[IND] 5 min readOraCore Editors

EU AI Act’s 2026 Omnibus buys firms more time

3 EU AI Act deadlines shift, one new ban lands, and sandbox timing moves in the 2026 Omnibus adopted by the Council.

Share LinkedIn
EU AI Act’s 2026 Omnibus buys firms more time
What changed in the EU AI Act after the Council adopted the 2026 Omnibus?

The EU Council’s 2026 Omnibus delays some AI Act deadlines and adds a new ban on intimate-image abuse.

ItemOld dateNew date
Article 6(2) high-risk AIEarlier application2 December 2027
Article 6(1) regulated productsEarlier application2 August 2028
National AI sandboxesEarlier deadline2 August 2027
Non-consensual intimate imagery banNot listedDecember 2026

1. A later start for stand-alone high-risk AI

Get the latest AI news in your inbox

Weekly picks of model releases, tools, and deep dives — no spam, unsubscribe anytime.

No spam. Unsubscribe at any time.

The biggest compliance relief is for stand-alone high-risk systems under Article 6(2) and Annex III. Their application date moves to 2 December 2027, which gives providers more runway before Articles 9 through 15 start biting.

EU AI Act’s 2026 Omnibus buys firms more time

That matters for teams building systems in areas such as hiring, education, credit, and other Annex III uses. If your roadmap assumed an earlier date, the extra time can change testing, documentation, and launch sequencing.

  • Applies to stand-alone high-risk AI systems
  • New date: 2 December 2027
  • Linked obligations: Articles 9 to 15

2. Regulated products get the longest extension

High-risk AI embedded in regulated products under Article 6(1) now applies from 2 August 2028. That is the farthest-out date in the package, and it affects sectors that already work through product conformity processes.

Medical devices, machinery, vehicles, and similar product categories get more time to align AI controls with existing certification and safety workflows. For manufacturers, this is less about new policy and more about resetting internal release calendars.

  • Applies to regulated products with embedded AI
  • New date: 2 August 2028
  • Common sectors: medical devices, machinery, vehicles

3. A new prohibition targets intimate-image abuse

The Omnibus adds a prohibition on AI practices that generate, or assist in generating, non-consensual intimate imagery or child sexual abuse material. It also covers tools that digitally remove clothing from images of real people.

EU AI Act’s 2026 Omnibus buys firms more time

This prohibition takes effect in December 2026, so developers of generative tools cannot wait for the later high-risk deadlines to review model behavior. The practical task is to test for abuse pathways now and document the guardrails you can actually enforce.

  • Covered conduct: generating or assisting intimate-image abuse
  • Includes: clothing-removal tools on real-person images
  • Effective: December 2026

4. Sandbox deadlines move later too

The Council also postpones the deadline for member states to set up national AI regulatory sandboxes under Article 53. The new date is 2 August 2027, which gives governments more time to build the programs that innovators may want to join.

For companies, the change is mostly operational. If sandbox participation is part of your compliance or test strategy, you should recheck the timetable with the relevant national authority instead of relying on the old rollout plan.

Article 53 sandbox setup deadline: 2 August 2027

5. What does not change

The Omnibus is not a reset of the EU AI Act. It leaves earlier rules in force, including the Article 5 prohibited practices that have applied since 2 February 2025 and the general-purpose AI model obligations under Articles 51 through 56 that have applied since 2 August 2025.

That means companies still need to keep current compliance work moving. The new package mainly shifts timing for certain high-risk obligations, adds one new ban, and adjusts sandbox planning, but it does not reopen the parts already live.

  • Article 5 prohibited practices remain in force
  • GPAI obligations remain in force
  • Entry into force still depends on Official Journal publication

How to decide

If you build stand-alone high-risk AI, use the extra time to finish classification, testing, and documentation before December 2027. If you make regulated products, treat August 2028 as your new internal target and map it onto product certification cycles.

If you work on generative AI, the December 2026 ban is the deadline that matters most right now. And if your strategy includes a sandbox, check the revised August 2027 setup date with your national authority before you plan any pilot timeline.