Home / Blog / Article

Digital Omnibus: The New AI Deadlines for SMEs

The AI Omnibus moves several EU AI Act deadlines while the data omnibus is still open. What applies from August 2026 and which duties remain.

🤖 AI & AutomationPublished on August 22, 2026 | Read time: approx. 12 minutes | Author: Pragma-Code Editorial
Digital Omnibus and the new EU AI Act deadlines

The 2nd of August 2026 was supposed to be the day the EU AI Act became real for most companies. Then came the Digital Omnibus. Its AI half is politically settled, its data half is still working its way through Parliament — and many mid-sized companies across the DACH region took away exactly the wrong message: “We have time now.” This article separates what has actually moved, what has not, and which preparation pays off regardless of the final legal text.

Part of our Themen-Hub series:

This article is an in-depth expert contribution from our content cluster. Discover the complete overview on our main page:AI & Automation

Executive Summary
  • Two omnibuses, one misunderstanding: The Digital Omnibus on AI has been politically settled since the provisional agreement of 7 May 2026, while the broader data omnibus was still with Parliament and Council in the summer of 2026. Treating them as one produces a roadmap built on deadlines that do not exist.
  • Postponed is not cancelled: Prohibited AI practices and the AI literacy obligation have applied unchanged since 2 February 2025. New milestones move into December 2026 and into 2027 and 2028 — preparation time gets longer, not unnecessary.
  • The AI inventory survives every deadline: Without a reliable register of the AI capabilities actually in use, any risk classification is guesswork. That work is worthwhile regardless of the final legal text — and it is the part that takes longest.
AI Context 2026

The deadline that no longer is one

For two years, 2 August 2026 appeared on every compliance slide. It still does — but now with an asterisk. Understanding what the asterisk covers, and what it does not, saves both panic and unpleasant surprises.

1. What the Digital Omnibus actually is

On 19 November 2025 the European Commission tabled two regulatory proposals that have since travelled together under the label Digital Omnibus. One of them, formally COM(2025) 836, concerns only the AI Act and the basic aviation regulation. The other, COM(2025) 837, reaches much further: it amends the GDPR, the ePrivacy Directive, the Data Act, the NIS 2 Directive and the CER Directive, and repeals several older acts outright, among them the Data Governance Act and the Open Data Directive.

This split is not a bureaucratic subtlety. It is the source of most of the confusion we currently encounter in advisory conversations. The two proposals move through the legislative process at different speeds. On 7 May 2026, the European Parliament and the Council reached a provisional political agreement on the Digital Omnibus on AI. The data omnibus was not nearly as far along: the lead committees on Industry, Research and Energy and on Civil Liberties, Justice and Home Affairs only published their joint draft report on 22 June 2026 and debated it on 14 July 2026.

For a mid-sized company this matters concretely. Statements about postponed deadlines apply to the AI Act — not automatically to GDPR relief, not to Data Act obligations, and not to reporting channels under NIS 2. Building a compliance roadmap from headlines inevitably mixes timelines that have nothing to do with each other.

Definition of a simplification package: In EU parlance, an “omnibus” is a legal act that amends several existing acts at once. The goal is coherence — for example, removing duplicate reporting between the AI Act, the GDPR and NIS 2. The price is opacity while the process runs, because deadlines from several laws move at the same time.

2. The new deadline map

The original architecture of the AI Act was staggered: prohibited practices and AI literacy from February 2025, obligations for general-purpose AI models from August 2025, transparency duties under Article 50 and the requirements for Annex III systems from 2 August 2026. It is that third stage the AI omnibus stretches. The May 2026 agreement moves individual bundles of obligations into December 2026 and onwards to 2 August 2027, 2 December 2027 and 2 August 2028.

2 February 2025 — already binding law

The prohibition of the practices listed in Article 5 takes effect. At the same time, the AI literacy obligation under Article 4 applies: staff who operate AI systems must be trained for it. The omnibus does not touch this stage.

19 November 2025 — the Commission proposal

The Commission tables the Digital Omnibus package alongside the separate Digital Omnibus on AI, starting a legislative process that temporarily reduces planning certainty for companies before it improves it.

January and February 2026 — data protection opinions

The European Data Protection Board and the European Data Protection Supervisor support simplification but call for stronger safeguards, in particular on the question of when data still counts as personal.

7 May 2026 — provisional agreement on the AI omnibus

Parliament and Council settle politically on the amendments to the AI Act. The direction is now clear, the text is not yet in force. Legally, the AI Act in its current version continues to govern until the amendment appears in the Official Journal.

June and July 2026 — the data omnibus follows

Draft report from the ITRE and LIBE committees on 22 June, joint debate on 14 July. Several members insisted that simplification must not come at the expense of SMEs or consumer rights. No conclusion had been reached by August 2026.

December 2026 to August 2028 — the new milestones

The stretched bundles of AI Act obligations take effect in stages. For companies this means several small deadlines instead of one large one — organisationally harder, not easier.

