August 2026

AI Omnibus Enters into Force: Key Changes in the First Amendment to the EU AI Act

I. Introduction

The EU Artificial Intelligence Act (EU AI Act) is the world's first comprehensive legal framework for artificial intelligence. Compared with the US approach, which relies mainly on executive orders and sector-specific guidance and places greater emphasis on promoting innovation, the EU AI Act adopts stricter upfront regulation focused on AI's potential risks. The Act classifies AI systems into four categories according to their level of risk: unacceptable risk, high risk, limited risk, and minimal or no risk. Providers and deployers must comply with the obligations applicable to the category in which their AI systems fall.

On 19 November 2025, the European Commission announced the Digital Omnibus Package. The AI Omnibus is the part of that package dedicated to amending AI rules. The other proposed changes, covering the GDPR, the ePrivacy Directive, the NIS2 Directive and the Data Act, are still under consideration by the European Parliament and the Council and have not yet been adopted. The AI Omnibus is the first formal amendment to the EU AI Act since the Act entered into force on 1 August 2024. It was signed on 8 July 2026, published in the Official Journal of the European Union on 24 July 2026 as Regulation (EU) 2026/1744, and entered into force three days later, on 27 July 2026.

II. Key Changes under the AI Omnibus

1. Postponing the Application of Obligations for High-Risk AI Systems
For businesses, the most significant practical change is likely to be the revised timetable for obligations relating to high-risk AI systems. Depending on the category of system, the relevant obligations will now apply from 2 December 2027 or 2 August 2028. Providers and deployers of high-risk AI systems intended for use by public authorities must take the necessary steps to comply with the Act's requirements and obligations by 2 August 2030.
The extended timetable is intended to give businesses more time to understand and implement the relevant technical standards, guidance and assessment procedures.

2. Narrowing and Clarifying the Scope of High-Risk AI Systems
The amendments narrow and clarify when AI systems incorporated into regulated products qualify as "safety components" and may therefore be classified as high-risk AI systems. [1]   A safety component is a component that fulfils a safety function intended to prevent or mitigate risks to persons or property, or whose failure or malfunction may endanger people's health and safety or the safety of property. AI systems used solely for user assistance, performance optimisation, service efficiency, automation, convenience or non-safety-related quality control generally do not qualify as safety components.
This change provides a clearer basis for determining whether a particular AI system falls within the high-risk classification.

3. Simplifying and Clarifying Businesses' Compliance Obligations

a. Extending Compliance Relief to Small Mid-Cap Enterprises
Certain measures that ease compliance for small and medium-sized enterprises (SMEs) now also apply to small mid-cap enterprises (SMCs). These include simplified technical documentation and quality management requirements applied in proportion to the size of the business. When imposing fines, Member States must also take account of SMCs' interests and economic viability. For certain infringements, the maximum fine is the lower of the specified monetary amount and the applicable percentage of worldwide annual turnover. Overall, the amendments seek to align compliance burdens with business size and help companies make a smoother transition to the Act's regulatory requirements as they grow from SMEs into SMCs.

b. Clarifying Responsibilities Across the AI Value Chain
A distributor, importer, deployer or other third party shall be treated as the new provider of an AI system if it: (1) puts its name or trademark on a high-risk AI system already placed on the market or put into service; (2) makes a substantial modification to such a system and it remains a high-risk AI system after the modification; or (3) changes the intended purpose of an AI system already placed on the market or put into service so that it becomes a high-risk AI system.
The initial provider must make available the necessary information, technical documentation and assistance with testing to enable the new provider to fulfil its statutory obligations. This does not apply where the initial provider has clearly specified that the system must not be changed into a high-risk AI system.

In addition, as a general rule, providers of high-risk AI systems must enter into written agreements with third-party suppliers specifying how the suppliers will provide the information, technical access and assistance needed for compliance. Failure to meet these cooperation or written-agreement obligations may result in administrative fines.

