On this page · 12 sections
- What the Council actually approved on 29 June 2026
- The four dates that changed
- The deadline that moved closer
- What did not move
- The new prohibition nobody delayed
- What else the regulation changed
- What this changes on an engineering roadmap
- India-specific considerations
- A 90-day plan
- FAQ
- How eCorpIT can help
- References
Summary. On 29 June 2026 at 14:30 CEST, the Council of the EU gave final approval to the Digital Omnibus on AI, part of the "Omnibus VII" simplification package. The high-risk obligations that were due to apply on 2 August 2026 now apply on 2 December 2027 for stand-alone systems listed in Annex III, and on 2 August 2028 for high-risk AI embedded in regulated products. That is a 16-month reprieve on the single most expensive part of Regulation (EU) 2024/1689. One deadline moved the other way: the grace period for implementing transparency solutions for artificially generated content was cut from 6 months to 3, landing on 2 December 2026. The national AI regulatory sandbox deadline slipped to 2 August 2027. Penalties are untouched, still up to EUR 35,000,000 or 7% of worldwide annual turnover for prohibited practices under Article 5, and up to EUR 15,000,000 or 3% for breaches of provider, deployer and Article 50 transparency duties.
If you run an engineering roadmap that has "AI Act readiness" pencilled in for Q3 2026, the plan you wrote is now wrong in both directions. The expensive work got later. The cheap work got sooner.
What the Council actually approved on 29 June 2026
The Digital Omnibus on AI is a regulation that amends the AI Act rather than replacing it. The Commission proposed it on 19 November 2025 as the seventh omnibus package in the EU's simplification agenda. The Internal Market (IMCO) and Civil Liberties (LIBE) committees adopted their joint position on 18 March 2026 by 101 votes to 9, with 8 abstentions. Council and Parliament reached political agreement on 6 May 2026, and the Council's final green light came on 29 June 2026.
Marilena Raouna, Deputy Minister for European affairs of the Republic of Cyprus, framed the vote this way in the Council's press release: "With today's adoption, we are taking another decisive step towards a more competitive European Union. By providing greater legal certainty and ensuring a more harmonised implementation of AI rules across the EU, we are creating the conditions for innovation and growth to thrive in the single market."
The legislative act enters into force on the third day after publication in the Official Journal. As of 20 July 2026, that publication had been announced as imminent rather than completed, which matters for one narrow reason covered below.
The reason for the delay is not political cover. It is that the harmonised standards the high-risk regime depends on were not going to exist in time. The European Parliament's own summary of the committee position says the postponement was supported "given that key standards may not be finalised by the current deadline of 2 August 2026." A conformity assessment against a standard that has not been published is not a compliance exercise. It is a guess.
The four dates that changed
| Obligation | Previous date | New date | Net change |
|---|---|---|---|
| High-risk AI, stand-alone (Annex III) | 2 August 2026 | 2 December 2027 | 16 months later |
| High-risk AI embedded in regulated products | 2 August 2027 | 2 August 2028 | 12 months later |
| Transparency solutions for generated content | 2 February 2027 (as proposed) | 2 December 2026 | 2 months earlier |
| National AI regulatory sandboxes | 2 August 2026 | 2 August 2027 | 12 months later |
Two of those rows deserve care, because the reporting around them has been sloppy.
The Annex III row covers the categories most enterprises actually touch: biometrics, critical infrastructure, education, employment, access to essential services including credit scoring and insurance, law enforcement, migration and border management, and the administration of justice. If you are scoring CVs, pricing credit, or triaging students, this is your row.
The embedded-products row covers AI used as a safety component in products already governed by EU sectoral safety law: medical devices, machinery, toys, radio equipment, lifts, watercraft. The Council's release confirms these get a parallel 12-month extension.
The deadline that moved closer
This is the part most summaries get wrong, and it is the part with a bill attached in 2026 rather than 2027.
Article 50 of the AI Act requires providers of AI systems that generate synthetic audio, image, video or text to mark those outputs in a machine-readable format, detectable as artificially generated or manipulated. Deployers creating deepfakes must disclose that the content is artificially generated. Those obligations apply from 2 August 2026 and that date did not move.
What moved is the grace period for getting the technical marking in place. The Commission's proposal would have given providers until 2 February 2027. The Parliament's committees wanted 2 November 2026. The final text cuts the grace period from 6 months to 3, setting the deadline at 2 December 2026.
So the sequencing for anyone shipping generative features into the EU is: obligation live 2 August 2026, technical implementation due 2 December 2026. That is roughly four months from today. Watermarking, provenance metadata and a detectable output format are engineering work, not policy work, and they touch the serving path rather than a document repository. We have written separately on the implementation detail in our developer guide to Article 50 content marking.
The uncomfortable arithmetic: the obligation that got delayed by 16 months is the one most teams had budgeted for, and the obligation that got pulled forward by 2 months is the one most teams had filed under "later."
