This summer the European Union changed its own AI rulebook. The so-called Digital Omnibus on AI was agreed by the Council and the Parliament on 7 May 2026, approved by the Parliament's plenary on 16 June and published in the Official Journal on 24 July as Regulation (EU) 2026/1744. Headlines focused on the delays. For most companies that simply use AI, the more important news is what did not move.
What was postponed
The heaviest obligations, the ones for high-risk AI systems, now start later:
- 2 December 2027 for stand-alone high-risk systems, such as AI used to screen job candidates or assess creditworthiness.
- 2 August 2028 for high-risk AI built into regulated products, such as machinery or medical devices.
If your company builds or buys this kind of system, you have more time to prepare. It is a deferral, not a cancellation.
What already applies
Two groups of rules are in force today and the Omnibus did not change their timing.
Prohibited practices. Since February 2025 some uses of AI are banned outright, such as manipulative techniques or social scoring. The Omnibus added a new ban on AI that generates non-consensual intimate images or child sexual abuse material.
Transparency. Since 2 August 2026 people must be told when they are talking to an AI system, unless it is obvious from the context, and deepfakes must be disclosed as such. If your website has a chatbot or you publish AI-generated images and video, this concerns you now. Providers of AI tools that were already on the market have until 2 December 2026 to add machine-readable marking to generated content.
AI literacy is still an obligation
The Commission had proposed turning the AI literacy rule into a simple encouragement. The final text did not go that far. Under the revised Article 4, companies that provide or use AI systems must still take measures to support the AI literacy of their staff, while the Commission and Member States support those efforts with guidance. The law does not set a specific level that each person must reach, but a company should be able to show what it has done.
In practice: if your people use AI at work, you need a documented training effort, not a certificate for every employee.
Good news for growing companies
Several simplifications that were reserved for SMEs now also cover small mid-cap companies, including lighter technical documentation, proportionate management systems and capped fines.
A five-step checklist
- Map the AI you use. List the tools, who uses them and with which data.
- Check for chatbots and generated content. Add a clear notice where customers interact with AI and label synthetic media.
- Write a short AI usage policy. Which tools are allowed, which data can be shared, who reviews the output.
- Train and document. Keep attendance lists, materials and dates for your AI literacy activities.
- Flag potential high-risk uses. Recruitment, credit and safety-critical uses need a closer look before December 2027.
This is the ground our AI Evolution Program covers in its first weeks: a map of the processes, a usage policy and documented training for every department. This article is general information, not legal advice.