AI Omnibus in Force | The New EU AI Act Deadlines

AI Omnibus in Force | The New EU AI Act Deadlines

Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026.

  • Amends the AI Act (2024/1689)
  • Amends the EASA Regulation (2018/1139)
  • Amends the Machinery Regulation (2023/1230)

The AI Act has not been delayed. Only one block of obligations moved. Everything else applies on 2 August 2026.

Still applies — unchanged

  • Prohibited practices (Art. 5) — since 2 February 2025
  • General-purpose AI rules (Chapter V) — since 2 August 2025
  • General application date — 2 August 2026
  • Art. 50 transparency — AI-interaction disclosure, deepfake labelling, machine-readable marking

Carve-out: generative systems on the market before 2 August 2026 have until 2 December 2026 for the Art. 50(2) marking obligations.

Moved — the high-risk timetable

Category Basis New deadline
Standalone high-risk (recruitment, credit, education, biometrics) Art. 6(2) + Annex III 2 Dec 2027
AI embedded in regulated products (machinery, medical devices, lifts, toys) Art. 6(1) + Annex I 2 Aug 2028
  • Covers Chapter III, Sections 1–3 only (excl. Art. 6(5))
  • Fixed calendar dates — the readiness condition in the original proposal was removed
  • Arts. 102–110 applicable from 27 July 2026

New prohibitions — from 2 December 2026

Art. 5(1)(ba) and (bb) ban AI systems generating or manipulating:

  • Non-consensual intimate material — realistic, identifiable person, no explicit consent
  • Child sexual abuse material — subject to the national “without right” defence

Why it matters most:

  • Intent is irrelevant. Providers are caught where the output is reasonably foreseeable and reproducible and safeguards are inadequate — Art. 5(1a)(a)(ii)
  • Fine tier: up to €35m or 7% of global turnover
  • Deployers caught only where they use the system for that purpose
  • Your defence is evidence:
    • refusal training
    • prompt guardrails
    • output filtering
    • abuse detection
    • notice-and-action
    • documented correction of circumvention
  • Not caught: cropping/contrast/captions, virtual try-on, medical imaging, non-realistic art

AI literacy — softened, not deleted

  • Old: ensure a sufficient level
  • New: take measures to support development — no specific level guaranteed for any individual
  • Still do it: a documented, role-based AI training and acceptable-use policy remains your evidence in employment and GDPR disputes

Art. 4a — wider legal basis for bias testing

Art. 10(5) deleted, replaced by a free-standing Art. 4a:

  • Wider scope — now covers deployers of high-risk systems and providers/deployers of non-high-risk AI systems and models
  • Strict cumulative conditions:
    • no alternative data
    • pseudonymisation
    • access controls
    • no third-party transfer
    • deletion on correction
    • justification in the Art. 30 GDPR register
  • A permission, not a duty

Effect: a Union-law basis under Art. 9(2)(g) GDPR to process special-category data to test for discriminatory output — if safeguards are built first.

Scope relief

  • “Safety component” narrowed — only where the intended purpose is to prevent or mitigate health and safety risks (Art. 3(14))
  • Art. 6(1a) — user assistance, performance optimisation, efficiency, automation, convenience, quality control: not safety components
  • Art. 6(1b) — unless failure would endanger health and safety
  • Art. 6(1c) — non-health-and-safety third-party assessment (spectrum, EMI) doesn’t trigger Art. 6(1)(b)
  • Art. 43(3) — embedding high-risk AI does not force a third-party conformity route
  • Machinery moves from Annex I Section A to Section B

SME / small mid-cap relief

New Art. 3 definitions of SME and SMC unlock:

  • Simplified Annex IV documentation that notified bodies must accept (Art. 11(1))
  • Size-proportionate quality management (Art. 17(2))
  • Simplified QMS extended from microenterprises to all SMEs and start-ups (Art. 63)
  • Priority access to the new EU-level sandbox (Art. 57(3a))

Sandboxes and governance

  • National sandboxes operational by 2 August 2027
  • EU-level sandbox — AI Office may run one; real-world testing extended (Arts. 60, 60a)
  • AI Office competence widened to systems built on GPAI models within the same undertaking
  • Commission gains market surveillance powers over AI in VLOPs/VLOSEs under the DSA

Greece

The national framework is no longer pending.

