Back

EU AI Act After the Digital Omnibus: What Applies Now and the New Deadlines for Law Firms

Three European Union flags waving outside the Berlaymont building in Brussels, Belgium.

The EU AI Act was changed on 27 July 2026. On that date the Digital Omnibus on AI came into force: Regulation (EU) 2026/1744, signed on 8 July and published in the Official Journal on 24 July. The biggest change is time. The high-risk rules that were due on 2 August 2026 now start on 2 December 2027 for stand-alone systems and on 2 August 2028 for AI built into regulated products. Some parts did not move at all. The transparency duties in Article 50 have applied since 2 August 2026, and the bans and AI literacy rules have applied since February 2025.

This guide sets out what the Omnibus changed, what already binds your firm or legal team, and a working timeline up to 2030. It is written for managing partners, general counsel and the people who end up owning AI policy. Every date comes from the Official Journal text or the Commission’s own pages.

Key points

  • High-risk rules for Annex III systems (hiring, credit scoring, AI used by courts and more) now apply from 2 December 2027. Rules for AI embedded in products under Annex I apply from 2 August 2028.
  • Article 50 transparency duties (telling people they are dealing with a chatbot, labelling deepfakes) have applied since 2 August 2026. Only one narrow grace period exists: providers of generative systems already on the market have until 2 December 2026 for machine-readable marking.
  • New bans on AI that creates non-consensual intimate images and child sexual abuse material apply from 2 December 2026.
  • The AI literacy duty in Article 4 was softened, not removed. Firms must still take measures to support their staff’s AI literacy.
  • Most legal research and drafting tools used by firms are not high-risk. The Annex III trigger for legal work is use by or for a court, or in alternative dispute resolution.

What is the Digital Omnibus on AI?

The Commission put forward the Omnibus on 19 November 2025 as part of its simplification package. The aim was to give businesses more time for high-risk compliance, because the standards and guidance they need were running late. The Parliament adopted its position on 16 June 2026 and the Council gave its final approval on 29 June 2026. The regulation amends the AI Act (Regulation (EU) 2024/1689) and two product safety laws, and it came into force on the third day after publication, 27 July 2026. The Commission confirms this on its AI Omnibus page.

One detail catches people out. The EUR-Lex record shows “8 July 2026” as the document date. That is the signing date. The law was published on 24 July and applies from 27 July.

What already applies under the EU AI Act?

The Act was always staged. Three waves were live before the Omnibus arrived, and the Omnibus did not reverse any of them. The Commission’s AI Act Service Desk timeline is the cleanest official summary.

  • From 2 February 2025: the definitions, the AI literacy duty (Article 4) and the list of prohibited practices (Article 5), such as social scoring, manipulative techniques that cause harm, and emotion recognition in workplaces and schools.
  • From 2 August 2025: the rules for general-purpose AI models (Chapter V), the governance structure, and the penalty framework. Member States also had to name their national authorities and set penalty rules by this date.
  • From 2 August 2026: the Article 50 transparency duties, and the Commission’s power to fine providers of general-purpose AI models.

That last wave matters for firms more than most coverage suggests. If your firm puts a chatbot on its website, or a client-facing intake assistant, Article 50 requires that people are told they are interacting with an AI system unless that is obvious. If your marketing team uses AI to generate realistic images or video of people, deepfake labelling applies. The Commission published its final guidelines on Article 50 in July 2026, alongside a code of practice on marking AI-generated content.

The new deadlines, in one table

WhatOriginal dateDate after the OmnibusWhere it comes from
Prohibited practices and AI literacy2 Feb 2025Unchanged (literacy duty softened)Art. 113; new Art. 4
General-purpose AI model obligations2 Aug 2025UnchangedArt. 113(b)
Article 50 transparency duties2 Aug 2026UnchangedArt. 113
Machine-readable marking for generative systems already on the market2 Aug 20262 Dec 2026New Art. 111(4)
New bans: non-consensual intimate imagery and CSAM generationNot in original Act2 Dec 2026New Art. 5(1)(ba) and (bb)
National regulatory sandboxes operational2 Aug 20262 Aug 2027Art. 57(1)
High-risk systems in Annex III (employment, credit, justice, education and others)2 Aug 20262 Dec 2027Art. 113(c)(i)
High-risk AI embedded in Annex I products (machinery, medical devices and others)2 Aug 20272 Aug 2028Art. 113(c)(ii)
Public authorities using legacy high-risk systems2 Aug 2030UnchangedArt. 111(2)

Is AI literacy still mandatory?

Yes, but in a lighter form, and this is where many summaries go wrong. Some coverage, and even the Commission’s own short description, says the duty was “transferred” to the Commission and Member States. The text is more careful than that. The new Article 4 says providers and deployers “shall take measures to support the development of AI literacy of their staff”. It then adds that this “does not require providers or deployers to guarantee any specific level of AI literacy of any individual”. The Commission and Member States must support and facilitate compliance, and the Commission will publish practical examples.

So the duty still sits with your firm. What has gone is any suggestion that you must certify each lawyer to a set standard. A sensible response is a short, recorded training programme on the tools your people actually use, the firm’s AI policy, and the limits of generative output. If you do not yet have a written policy, our law firm AI policy template is a starting point.

