July 2026 · Research
EU AI Omnibus Is Now Law: Regulation (EU) 2026/1744 in Force — Enterprises Must Update Compliance Calendars
On July 24, 2026, the Digital Omnibus on AI was published in the L series of the Official Journal of the European Union as Regulation (EU) 2026/1744. It entered into force just three days later on July 27 — an accelerated timeline justified explicitly by the urgency of providing legal certainty before the August 2 enforcement deadline. The proposal era is officially over. This is now law, with binding effect across all 27 member states.

Key Definitions
EU AI Omnibus Is Now Law: Regulation (EU) 2026/1744 in Force On July 24, 2026, the Digital Omnibus on AI was published in the L series of the Official Journal of the European Union as Regulation (EU) 2026/1744. It entered into force just three days later on July 27 — an accelerated timeline justified explicitly by the urgency of providing legal certainty before the August 2 enforcement deadline. The proposal era is officially over. This is now law, with binding effect across all 27 member states.
What It Contains: 47 Recitals, 4 Articles, 1 New Annex
Regulation (EU) 2026/1744 is a compact but consequential amending regulation. It contains 47 recitals explaining the legislative rationale, four operative articles, and one new Annex XIV to the AI Act. Despite its brevity, the amendments touch three core dimensions of the EU AI Act: the compliance timeline, enforcement architecture, and prohibited practices.
Fixed Calendar Dates — No More Conditional Triggers
The most substantive change introduced by the Digital Omnibus is the conversion of high-risk AI obligations from conditional triggers to fixed calendar dates. Under the original AI Act, high-risk Annex III systems were subject to the standard becoming applicable only after harmonized standards were published — a condition-based mechanism that left enterprises unable to plan with certainty. The Omnibus replaces this with explicit, unconditional deadlines:
- August 2, 2026 — Article 50 transparency obligations unchanged. Chatbot disclosure, AI content labeling, deepfake marking, and machine-readable watermarking proceed as originally scheduled
- December 2, 2026 — New Article 5 prohibitions enter into force, covering non-consensual intimate imagery (AI-generated or processed pornographic/private content) and the generation of child sexual abuse material (CSAM)
- December 2, 2027 — High-risk AI systems listed in Annex III become subject to the full obligations (deferred from August 2026, a delay of approximately 16 months)
- August 2, 2028 — High-risk obligations for Annex I AI systems embedded in regulated products (medical devices, vehicles, industrial equipment) take effect
The practical effect of this fixed-calendar mechanism is clear: enterprises can now build compliance roadmaps around concrete dates, free from the uncertainty of standards publication timelines.
Article 75a — AI Office Gains Enforcement Powers
The Digital Omnibus introduces a new Article 75a that grants the AI Office direct enforcement authority — arguably the most institutionally significant change in the entire regulation. Under Article 75a, the AI Office can:
- Conduct on-site inspections, including entering premises and examining equipment and data
- Seal premises and records for up to 90 days
- Impose periodic penalty payments of up to 5% of average daily worldwide turnover
- Intervene directly when member state market surveillance authorities have not taken sufficient action
This transforms the AI Office from a policy-making body into an operational enforcement authority. For cross-border enterprises, this means facing not 27 fragmented enforcement regimes but a single central authority capable of launching EU-wide coordinated actions. The addition of Article 75a fundamentally changes the enforcement landscape of the EU AI Act.
New Article 5 Prohibitions — Non-Consensual Intimate Imagery and CSAM Generation
The Digital Omnibus adds two new prohibited AI practices to Article 5, effective December 2, 2026:
First, the AI-generated creation or processing of non-consensual intimate imagery. This covers private images created or modified using AI tools (including deepfake pornography), regardless of whether the original source material was obtained with consent. It complements the illegal content framework under the Digital Services Act (DSA).
Second, the AI generation of child sexual abuse material (CSAM). The regulation explicitly prohibits AI systems designed specifically for generating CSAM, as well as high-risk AI systems designed to evade CSAM detection measures. This aligns with the EU's broader legislative push to combat online child sexual exploitation.
