EU AI Omnibus Officially Takes Effect: Why Did the EU Revise the AI Act?

EU AI Omnibus Officially Takes Effect: Why Did the EU Revise the AI Act?

Notice

This article is based on materials published by the European Commission and official EU legal sources as of July 29, 2026. The detailed scope of application of the AI Act and the obligations applicable to individual companies may vary depending on the type of AI system and the role of the operator. The discussion of U.S. and EU AI rules and the future formation of international standards is an analysis based on the current regulatory and industry landscape.


On July 27, 2026, the EU AI Omnibus officially took effect.

The EU had already established a comprehensive legal framework for the development and use of artificial intelligence through the AI Act.

This time, however, it readjusted some of the application schedules, corporate compliance procedures, and supervisory structures of the AI Act that had already been established.

The biggest change is that the application dates for major obligations concerning high-risk AI have been pushed back significantly.

High-risk AI used in certain areas such as education, employment, biometrics, critical infrastructure, migration, asylum, and border management will be subject to the relevant obligations from December 2, 2027, while high-risk AI embedded in products already subject to existing EU product safety regulations, such as machinery and lifts, will be subject to the relevant rules from August 2, 2028.

On the other hand, new prohibitions have been added for systems that use AI to generate or manipulate sexually explicit or intimate content without the consent of the person involved.

The schedule for national regulatory sandboxes has also been adjusted, and a separate legal basis has been established for operating an EU-level regulatory sandbox.

The important point when understanding the AI Omnibus is not simply that several dates have changed.

It is necessary to look at the fact that the EU is readjusting the AI rules it has already created so that they can actually work in industry.


What Is the AI Omnibus?

The AI Omnibus is not a new AI legal framework that replaces the existing AI Act.

It maintains the basic framework of the AI Act while readjusting the schedules, procedures, corporate obligations, and supervisory structures needed for actual implementation.

The European Commission proposed AI-related adjustments in November 2025 as part of the Digital Omnibus package, and after the legislative process, they officially took effect on July 27, 2026.

If the AI Act established the EU’s basic AI rules, the AI Omnibus can be seen as readjusting the parts needed to apply those rules in practice.


The Supervisory Role of the AI Office Is Also Expanding

The AI Omnibus expands the supervisory role of the EU AI Office over certain AI systems based on general-purpose AI (GPAI) models provided by the same provider, as well as certain AI systems integrated into very large online platforms (VLOPs) and very large online search engines (VLOSEs) under the Digital Services Act (DSA).

The direction is toward enabling more consistent supervision at the EU level of AI systems provided across multiple Member States.


The Biggest Change Is the Application Schedule for High-Risk AI

The first point to look at in the AI Omnibus is the application schedule for high-risk AI rules.

Under the existing AI Act, major high-risk AI rules were scheduled to apply in stages beginning in 2026.

However, the schedule has been significantly adjusted through the AI Omnibus.

High-risk AI systems covered by Annex III, including those used in education, employment, biometrics, critical infrastructure, migration, asylum, and border management, will be subject to the relevant rules from December 2, 2027.

High-risk AI covered by Annex I that is embedded in products already subject to existing EU product safety regulations, such as machinery, lifts, and medical devices, will be subject to the relevant rules from August 2, 2028.

This is not simply a matter of giving companies more time to prepare.

To apply high-risk AI rules in practice, detailed technical standards and conformity assessment systems are needed so that companies can determine what requirements they must meet.

However, concerns were raised that the relevant harmonized standards and conformity assessment infrastructure had not been sufficiently prepared according to the original schedule.

If the standards are unclear, companies may find it difficult to determine what they need to prepare, and supervisory authorities may also face uncertainty over what criteria should be used to assess conformity.

Ultimately, the application dates were adjusted so that the standards and support systems that companies and supervisory authorities can actually use can be prepared together with the rules.


New Prohibited Uses Have Also Been Added

The changes are not limited to schedules.

The AI Omnibus also adds new items to the types of AI use prohibited under the AI Act.

