Last updated: July 10, 2026
TL;DR — EU AI Act Omnibus, in 30 seconds
The EU formally adopted the “Omnibus VII” amendments to the AI Act on June 29, 2026, after Parliament’s approval on June 16 (423–57, 174 abstentions). Three things changed:
- High-risk deadlines moved: Dec 2, 2027 for stand-alone Annex III systems (was Aug 2026); Aug 2, 2028 for Annex I embedded systems (was Aug 2027).
- Transparency did NOT move: Article 50 disclosure rules and GPAI enforcement are still live Aug 2, 2026. Watermarking gets a grace period only for systems already on the market before that date — pushed to Dec 2, 2026.
- New ban added: AI systems generating non-consensual intimate imagery or CSAM are now prohibited outright, effective Dec 2, 2026.
Fines are unchanged (up to €35M/7% for banned practices, €15M/3% for high-risk violations). If you have EU customers, this applies to you regardless of where you’re based — see the North America section below.
If your organization builds, sells, or deploys AI systems that touch the EU market, the compliance calendar you were planning against changed this year. This affects any provider or deployer of high-risk AI systems, general-purpose AI models, or AI-generated content tools with EU exposure — regardless of where you’re headquartered. By the end of this article, you’ll know exactly which deadlines moved, which didn’t, and what to do about it this week.
The Omnibus is now law — here’s the timeline that matters
On May 7, 2026, the Council and Parliament reached a political agreement to amend the AI Act as part of the so-called “Omnibus VII” legislative package in the EU’s simplification agenda (Council of the EU). That agreement wasn’t just a proposal — it went the distance. Parliament gave its final approval on June 16, 2026, and the Council followed with formal adoption on June 29, 2026, completing the amendment process for Regulation (EU) 2024/1689 (Council of the EU, June 29 release).
The vote itself is worth noting: Parliament approved the text 423 votes in favor to 57 against, with 174 abstentions — a much narrower margin than the 569-vote mandate Parliament had given negotiators back in March, a sign that “simplification” was more contested internally than the headline suggests (Licentium).
Revised deadlines at a glance:
| Obligation | Original deadline | New deadline |
| Stand-alone high-risk AI (Annex III) — employment, education, credit scoring, biometric ID, critical infrastructure | Aug 2, 2026 | Dec 2, 2027 |
| High-risk AI embedded in regulated products (Annex I) — medical devices, machinery, toys, lifts | Aug 2, 2027 | Aug 2, 2028 |
| Watermarking (Article 50(2)), systems on market before Aug 2, 2026 | Aug 2, 2026 | Dec 2, 2026 |
| Article 50 transparency obligations (new systems) | Aug 2, 2026 | Unchanged — Aug 2, 2026 |
| GPAI Commission enforcement powers | Aug 2, 2026 | Unchanged — Aug 2, 2026 |
| New prohibition: non-consensual intimate imagery / CSAM | – | Dec 2, 2026 |
What actually moved (and what didn’t)
The instinct is to read “Omnibus” as “everything got pushed back.” That’s wrong, and it’s the mistake most likely to burn compliance teams this year.
Article 50 transparency obligations — the requirement to tell users they’re interacting with AI — were not delayed and remain enforceable from August 2, 2026. If you run a consumer-facing chatbot, emotion-detection tool, or any system generating synthetic content, that deadline is live regardless of what else shifted. GPAI penalty powers for the Commission activate on the same date (informed, clearly).
Watermarking is where it gets specific: for generative systems already on the market before August 2, 2026, the deadline to implement machine-readable watermarking was postponed from August 2026 to December 2, 2026. But systems placed on the market after August 2, 2026 get no grace period — they must comply from day one. A company that ships a new generative feature in September 2026 doesn’t inherit the extension a competitor who launched in July gets to keep.
The new prohibition nobody negotiated away
The single substantive addition to the Act’s banned-practices list — not a deadline change, an actual new prohibition — targets AI systems that generate non-consensual intimate imagery. The Council’s own announcement frames it plainly: the law now bans AI systems that generate nude images of real people or edit clothing out of existing photos to reveal intimate parts, alongside AI-generated child sexual abuse material, effective December 2, 2026.
This was the one piece of the negotiation the left flank of Parliament refused to trade away in exchange for industry’s deadline extensions, and it applies to both providers placing such systems on the market and deployers using them — with no phase-in comparable to the high-risk extensions (DataGuidance).
