The Digital Omnibus: What the AI Act Postponed and What Stayed
Regulation (EU) 2026/1744 pushed high-risk rules to 2027 and 2028. Article 50 did not move. What changes on 2 December and what to do now.

What was published, and why
On 24 July 2026 Regulation (EU) 2026/1744 was published in the Official Journal of the European Union, and it entered into force three days later, on 27 July. It is the first amendment to the AI Act, Regulation (EU) 2024/1689, since that was adopted in 2024, and it is what is called an omnibus: one law that changes several rules at once instead of rewriting them one by one. The reason given publicly is practical. The harmonised technical standards and guidance that companies needed in order to meet the heavier obligations were not ready, and European business asked for time and certainty. An obligation nobody can measure is hard to comply with and harder still to enforce, and that is the logic of the delay. What matters to whoever runs a small company is separating two things most headlines blend together: what was postponed and what still applies today. This article makes that separation, says where the sources disagree, and sets out what we would do over the next three months.
What was postponed: high risk
The obligations for high-risk systems were pushed back, on two different dates. Annex III systems become subject to the rules on 2 December 2027. Annex I systems, meaning AI built into products that already have their own EU legislation, move to 2 August 2028. Annex III is the list that touches the most companies without their knowing. It covers, among other areas, recruitment and staff management, credit assessment, access to essential services, education and training, and critical infrastructure. A small company using an automatic CV filter, or a scoring system to decide what payment terms each customer gets, is potentially on this list. Annex I concerns AI that is part of a regulated product: machinery, medical devices, toys, vehicles. It is the world of manufacturers rather than of software service providers. What the delay does not do is change the content of the obligations. The risk-based model and the underlying protections stay; what moved is the calendar.
What did not change: and it is what touches your chatbot
Three blocks of rules still apply on their original dates, and it helps to keep track of which is which. The prohibited practices in Article 5 have applied since 2 February 2025. The obligations for general-purpose AI models have applied since 2 August 2025. And the transparency obligations in Article 50 have applied since 2 August 2026: anyone interacting with an AI system has to know it, artificially generated content has to be identifiable, and content imitating real people has to be labelled. For anyone with a chatbot on a website or on WhatsApp, this is what counts, and the omnibus gave it no extra time. We wrote about it in the article on chatbots and the AI Act: the first message has to say artificial intelligence in full, in every language the bot speaks. A marketing adjective such as smart assistant does not do it.
| Rule | Applies from |
|---|---|
| Prohibited practices (Art. 5): in force | 02/02/2025 |
| General-purpose AI models: in force | 02/08/2025 |
| Transparency (Art. 50): in force | 02/08/2026 |
| Machine-readable marking, systems already on the market: end of grace period | 02/12/2026 |
| New prohibitions (intimate material without consent, child sexual abuse) | 02/12/2026 |
| High risk, Annex III: postponed | 02/12/2027 |
| High risk, Annex I: postponed | 02/08/2028 |
What arrives on 2 December 2026
The omnibus did not only postpone: it also added. Two things carry a date of 2 December 2026, a little over two months away. The first is new prohibitions: generating or manipulating intimate material without consent, and offences involving child sexual abuse material, become expressly banned. It does not touch most companies, but it is a good reason to have a clause excluding it explicitly in any policy on the use of AI. The second is a grace period for technical marking. Article 50 requires AI-generated content, whether image, audio, video or text, to be marked in a machine-readable format. According to the sources we consulted, systems already on the market before 2 August 2026 have until 2 December 2026 to meet this technical part. The obligation to tell the user, the visible one, does not appear in that grace period. There was also a rewording of AI literacy in Article 4, which now asks for sufficient knowledge and competence, suited to the context and the technical background of whoever uses the tools. In practice it is still expected that people using the tools are trained, now with the test of suitability to the actual case.
Spain and Portugal: who supervises
In both countries who supervises is already settled, even if the national framework is still closing. In Portugal the Government designated ANACOM, on 19 September 2025, as the national supervisory authority and single point of contact, with the job of coordinating the sector authorities, among them the Banco de Portugal, the ASF and the CMVM. For a software company that means the default counterpart is ANACOM, and that in a regulated field such as banking, insurance or capital markets a second authority may be looking at the same system. In Spain the authority is AESIA, the Spanish Agency for the Supervision of Artificial Intelligence, based in A Coruña. There is also an organic law bill in progress in the Congress on the proper use and governance of AI, which names AESIA and sets out the national penalty regime. We do not treat it as law: until it passes, what counts is the EU regulation and what it already assigns to the authorities. For anyone serving both markets the consequence is simple. The underlying rules are the same on both sides; the authority, the language of communications and the timetable of national laws are not.
Why you will find contradictory information
If you search this week you will find articles saying the high-risk rules apply from 2 August 2026. Plenty of Portuguese and Spanish sites still carry that version. They are not lying: they were written before the omnibus, or not updated after it. How to check, in order of reliability. The number of the regulation: look for Regulation (EU) 2026/1744. The date of the article you are reading: if it is earlier than 24 July 2026 it may be out of date. And the text in the Official Journal, which is the only source that decides. A note on our own verification, because the difference matters. We confirmed the dates above in two independent secondary sources that agree with each other, and we could not open the full text in the Official Journal from our tools. If you are about to make a decision that costs money, whether a contract, a budget or a change of supplier, read the regulation or ask someone who will. This article is not legal advice.
What we would do over the next three months
What we would do, in this order, if the company were ours. First, what is already enforceable. If you have a chatbot, a voice assistant or an agent that talks to customers, review the first message in every language. It is half an hour of work and it is the only obligation whose date has already passed. Second, find out whether you are in Annex III. It is not a technical question, it is a question about what the system is for: does it decide about people, whether hiring, granting credit or giving access to a service? If so you have until 2 December 2027, and the mistake would be to read that as permission to do nothing until then. Documentation, testing and human oversight take months to build properly. Third, if you buy AI from suppliers, ask them in writing for their compliance timetable. A supplier who cannot answer is telling you something. Fourth, put 2 December 2026 in the calendar: technical marking for systems already on the market and the new prohibitions arrive then. And what we would not do: panic. If you use AI tools only internally, to draft or summarise, little of this concerns you today. The heavy part of the law falls on whoever supplies systems and on whoever uses them to decide about people.
Frequently Asked Questions
Is the Digital Omnibus already in force?
Yes. Regulation (EU) 2026/1744 was published in the Official Journal on 24 July 2026 and entered into force on 27 July. It is the first amendment to the AI Act since it was adopted.
Does my chatbot have to say it is AI now?
Yes. The transparency obligations in Article 50 have applied since 2 August 2026 and the omnibus did not postpone them. The first message should say artificial intelligence in full, in every language the bot answers in.
What is Annex III of the AI Act?
It is the list of uses treated as high risk, such as recruitment, credit assessment, access to essential services, education and critical infrastructure. The obligations for those systems moved to 2 December 2027.
What happens on 2 December 2026?
New prohibitions arrive, such as generating or manipulating intimate material without consent, and the grace period ends for machine-readable technical marking of systems that were already on the market before 2 August 2026.
Does this apply if I only use AI tools at work?
Largely no. The weight of the obligations falls on whoever supplies systems and on whoever uses them to decide about people. Users are covered by the AI literacy requirement in Article 4. If you have doubts about a specific case, ask a lawyer: this article is not legal advice.