Digital Omnibus AI: should we really wait to become compliant?

Picture of Nicolas Fetiveau
Nicolas Fetiveau
Fondateur associé d’Eterra Partners, Nicolas Fetiveau dispose d’une solide expérience de plus de 20 ans dans le développement commercial à l’échelle internationale.
Sommaire

AUTEUR

Fondateur associé d’Eterra Partners, Nicolas Fetiveau dispose d’une solide expérience de plus de 20 ans dans le développement commercial à l’échelle internationale.

Key takeaways:

Digital Omnibus AI: what has really changed?

The AI Act, or European regulation on artificial intelligence, came into force on August 1st, 2024. This regulation (EU) 2024/1689 classifies AI systems according to four risk levels and imposes graduated obligations. The major change of the Digital Omnibus AI concerns the timeline for applying the “high risk” obligations.

Discussion managériale sur le lanceur d'alerte en entreprise

Why the European Commission voted for a postponement

The postponement is a pragmatic observation. The implementation of the AI Act was falling behind. Two blockages stood out. First, the designation of competent national authorities was lagging in several member states. Second, the harmonized standards essential to the compliance of high risk systems were not finalized.

Without these tools, companies faced obligations without technical instructions. The Digital Omnibus AI therefore responds to a problem of operability, not a desire to deregulate.

  • Sapin II Law: anti-corruption prevention and third-party vetting.
  • GDPR: data protection and data processing governance.
  • Duty of Care (Devoir de vigilance): identification of violations of fundamental rights.
  • CSRD: sustainability reporting and reliability of ESG information.
  • AI Act: risk classification and compliance of AI systems.

The new AI Act timeline after the Digital Omnibus

  • According to the provisional agreement, the obligations applicable to standalone high risk systems (annex III) move from August 2nd, 2026 to December 2nd, 2027.
  • For AI integrated into regulated products (annex I) (medical devices, machinery, vehicles), the deadline is set at August 2nd, 2028.

Which obligations are affected by the postponement to December 2027

The postponement precisely targets high risk systems. Annex III covers sensitive uses. These include:

  • Recruitment
  • Credit scoring
  • Education
  • Law enforcement
  • Border management.

These are the systems that benefit from the extension until December 2nd, 2027. The deadline granted to member states to create regulatory sandboxes is also pushed back to August 2nd, 2027. Everything else continues to move forward according to the original timeline.

Canal Destinataire Quand l'utiliser
Signalement interne L'employeur ou le référent désigné dans l'entreprise Voie privilégiée quand un dispositif fiable existe
Signalement externe Le Défenseur des droits, une autorité compétente ou l'autorité judiciaire Directement possible, sans passage interne préalable
Divulgation publique La presse, les médias, les réseaux sociaux En dernier recours, sous conditions strictes

Une protection solide contre les représailles

This is the point that many companies overlook. The Digital Omnibus AI pushes back high risk, but a significant part of the AI Act remains fully applicable. Reading the postponement as a general pause is a costly misinterpretation.

La documentation et le respect absolu de la confidentialité de l'identité du lanceur d'alerte et des faits rapportés

AI Literacy (article 4): subject to sanctions from August 2nd, 2026

Article 4 has imposed a clear obligation since February 2nd, 2025. Providers and deployers must ensure a sufficient level of AI literacy among their teams. The Digital Omnibus AI softens the wording: it is now about supporting the development of this culture, rather than guaranteeing a precise level. The obligation nonetheless remains real and enforceable.

Votre dispositif d'alerte est il vraiment fiable ?

Nos experts vous aident à identifier les failles et à sécuriser votre procédure.

Prohibited AI practices: in force since February 2025

Unacceptable risk practices have been prohibited since February 2nd, 2025:

  • Social scoring
  • Behavioral manipulation
  • Real time biometric identification in public spaces

The Digital Omnibus AI adds to this the prohibition of systems generating non consensual intimate images and child sexual abuse content. These prohibitions carry the heaviest sanctions under the regulation.

YOUR QUESTIONS

FAQ - Digital Omnibus and AI Act compliance

Before contacting us, you may have these questions. Here are direct answers from our senior consultants.

Is the Digital Omnibus AI final?

No. As of June 2026, the agreement remains provisional. The text must still be voted on in plenary by the European Parliament, then adopted by the Council. It will then be published in the Official Journal of the European Union, normally before August 2nd, 2026. As long as this publication does not occur, the original deadlines of the AI Act remain legally applicable.

All providers and deployers of AI systems.

Prohibited practices (article 5), GPAI obligations and transparency obligations (article 50) carry active sanctions. Fines can reach 35 million euros or 7% of global turnover for the most serious infringements, under article 99 of the regulation.

Relying on an AI Act compliance firm such as Eterra makes it possible to secure every step: mapping, qualification of your status, governance, training.

Et si votre conformité devenait un levier de confiance ?

Nos experts construisent avec vous un dispositif d'alerte sur mesure.
This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.