The waiting is over. Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal of the European Union on July 24, 2026 and entered into force this morning, July 27. It took three days — the compressed timeline the regulation itself calls “a matter of urgency” — because the AI Act’s general application date falls on August 2, just six days from now.
This is not another step in a political process. There are no more votes, no more consultations, no more provisional agreements. The regulation amends the EU AI Act and is now part of EU law. The deadlines it sets are real, enforceable deadlines.
What Changes as of Today
The Omnibus amends three things: the AI Act itself (Regulation EU 2024/1689), civil aviation rules for AI embedded in aircraft systems, and machinery regulation for AI in physical products.
For most businesses, the relevant changes are to the AI Act. The core amendments:
High-risk AI in standalone systems (Annex III) — the December 2, 2027 deadline is now fixed in law. AI used in employment and recruitment, education, access to essential services, law enforcement and border control, and credit scoring falls into this category. These systems must have risk management systems, technical documentation, transparency obligations, and human oversight measures in place by that date.
High-risk AI embedded in regulated products (Annex I) — extended to August 2, 2028. If your AI is built into machinery, medical devices, vehicles, toys, or other products already regulated under EU product safety law, this is your date.
Non-consensual intimate imagery ban — confirmed in the Omnibus, active from December 2026. Any AI image generation or editing product operating in the EU needs a compliance review against this provision now.
What Has Not Changed
This is the part many businesses are misreading. The Omnibus extended high-risk deadlines. It did not extend everything.
General Purpose AI (GPAI) obligations apply on August 2, 2026. In six days. If your business deploys a foundation model, uses a large language model as part of a product, or exposes a GPAI system to EU users, your transparency, documentation, and copyright diligence obligations are not deferred. They are imminent.
Prohibitions on unacceptable-risk AI remain at August 2, 2026. Social scoring systems, real-time biometric surveillance in public spaces, and emotion recognition in workplaces and educational settings are banned from operating in EU markets starting August 2. These bans did not move.
AI literacy requirements — deployers of AI must take reasonable steps to ensure their staff have sufficient AI literacy. This is also not deferred.
What August 2 Actually Means
For businesses deploying AI in EU-exposed contexts, the August 2 date marks the formal start of enforcement on the provisions that were not extended. Regulators across EU member states have been building enforcement capacity throughout 2026. The first enforcement actions will focus on the most visible violations.
In practical terms, that means:
GPAI transparency requirements. If you deploy a chatbot, voice agent, or AI-assisted decision system that operates in the EU, users must be able to tell they are interacting with AI. Systems must carry clear disclosure. Document this.
Copyright and data sourcing documentation. Providers of GPAI systems must publish summaries of training data used, in sufficient detail to allow copyright owners to assess compliance. If you are building on top of a GPAI system, understand what your provider has published and whether your obligations flow down.
GPAI classification. If you have not yet determined whether your AI system qualifies as a General Purpose AI model under the Act, you need a legal determination by August 2. The classification drives your obligations.
The Six-Day Action List
This is not a time for detailed strategy documents. If you have EU exposure and have not yet addressed these, do them this week:
1. Confirm your GPAI classification. If you deploy or provide an AI system that can perform a wide range of distinct tasks and that has broad applicability, you likely qualify. Get a legal opinion.
2. Check your transparency disclosures. Every customer-facing AI interface that operates in the EU needs to clearly indicate it is AI-driven. Review chatbots, voice tools, automated email, and AI-assisted decision outputs.
3. Know what high-risk category you are in. Even though the December 2027 deadline gives you 16 months, the clock on high-risk compliance has started today. Businesses that begin their risk management and documentation work now will be in a fundamentally better position than those who treat 2027 as far away.
4. Document your AI inventory. The obligations that apply from August 2 are auditable. Regulators will ask what AI systems you use, where they process EU personal data, and what oversight controls you have in place. An AI inventory is the baseline for any of this.
What This Means for Business
The pace of EU AI regulation has been unusual: years of negotiation followed by months of fast-moving amendments, and now a final regulation that entered force in three days. The urgency language in the Omnibus itself reflects how close the general application date was to publication.
The net result is that the EU has hit its reset button on high-risk AI timelines, giving most businesses until December 2027 to build real compliance infrastructure. But the August 2 provisions — GPAI, prohibitions, AI literacy — were treated as non-negotiable. They apply to a large portion of AI deployments already in the market.
For business leaders, the honest assessment is this: if your AI deployments have EU exposure and you have not addressed GPAI transparency and documentation, you are late. Six days is not enough time to build a compliance programme from scratch, but it is enough time to stop being unaware of your obligations and to document where the gaps are.
The December 2027 runway is a genuine opportunity to do high-risk compliance properly. The Omnibus did not grant permission to ignore August 2 while you focus on it.
Enterprise DNA’s Omni Advisory works with business leaders on exactly this: understanding where your AI deployments sit relative to the EU AI Act categories, identifying which obligations apply now versus in 2027, and building the governance infrastructure that regulators will expect to see. If you are trying to get clarity on your position before August 2, that conversation is worth having this week.