  • Passed 16 July 2026 — “Μέτρα εφαρμογής του Κανονισμού (ΕΕ) 2024/1689 — Τροποποίηση του ν. 4961/2022”
  • Places Greece among the first Member States with a complete national mechanism

Who does what:

  • Hellenic Data Protection Authority (ΑΠΔΠΧ) — central market surveillance authority and national contact point
  • EETT — notifying authority, hosting the new AI Coordination and Expertise Centre
  • Art. 77 fundamental-rights authorities (notified November 2024) — HDPA, Ombudsman, ADAE, GNCHR

What the law adds:

  • Administrative sanctions, extending to public sector bodies
  • Unified national complaints procedure
  • Criminal penalties for removing Art. 50 transparency labels from deepfake content — a national add-on with no direct AI Act equivalent
  • National regulatory sandbox for start-ups and SMEs
  • ν. 4961/2022 amended, not repealed — its employer-notification and registry duties survive below the high-risk threshold

Two timing points:

  • The Greek law was voted eleven days before the Omnibus entered force, so it implements the AI Act as it stood. The moved Chapter III deadlines flow from the Regulation and apply directly in any event — but read the national provisions against the amended text, not the original.
  • The deepfake-label provision bites first. It attaches to Art. 50, which applies from 2 August 2026 and did not move.

Elsewhere in the Union, Art. 70 designations remain outstanding. A missing designation delays enforcement — it does not suspend the obligation. The AI Act is directly applicable.

Do this now

  • Inventory and date-stamp every AI system — the Art. 50(2) and Art. 111(2) periods both turn on it (grace period now runs by type and model)
  • Re-run high-risk classification against the narrowed safety-component test; document it
  • Ship Art. 50 compliance by 2 August 2026 — in Greece, with criminal exposure now attached to label removal
  • Build the nudification/CSAM safeguards file by 2 December 2026
  • Update the AI literacy programme to the new Art. 4
  • Reassess bias testing under Art. 4a
  • Revisit supplier contracts — Art. 25(2) cooperation duties are now itemised; the open-source carve-out excludes GPAI models
  • Treat December 2027 as a delivery date

FAQ

Is the EU AI Act delayed?

  • Partially — only Chapter III, Sections 1–3
  • New dates: 2 December 2027 and 2 August 2028
  • Unchanged: the 2 August 2026 date, the prohibitions, GPAI rules and Art. 50

When do the nudification and CSAM bans apply? 2 December 2026.

Is AI literacy still required? Yes, in softened form under the rewritten Art. 4.

Does this apply to non-EU companies? Yes — extraterritorial scope unchanged.

Who enforces in Greece?

  • Hellenic Data Protection Authority — central market surveillance authority
  • EETT — notifying authority
  • Both under the implementing law passed on 16 July 2026

We advise providers, deployers, importers and distributors on:

  • AI Act classification and conformity
  • Generative-AI safeguards
  • The GDPR interface
  • Supplier contracting
  • Regulator engagement

In Greek, English and Italian.

[Contact Tsamichas Law Firm →]

General information only, not legal advice.


SEO notes (remove before publishing)

  • Slug: /insights/ai-omnibus-eu-ai-act-deadlines
  • Title tag (49): AI Omnibus in Force: New EU AI Act Deadlines
  • Meta (149): Regulation (EU) 2026/1744 is in force. New high-risk deadlines, the nudification ban and AI literacy changes — plus what still applies from 2 August.
  • Primary keyword: AI Omnibus
  • Secondary keywords:
    • Regulation (EU) 2026/1744
    • Digital Omnibus on AI
    • EU AI Act deadlines 2027
    • is the EU AI Act delayed
    • AI Act Greece
    • Greek AI Act implementing law
    • ΑΠΔΠΧ AI Act
    • nudification ban EU
    • AI literacy Article 4
    • AI Act lawyer Athens
  • Schema: Article + FAQPage + LegalService; include datePublished, dateModified, author linked to a lawyer bio (E-E-A-T on legal YMYL)
  • Internal links: AI Governance · MiCA/Web3 · GDPR · Contact · Greek AI Act implementing law (forthcoming — reserve /insights/greece-ai-act-implementing-law)
  • External links:
    • https://eur-lex.europa.eu/eli/reg/2026/1744/oj
    • https://digital-strategy.ec.europa.eu/en/news/ai-omnibus-enters-force
  • Image alt: AI Omnibus Regulation EU 2026/1744 AI Act deadlines
  • Review triggers:
    • Art. 2(13) delegated acts — 2 Aug 2027
    • Commission Annex I guidelines — 1 Aug 2027
    • FEK publication and law number of the Greek implementing law