Enterprise Action: Update Compliance Calendars Immediately
With the Digital Omnibus now formally law, enterprises must take the following actions immediately:
- Update internal compliance calendars — Mark August 2 transparency, December 2 prohibitions, December 2027 high-risk, and August 2028 embedded-system deadlines as hard, unconditional cut-offs
- Article 50 transparency countdown — August 2 enforcement is unchanged, with less than one week remaining. Any outstanding AI interaction disclosures, content labels, and deepfake markings must go live now
- Assess new Article 5 prohibition impact — Review product and service lines for any systems or features that could generate non-consensual intimate imagery or CSAM. Remediation must be complete by December 2, 2026
- Prepare for AI Office inspections — Article 75a's on-site inspection powers mean enterprises must maintain readily accessible documentation for high-risk AI systems, including technical documentation, risk management records, and compliance evidence
- Replan high-risk compliance roadmaps — Use the December 2027 deadline to build a pragmatic compliance trajectory. But do not treat this as a "delay" — it is a fixed final deadline with no further extension
Compliance Calendar at a Glance
- August 2, 2026 → Article 50 transparency obligations enforceable (not deferred)
- December 2, 2026 → New Article 5 prohibitions in force (non-consensual intimate imagery, CSAM generation)
- December 2, 2027 → Annex III high-risk AI system obligations apply
- August 2, 2028 → Annex I embedded-product AI system obligations apply
Why Three Days to Entry into Force? The Urgency Logic
Regulation (EU) 2026/1744 was published on July 24 and entered into force on July 27 — just three days later. EU regulations typically enter into force on the 20th day following publication. This extraordinary acceleration is justified explicitly in the recitals: with the August 2 enforcement date imminent, the market needed certainty. Under the normal 20-day cycle, enterprises would have faced continued legal ambiguity well after July 24.
This emergency procedure also sends a clear signal: the European legislature views the Digital Omnibus primarily as a timeline calibration exercise, not a deregulatory measure. The fact that Article 50 transparency obligations were left completely untouched is the strongest evidence of this intent.
FAQ
What It Contains: 47 Recitals, 4 Articles, 1 New Annex+
Regulation (EU) 2026/1744 is a compact but consequential amending regulation. It contains 47 recitals explaining the legislative rationale, four operative articles, and one new Annex XIV to the AI Act. Despite its brevity, the amendments touch three core dimensions of the EU AI Act: the compliance timeline, enforcement architecture, and prohibited practices.
Fixed Calendar Dates — No More Conditional Triggers+
The most substantive change introduced by the Digital Omnibus is the conversion of high-risk AI obligations from conditional triggers to fixed calendar dates. Under the original AI Act, high-risk Annex III systems were subject to the standard becoming applicable only after harmonized standards were published — a condition-based mechanism that left enterprises unable to plan with certainty.
Article 75a — AI Office Gains Enforcement Powers+
The Digital Omnibus introduces a new Article 75a that grants the AI Office direct enforcement authority — arguably the most institutionally significant change in the entire regulation. Under Article 75a, the AI Office can:
New Article 5 Prohibitions — Non-Consensual Intimate Imagery and CSAM Generation+
The Digital Omnibus adds two new prohibited AI practices to Article 5, effective December 2, 2026:
Enterprise Action: Update Compliance Calendars Immediately+
With the Digital Omnibus now formally law, enterprises must take the following actions immediately:
How OOMeta Can Help
OOMeta's AI Agent governance platform manages the full EU AI Act compliance lifecycle — from high-risk system documentation automation and Article 50 transparency compliance to AI Office inspection readiness. Our compliance engine covers the complete Digital Omnibus-adjusted timeline, automatically tracking deadline changes and updating compliance workflows.
References
- NicFab: "Digital Omnibus on AI: Regulation (EU) 2026/1744 Is Published in the Official Journal" — https://www.nicfab.eu/en/posts/digital-omnibus-ai-official-journal/
- Modulos: "EU AI Act Omnibus Published: New Deadlines Are Now Law" — https://www.modulos.ai/blog/eu-ai-act-omnibus-now-law
- Law & Technology: "Digital Omnibus on AI in the Official Journal" — https://lawandtechnology.eu/en/digital-omnibus-on-ai-official-journal-regulation-2026-1744/
- EUR-Lex: Regulation (EU) 2026/1744 — http://data.europa.eu/eli/reg/2026/1744/oj