Digital Omnibus AI: should we really wait to become compliant?

Picture of Edgar Moreau
Edgar Moreau

Key takeaways:

Digital Omnibus AI: what has really changed?

The AI Act, or European regulation on artificial intelligence, came into force on August 1st, 2024. This regulation (EU) 2024/1689 classifies AI systems according to four risk levels and imposes graduated obligations. The major change of the Digital Omnibus AI concerns the timeline for applying the “high risk” obligations.

Êtes-vous protégé contre le risque de corruption ?

Nos experts vous aident à évaluer vos failles et structurer votre dispositif

Why the European Commission voted for a postponement

The postponement is a pragmatic observation. The implementation of the AI Act was falling behind. Two blockages stood out. First, the designation of competent national authorities was lagging in several member states. Second, the harmonized standards essential to the compliance of high risk systems were not finalized.

Without these tools, companies faced obligations without technical instructions. The Digital Omnibus AI therefore responds to a problem of operability, not a desire to deregulate.

  • Sapin II Law: anti-corruption prevention and third-party vetting.
  • GDPR: data protection and data processing governance.
  • Duty of Care (Devoir de vigilance): identification of violations of fundamental rights.
  • CSRD: sustainability reporting and reliability of ESG information.
  • AI Act: risk classification and compliance of AI systems.
Équipe en réunion analysant la mise en place d'un système de management ISO 37001 dans l'entreprise

The new AI Act timeline after the Digital Omnibus

  • According to the provisional agreement, the obligations applicable to standalone high risk systems (annex III) move from August 2nd, 2026 to December 2nd, 2027.
  • For AI integrated into regulated products (annex I) (medical devices, machinery, vehicles), the deadline is set at August 2nd, 2028.

Which obligations are affected by the postponement to December 2027

The postponement precisely targets high risk systems. Annex III covers sensitive uses. These include:

  • Recruitment
  • Credit scoring
  • Education
  • Law enforcement
  • Border management.

These are the systems that benefit from the extension until December 2nd, 2027. The deadline granted to member states to create regulatory sandboxes is also pushed back to August 2nd, 2027. Everything else continues to move forward according to the original timeline.

Obtenir la certification ISO 37001

This is the point that many companies overlook. The Digital Omnibus AI pushes back high risk, but a significant part of the AI Act remains fully applicable. Reading the postponement as a general pause is a costly misinterpretation.

Audit interne et checklist de conformité dans le cadre d'une certification ISO 37001

AI Literacy (article 4): subject to sanctions from August 2nd, 2026

Article 4 has imposed a clear obligation since February 2nd, 2025. Providers and deployers must ensure a sufficient level of AI literacy among their teams. The Digital Omnibus AI softens the wording: it is now about supporting the development of this culture, rather than guaranteeing a precise level. The obligation nonetheless remains real and enforceable.

Prohibited AI practices: in force since February 2025

Unacceptable risk practices have been prohibited since February 2nd, 2025:

  • Social scoring
  • Behavioral manipulation
  • Real time biometric identification in public spaces

The Digital Omnibus AI adds to this the prohibition of systems generating non consensual intimate images and child sexual abuse content. These prohibitions carry the heaviest sanctions under the regulation.

YOUR QUESTIONS

FAQ - Digital Omnibus and AI Act compliance

Before contacting us, you may have these questions. Here are direct answers from our senior consultants.

Is the Digital Omnibus AI final?

No. As of June 2026, the agreement remains provisional. The text must still be voted on in plenary by the European Parliament, then adopted by the Council. It will then be published in the Official Journal of the European Union, normally before August 2nd, 2026. As long as this publication does not occur, the original deadlines of the AI Act remain legally applicable.

All providers and deployers of AI systems.

Prohibited practices (article 5), GPAI obligations and transparency obligations (article 50) carry active sanctions. Fines can reach 35 million euros or 7% of global turnover for the most serious infringements, under article 99 of the regulation.

Relying on an AI Act compliance firm such as Eterra makes it possible to secure every step: mapping, qualification of your status, governance, training.

Votre système anti corruption répond-il aux exigences de l'ISO 37001:2025 ?

L'expertise Eterra vous accompagne de l'audit jusqu'à la certification
This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.