A representative example is so-called AI “nudification” systems.

AI systems that generate or manipulate sexually explicit or intimate images, videos, or audio without the consent of the person involved, as well as AI systems that generate or manipulate child sexual abuse material, have been added to the prohibited categories.

These prohibitions will apply from December 2, 2026.

This shows that the AI Omnibus does not simply adjust implementation schedules or administrative procedures, but also adds prohibited areas in response to newly emerging AI risks.


AI Regulatory Sandboxes Are Also Being Reorganized

The testing environment that allows companies to apply AI rules in practice is also being expanded.

What Is an AI Regulatory Sandbox?

A regulatory sandbox is a system that allows companies to test new technologies or services under the supervision of regulators in conditions close to a real-world environment.

Companies can test new AI systems in an actual environment and check regulatory requirements before fully launching them in the market.

Regulators can also observe how new AI technologies actually operate and what kinds of problems arise, rather than assessing them only through documents.

The Deadline for National Sandboxes Has Also Been Adjusted

The existing AI Act requires each Member State to operate at least one AI regulatory sandbox.

Under the AI Omnibus, the deadline for establishing and operating national AI regulatory sandboxes has been adjusted to August 2, 2027.

This is the schedule for national-level sandboxes operated independently by each Member State.

An EU-Level Sandbox Will Also Be Established Separately

Separately, a new legal basis has been established for the EU AI Office to establish an EU-level regulatory sandbox.

This system does not replace national sandboxes.

It creates a structure that can operate separately from Member State-level sandboxes and can address certain AI systems supervised at the EU level or cases involving multiple Member States.

In other words, the sandbox policy has not been simplified into a single system.

The adjustment of the schedule for preparing national testing infrastructure and the creation of a separate EU-level testing framework are taking place at the same time.


Compliance Procedures for SMEs and Some Mid-Cap Companies Have Also Been Adjusted

The AI Omnibus also includes adjustments that take into account company size and realistic capacity to respond.

Some support and simplified measures that had previously focused on small and medium-sized enterprises are being extended to certain mid-cap companies.

The AI Act applies in the same market to both large global companies and SMEs with limited resources.

Therefore, the same procedures can create very different levels of burden depending on a company’s size and capacity to respond.

These adjustments can be viewed as part of the process of making AI rules workable for actual companies.


AI Transparency Obligations Also Apply from August 2

Another important date follows shortly after the AI Omnibus takes effect.

Some transparency obligations under Article 50 of the AI Act will apply from August 2, 2026.

For example, AI system providers must ensure that when a person interacts directly with AI, the person can recognize that the other party is AI.

In some cases, machine-readable markings must also be applied so that the origin of content generated or manipulated by AI can be identified.

Businesses that use AI systems are also subject to certain obligations.

Transparency obligations may apply to deepfakes, emotion recognition and biometric categorization systems, and certain text on matters of public interest that is generated or manipulated by AI and published without sufficient human review.

However, there is an important transitional rule.

Generative AI systems already placed on the market before August 2, 2026, are given a transition period until December 2, 2026, for the obligations under Article 50(2) concerning the marking and detection of AI-generated content.

Therefore, it is necessary to distinguish between the fact that transparency rules begin to apply on August 2 and the fact that some existing generative AI systems receive an additional transition period.


Why Did the EU Revise the AI Act It Had Already Created?

It is difficult to create complete rules from the beginning for a technology such as AI that develops rapidly.

A schedule that appeared appropriate when the law was created may reveal problems when actual implementation is prepared.

The technical standards companies need in order to comply with the rules may not be ready, or procedures may overlap when multiple laws apply at the same time.

New AI technologies may also create risks that were not anticipated when the law was originally created.

Several of these issues appeared at the same time in the AI Omnibus.

The application schedule for high-risk AI rules was adjusted so that the necessary standards and assessment systems could be prepared.

The preparation schedule for national sandboxes was also reset, and a new EU-level sandbox was created.

