Key takeaways:
- The Digital Omnibus AI pushes back the "high risk" obligations of the AI Act to December 2027, but this postponement is not a general pause: several obligations remain fully applicable as of 2026.
- AI Literacy (article 4), prohibited practices and transparency obligations (article 50) are active. Ignoring them exposes companies to sanctions that can reach 35 million euros or 7% of global turnover.
- As of June 2026, the Digital Omnibus AI has not yet been definitively adopted: as long as publication in the Official Journal has not taken place, the original deadlines of the AI Act remain legally in force.
- Comprendre cette norme, c'est se doter d'un outil de gouvernance solide et reconnu partout dans le monde.
Digital Omnibus AI: what has really changed?
The AI Act, or European regulation on artificial intelligence, came into force on August 1st, 2024. This regulation (EU) 2024/1689 classifies AI systems according to four risk levels and imposes graduated obligations. The major change of the Digital Omnibus AI concerns the timeline for applying the “high risk” obligations.
Êtes-vous protégé contre le risque de corruption ?
Why the European Commission voted for a postponement
The postponement is a pragmatic observation. The implementation of the AI Act was falling behind. Two blockages stood out. First, the designation of competent national authorities was lagging in several member states. Second, the harmonized standards essential to the compliance of high risk systems were not finalized.
Without these tools, companies faced obligations without technical instructions. The Digital Omnibus AI therefore responds to a problem of operability, not a desire to deregulate.
- Sapin II Law: anti-corruption prevention and third-party vetting.
- GDPR: data protection and data processing governance.
- Duty of Care (Devoir de vigilance): identification of violations of fundamental rights.
- CSRD: sustainability reporting and reliability of ESG information.
- AI Act: risk classification and compliance of AI systems.
The new AI Act timeline after the Digital Omnibus
- According to the provisional agreement, the obligations applicable to standalone high risk systems (annex III) move from August 2nd, 2026 to December 2nd, 2027.
- For AI integrated into regulated products (annex I) (medical devices, machinery, vehicles), the deadline is set at August 2nd, 2028.
Which obligations are affected by the postponement to December 2027
The postponement precisely targets high risk systems. Annex III covers sensitive uses. These include:
- Recruitment
- Credit scoring
- Education
- Law enforcement
- Border management.
These are the systems that benefit from the extension until December 2nd, 2027. The deadline granted to member states to create regulatory sandboxes is also pushed back to August 2nd, 2027. Everything else continues to move forward according to the original timeline.
Obtenir la certification ISO 37001
This is the point that many companies overlook. The Digital Omnibus AI pushes back high risk, but a significant part of the AI Act remains fully applicable. Reading the postponement as a general pause is a costly misinterpretation.
AI Literacy (article 4): subject to sanctions from August 2nd, 2026
Article 4 has imposed a clear obligation since February 2nd, 2025. Providers and deployers must ensure a sufficient level of AI literacy among their teams. The Digital Omnibus AI softens the wording: it is now about supporting the development of this culture, rather than guaranteeing a precise level. The obligation nonetheless remains real and enforceable.
- Nuance à garder en tête : L'ISO 37001 reste une démarche volontaire. Elle ne se substitue pas à la loi. Elle offre en revanche un moyen solide de démontrer sa diligence raisonnable, notamment en cas de contrôle par l'Agence française anticorruption.
Prohibited AI practices: in force since February 2025
Unacceptable risk practices have been prohibited since February 2nd, 2025:
- Social scoring
- Behavioral manipulation
- Real time biometric identification in public spaces
The Digital Omnibus AI adds to this the prohibition of systems generating non consensual intimate images and child sexual abuse content. These prohibitions carry the heaviest sanctions under the regulation.
- L'ISO 37001 est un système de management anti-corruption complet, désormais renforcé par sa version 2025. La vraie question n'est plus de savoir s'il faut s'y intéresser, mais comment structurer efficacement sa démarche.
YOUR QUESTIONS
FAQ - Digital Omnibus and AI Act compliance
Before contacting us, you may have these questions. Here are direct answers from our senior consultants.
—
Is the Digital Omnibus AI final?
No. As of June 2026, the agreement remains provisional. The text must still be voted on in plenary by the European Parliament, then adopted by the Council. It will then be published in the Official Journal of the European Union, normally before August 2nd, 2026. As long as this publication does not occur, the original deadlines of the AI Act remain legally applicable.
Who is affected by AI Literacy as of August 2nd, 2026?
All providers and deployers of AI systems.
Which sanctions are already applicable in 2026?
Prohibited practices (article 5), GPAI obligations and transparency obligations (article 50) carry active sanctions. Fines can reach 35 million euros or 7% of global turnover for the most serious infringements, under article 99 of the regulation.
How can you get support to anticipate AI Act compliance?
Relying on an AI Act compliance firm such as Eterra makes it possible to secure every step: mapping, qualification of your status, governance, training.