The most important sentence about this timeline is this: a provisional political agreement is not binding law. Until the amended text is published in the Official Journal of the European Union, the AI Act applies in its existing form. Anyone writing an internal policy today should therefore tie it to the substance — “our chatbot is labelled as AI” — rather than to a date that may still move.

3. What remains unchanged

Three blocks of obligations are untouched by the entire omnibus debate and are therefore enforceable today.

Prohibited practices

Article 5 has applied since February 2025. Emotion recognition in the workplace, certain forms of biometric categorisation and social scoring are banned — regardless of company size, and regardless of whether the capability is merely a side feature of purchased software.

AI literacy under Article 4

AI Literacy has been mandatory since 2 February 2025. The Digital Omnibus shifts the emphasis towards state support, but it does not remove the operational responsibility. Documented training is the cheapest evidence a company can produce in a dispute.

The GDPR in full

As soon as an AI system processes personal data, legal basis, purpose limitation, data minimisation, data subject rights and security measures apply unchanged. No AI Act milestone alters that. For most mid-sized companies this is the larger operational risk.

There is also a practical consideration that has little to do with law. Customers, insurers and contracting authorities now ask about AI governance. A company that cannot explain in a tender which AI capabilities sit inside its value chain loses points long before any authority ever asks. We see the same pattern with cybersecurity requirements being passed down the supply chain, which we described in detail in NIS2 in the Supply Chain.

4. The AI inventory as foundation

When we discuss AI compliance with mid-sized companies, the conversation almost always starts with the same misjudgement: people believe they know where AI is in use. In reality, most organisations can list their servers and licences cleanly but not their AI landscape. The reason is structural. AI rarely arrives as an “AI project”. It arrives as a feature inside software that was already there: the summary in the ticketing system, the suggested text in the CRM, the anomaly detection in the accounting tool, the pre-filter in applicant tracking.

That last case is the delicate one. An automated pre-filter for job applications potentially falls under Annex III as a High-Risk AI System, with duties on risk management, technical documentation and human oversight. A translation tool in the same building falls into none of those categories. The difference decides an entire year of effort, and it cannot be guessed. It follows from the purpose and the context of use.

Shadow AI in the business units

The Stanford AI Index 2026 reports population-level adoption of generative AI reaching 53 per cent within three years. Translated to a company: your business units are already using AI, whether or not it appears in the tool catalogue. What is not inventoried can neither be classified nor secured.

Purchased AI inside standard software

Many obligations fall on the deployer, not only the provider. If your HR system activates a ranking feature, the deployer obligation arises with you — even though you neither trained nor selected the model. Contract clauses and vendor statements therefore belong in the inventory.

Unclear accountability

An inventory without named owners is a spreadsheet, not a steering instrument. Every row needs a person who decides on changes of purpose, shutdown and escalation — otherwise responsibility lands personally with the management board when something goes wrong.

A usable AI Inventory needs at least seven columns per entry: system and version, concrete purpose of use, categories of data involved, vendor and contractual basis, your own role (provider or deployer), the accountable person, and a preliminary risk classification. Nothing more is required at the start — but anything less is too little to support a decision.

Expert tip: inventory through invoices, not surveys

Questionnaires sent to business units reliably deliver half the truth. The faster and more complete route runs through accounts payable and the corporate card statements of the past twelve months: every SaaS subscription with an AI feature shows up there, including the ones nobody remembers. Complement this with a review of the approved OAuth applications in your identity provider.

5. The GDPR interface

The most interesting part of the Digital Omnibus is not the postponement but the attempt to rebalance the relationship between the GDPR and the AI Act. Three points matter in practice.

Comparison: status quo 2026 vs. proposed omnibus rules

Status quo (applicable law)
  • Legal basis: AI training under Article 6(1)(f) GDPR requires a strict case-by-case balancing test with considerable justification risk.
  • Personal data: Under the case law of the Court of Justice, practically any dataset with residual identifiability counts as personal.
  • AI literacy: A clear operational duty since February 2025, without a state support structure.
  • Bias testing: Processing special categories of data for fairness testing sits in a legal grey zone.
Proposed in the Digital Omnibus
  • Legal basis: Legitimate Interest is to be strengthened explicitly for the development and operation of AI.
  • Personal data: Relief for pseudonymised data where re-identification is practically difficult.
  • AI literacy: Emphasis shifts towards state-funded support rather than a purely operational obligation.
  • Bias testing: Processing of sensitive data for bias detection permitted, but only where strictly necessary and with safeguards.

In their opinions of January and February 2026, the European Data Protection Board and the European Data Protection Supervisor signalled broad support while making clear that the redefinition of personal data in particular remains politically contested. For companies this means the planned relief cannot support any processing today. Anyone planning an AI initiative that would not work without that relief is planning an initiative with open legal risk.

The workable route remains the one we take in projects involving sensitive data: as much processing as possible inside your own infrastructure, a clear separation between training and operational data, and pseudonymisation at the source. We described what that looks like technically when company data has to be made searchable in Local Enterprise RAG.