The quieter changes: SMEs, AI literacy, and bias data
Three smaller amendments are worth flagging if you run a mid-sized organization:
- SME protections now reach further. Simplified documentation, reduced fine caps, and sandbox priority access — previously SME-only — now extend to “small mid-cap” companies, defined as firms with up to 750 employees and €150 million in annual revenue (Latham & Watkins).
- AI literacy got softer, not stricter. Article 4 originally required organizations to “ensure a sufficient level” of AI literacy among staff. The amended text downgrades this to an obligation for the Commission and Member States to support and facilitate literacy development — no enforceable competency bar (Mishcon de Reya).
- Bias-detection data access widened. The right to process special-category personal data (health, biometric, ethnicity) specifically to detect and correct bias in AI models now extends to all AI systems, not just high-risk ones — under a strict-necessity test that requires documenting why synthetic or anonymized data couldn’t do the job instead (Mishcon de Reya). Providers relying on the Article 6(3) exemption also remain required to register their systems in the EU database — a proposal to remove that obligation was dropped in the final text (Sidley Austin).
Fines for actual violations are unchanged: up to €15 million or 3% of global turnover for high-risk non-compliance, and up to €35 million or 7% for prohibited practices. The Omnibus simplified timing and scope. It did not soften enforcement.
North America: what this means if you’re not in the EU at all
None of this is an EU-only story. The AI Act’s extraterritorial reach means a US or Canadian company can fall in scope with zero EU offices, employees, or servers — the trigger is whether your AI system is placed on the EU market or its output is used by people in the EU, not where you’re incorporated.
For US organizations, there’s no federal equivalent to map against — instead, a patchwork. Texas enforces the Responsible AI Governance Act (TRAIGA), in effect since January 1, 2026, with penalties from $10,000 to $200,000 per violation and named compliance with NIST AI RMF as an affirmative defense. California’s SB 53, effective the same date, targets frontier developers specifically — companies above $500 million in revenue training models above 10²⁶ FLOPs. Neither substitutes for EU AI Act compliance if you have EU customers; they’re additive, not equivalent.
The practical move most compliance teams land on is to map EU AI Act documentation to the NIST AI RMF structure, since NIST’s Govern/Map/Measure/Manage functions are already the reference point most US regulators and auditors expect.
Canada doesn’t have an enacted AI-specific statute at all right now. The federal Artificial Intelligence and Data Act (AIDA) died on the order paper when Parliament was prorogued in January 2025, and there’s no confirmed timeline for reintroduction. In its place, Canadian organizations are working from the federal Voluntary Code of Conduct for Generative AI, the binding Directive on Automated Decision-Making for federal institutions, and emerging provincial rules like Ontario’s Bill 194 (Schwartz Reisman Institute). A Canadian company with EU customers is still fully in scope for the AI Act even though its own domestic framework remains unsettled — which makes the EU Act, not AIDA, the more concrete document to build a governance program against today.
What to do this week
The deadline extensions buy planning time, not a reason to pause. Concretely:
- Re-classify your AI system inventory against the two-tier deadline — separate anything that’s a stand-alone Annex III system (December 2027) from anything embedded in an Annex I regulated product (August 2028). They’re no longer on the same clock.
- Check your Article 50 status specifically — this deadline did not move. If you have a customer-facing AI system or generate synthetic content, confirm your transparency disclosures are ready for August 2, 2026.
- Audit generative content systems already on the market before August 2, 2026 to claim the watermarking grace period through December — new launches after that date won’t get it.
- Screen for anything that could be read as generating non-consensual intimate imagery, even incidentally (e.g., image-editing features), against the new December 2026 prohibition.
- If you’re a mid-sized company near the SME threshold, check whether the new “small mid-cap” definition (≤750 employees, ≤€150M revenue) now qualifies you for simplified documentation you weren’t eligible for before — and compare it against how ISO/IEC 42001 certification could cover the same ground.
Where Fruggr fits
Extended deadlines don’t remove the need for a documented, auditable AI governance program — they just change which systems need one first. Fruggr’s compliance module maps your AI inventory against the AI Act’s revised timeline automatically, so you know which systems are on the 2026, 2027, or 2028 clock without rebuilding your tracking from scratch.