Promethean

The Digital Omnibus on AI: Provisional Agreement to Postpone and Recalibrate the EU AI Act’s High-Risk Regime

  • News
  • 7 mins read

On 7 May 2026, the Council presidency and European Parliament negotiators reached a provisional political agreement on the Digital Omnibus on Artificial Intelligence (the “Digital Omnibus on AI”), a targeted package of amendments to Regulation (EU) 2024/1689 (the “EU AI Act”). The Digital Omnibus on AI forms part of the Commission’s Omnibus VII simplification package, originally proposed on 19 November 2025, and represents the first substantive set of amendments to the EU AI Act since its adoption in June 2024. The agreement materially postpones the application of the high-risk regime, refines the interplay between the EU AI Act and existing sectoral product safety legislation, and introduces a small number of new substantive obligations, most notably in relation to non-consensual intimate imagery and AI-generated child sexual abuse material.

 

The provisional agreement remains subject to formal endorsement by both the Council and the European Parliament, followed by the customary legal-linguistic scrub, with formal adoption anticipated ahead of the previously applicable 2 August 2026 deadline. Once adopted, the amendments will be published in the Official Journal of the European Union and enter into force three days thereafter.

Revised Implementation Timeline for High-Risk AI Systems 

The central element of the Digital Omnibus on AI is the staggered postponement of the compliance obligations applicable to high-risk AI systems (“HRAIS”). High-risk AI systems falling within Annex III of the EU AI Act, including use cases in biometrics, critical infrastructure, education, employment, access to public and private services, law enforcement, migration and border control, and the administration of justice, will now become subject to compliance obligations from 2 December 2027, representing a 16-month deferral from the originally applicable date of 2 August 2026. High-risk AI systems falling within Annex I, namely AI systems that are products, or safety components of products, covered by EU product safety legislation such as medical devices, toys, lifts and radio equipment, will become subject to compliance obligations from 2 August 2028, representing a 12-month deferral.

The deferral reflects, in substance, the operational reality that the harmonised technical standards, guidance documents and conformity assessment infrastructure necessary to support compliance with the high-risk regime are not yet fully in place. The additional time is intended to allow the European standardisation bodies, the Commission and the AI Office to finalise the supporting framework before substantive obligations take effect.

Refined Interaction with Sectoral Product Safety Legislation

The Digital Omnibus on AI also recalibrates the relationship between the EU AI Act and existing sectoral product safety regimes. The Machinery Regulation has been moved from Annex I, Section A to Section B of the EU AI Act, with the consequence that AI-related safety obligations affecting machinery will be addressed through delegated acts under the Machinery Regulation rather than by direct application of the EU AI Act. The Commission is also empowered, through implementing acts, to disapply overlapping AI Act requirements in sectors where equivalent obligations are already imposed under sectoral legislation, addressing long-standing industry concerns regarding regulatory duplication.

In parallel, the definition of “safety component” has been narrowed. AI components used solely for user assistance, performance optimisation, efficiency, automation, convenience or quality control will not be treated as safety components for the purposes of Article 6(1) of the EU AI Act, and will therefore fall outside the high-risk classification, unless a failure or malfunction of the relevant component could endanger health or safety.

New Prohibitions: Non-Consensual Intimate Imagery and CSAM

Notwithstanding the broader simplification thrust of the package, the co-legislators introduced two new prohibited AI practices under Article 5 of the EU AI Act. The provisional agreement prohibits the placing on the market, the putting into service and the use of AI systems that generate or manipulate realistic depictions of an identifiable natural person’s intimate parts, or of an identifiable natural person engaged in sexually explicit activities, in the absence of that person’s freely given, specific, informed, unambiguous and explicit consent. The agreement also prohibits the use of AI systems to generate child sexual abuse material (“CSAM”). The new prohibitions are expected to apply from 2 December 2026 and respond directly to the proliferation of so-called “nudifier” applications and the documented misuse of generative AI tools.

Transparency Obligations and Synthetic Content 

The grace period for the implementation of transparency obligations applicable to AI-generated content, including watermarking and machine-readable marking requirements under Article 50 of the EU AI Act, has been shortened from six months to three months. Providers of generative AI systems placed on the EU market will therefore be required to comply with the relevant transparency and labelling obligations by 2 December 2026, a materially shorter runway than originally envisaged. This represents one of the earliest live compliance obligations under the revised framework and requires near-term engineering and governance preparation for operators deploying generative AI features in the EU market.

Relief for SMEs and Small Mid-Caps

The Digital Omnibus on AI extends a number of compliance reliefs previously available only to small and medium-sized enterprises (“SMEs”) to small mid-cap companies (“SMCs”), defined as companies with up to 500 employees. The extended reliefs include simplified technical documentation requirements, proportionate penalties, and less prescriptive quality management system obligations. The deadline for Member States to establish at least one national AI regulatory sandbox has also been postponed by one year to 2 August 2027, providing national competent authorities with additional time to operationalise the relevant frameworks.

Implications for Maltese Operators

For Malta-based operators, the Digital Omnibus on AI has a number of practical implications. Providers and deployers of HRAIS within the meaning of Annex III now benefit from a defined extended runway to 2 December 2027 to complete inventories, conformity assessments, risk management documentation and post-market monitoring frameworks. Operators integrating AI into regulated products covered by Annex I, including medical devices and machinery, should reassess scoping and supplier obligations in light of the revised interaction with sectoral product safety legislation. Providers of generative AI features should treat 2 December 2026 as a near-term operational deadline for transparency and watermarking compliance, and for any Article 5 assessment of exposure to the new NCII and CSAM prohibitions.

For Malta’s financial services, gaming and digital assets sectors in particular, the Digital Omnibus on AI does not displace existing sectoral and horizontal obligations that continue to apply in parallel. AI-related risks remain subject to data protection requirements under the GDPR, product liability rules, sector-specific obligations under MFSA-administered frameworks, and obligations arising under the EU AML/CFT package. Operators should treat the EU AI Act deferrals as a recalibration of timelines, not as a reduction in the underlying risk exposure or in the supervisory expectations attaching to AI deployment.

Outlook

The Digital Omnibus on AI marks a significant moment in the evolution of European digital governance. The architecture of the EU AI Act remains intact, the prohibited practices regime has in fact been strengthened, and the general-purpose AI rules already in force are unaffected. What has changed is the calibration of the high-risk regime against the operational reality of standards readiness and the political pressure on European competitiveness following the Draghi Report. Operators that treat the additional time as an opportunity to implement structured AI governance, rather than as licence to defer preparation, will be best positioned to manage compliance as the revised deadlines approach and as the Commission publishes the supporting guidance and standards.

How Promethean Can Assist

 Promethean advises providers, deployers and importers of AI systems operating in or from Malta on the implications of the EU AI Act and the Digital Omnibus on AI. Our team supports clients in conducting AI inventory and classification exercises, mapping use cases against the revised Annex I and Annex III timelines, assessing exposure to the new Article 5 prohibitions on non-consensual intimate imagery and CSAM, preparing for the 2 December 2026 transparency and watermarking obligations, and aligning AI governance frameworks with parallel obligations under the GDPR, MFSA-administered frameworks and the EU AML/CFT package. For further information on how the Digital Omnibus on AI may affect your operations, please contact us.