What did not move
Several things stayed exactly where they were, and treating the Omnibus as a blanket pause is the fastest way to get this wrong.
The Article 5 prohibitions have applied since 2 February 2025. General-purpose AI model obligations under Chapter V have applied since 2 August 2025. The penalty regime in Article 99 entered into force on 2 August 2025. AI literacy duties under Article 4 are unchanged. None of that was touched by the Omnibus.
Article 99 sets three tiers, and the Omnibus left all three intact:
| Infringement | Maximum fine | Turnover cap | Applies since |
|---|---|---|---|
| Prohibited practices (Article 5) | EUR 35,000,000 | 7% of worldwide annual turnover | 2 August 2025 |
| Provider, deployer, importer, distributor and Article 50 duties | EUR 15,000,000 | 3% of worldwide annual turnover | 2 August 2025 |
| Incorrect or misleading information to authorities | EUR 7,500,000 | 1% of worldwide annual turnover | 2 August 2025 |
| SMEs and start-ups | Lower of the two | Lower of the two | 2 August 2025 |
| Union institutions and bodies | Set under Article 100 | Not turnover-based | 2 August 2025 |
Note the SME rule in Article 99(6): for SMEs including start-ups, the fine is capped at whichever of the fixed amount or the percentage is lower, which inverts the "whichever is higher" rule that applies to larger undertakings.
The new prohibition nobody delayed
The Omnibus adds a prohibited practice rather than removing one. The new provision bans AI practices generating non-consensual sexual and intimate content, and AI-generated child sexual abuse material. The Council's release states that systems generating nude images of real people, or editing clothes out of existing photos, are set to be banned as of December this year.
The Parliament's committee text framed the same ban around "nudifier" systems that create or manipulate sexually explicit or intimate imagery resembling an identifiable real person without consent, with a carve-out for systems carrying effective safety measures that prevent users from producing such images.
Michael McNamara (Renew, IE), co-rapporteur for the LIBE committee, said of the compromise: "I'm glad that it was possible to achieve a compromise acceptable to the majority of the Parliament and at least the centrist parties. And that that compromise included a proposal to ban so-called nudification apps which I believe is something that our citizens expect of the co-legislators."
For anyone operating an image model, an editing product, or an API that resells one, this lands in the Article 5 tier: EUR 35,000,000 or 7%. It is the most expensive tier in the regulation and it arrives in December 2026, not December 2027.
What else the regulation changed
Four structural changes matter for how you scope compliance work.
Sectoral overlap resolution. The regulation creates a mechanism to limit the AI Act's application where sectoral law already imposes similar AI-specific requirements, implemented through implementing acts. Products covered by the machinery regulation were exempted from direct applicability, with the Commission empowered to add health and safety requirements for high-risk AI under the machinery regulation instead. If you build medical devices or industrial machinery, you may end up under one regime rather than two.
AI Office competence. The text clarifies the AI Office's supervisory competence over AI systems built on general-purpose models where the model and the system come from the same provider, and lists exceptions where national authorities stay competent: law enforcement, border management, judicial authorities and financial institutions. For a fintech deploying a GPAI-based system, the supervisor is the national authority, not Brussels.
Bias-correction data processing. MEPs backed allowing providers to process personal data to detect and correct bias in AI systems, with safeguards limiting it to cases where it is strictly necessary. This resolves a real conflict engineering teams have been stuck in, where measuring disparate impact required the very attributes you were not supposed to hold.
Small mid-caps. Support measures previously reserved for SMEs extend to small mid-cap enterprises, aimed at companies that have outgrown SME status but not the compliance overhead.
Arba Kokalari (EPP, SE), co-rapporteur for the IMCO committee, put the intent bluntly: "We want predictable, stop-the-clock, simplified rules that remove overlaps with sectoral legislation and reduce fragmentation between Member States. Companies now need clarity on whether they are high risk or not."
What this changes on an engineering roadmap
The delay is real, and it is worth being honest about what it buys and what it does not.
What it buys: 16 months before Articles 8 to 15 apply to Annex III systems. That is the risk management system, data governance, technical documentation, automatic logging, human oversight, accuracy and cybersecurity requirements, plus conformity assessment, an EU declaration of conformity, CE marking and registration in the EU database. That work is measured in quarters, not sprints, and most of it was not going to be finishable against unpublished standards.
What it does not buy: any relief on transparency, prohibitions, GPAI duties or penalties. And it does not stop your enterprise customers from asking for AI Act artefacts in procurement, because their own legal teams are working to the old calendar until someone tells them otherwise.