Open item before publishing: insert the law number and FEK citation for the Greek implementing law in place of the voting date.

Tsamichas Law Firm | AI Governance | Athens · 28 July 2026

Regulation (EU) 2026/1744 — the Digital Omnibus on AI — entered into force on 27 July 2026.

  • Amends the AI Act (2024/1689)
  • Amends the EASA Regulation (2018/1139)
  • Amends the Machinery Regulation (2023/1230)

The AI Act has not been delayed. Only one block of obligations moved. Everything else applies on 2 August 2026.

Still applies — unchanged

  • Prohibited practices (Art. 5) — since 2 February 2025
  • General-purpose AI rules (Chapter V) — since 2 August 2025
  • General application date — 2 August 2026
  • Art. 50 transparency — AI-interaction disclosure, deepfake labelling, machine-readable marking

Carve-out: generative systems on the market before 2 August 2026 have until 2 December 2026 for the Art. 50(2) marking obligations.

Moved — the high-risk timetable

Category Basis New deadline
Standalone high-risk (recruitment, credit, education, biometrics) Art. 6(2) + Annex III 2 Dec 2027
AI embedded in regulated products (machinery, medical devices, lifts, toys) Art. 6(1) + Annex I 2 Aug 2028
  • Covers Chapter III, Sections 1–3 only (excl. Art. 6(5))
  • Fixed calendar dates — the readiness condition in the original proposal was removed
  • Arts. 102–110 applicable from 27 July 2026

New prohibitions — from 2 December 2026

Art. 5(1)(ba) and (bb) ban AI systems generating or manipulating:

  • Non-consensual intimate material — realistic, identifiable person, no explicit consent
  • Child sexual abuse material — subject to the national “without right” defence

Why it matters most:

  • Intent is irrelevant. Providers are caught where the output is reasonably foreseeable and reproducible and safeguards are inadequate — Art. 5(1a)(a)(ii)
  • Fine tier: up to €35m or 7% of global turnover
  • Deployers caught only where they use the system for that purpose
  • Your defence is evidence:
    • refusal training
    • prompt guardrails
    • output filtering
    • abuse detection
    • notice-and-action
    • documented correction of circumvention
  • Not caught: cropping/contrast/captions, virtual try-on, medical imaging, non-realistic art

AI literacy — softened, not deleted

  • Old: ensure a sufficient level
  • New: take measures to support development — no specific level guaranteed for any individual
  • Still do it: a documented, role-based AI training and acceptable-use policy remains your evidence in employment and GDPR disputes

Art. 4a — wider legal basis for bias testing

Art. 10(5) deleted, replaced by a free-standing Art. 4a:

  • Wider scope — now covers deployers of high-risk systems and providers/deployers of non-high-risk AI systems and models
  • Strict cumulative conditions:
    • no alternative data
    • pseudonymisation
    • access controls
    • no third-party transfer
    • deletion on correction
    • justification in the Art. 30 GDPR register
  • A permission, not a duty

Effect: a Union-law basis under Art. 9(2)(g) GDPR to process special-category data to test for discriminatory output — if safeguards are built first.

