
Phase 3 of the AI Act Following the Adjustments Made by the Omnibus Regulation
On August 2, 2026, Phase 3 of the implementation of the AI Act (Regulation (EU) 2024/1689 establishing harmonized rules on artificial intelligence) began.
As we explained in our previous article (see article), the AI Act provided for the implementation of its key measures—including those relating to high-risk AI systems—on August 2, 2026, two years after the regulation’s entry into force.
However, given the delay in developing common guidelines to regulate high-risk AI systems at the European level, and the fact that the AI Act’s initial provisions would have entailed high compliance costs for businesses—raising serious concerns about a potential brake on AI innovation in Europe— the European Commission presented in November 2025 the “simplification package” for the AI Act, titled “Digital Omnibus on Artificial Intelligence.”
The final text of the Digital Omnibus, adopted in June 2026, also included a new ban on AI systems capable of generating images of nude people, in light of the controversy sparked by the mass generation of non-consensual sexual images via the AI assistant Grok (developed by xAI) on the social media platform X.
It entered into force in the Member States on July 27, 2026, as Regulation (EU) 2026/1744 of July 8, 2026, thereby amending and supplementing several provisions of the AI Act.
The main changes introduced by the “Digital Omnibus” Regulation—adopted on July 8, 2026, as a European regulation and effective as of July 27, 2026—as well as the provisions of the third phase of the AI Act, which were not amended by this regulation and took effect as scheduled on August 2, 2026, are as follows.
I. Key Changes Introduced by the Omnibus Regulation
1. Adjustment of Compliance Deadlines for High-Risk AI Systems
The Omnibus Regulation amended the effective date of the provisions of the AI Act relating to high-risk AI systems as follows, in order to allow companies that develop and use such systems to prepare the detailed technical documentation required by the AI Act and to train the necessary personnel:
The Omnibus Regulation amended the effective date of the AI Act’s provisions regarding high-risk AI systems as follows, to allow companies that develop and use such systems to prepare the detailed technical documentation required by the AI Act and to train the necessary personnel:
Implementation of the obligations regarding high-risk AI systems used in the areas listed in Annex III (biometrics, critical infrastructure, education, employment, access to essential services, law enforcement, migration, and the administration of justice) (originally scheduled for August 2, 2026): December 2, 2027
Implementation of the obligations relating to high-risk AI systems integrated into products subject to the safety regulations set forth in the Union harmonization legislation referred to in Annex I (toys, radio equipment, in vitro diagnostic medical devices, civil aviation safety, agricultural vehicles, etc.) (originally scheduled for August 2, 2027): August 2, 2028.
2. The reducing of certain obligations imposed on suppliers and deployers of AI systems
a) Technical documentation requirement for suppliers of high-risk AI systems
Article 11 of the AI Act requires suppliers of high-risk AI systems to prepare, maintain, and keep up to date the detailed technical documentation set forth in Annex IV before placing such systems on the market or putting them into service.
The same article provides for the Commission to establish a simplified technical documentation form for SMEs, including startups, in order to alleviate excessive administrative burdens. The AI Omnibus Act has expanded the scope of this simplified technical documentation to include mid-sized companies.
b) Requirement for AI “literacy” for suppliers and deployers of AI systems
Furthermore, the AI Omnibus Act has eased the obligation for suppliers and deployers of AI systems to ensure a sufficient level of AI proficiency among their staff and among individuals who use these systems on their behalf (AI literacy, Article 4 of the AI Act), by explicitly stating that it does not require them to ensure a specific level or certification for each individual. From now on, providers and deployers of AI systems are required only to take the necessary measures to ensure their employees’ proficiency in AI.
3. Adjustments to the deadlines for establishing the “AI regulatory sandbox” at the national level
The AI Act initially provided that Member States must establish, no later than August 2, 2026, the “AI regulatory sandbox”—a controlled environment where innovative companies can test their technology or services without necessarily having to comply with the entire regulatory framework that would normally apply (Article 57 of the AI Act). This deadline was extended to August 2, 2027, by the Omnibus Regulation.
4. New Ban on AI Applications That Violate Human Dignity and Fundamental Rights
The Omnibus Regulation added, to Article 5 of the AI Act—which concerns the total ban on the development, import, sale, and use of AI systems posing an unacceptable risk from a fundamental rights perspective—a new paragraph (b-a) prohibiting the placing on the market, the putting into service, or the use of AI systems that generate sexually explicit images without the consent of the person concerned.
This new prohibition will take effect in the Member States as of December 2, 2026 (Article 113 of the AI Act). As of that date, suppliers, deployers, and importers who make “undressing deepfakes” (“nudification” applications) available in EU Member States will be subject to a fine of up to 35 million euros or 7% of the company’s total global revenue.