New prohibitions were added for AI that generates or manipulates non-consensual intimate content and child sexual abuse material.

In other words, rather than leaving the already established AI Act unchanged, the EU has begun readjusting it in response to actual industry conditions and technological change.


What Matters More in This News Is the “Second Stage”

When the AI Act was first created, what drew the most attention was the fact that the EU had established the world’s first comprehensive legal framework for AI.

But the AI Omnibus requires us to look at a slightly different point.

The EU has already created the rules.

Companies are now preparing products and services to comply with those rules, and regulators are building supervisory and enforcement systems.

In that process, problems have been identified, including standards that were not sufficiently prepared and burdens that may arise when companies apply the rules in practice.

At the same time, new risks created by emerging AI technologies have appeared.

The EU has now begun reflecting these issues back into its laws and institutions.

Rulemaking → Preparation for Application → Identification of Problems → Adjustment → Enforcement → Stabilization

A regulatory framework does not become complete simply because a law has been enacted.

Specific standards are formed through the process of companies actually applying the rules, regulators making judgments, technical standards and cases accumulating, and necessary parts being adjusted again.

The important meaning of the AI Omnibus is that the EU has moved beyond the stage of creating AI rules and entered the stage of refining them through actual operation.


The United States Leads in AI Technology, but a Different Trend Is Emerging in Regulation

The United States currently leads global AI technology and industry.

Major AI companies such as OpenAI, Google, Microsoft, and Meta are based in the United States, and U.S. companies also have significant influence in AI semiconductors, cloud computing, and platforms.

Therefore, the position of the United States in terms of AI technology and industrial influence is clear.

However, a somewhat different trend is emerging in AI regulation.

The EU created the AI Act based on its single market and legal framework applying across 27 Member States, and it is now gaining experience in actual implementation and regulatory adjustment.

While the United States has strong influence in AI technology and markets, the EU is gaining experience earlier in legally institutionalizing AI rules and operating them in practice.

It is still too early to define the current situation as a regulatory competition between the United States and the EU.

In the United States, the federal government, state governments, regulatory agencies, and private companies are all participating in the formation of AI rules and standards.

However, it is clear that alongside the development of AI technology, the process of determining the rules under which that technology will operate is also moving quickly.


The models and services supplied to the global market by U.S. AI companies can become de facto standards in the market.

These are called de facto standards.

In contrast, the EU is creating legal standards that companies must follow through laws such as the AI Act.

These can be viewed from the perspective of de jure standards.

The two standards are created in different ways.

One is created through technology and markets, while the other is created through laws and institutions.

However, from the perspective of a global AI company, the two cannot be completely separated.

Even AI models and services developed in the United States must comply with EU rules if they are offered in the EU market.

Ultimately, the standards of the market that creates the technology and the legal standards that govern how the technology is operated will meet within actual products and services.


Different Rules Are Themselves a Cost for Companies

This is where the issue of costs for global AI companies becomes important.

Suppose the United States and the EU have significantly different methods for classifying AI system risks, informing users, labeling AI-generated content, or setting documentation standards.

Companies may have to build different response systems for different markets even when offering the same AI service.

This can affect not only product design, but also model evaluation, data governance, legal and compliance functions, internal controls, documentation, audits, and user interfaces.

If different countries establish different standards, these costs may increase further.

A company’s costs are determined not only by the content of the rules. The need to comply with different standards in different markets is itself a cost.

Therefore, in the global AI industry, it is important not only to consider what rules should be created, but also how compatible the rules of different countries and regions can become.


Accounting Standards Have Experienced a Similar Problem

This issue is not unique to the AI industry.

In accounting, companies and investors have also faced additional costs when different countries and markets use different accounting standards.

To compare financial statements prepared under different standards, investors must understand the differences between the standards and analyze the figures again.

Companies can also face additional costs if they have to respond to different disclosure and accounting standards when accessing multiple capital markets.