Scope relief

  • “Safety component” narrowed — only where the intended purpose is to prevent or mitigate health and safety risks (Art. 3(14))
  • Art. 6(1a) — user assistance, performance optimisation, efficiency, automation, convenience, quality control: not safety components
  • Art. 6(1b) — unless failure would endanger health and safety
  • Art. 6(1c) — non-health-and-safety third-party assessment (spectrum, EMI) doesn’t trigger Art. 6(1)(b)
  • Art. 43(3) — embedding high-risk AI does not force a third-party conformity route
  • Machinery moves from Annex I Section A to Section B

SME / small mid-cap relief

New Art. 3 definitions of SME and SMC unlock:

  • Simplified Annex IV documentation that notified bodies must accept (Art. 11(1))
  • Size-proportionate quality management (Art. 17(2))
  • Simplified QMS extended from microenterprises to all SMEs and start-ups (Art. 63)
  • Priority access to the new EU-level sandbox (Art. 57(3a))

Sandboxes and governance

  • National sandboxes operational by 2 August 2027
  • EU-level sandbox — AI Office may run one; real-world testing extended (Arts. 60, 60a)
  • AI Office competence widened to systems built on GPAI models within the same undertaking
  • Commission gains market surveillance powers over AI in VLOPs/VLOSEs under the DSA

Greece

The national framework is no longer pending.

  • Passed 16 July 2026 — “Μέτρα εφαρμογής του Κανονισμού (ΕΕ) 2024/1689 — Τροποποίηση του ν. 4961/2022”
  • Places Greece among the first Member States with a complete national mechanism

Who does what:

  • Hellenic Data Protection Authority (ΑΠΔΠΧ) — central market surveillance authority and national contact point
  • EETT — notifying authority, hosting the new AI Coordination and Expertise Centre
  • Art. 77 fundamental-rights authorities (notified November 2024) — HDPA, Ombudsman, ADAE, GNCHR

What the law adds:

  • Administrative sanctions, extending to public sector bodies
  • Unified national complaints procedure
  • Criminal penalties for removing Art. 50 transparency labels from deepfake content — a national add-on with no direct AI Act equivalent
  • National regulatory sandbox for start-ups and SMEs
  • ν. 4961/2022 amended, not repealed — its employer-notification and registry duties survive below the high-risk threshold

Two timing points:

  • The Greek law was voted eleven days before the Omnibus entered force, so it implements the AI Act as it stood. The moved Chapter III deadlines flow from the Regulation and apply directly in any event — but read the national provisions against the amended text, not the original.
  • The deepfake-label provision bites first. It attaches to Art. 50, which applies from 2 August 2026 and did not move.

Elsewhere in the Union, Art. 70 designations remain outstanding. A missing designation delays enforcement — it does not suspend the obligation. The AI Act is directly applicable.

Do this now

  • Inventory and date-stamp every AI system — the Art. 50(2) and Art. 111(2) periods both turn on it (grace period now runs by type and model)
  • Re-run high-risk classification against the narrowed safety-component test; document it
  • Ship Art. 50 compliance by 2 August 2026 — in Greece, with criminal exposure now attached to label removal
  • Build the nudification/CSAM safeguards file by 2 December 2026
  • Update the AI literacy programme to the new Art. 4
  • Reassess bias testing under Art. 4a
  • Revisit supplier contracts — Art. 25(2) cooperation duties are now itemised; the open-source carve-out excludes GPAI models
  • Treat December 2027 as a delivery date

FAQ

Is the EU AI Act delayed?

  • Partially — only Chapter III, Sections 1–3
  • New dates: 2 December 2027 and 2 August 2028
  • Unchanged: the 2 August 2026 date, the prohibitions, GPAI rules and Art. 50

When do the nudification and CSAM bans apply? 2 December 2026.

Is AI literacy still required? Yes, in softened form under the rewritten Art. 4.

Does this apply to non-EU companies? Yes — extraterritorial scope unchanged.

Who enforces in Greece?

  • Hellenic Data Protection Authority — central market surveillance authority
  • EETT — notifying authority
  • Both under the implementing law passed on 16 July 2026

We advise providers, deployers, importers and distributors on:

  • AI Act classification and conformity
  • Generative-AI safeguards
  • The GDPR interface
  • Supplier contracting
  • Regulator engagement

Μοιραστείτε αυτήν την ανάρτηση

Κλείστε το ραντεβού σας.

Πετυχαίνουμε μαζί αγωνιζόμενοι για Δικαίωμα και Δικαιοσύνη.

Καλέστε μας

+30 210 363 8590