Few pieces of technology regulation have generated as much debate in the past year as the digital omnibus on AI. Since the European Commission published its proposal on 19 November 2025, businesses deploying artificial intelligence across the EU have been working out exactly which obligations under the AI Act still apply, which have been delayed, and which have changed shape entirely.
For any organization using computer vision or agentic computer vision systems in regulated environments such as manufacturing, healthcare, or transportation, the digital omnibus proposal is not an abstract policy exercise. It affects compliance timelines, documentation requirements, and how AI-generated content must be labeled going forward. Here is what changed, when, and what it means in practice.
TL;DR The digital omnibus on AI does not change the ambition behind the EU AI Act. It changes the pace at which that ambition becomes enforceable, giving regulators, notified bodies, and businesses more realistic runway to get the technical standards right.
For organizations building artificial intelligence and computer vision systems for regulated industries, the sensible response has not changed since November 2025: keep building toward compliance, because the obligations under the AI Act have moved in time, not in substance.
What is the Digital Omnibus on AI?
The digital omnibus on AI is a targeted legislative package amending Regulation (EU) 2024/1689, better known as the EU AI Act, along with related rules on civil aviation and machinery. The European Commission published the proposal on 19 November 2025 to address implementation challenges and lighten the regulatory burden identified following the entry into force of the Artificial Intelligence Act. It sits alongside two related instruments forming the broader digital omnibus package, which also covers data, cybersecurity, and privacy rules.

The core rationale is straightforward: the AI Act set ambitious deadlines for compliance, but the technical standards, conformity assessment bodies, and national competent authorities needed to actually operationalize those deadlines were not ready in time. Rather than rewrite the AI Act’s risk-based structure, the omnibus adjusts timing and scope so that regulatory frameworks can catch up with reality.
The Digital Omnibus resolves this by deferring the stand-alone high-risk AI obligations to 2 December 2027. For AI systems embedded in products already subject to EU product safety legislation, the deadline shifts further to 2 August 2028.
That single change, more than any other, defines how the next two years of AI compliance work will unfold for companies operating in or selling into the EU.
Bring a new AI vision application to life.
Why the Commission Proposed the Digital Omnibus Package
The AI Act entered into force on 1 August 2024, with obligations rolling out in phases. Prohibited practices and AI literacy obligations applied first, in February 2025, followed by governance rules for general-purpose AI models in August 2025. The next milestone, originally set for August 2026, was meant to bring most high-risk AI systems requirements into force.
The problem was one of sequencing. Harmonized technical standards businesses need to demonstrate compliance were still being drafted, notified bodies had not been fully designated in several member states, and companies reported needing roughly a year of lead time per standard once available. Faced with that gap, the Commission concluded that strict deadlines without supporting infrastructure would create legal uncertainty rather than genuine safety gains. The digital omnibus proposal was its answer.

Timeline: From Proposal to Entry into Force
The path from law proposal took roughly eight months and moved through the ordinary EU legislative procedure.
| Date | Milestone |
|---|---|
| 19 November 2025 | European Commission publishes the digital omnibus proposal |
| 13 March 2026 | Council of the EU agrees its general negotiating position |
| 7 May 2026 | Parliament and Council reach provisional agreement |
| 16 June 2026 | European Parliament formally endorses the text |
| 29 June 2026 | Council of the EU gives final green light |
| 8 July 2026 | Final act signed, and regulation enters into force following publication in the Official Journal |
That is a notably fast turnaround for EU legislation, reflecting pressure from industry and member states to resolve implementation uncertainty before the original August 2026 deadline arrived.
Key changes to High-Risk AI Systems
The headline change concerns high-risk AI systems, the category covering AI used in employment, education, credit scoring, law enforcement, and critical infrastructure, among other sensitive areas.
The Commission proposed linking the application timeline for high-risk AI systems to the availability of harmonized standards. Once the Commission confirms that those tools are available, the rules apply no later than 2 December 2027 for stand-alone high-risk AI systems and by 2 August 2028 for those embedded in products. This gives providers and deployers considerably more runway than the original AI Act allowed, though the underlying obligations, including risk management, documentation, and human oversight, have not been simplified.
A few points worth flagging for compliance teams:
- The deferral applies to the application date, not the classification rules, so systems that were high-risk before the omnibus remain high-risk now.
- Providers previously exempted from high-risk classification under narrow carve-outs no longer need to register those systems in the EU database and instead document a self-assessment.
- New Article 4-bis provisions let providers of high-risk systems process special categories of personal data, under safeguards, to detect and correct bias.
Organizations building safety and compliance monitoring tools on top of computer vision should treat the extended timeline as an opportunity rather than a reason to pause preparation, since development and operation requirements for high-risk systems remain substantively unchanged.
Transparency Obligations and AI-Generated Content
Not everything was delayed. Article 50 transparency rules still require people to be informed when they are interacting with AI, when emotion-recognition or biometric-categorisation systems are in use, and when content is a deepfake or certain AI-generated public-interest material. These obligations remain on schedule from August 2026.

