Digital Omnibus on AI: Regulation (EU) 2026/1744
Issuer: European Parliament & Council
Date: 27 JUL 2026
Status: IN FORCE in European Union, as of 29 JUL 2026
Defers high-risk application to 2 Dec 2027 (Annex III) / 2 Aug 2028 (Annex I); adds nudifier/NCII + AI-CSAM bans (2 Dec 2026); SME simplifications; substance of high-risk duties unchanged.
Proposed 19 Nov 2025 (COM(2025) 836) because harmonised standards, notified bodies and national authorities were behind schedule. It moved only the high-risk application dates to fixed dates: rejecting floating dates tied to standards-readiness, while Art. 50 transparency, GPAI rules, prohibitions and the full penalty regime stayed on track.
What it actually requires (5 provisions)
- High-risk duties deferred: 2 Dec 2027 (Annex III stand-alone) · 2 Aug 2028 (Annex I embedded in regulated products)
- New Art. 5 bans from 2 Dec 2026: 'nudifier'/NCII generators and AI-CSAM systems
- SME simplifications extended to small mid-caps
- Resolves overlaps with sectoral product law (e.g. Machinery Regulation); expands the AI Office's remit
- Substance of high-risk requirements not watered down
How its status moved
- PROPOSEDCOM(2025) 836, 19 Nov 2025
- ADOPTEDEP 423 to 57 (16 Jun) · Council (29 Jun 2026)
- IN FORCEPublished OJ 24 Jul 2026: binding law 27 Jul 2026
Sources (1)
Reg. 2026/1744: Digital Omnibus on AI
Published in the Official Journal 24 Jul 2026, in force 27 Jul 2026: the deferred high-risk dates are now binding law, not proposals.
The rest of the European Union stack
5 more instruments in this jurisdiction, each with its own status, provisions and sources.
- EU AI Act: Regulation (EU) 2024/1689IN FORCEWorld's first horizontal AI law; four-tier risk pyramid; extraterritorial (Art. 2).
- GPAI rules (Chapter V) + Code of PracticeIN FORCEDocumentation, copyright policy, training-data summary; systemic-risk tier >10²⁵ FLOPs; open-source carve-out; Meta declined to sign; enforcement powers activate 2 Aug 2026 (Implementing Reg. 2026/1755).
- European AI OfficeIN FORCEEU-level GPAI regulator: evaluate models, demand access, sanction; expanded remit under the Omnibus.
- Art. 50 transparency dutiesUPCOMINGChatbot disclosure; machine-readable synthetic-content marking; visible deepfake labels.
- GDPR Art. 22IN FORCERight not to be subject to purely automated decisions: the ancestor of the rights-based approach.
Where this sits in the wider picture
- The European Union regime dossier gives the doctrine this instrument belongs to, next to the other two jurisdictions.
- The Framework Explorer, filtered to EU lists every instrument in this jurisdiction in one filterable index.
- The governance simulator shows what these rules do to a real AI system, next to what the other two jurisdictions do to the same one.
- The timeline places this date beside what the other capitals were doing that month.
Knowing the instrument is step one. Complying with it is the job.
The programs teach the work that follows a rule like this one: classification calls, conformity assessment, filings, documentation, and the judgment to defend every decision.
VERIFIED 29 JUL 2026. Every fact on this page is drawn from the sources listed above and dated to the day it was checked. Study aid, not legal advice: the official texts are always authoritative.