The practical read for the next two quarters:
| Work item | Drive by | Why now |
|---|---|---|
| Machine-readable marking on generated outputs | 2 December 2026 | Grace period cut to 3 months |
| Deepfake disclosure in product UX | 2 August 2026 | Article 50 date unchanged |
| Prohibited-practice review of image and editing features | December 2026 | New Article 5 tier, 7% exposure |
| Annex III classification of every model in production | Q4 2026 | Determines whether the 2027 date applies at all |
| Risk management and technical documentation | Through 2027 | 2 December 2027 target, standards pending |
| Sandbox engagement with a national authority | From 2 August 2027 | Sandboxes now due a year later |
The classification step is the one to do first, and it is cheap. Until you know which of your systems land in Annex III, you cannot tell whether the Omnibus gave you 16 months or nothing at all. Most teams discover the count is smaller than feared and the transparency exposure is larger.
The real cost here is usually the inventory, not the controls.
India-specific considerations
For Indian product companies and service firms, three things follow.
The AI Act applies extraterritorially where output is used in the Union, so a Gurugram or Bengaluru team shipping a SaaS product to EU customers is in scope regardless of where the model runs. The delay applies to those teams identically.
The transparency work is the immediate one. An Indian SaaS company embedding a generative feature for EU users needs machine-readable marking by 2 December 2026, on the same clock as a German competitor.
The domestic calendar runs alongside it, not instead of it. India's Digital Personal Data Protection Act 2023 has its own phased sequence running into 2027. Teams that build one governance capability for both regimes tend to do better than teams running two programmes, and the overlap is largest in data governance, logging and record-keeping. We have covered the Indian side in our DPDP engineering playbook for Indian startups and the cost picture for the 2027 deadline.
For product teams already building agent systems, the governance layers you need for the AI Act's logging and human-oversight requirements overlap heavily with what you need for agent control generally, which we have written about in our guide to enterprise AI agent governance layers.
A 90-day plan
If you own this, here is a sequence that fits before 2 December 2026.
Weeks 1 to 2: inventory every AI system and model in production or committed for the next two quarters. Record the provider, the deployment role (are you provider or deployer?), whether output reaches EU users, and whether the system generates synthetic audio, image, video or text.
Weeks 3 to 4: classify against Annex III and against Article 5. The Article 5 pass is the urgent one now that the non-consensual imagery prohibition is in. Any feature that edits people in photographs deserves a specific look.
Weeks 5 to 8: implement machine-readable marking on every generative output path and disclosure in the UX for deepfake-capable features. This is serving-path engineering. Budget for the latency and storage overhead of provenance metadata rather than discovering it in load testing.
Weeks 9 to 12: build the record-keeping spine you will need in 2027 anyway. Automatic logging, model and dataset documentation, and a risk register. Doing it now against a 2027 deadline is cheaper than doing it in 2027 against a 2027 deadline.
Then revisit in Q1 2027, when the harmonised standards that caused this delay should actually exist, and the conformity assessment work can be scoped against something real. Approaches that treat privacy and governance as an architecture problem rather than a documentation problem hold up better here, a pattern we have written about in privacy-first AI architecture.
FAQ
How eCorpIT can help
eCorpIT is a CMMI Level 5 certified engineering organisation in Gurugram, and our senior engineering teams design applications aligned with EU AI Act and DPDP requirements rather than bolting governance on afterwards. We help teams inventory and classify AI systems, build machine-readable content marking into serving paths, and put the logging and documentation spine in place ahead of the December 2027 high-risk date. If you need the Article 50 work done before 2 December 2026, contact us and we will scope it against your actual model inventory.
References
- Artificial Intelligence: Council gives final green light to simplify and streamline rules - Council of the EU press release, 29 June 2026.
- MEPs support postponement of certain rules on artificial intelligence - European Parliament press release, 18 March 2026.
- Artificial intelligence: Council and Parliament agree to simplify and streamline rules - Council of the EU, 6 May 2026.
- Regulation on the simplification of the implementation of harmonised rules on artificial intelligence (Digital omnibus on AI), 29 June 2026 - Council document PE-30-2026-INIT.
- Digital omnibus on AI, Commission proposal, 17 November 2025 - Council document ST-15708-2025-INIT.
- Article 99: Penalties - EU Artificial Intelligence Act, Regulation (EU) 2024/1689.
- Article 50: Transparency Obligations for Providers and Deployers of Certain AI Systems - EU Artificial Intelligence Act.
- Annex III: High-Risk AI Systems Referred to in Article 6(2) - EU Artificial Intelligence Act.
- Article 57: AI Regulatory Sandboxes - EU Artificial Intelligence Act.
- Article 113: Entry into Force and Application - EU Artificial Intelligence Act.
- Section 2: Requirements for High-Risk AI Systems (Articles 8 to 15) - EU Artificial Intelligence Act.
- Article 5: Prohibited AI Practices - EU Artificial Intelligence Act.
- Digital Omnibus on AI782651) - European Parliamentary Research Service briefing, 2026.
- Text of the compromise amendments approved on 18.03.2026 - IMCO and LIBE committees.
Last updated: 20 July 2026.