On 27 July 2026, the Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force just three days after publication in the Official Journal, and less than a week before the AI Act’s original high-risk compliance deadline was due to go in effect. The AI Act sets out rules for how AI systems are developed and used across the EU, with the strictest obligations reserved for so-called ‘high-risk’ systems. Since the Commission’s initial call for evidence, ACT has been engaging with policymakers regarding the AI Act, raising concerns from our members that the high-risk obligations were disproportionate for small companies. The good news is that the AI Omnibus helps to address several of those concerns. Here’s what changed on the AI Act, where the gaps remain, and the specifics of how this applies to you.

What we asked for and got

  • Small mid-caps finally get a seat at the SME table. Several flexibilities that used to stop at the small and medium-sized enterprise (SME) threshold now extend to small mid-cap (SMC) companies (under 750 employees and €150 million turnover) including simplified technical documentation that notified bodies must now accept, a quality management system scaled to company size, and priority sandbox access. This is a change ACT has pushed for directly; plenty of our members will hopefully outgrow the SME definition long before they have the compliance infrastructure of a large platform. This helps close that gap.
  • More room to test. The Omnibus expands real-world testing outside sandboxes, including for Annex III systems (specific high-risk use cases, such as recruitment, education, and credit scoring), and creates an EU-level regulatory sandbox with priority access for SMEs, startups, and SMCs. For ACT members building in regulated verticals such as health tech, fintech, and ed-tech, this is where a lot of practical de-risking will happen, assuming the sandbox delivers on accessibility.
  • The compliance clock is reset, not removed. Annex III high-risk obligations now apply from 2 December 2027 instead of August 2026, and Annex I embedded high-risk systems (machinery, toys, lifts) move to 2 August 2028. The Article 5 prohibited practices and the Chapter V general-purpose AI rules are untouched, those have applied since February and August 2025 respectively. Transparency obligations under Article 50 still land on 2 August 2026, with only the machine-readable content-marking piece getting a grace period to December 2026 for systems already on the market.
  • Lighter administrative asks. AI literacy becomes an obligation of reasonable measures rather than a guaranteed outcome, with the Commission and Member States taking on more of the practical-guidance burden through a shared information platform. EU database registration for exempted systems is simplified. And there’s now explicit legal room to process special categories of personal data for bias detection and correction, closing a gap that made bias auditing legally difficult.
  • Two other obligations to look out for. The new ban on AI systems that generate non-consensual intimate imagery (‘nudifier’ apps) or CSAM stays in force, with a hard deadline of 2 December 2026. And expanded AI Office oversight of systems built on general-purpose models and embedded in large platforms and search engines applies immediately from entry into force, with no separate compliance deadline of its own.

What we asked for that didn’t make it in

Not everything on our wish list landed.

  • Lack of compliance support tools. We have consistently called for more practical support tools, templates, and guidance apart from the changes to the legal text itself. What we got is mostly the latter. The literacy platform is a step toward the former, but it’s not yet the compliance toolkit we wanted.
  • No parallel relief for GPAI obligations. The Chapter V general-purpose AI (GPAI) rules, which already apply, weren’t touched. ACT members building on or with foundation models don’t get the same breathing room that Annex III and Annex I now have.
  • A substantive burden, regardless of timing, remains. Delaying a deadline doesn’t reduce what compliance costs when you have to comply. Commission impact assessments cited during the debate put the cost of a single high-risk product’s compliance in the hundreds of thousands of euros. That number doesn’t change just because the deadline moved.
  • Sandbox access is a promise, not yet a guarantee. The EU-level sandbox’s value depends entirely on its entry requirements and what participation delivers, and neither is fully specified yet. We’ll be watching the implementing detail closely.
  • No blanket simplification of the AI Act/GDPR/DSA interplay. A clearer, single answer on how the AI Act interacts with the General Data Protection Regulation (GDPR) and the Digital Services Act (DSA) is needed. The Omnibus only partially addresses this, mainly through the bias-detection carve-out; broader interplay questions are still left to guidance and case-by-case interpretation.
  • No assurance on conformity assessment capacity. Procedures for conformity assessment bodies are simplified, but the underlying bottleneck, too few designated bodies to handle the coming wave of high-risk assessments, isn’t solved by procedural tweaks alone. Whether capacity catches up before December 2027 is still an open question.

What this means for you in practice (and fast approaching deadlines)

  1. Re-run your AI inventory. Don’t just re-check ‘high-risk or not’, separate Annex III systems, Annex I product-embedded systems, GPAI-based systems, systems generating synthetic content, and anything already on the market before 2 August 2026. Each now sits on a different compliance clock.
  2. Check if you now qualify as an SMC. If you’ve outgrown SME status but stayed under 750 employees and €150 million turnover, you likely have new access to simplified documentation and sandbox priority, which is worth a fresh look even if you assumed the AI Act’s lighter-touch provisions weren’t for you anymore.
  3. Don’t skip the 2 August 2026 transparency deadline. It’s days away and untouched by the Omnibus. If your product interacts with users or generates synthetic content, that obligation is live regardless of the Annex III reset.
  4. Flag any nudifier-adjacent or CSAM-risk functionality immediately. The ban is already in force, with a hard compliance date of 2 December 2026 for anything currently on the market.
  5. Watch the sandbox implementing rules. Priority access on paper is only useful if entry criteria are workable for a small team. We’ll flag details as the Commission publishes them.

We’ll keep tracking implementing guidance, sandbox rules, and conformity assessment capacity as they develop, and will flag anything that changes this picture for the startup community. Below you can find some resources that might be useful.

Resources