The one meaningful adjustment concerns the machine-readable marking requirement under Article 50(2), which requires providers of systems generating synthetic audio, image, video, or text to ensure outputs are marked in a machine-readable format and detectable as artificially generated. That watermarking obligation has been delayed until 2 December 2026 for systems already on the market before the original deadline, giving providers time to align with technical standards and the forthcoming Code of Practice on labeling AI-generated content.
The omnibus also adds new prohibited practices under Article 5: a ban on AI systems that generate or manipulate realistic images, video, or audio of an identifiable person’s intimate parts without consent, and a parallel prohibition on AI systems used to generate abusive material. Neither new ban benefits from a transition period.
AI Literacy Obligations
AI literacy obligations under Article 4 became applicable in February 2025 and require providers and deployers to ensure staff and others operating AI systems on their behalf have sufficient understanding of the technology. The Commission’s original proposal would have removed the direct obligation from businesses and shifted responsibility toward EU institutions and member states, encouraging literacy more broadly.
That point proved contentious during negotiations. The final compromise assigns the Commission and member states an active role in promoting AI literacy through concrete programs, while operational responsibility for training staff remains with businesses. Companies should not treat this as a repeal. Internal literacy programs, particularly for teams operating vision language models or generative AI tools, remain a practical necessity even where the legal framing has shifted.
Small Mid-Cap Companies Gain New Relief
One of the more consequential but less publicized changes is the creation of a new regulatory category: small mid-cap companies, or SMCs. The category exists to close a gap in the AI Act’s original framework. Companies that outgrow the EU’s small and medium-sized enterprise (SME) thresholds, currently fewer than 250 employees and either €50 million in turnover or €43 million on the balance sheet, lose access to the compliance relief the AI Act reserves for smaller businesses, even though they are still far from the scale of a large corporation.

SMCs are defined as enterprises that exceed those SME thresholds but employ fewer than 750 people and have an annual turnover not exceeding €150 million or an annual balance sheet total not exceeding €129 million. In practice, a company with 400 employees and €80 million in turnover is too large to count as an SME but fits comfortably within the SMC thresholds, so it qualifies for SMC treatment instead.
Under the original AI Act, simplified compliance measures were reserved for microenterprises and SMEs. The omnibus extends several of these benefits to SMCs, including:
- Simplified technical documentation templates that notified bodies must accept for high-risk systems.
- More proportionate quality management system expectations under Article 17.
- Priority access to regulatory sandboxes, including a new EU-level sandbox operated by the AI Office.
- Fine calculation methods that account for company size and economic viability, though this does not extend to penalties for prohibited practices under Article 5.
For the many mid-sized companies building computer vision applications for manufacturing or logistics that have outgrown SME thresholds but still lack the compliance resources of large enterprises, this is a genuine and practical concession.
A Stronger AI Office
The digital omnibus also reshapes AI governance. The Council of the EU approved legislation expanding the AI Office’s oversight of platforms regulated under the DSA, particularly in supporting oversight of AI systems built on general-purpose models and those embedded in very large online platforms. The recitals acknowledge this expanded role will require the AI Office to be adequately staffed and resourced.
This matters for anyone deploying foundation models or general-purpose AI in EU markets, since it clarifies which authority, the AI Office or national regulators, holds jurisdiction over which systems, reducing the risk of duplicate or conflicting enforcement.
What this Means for Computer Vision and Agentic AI Deployments
For teams building computer vision platforms or agentic systems that combine perception with autonomous decision-making, the digital omnibus changes the compliance calendar without changing the underlying expectations. High-risk system obligations are deferred, but the technical standards those systems will eventually need to meet are still being finalized, not abandoned.
The practical guidance from legal advisors tracking this file is consistent: use the additional time productively. Continue building GDPR-compliant data pipelines, document model provenance, and maintain audit trails for AI-generated content, since these practices will be expected regardless of when enforcement begins. Treating the extended deadline as a license to deprioritize governance risks compressing years of preparation into a much shorter window later.
