simplify the existing AI Act and to facilitate its timely, smooth and practical implementation.
On 29 June 2026, the proposal was formally approved by the Council of the European Union. Once the AI Omnibus is officially published, the amendments discussed below will enter into force on the third day following publication.
In our previous newsletters, we already discussed the publication of the AI Act and the entry into force of its first obligations. In this newsletter, we outline the key changes introduced by the AI Omnibus and explain their practical implications for your organisation.
In summary: the AI Omnibus does not fundamentally alter the AI regulatory framework. Instead, it focuses on improving the practicability of compliance and providing additional support for organisations. It clarifies certain provisions of the AI Act, grants organisations more time to comply with obligations relating to high-risk AI systems and prohibits AI systems which are capable of generating non-consensual and sexually explicit content. While some deadlines have been postponed, the majority of obligations under the AI Act remain unchanged. Organisations should therefore continue to ensure that their AI use, governance and documentation frameworks are in order.
1. More time for high-risk AI systems
One of the most significant changes introduced by the AI Omnibus is the postponement of certain obligations under the AI Act. Under the original framework, obligations relating to high-risk AI systems were scheduled to become applicable from 6 August 2026.
The AI Omnibus postpones these deadlines as follows:
- Obligations applicable to AI systems deployed in high-risk sectors (including biometrics, critical infrastructure, education, employment, migration and border control) will apply from 2 December 2027;
- Obligations applicable to AI systems that are integrated into regulated products (including lifts and toys) will apply from 2 August 2028.
This additional implementation period is intended to give organisations sufficient time to prepare thoroughly for compliance. During this period, technical standards and other supporting tools may also be further developed.
In addition, the European Commission will publish further guidance to clarify the interaction between the various obligations applicable to high-risk AI systems. The objective is to facilitate compliance and minimise administrative burdens for organisations.
2. Expansion of prohibited AI systems
The AI Omnibus places greater emphasis on the protection of the fundamental rights of European citizens.
It expands the existing list of prohibited AI practices by introducing an explicit prohibition on high-risk AI systems that generate non-consensual and sexually explicit or intimate content, including so-called “nudification” applications.
As of 2 December 2026, it will be prohibited to place such AI systems on the EU market unless providers implement the necessary technical measures to prevent the generation of such content. The prohibition will also apply to users who deploy AI systems for these purposes.
3. Simplified requirements for smaller businesses
For small mid-cap enterprises (SMCs), which fall just outside the traditional SME definition, the AI Omnibus introduces a number of simplifications and clarifications. The benefits granted to SMEs under the AI Act will be extended to these organisations as well.
In practice, SMCs will now also benefit from:
- Simplified documentation requirements aimed at reducing administrative burdens;
- Compliance expectations regarding quality management and internal governance processes that are proportionate to the organisation’s size and resources;
- Lower enforcement thresholds intended to avoid sanctions during initial implementation phases.
4. Expansion of regulatory sandboxes
The AI Act already allows businesses developing AI systems to conduct testing within controlled environments known as regulatory sandboxes. These testing environments enable organisations to develop and test AI systems under regulatory supervision, without compliance shortcomings identified within the sandbox automatically resulting in enforcement measures or fines.
The AI Omnibus now provides for the establishment of an EU-level regulatory sandbox for AI systems with a cross-border dimension. This European sandbox is intended to strengthen cooperation between national sandboxes and promote a more consistent application of AI regulation across the European Union.
In doing so, the AI Omnibus also seeks to stimulate innovation among SMEs by granting them priority access to this European testing environment.
5. Changes to the AI literacy obligation
Until recently, organisations using AI systems were required to ensure a sufficient level of AI literacy within the workplace, so that employees possessed an adequate understanding of the AI systems used within the organisation.
The AI Omnibus significantly softens this obligation. While organisations must still make reasonable efforts to promote AI literacy internally, they will no longer be held responsible where an individual employee lacks sufficient AI knowledge.
Instead, the European Commission and the Member States will assume a greater role in supporting AI literacy initiatives by providing practical examples, guidance and recommendations to organisations seeking to improve AI literacy among their workforce.
6. Interaction between the AI Act and product safety regulations
The original AI Act imposed additional obligations on organisations integrating AI systems into products such as medical devices or industrial robots. Organisations would therefore have been required to comply simultaneously with the AI Act and existing European product safety regulations.
The AI Omnibus seeks to eliminate these overlapping obligations by clarifying the relationship between the two regulatory frameworks. This should enable organisations to coordinate their compliance efforts more efficiently, reducing compliance costs while increasing legal certainty.
7. Possible future amendments
In parallel with the AI Omnibus, discussions are ongoing regarding a proposed Digital Omnibus, an initiative aimed at improving the consistency and alignment of various pieces of digital legislation.
One of the proposed amendments would permit, under certain conditions, the processing of personal data for AI training purposes without obtaining the data subject’s consent. In such circumstances, the processing would rely on the controller’s legitimate interest as the lawful basis for processing. Additional technical and organisational safeguards would be required, and data subjects would need to be given the opportunity to object to the processing.
It is important to note, however, that this proposal remains under discussion and is not currently applicable.
What does this mean for your organisation?
The AI Omnibus constitutes a further step towards a regulatory framework that not only governs the use of AI but also takes into account the practical realities faced by organisations.
Although certain application dates have been postponed, the impact of these amendments should not be underestimated. Moreover, the majority of obligations under the AI Act will remain applicable as from 2 August 2026 without modification.
Now is the appropriate time for organisations that have already begun implementing AI systems to assess the impact of the new AI rules and obtain the necessary legal guidance. In particular, organisations should:
- identify existing and planned AI use cases;
- determine the risk classification of each AI system;
- establish internal policies and basic AI training programmes;
- align contracts, internal policies and documentation with the revised timelines; and
- monitor the publication of additional guidance and implementing measures.
The Technology, Digital and Data Team of Monard Law remains available to assist with any questions relating to the AI Act, innovative technologies, the EU’s digital strategy, privacy and data protection.
Authors:
- Jade Claessens, Monard Law
- Jill Leen, Monard Law
- Kristof Zadora, Monard Law
- Dylan Verhulst, Monard Law