4. New Safeguards for Fundamental Rights

a. Allowing More Providers and Deployers to Process Special Categories of Personal Data for Bias Detection and Correction
The new Article 4a expands the range of entities permitted to process special categories of personal data for AI bias detection and correction. [2]   Previously, the EU AI Act allowed only providers of high-risk AI systems to process such data where necessary to detect bias. The amendments extend this permission, subject to conditions, [3] to deployers of high-risk AI systems, as well as providers and deployers of other AI systems and models.
Such processing must meet strict necessity and safeguard requirements. These include ensuring that the same purpose cannot be achieved effectively using other data, restricting the re-use of and access to the data, and applying pseudonymisation and appropriate information security measures. The data must be deleted once the bias has been corrected or the retention period has expired, whichever occurs first.

b. New Prohibitions on Sexual Deepfakes and Child Sexual Abuse Material
As AI-generated content becomes increasingly common, the amendments expressly prohibit using AI to generate or manipulate realistic depictions of an identifiable natural person's intimate parts or sexually explicit activities without that person's consent. They also prohibit generating or manipulating child sexual abuse material or performances, except where permitted under national law. For providers, the prohibition applies where generating such content is the system's intended purpose, or where such an outcome is reasonably foreseeable but adequate safeguards are not in place. Merely enhancing the quality of existing intimate material or changing its background is outside the scope of the prohibition, provided this does not increase the exposure of intimate parts or alter the nature of the sexually explicit activities depicted. The two new prohibitions apply from 2 December 2026, rather than from the date on which the AI Omnibus entered into force.

5. Strengthening Support for Innovation and Centralising Enforcement

a. Expanding Regulatory Sandboxes and Real-World Testing
The amendments allow the AI Office to establish Union level AI regulatory sandboxes for systems under its supervision, with a key objective of helping SMEs, start-ups and SMCs access the market. Member States must ensure that at least one national AI regulatory sandbox is operational by 2 August 2027. Sandboxes may include testing in real-world conditions, allowing businesses to test AI systems in actual operating environments before they are placed on the market or put into service. The amendments also expand the scope of such testing.

b. Centralising Supervision and Enforcement in the AI Office
The amendments centralise supervision of AI systems with a broader impact in the AI Office at EU level. They also clarify the respective remits of the AI Office and national competent authorities, providing a clearer division of supervisory responsibilities. The amendments introduce related investigation and enforcement mechanisms, including powers to request information, evaluate AI systems, appoint external experts or auditors, adopt decisions making commitments binding, establish non-compliance and impose fines. They also require adequate staffing, funding and technical resources so that the AI Office can carry out its supervisory tasks effectively and promptly.

III. Conclusion

The AI Omnibus does more than ease the EU AI Act's requirements: it adjusts the scope, timing and allocation of businesses' compliance obligations. By postponing certain obligations for high-risk AI systems, it gives businesses more time to prepare and greater flexibility in compliance. At the same time, it clarifies the compliance and cooperation duties of participants across the AI value chain and introduces further safeguards for fundamental rights, including rules on bias detection, sexual deepfakes and child sexual abuse material. Overall, while some regulatory burdens are reduced, businesses' responsibilities become clearer and more specific. The amendments also bring the EU's AI regulatory framework more closely into line with the practical realities businesses face, while allowing greater compliance flexibility and strengthening support for innovation.
[1] The EU AI Act classifies AI systems as high-risk in two main situations. First, an AI system may qualify if it is a safety component of a regulated product covered by Annex I, or is itself such a product, and the product is required by law to undergo a third-party conformity assessment because of health or safety risks. Second, AI systems used for the purposes listed in Annex III are, in principle, classified as high-risk. A clear definition of "safety component" is therefore important for determining whether the first category applies, which is the reason for this amendment.
[2] To protect people from discrimination that may result from bias in AI systems, providers and deployers should, by way of exception, be permitted to process special categories of personal data where necessary to detect and correct such bias.
[3] Deployers of high-risk AI systems, and providers and deployers of other AI systems and AI models, may process special categories of personal data only where the potential bias is likely to affect health and safety of persons, adversely affect fundamental rights, or lead to discrimination prohibited pursuant to Union law.

The contents of all materials (Content) available on the website belong to and remain with Lee, Tsai & Partners.  All rights are reserved by Lee, Tsai & Partners, and the Content may not be reproduced, downloaded, disseminated, published, or transferred in any form or by any means, except with the prior permission of Lee, Tsai & Partners.  The Content is for informational purposes only and is not offered as legal or professional advice on any particular issue or case.  The Content may not reflect the most current legal and regulatory developments.

Lee, Tsai & Partners and the editors do not guarantee the accuracy of the Content and expressly disclaim any and all liability to any person in respect of the consequences of anything done or permitted to be done or omitted to be done wholly or partly in reliance upon the whole or any part of the Content. The contributing authors’ opinions do not represent the position of Lee, Tsai & Partners. If the reader has any suggestions or questions, please do not hesitate to contact Lee, Tsai & Partners.