MICKAI®ArticlesEU Digital Omnibus locks AI Act c…
Article · 5 August 2026

EU Digital Omnibus locks AI Act calendar and keeps August transparency

The Digital Omnibus resets high-risk deadlines but leaves the 2 August 2026 transparency line intact, and procurement teams now buy against a locked calendar.

Author
Micky Irons
Published
5 August 2026
Follow Micky Irons
LinkedInX
eu ai actdigital omnibusregulation 2026/1744article 50high-risk ai
EU Digital Omnibus locks AI Act calendar and keeps August transparency

The EU Digital Omnibus, Regulation (EU) 2026/1744, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It defers high-risk AI Act obligations to 2 December 2027 and 2 August 2028, leaves the 2 August 2026 transparency line intact, and adds two new Article 5 prohibitions from 2 December 2026. Regulated buyers now procure against a locked calendar.

What the Digital Omnibus actually changed

The Commission tabled the Omnibus to smooth an AI Act rollout that had drifted from the 2024 timetable, and the final text lands more surgically than the leaked draft feared. Regulation (EU) 2026/1744 keeps the two-tier fine structure of the parent Act intact, but resets the countdown for stand-alone high-risk systems described in Annex III to 2 December 2027, and for AI embedded as a safety component in regulated products under Annex I to 2 August 2028. The high-risk suite of risk management, technical documentation, data governance, human oversight and third-party conformity assessment now attaches to those later dates rather than to 2 August 2026.

The obligations that did not move matter more for the fourth quarter than the ones that did. Article 5 prohibitions on social scoring, untargeted facial-image scraping and manipulative subliminal techniques have been live since 2 February 2025 and continue with no relief. The Omnibus adds two new prohibited practices, effective 2 December 2026: AI systems designed to generate non-consensual intimate imagery and child sexual abuse material. Article 4 AI literacy has applied since 2 February 2025, with national market surveillance authorities beginning enforcement on 2 August 2026. Article 50 transparency, covering chatbots, AI-generated content, biometric categorisation, emotion recognition and deepfakes, holds firm at 2 August 2026. General-purpose model obligations, in force from 2 August 2025 for new models and 2 August 2027 for legacy models, are untouched by the Omnibus.

The calendar every regulated buyer now uses

The table below shows the calendar procurement teams should now be planning against. Every date is drawn from the parent AI Act as amended by Regulation (EU) 2026/1744, and every date is a hard obligation on the buyer, not a target.

DeadlineObligationReferenceStatus after Omnibus
2 February 2025Prohibited practices and AI literacy in forceArticles 4 and 5Live, unchanged
2 August 2025GPAI obligations for new modelsChapter VLive, unchanged
2 August 2026Transparency at every touchpoint; Article 4 enforcement opensArticle 50Enforceable, unchanged
2 December 2026New Article 5 prohibitions: non-consensual intimate imagery and CSAM generationArticle 5 (as amended)Introduced by Regulation (EU) 2026/1744
2 August 2027GPAI obligations for legacy modelsChapter VLive, unchanged
2 December 2027High-risk stand-alone systemsAnnex IIIDeferred from 2 August 2026
2 August 2028High-risk safety componentsAnnex IDeferred from 2 August 2027

Why procurement teams should not read this as relief

A deferral is a runway, not a cancellation. Buyers in employment, education, credit scoring, law enforcement and critical infrastructure gain sixteen months on Annex III, but the transparency line and the prohibitions arrive first. A vendor that cannot demonstrate auditable behaviour, per-touchpoint disclosure and hardware-bound execution before 2 August 2026 will still fail an Article 50 conformity check, whatever the Annex III clock says. The Omnibus rewards suppliers who can prove control today, and it exposes procurement teams that treated the earlier rollout as optional.

The Omnibus also tightens the definition of what counts as a substantive change to a high-risk system, which forces contractual clarity on model updates, weights swaps and fine-tuning. Procurement teams that wrote AI clauses in 2024 or 2025 need to reopen them, because a silent model upgrade during a live contract can trigger a fresh conformity assessment and a fresh fine window. National authorities in Germany, France, the Netherlands and Ireland have already signalled that they will read the definition strictly.

