AI Omnibus Grants Extra 18 Months for High-Risk AI Rules While Immediately Banning Deepfake Intimate Imagery

gray globe, europe highlighted blue with star halo; AI Omnibus Postpones Certain AI Act Compliance Deadlines

A sweeping revision to Europe’s artificial intelligence rulebook has arrived, but companies hoping for a lengthy reprieve may find the clock still ticking loudly. Regulation (EU) 2026/1744, branded the AI Omnibus, hit the EU Official Journal on 24 July 2026 and took legal effect three days later. Beneath the headlines celebrating postponed deadlines, immediate duties still loom.

The core shift involves high-risk AI systems. Standalone applications tied to areas like hiring, schooling, credit scoring, policing, and essential infrastructure now face a compliance date of 2 December 2027, pushed back from the original 2 August 2026. Meanwhile, AI built into products already governed by EU safety rules, think medical devices, machinery, and toys, gets an even longer runway until 2 August 2028.

These extensions do not, however, touch several pressing requirements. Rules covering general-purpose AI models remain locked on their original schedule. Transparency mandates, systemic risk obligations, and reporting duties for the most powerful models stay in force as initially planned.

The Omnibus also carves out two fresh prohibitions. Starting 2 December 2026, systems engineered to create or alter lifelike intimate imagery or child sexual abuse material become explicitly illegal under the AI Act. Although other laws already tackle such offenses, this gives regulators a direct enforcement tool inside the AI framework.

Power dynamics within enforcement are shifting as well. The European AI Office now holds exclusive supervisory authority over certain AI systems that rely on general-purpose models, along with those woven into very large online platforms and search engines regulated by the Digital Services Act. Its upgraded toolkit mirrors the muscle of competition watchdogs: launching probes, demanding documents, conducting on-site inspections, securing binding promises, and levying periodic fines reaching 5% of average daily turnover for ongoing breaches.

Transparency obligations refuse to wait. From 2 August 2026, organizations must still disclose AI interactions, label deepfakes and specified AI-generated material, and notify authorities about emotion recognition or biometric categorization systems. A narrow four-month grace window applies solely to machine-readable marking rules for generative AI systems already circulating before that date.

For teams building or deploying high-risk tools, the AI Omnibus offers breathing room, not a hall pass. The grace period covers select obligations, yet significant compliance milestones sit just around the corner. Preparation that stalls now risks scrambling later.