6. Germany: implementation and supervision

An EU regulation applies directly. National rules are nonetheless needed so that competences, procedures and supervision work in practice. That is precisely what the Federal Ministry for Digital Affairs and State Modernisation is working on with an act implementing the AI Regulation. The ministry points out that the rules apply directly from 2 August 2026 in principle — a statement that should not be read as an all-clear merely because individual deadlines are being stretched at European level.

The Federal Network Agency has already built an information structure on the AI Act for companies. In practice, one question dominates and the implementing act has to answer it: which authority examines what, and what does a procedure actually feel like? Until that is settled, the same rule applies as with any new supervisory regime — companies with their documentation in order negotiate from a very different position than companies that only start looking once the letter arrives.

7. Roadmap: 90 days to workable governance

The following sequence has proven itself in our projects. It is deliberately cut so that every step delivers value on its own — even if the legal text changes again.

  1. Days 1 to 15: inventory through accounting

    Review the accounts payable ledger and card statements of the past twelve months, plus the approved OAuth applications in your identity provider. The result is a raw list of every tool with an AI feature, including the shadow IT that never surfaces in a survey.

  2. Days 16 to 30: clarify purpose and role per entry

    For each row, record what the system is actually used for and whether your organisation acts as provider or as deployer. These two data points determine nearly every subsequent obligation and can only be settled in conversation with the business unit.

  3. Days 31 to 45: preliminary risk classification

    Compare against Article 5 and Annex III. The aim is not legal finality but a defensible sorting into three piles: uncritical, transparency-relevant, potentially high-risk. The third pile gets a name, a budget and a date.

  4. Days 46 to 60: implement transparency technically

    Label chatbots and AI-generated content wherever users encounter them. This is the step with the best ratio of effort to effect: technically manageable, immediately visible, and usable as evidence in any later review.

  5. Days 61 to 75: training and escalation path

    Documented AI literacy training for every role working with AI systems, plus a clearly named escalation path for anomalous output. Both are already binding duties and can be completed without waiting for open legislative files.

  6. Days 76 to 90: make governance permanent

    Decide who maintains the inventory, how often it is reviewed and how new tools enter it. Without this step the entire groundwork is stale within six months — the most common reason compliance projects get paid for twice.

The Digital Omnibus buys time. It does not buy clarity. Clarity begins when a company knows which AI it actually operates — and no extension makes that work any shorter.

Quick check: your AI governance in August 2026

Complete AI inventory including purchased features inside standard software
A named accountable person per system, not merely a department
Documented AI literacy training — a binding duty since February 2025
Chatbots and AI content visibly labelled, independent of the final deadline
No initiative resting solely on relief that has not yet been adopted
A fixed review cadence so the inventory does not age out within two quarters

Conclusion

For a long time, 2 August 2026 was the date on which the EU AI Act was going to become concrete for mid-sized companies. The Digital Omnibus defused that date for parts of the regulation — and created a new problem in the process: one milestone has become several, spread across two and a half years, in a procedure whose data half was still open in the summer of 2026. For companies that had hoped for planning certainty, that is the worse news.

The good news is that the substantial part of the work is independent of all of it. A company that knows which AI capabilities it deploys, who is accountable for them and what purpose they serve can complete any classification in days rather than months — whichever version of the text finally lands in the Official Journal. A company without that knowledge will experience every deadline as a crisis, including the postponed one.

Our recommendation is therefore unspectacular: use the time you have gained for the inventory rather than for waiting. It is the one step guaranteed not to have been wasted. Our 5-step audit protocol for AI workflows shows how a structured review of existing workflows runs in practice.

Do you have questions about AI governance in your company?

Book a free initial consultation

Have a vision?

Let's check together how we can make your idea take flight.

Book your free strategy call now

Extended Specialized Glossary

Digital Omnibus

A legislative package proposed by the European Commission on 19 November 2025 to simplify and align existing digital law, including the GDPR, the Data Act, ePrivacy, NIS 2 and the AI Act. It consists of an AI-specific proposal and a broader data proposal.

AI Inventory

A complete, maintained register of every AI capability in use across a company, including purpose, data sources, vendor, accountable owner and risk classification. It is the prerequisite for any classification under the AI Act.

AI Literacy

The obligation set out in Article 4 of the AI Act to train staff in the competent use of AI systems. It has applied since 2 February 2025 and is independent of the risk class of the system in question.

High-Risk AI System

An AI system deployed in a sensitive field listed in Annex III of the AI Act, such as recruitment, credit scoring or critical infrastructure. Such systems carry duties on risk management, technical documentation and human oversight.

Legitimate Interest

A legal basis under Article 6(1)(f) GDPR that permits processing without consent where the controller's interests override the rights of data subjects. The Digital Omnibus aims to strengthen it explicitly for AI training.

Alexander Ohl

Alexander Ohl

Pragma-Code Support (AI)• Online

Hello! I am the Pragma-Code Assistant. How can I help you today? You can ask me about our services or select a topic below.