What auditable behaviour looks like today

The regulation reads best alongside the Commission's Article 50 guidelines of 20 July 2026, which specify that transparency must be perceptible to the end user at the point of interaction, not buried inside a data processing notice or a terms-of-service update. That means an evidentiary record showing, for each interaction, which model spoke, which data it saw, what action followed and who authorised it. Regulators can request that record. Auditors can sample it. Litigants can subpoena it. Providers who cannot produce a signed record at that granularity carry the risk personally under Article 25 of the parent Act.

We build the Open Audit Record for exactly this problem. Every consequential action inside MICKAI is signed with post-quantum signatures and written to a tamper-evident ledger any outside party can verify offline, in a browser, with no network and no trust in us. That is the artefact a conformity assessor asks for on 2 August 2026 and again on 2 December 2027. It is also the artefact a regulated buyer's own legal team needs to answer a data protection authority without waiting on a vendor incident-response ticket.

How on-premise execution changes the calendar

The AI Act does not care where a system runs, but the fine schedule and the Data Act do. When the AI runs on hardware the buyer owns, on premise and air gapped, personal data never crosses a border, model weights never leave a controlled facility, and the deployer holds the evidence in its own custody. That collapses the joint controller argument, closes the international transfer risk under Chapter V of the GDPR, and lets a legal team answer a regulator with a single custody chain rather than three subprocessor letters and a hyperscaler status page.

MICKAI is a Sovereign Intelligence Operating System. It runs 63 studios on one operating system, ten production-ready at launch and 53 in development, all executing under a single audit ledger. The design predates the Digital Omnibus, and the calendar the Omnibus locks is the calendar we were built for.

Which AI Act deadlines still apply to a regulated buyer procuring on-prem AI in the last quarter of 2026?

In Q4 2026 the binding deadlines are the 2 August 2026 Article 50 transparency line, the ongoing Article 5 prohibitions in force since 2 February 2025, the enforcement window that opened on 2 August 2026 for the Article 4 AI literacy obligations, and the two new Article 5 prohibitions on non-consensual intimate imagery and CSAM generation from 2 December 2026. High-risk Annex III obligations do not attach until 2 December 2027, but any system placed on the market before that date must still meet transparency and prohibition rules.

Does the Digital Omnibus reduce the fine schedule?

No. The Article 99 penalties are untouched. Prohibited practices under Article 5 remain punishable by up to EUR 35 million or 7% of global annual turnover. Other violations, including Article 50 breaches, remain capped at EUR 15 million or 3%. Supplying incorrect information to a national authority is limited to EUR 7.5 million or 1%. National regulators retain full discretion within those ceilings.

What happens if a buyer procures without a calendar-locked plan?

Two exposures open. First, contractual: any AI clause silent on model version, data residency or audit access will need renegotiation before Annex III attaches, and vendors will resist changes after that date. Second, evidential: without a signed action record from day one, a 2027 conformity assessment has nothing to sample, and the buyer bears the risk rather than the vendor. Locking the calendar into procurement now is cheaper than remediation later.

What is MICKAI?

MICKAI is a Sovereign Intelligence Operating System that runs entirely on hardware the customer owns, on premise and air gapped, with no data egress. Every consequential action is signed into the Open Audit Record, a post-quantum, tamper-evident ledger any outside party can verify offline. The platform ships 63 studios, ten production-ready at launch and 53 in development, and is protected by 104 filed UK patent applications across 2,340 claims.

Subscribe
Get every new Mickai article by email.

Long-form essays on sovereign AI from Micky Irons. One email per article. No tracking, no marketing, no third parties. Every email includes a one-click unsubscribe link.

Prefer RSS? Subscribe at /articles/feed.xml.

Originally published at https://mickai.co.uk/articles/eu-digital-omnibus-ai-regulation-2026-1744. If you operate in a regulated sector or want sovereign AI on your own hardware, the audit form on mickai.co.uk is the entry point.
More articles