As the International Financial Reporting Standards, or IFRS, have been used in many countries, comparability—the ability to compare companies’ financial information under the same standards—has also had important significance.

A structurally similar issue could emerge in AI.

If standards for AI risk assessment, transparency, documentation, and data management differ significantly across markets, global companies will have to operate separate management systems to comply with each set of standards.

Ultimately, differences in standards can lead to comparison costs and compliance costs.


Could the “Brussels Effect” Also Appear in AI?

The concept of the Brussels Effect is often used to describe the phenomenon in which EU regulation influences companies and markets outside the EU.

Global companies must comply with EU rules if they want to operate in the EU market.

However, companies may decide that applying EU standards across their global products and operating systems is more efficient than creating separate products and management systems only for the EU market.

In this case, even though EU law does not directly apply to other countries, it can ultimately influence the operating standards of global companies.

This phenomenon has already been observed in areas such as data protection and product and environmental regulation.

Could something similar happen in AI?

It is still difficult to draw a conclusion.

This is because the United States has very strong technological and market influence in the AI industry.

EU legal standards could spread as common standards for global companies, or de facto standards created by the U.S. AI industry could have a greater influence on the formation of international standards.

The two systems could also influence each other and converge toward a certain set of common standards.

What matters is that as the global AI industry grows, the cost of complying with different rules at the same time may also increase.

Which standards become common operating standards for global companies could ultimately affect corporate cost structures and market-entry strategies.


What Should We Watch Going Forward?

First, how quickly the technical standards and conformity assessment systems needed to apply high-risk AI rules are actually established.

Because one of the important reasons behind the schedule adjustment was the readiness of the relevant standards and assessment infrastructure, it will be important to see how precisely the EU can develop concrete standards by 2027.

Second, how national AI regulatory sandboxes and the EU-level sandbox divide their roles in practice.

If national testing environments and the EU-level testing environment operate in a complementary way, experience accumulated from applying AI rules in actual industry could also build more quickly.

Third, how global AI companies implement transparency obligations in their actual products from August 2.

It will be possible to observe in actual services how users are informed that they are interacting with AI and how AI-generated or manipulated content is labeled.

Fourth, whether features created to respond to EU rules are applied only in the EU market.

If global AI companies begin applying features or management systems created to respond to EU rules to their services in other countries as well, this could be one signal for assessing whether the Brussels Effect is emerging in AI.

Fifth, how much U.S. and EU AI-related standards converge over the long term.

The greater the differences between the standards of the two markets, the more likely the response costs for global companies are to increase.

Conversely, if major principles and technical standards develop in a mutually compatible direction, common rules for the global AI industry may emerge.


DANA NOTES Commentary

The AI Omnibus involves changes that are too broad to view simply as the EU making a few administrative adjustments to the AI Act.

The EU significantly adjusted the application dates for high-risk AI rules, securing time to prepare the standards and assessment systems needed for actual implementation. It also adjusted the schedule for national sandboxes and established a new EU-level sandbox. At the same time, it added new prohibited uses in response to emerging AI risks.

These changes show that the EU has entered the process of making the AI rules it has already created work in actual industry.

U.S. companies lead the global market in AI technology and industry.

In contrast, the EU is gaining experience earlier in the legal institutionalization and practical application of AI rules.

The EU has already moved beyond the stage of creating AI rules and is experiencing the process of applying them, identifying problems, and adjusting them again.

And this process may not end within the EU.

Global AI companies operate simultaneously in multiple markets, including the United States and the EU.

If they have to build different AI management systems for each market, additional costs can arise across product development, data management, legal functions, internal controls, and audits.

Therefore, when looking at AI rules going forward, it is necessary to consider not only which region creates stronger rules, but also which standards ultimately become common operating standards for global companies.

Alongside competition in AI technology, the formation of international rules governing how AI should operate is also underway.

The AI Omnibus is worth watching because, in this process, the EU is moving beyond rulemaking into the actual application and adjustment of those rules, and toward the stabilization of AI governance.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top