5. Framework Ensuring the Protection of Personal Data During Bias Detection
Originally, Article 10(5) of the AI Act provided that providers of high-risk AI systems using machine learning technology (which involves training AI models to recognize patterns and regularities in data so that they can make predictions or decisions) could, to the extent strictly necessary to ensure the detection and correction of bias, exceptionally process special categories of personal data.
However, this provision proved to be incompatible with Article 9 of the GDPR, which in principle prohibits the processing of “special categories of personal data (sensitive data),” such as those relating to racial or ethnic origin or health. For this reason, the Omnibus Regulation introduced a new Article 4a titled “Processing of certain categories of personal data for the purposes of detecting and correcting bias”, replacing the former Article 10(5), in order to establish a clear framework allowing providers of high-risk AI systems to process sensitive data when detecting bias.
From now on, in order to process sensitive data when detecting bias, providers of high-risk AI systems must meet the following conditions (Article 4a, paragraph 1, subparagraphs a–e of the AI Act):
(1) the impossibility of effectively detecting and correcting bias through the processing of other data (in particular, anonymous or synthetic data);
(2) technical restrictions must be applied to prevent the reuse of such data, and privacy protection measures, such as anonymization, must be implemented;
(3) access to this data must be strictly controlled (only authorized persons may access it);
(4) this data must not be disclosed to third parties; and
(5) the data must be deleted once the bias has been corrected or the retention period for personal data has expired.
Furthermore, when providers of high-risk AI systems process sensitive data as part of bias detection, they must indicate, in the record of personal data processing activities provided for in Article 30 of the GDPR, the reasons why the processing of sensitive personal data was strictly necessary to detect and correct bias, as well as the reason why this objective could not be achieved by processing other data (Article 4a, paragraph 1, point f of the AI Act).
Providers and deployers of other AI systems and deployers of high-risk AI systems may, in exceptional cases, process such sensitive data when such processing is strictly necessary to ensure the detection and correction of biases that could harm the health and safety of individuals, negatively impact fundamental rights, or lead to discrimination prohibited under Union law (Article 4a(2) of the AI Act).
II. What Remains Unchanged: “Transparency Obligations” Applicable to Providers and Deployers of AI Systems with Specific Risk
The transparency obligations, set forth in Article 50 (Chapter IV) of the AI Act and applicable to AI systems posing specific risks (regardless of their risk level), were not amended by the Omnibus Regulation and took effect on August 2, 2026, as originally planned.
However, for providers of content-generation systems (audio, images, videos, or text) already on the market, the new Article 111(4) of the AI Act, introduced by the Omnibus Regulation, provides for an extension of the compliance deadline until December 2, 2026.
1. Principles
As a reminder, the four main transparency obligations for providers and deployers are as follows:
a) Obligations applicable to providers of AI systems posing specific risks
AI systems intended to interact directly with natural persons (chatbots, virtual assistants, or conversational agents): the obligation to design and develop these systems in such a way that the natural persons concerned are informed that they are interacting with an AI system.
AI systems that generate synthetic content such as audio, images, video, or text: the obligation to label such content in a machine-readable format that indicates it was generated or manipulated by AI.
b) Obligations Applicable to Deployers of AI Systems with Specific Risks
AI systems for emotion recognition or biometric categorization: obligation to inform individuals exposed to such systems about how the system operates and how personal data is processed.
AI systems that generate or manipulate image, audio, or video content constituting a deepfake: obligation to indicate that the content was generated or manipulated by AI.
AI systems that generate or manipulate text published for the purpose of informing the public on matters of public interest: obligation to indicate that the text was generated or manipulated by AI.
2. Exceptions
The transparency obligations imposed on providers and operators of high-risk AI systems are subject to provisions that exclude or limit their application in the following cases:
– AI systems that interact with individuals and are used for the purposes of prevention, detection, investigation, or criminal prosecution: exclusion from the application of transparency obligations.
– Visual, audio, or video content falling under the category of “deepfakes” that is displayed or presented as works of art: disclosure of information regarding deepfakes is permitted in a manner that does not interfere with the presentation or enjoyment of the work.
– AI systems that generate or manipulate text published for the purpose of informing the public on matters of public interest: exemption from transparency obligations when the use is authorized by law to detect, prevent, investigate, or prosecute criminal offenses or when the AI-generated content has undergone a human review process or editorial oversight and a natural or legal person bears editorial responsibility for the publication of the content.
3. Penalties
Effective August 2, 2026, these obligations apply to all providers and operators within the European Union (with the exception of providers of generative content systems that are already on the market, to whom these requirements apply as of December 2, 2026), and violations of these obligations are punishable by administrative fines of up to 15 million euros or 3% of the annual global revenue generated by the company in question.