August 2, 2026

EU AI Omnibus: A Practical Implementation Roadmap for Businesses

What businesses should do now

AI literacy

The EU AI Omnibus has entered into force, introducing targeted changes to the AI Act’s compliance framework, extending key implementation deadlines and reducing duplication for organisations developing or deploying AI systems in the EU. Organisations should review their training, policies and governance measures to ensure that they actively support AI literacy among employees and other relevant stakeholders, without treating the obligation as a guarantee of any particular proficiency level.

Bias detection and sensitive data

A new legal basis under Article 4a permits the exceptional processing of special categories of personal data where necessary to detect and correct bias in AI systems. Any reliance on this basis should be assessed alongside the GDPR and the Law Enforcement Directive, with the required safeguards clearly documented. Businesses should update their data-protection assessments, approval procedures and records before using sensitive data for bias-management purposes.

High-risk AI classification

Organisations should map their AI systems against Article 6 and Annexes I and III to determine which systems fall within the high-risk categories. For each system, the classification, applicable deadline and responsible internal owner should be recorded in a central compliance register.

Product compliance overlap

The Omnibus seeks to reduce duplication between the AI Act and sector-specific product rules, including the Machinery Regulation. Businesses should identify AI-enabled products already subject to equivalent safeguards and assess whether a streamlined compliance route may be available. Further European Commission guidance and implementing acts will be important in determining how the revised mechanism operates in practice.

Safety components

Companies should reassess whether AI used in regulated products qualifies as a safety component under Article 6(1), taking account of the clarified exclusions introduced by the Omnibus.

Regulatory relief for small mid-cap enterprises

Small mid-cap enterprises should assess whether they qualify for the new targeted regulatory relief. Eligible organisations may benefit from simplified technical documentation and a more proportionate penalty framework.

Impact assessments

Fundamental rights impact assessments under the AI Act should be aligned with data protection impact assessments under the GDPR or the Law Enforcement Directive. Cross-references between the assessments can reduce duplication while preserving a clear and auditable compliance record.

Synthetic-content marking

By 2 December 2026, providers of AI systems - including general-purpose AI systems placed on the market before 2 August 2026 - should ensure that synthetic content is marked in accordance with Article 50(2). Preparation should cover technical capabilities, metadata standards, user notices and relevant contractual arrangements.

High-risk AI systems under Article 6(2) and Annex III

Organisations operating high-risk AI systems under Article 6(2) and Annex III should use the extended period to complete their compliance programmes ahead of the 2 December 2027 deadline. Key workstreams include risk management, data governance, technical documentation, record-keeping, transparency, human oversight, accuracy, robustness and cybersecurity.

AI regulatory sandboxes

Member States must establish at least one operational national AI regulatory sandbox by 2 August 2027. Businesses should monitor national developments and identify projects that could benefit from supervised testing and early engagement with regulators.

Compliance deadline for Article 6(2) and Annex III systems

By 2 December 2027, relevant standalone high-risk AI systems should be fully compliant with the revised framework.Conformity preparations, internal approvals, supplier reviews and supporting documentation should be completed in advance.

Compliance deadline for Article 6(1) and Annex I systems

The deadline for high-risk AI systems covered by Article 6(1) and Annex I is 2 August 2028, including systems that are safety components of regulated products or are themselves regulated products. Compliance planning should be coordinated with the relevant sectoral conformity-assessment framework.

AI Office supervision

Providers and corporate groups developing both general-purpose AI models and AI systems should prepare for expanded supervision by the AI Office. Enhanced oversight may also apply where AI systems constitute, or are integrated into, very large online platforms or very large online search engines under the Digital Services Act.

Regulatory developments

The implementation timetable should be treated as a living compliance plan. Organisations should continue to monitor European Commission guidance, implementing acts and national enforcement developments. Maintaining a central regulatory tracker - and regularly updating the organisation’s AI inventory, risk assessments and implementation plan - will help ensure readiness as the framework develops.

‍

Prof. Martin Zahariev, PhD
Partner

Martin has not only been consistently providing high-quality legal service but has also become one of the youngest professors in Bulgaria and established himself undisputedly as the most prolific author in the law firm.

Related insights

Innovative solutions and customer care.
Get in touch