Is legal AI software high-risk under the AI Act?

For most firms and legal departments, no. The relevant entry is point 8(a) of Annex III. It covers AI “intended to be used by a judicial authority or on their behalf to assist a judicial authority in researching and interpreting facts and the law and in applying the law to a concrete set of facts”, or used in a similar way in alternative dispute resolution.

The trigger is who uses the system and for what. A research assistant, a contract review tool or a drafting co-pilot used by a law firm for its clients is not a system used by or for a judicial authority. It falls outside point 8(a). Three groups should look harder:

  • Vendors that sell to courts, tribunals or arbitral institutions. A case management or research product sold to a court for use by judges can fall inside Annex III. Under the Omnibus, AI used for the administration of justice stays with national authorities rather than the new AI Office.
  • ADR providers that build AI into how disputes are decided or recommended.
  • Firms acting as employers. Annex III point 4 covers AI used to recruit, filter applications, evaluate candidates, decide promotions or terminations, allocate tasks and monitor performance. A firm using AI screening in its trainee or associate hiring is a deployer of a high-risk system from 2 December 2027.

There is also a derogation in Article 6(3). A system listed in Annex III is not treated as high-risk if it only performs a narrow procedural task, improves the result of a human activity already completed, or does preparatory work, and does not profile people. The Commission’s guidance on this was due by 2 February 2026 and missed that date. A draft was published on 19 May 2026, the consultation closed on 23 July, and the final version is expected by the end of 2026. Until then, any classification call you make rests on the text and the draft.

What a deployer has to do from December 2027

If your firm uses a high-risk system, for instance in hiring, Article 26 sets your duties as a deployer. The Service Desk summary of Article 26 lists them. In practice they come down to these:

  1. Use the system in line with the provider’s instructions for use.
  2. Assign human oversight to people with the competence, training and authority to do it.
  3. Where you control the input data, make sure it is relevant and sufficiently representative for the purpose.
  4. Monitor operation, and report serious incidents and risks to the provider and the authorities.
  5. Keep the logs the system generates for at least six months.
  6. Inform workers and their representatives before putting the system into use in the workplace.
  7. Tell the people affected by decisions that a high-risk system is being used.

Deployers that must carry out a fundamental rights impact assessment under Article 27 get some relief: the Omnibus lets that assessment cross-refer to a GDPR data protection impact assessment, and the AI Office will produce a questionnaire template.

Other changes worth knowing

Relief for smaller businesses. The Omnibus creates a “small mid-cap” category, defined by reference to Commission Recommendation (EU) 2025/1099. Small mid-caps join SMEs in getting simplified technical documentation, a proportionate quality management system, and a fines rule where the lower of the fixed amount and the turnover percentage applies.

Sensitive data for bias testing. The old Article 10(5) is replaced by a new Article 4a. Providers of high-risk systems may process special category data where strictly necessary to detect and correct bias, under six conditions: no workable synthetic or anonymised alternative, pseudonymisation, access controls, no transfer to third parties, deletion once done, and records of processing. The permission is extended to other AI systems and to deployers. It creates no obligation to test.

A stronger AI Office. The AI Office gets exclusive competence over AI systems built on a provider’s own general-purpose model, and over AI in very large online platforms and search engines. Several areas stay with national authorities, including the administration of justice.

Value chain contracts. The cooperation duties between providers and the businesses that build on their systems (Article 25) are stronger, and breaching them is now fineable.

What are the fines?

The penalty levels in Article 99 did not change. Using a prohibited practice can cost up to EUR 35 million or 7 per cent of worldwide annual turnover, whichever is higher. Breaching most other obligations, including deployer duties and Article 50, can cost up to EUR 15 million or 3 per cent. Giving incorrect or misleading information to authorities can cost up to EUR 7.5 million or 1 per cent. For SMEs and now small mid-caps, the lower figure applies.

Enforcement will be uneven for a while. The Commission’s list of market surveillance authorities, last updated on 7 September 2026, still shows designations pending in a dozen Member States, including France, Germany, the Netherlands, Spain and Sweden, and no authority at all listed for six others. That is a gap in who enforces, not in what the law requires.

A practical plan for firms and legal teams

Now (before the end of 2026):

  • Build an inventory of every AI system the firm uses or offers, including tools inside products you already pay for.
  • Check website chatbots, intake bots and AI-generated marketing content against Article 50.
  • Record your AI literacy measures: who was trained, on what, and when.
  • Confirm no tool you use or sell falls within the Article 5 bans, including the two new ones from 2 December 2026.

During 2027:

  • Map any Annex III uses, starting with recruitment and HR, and decide whether Article 6(3) takes them out.
  • Ask HR technology vendors for their conformity plans and instructions for use, and update contracts to reflect Article 25.
  • Prepare worker notices, oversight roles and log retention before 2 December 2027.

If you advise clients: the Omnibus buys product companies time on Annex I systems until August 2028, but the Article 50 duties and the bans are live now. Client alerts that still quote 2 August 2026 as the high-risk start date need correcting. Our earlier EU AI Act guide for law firms covers the underlying structure, and the Legal Desire LegalTech hub tracks the tools themselves.

Frequently asked questions

When do the EU AI Act high-risk rules apply after the Digital Omnibus?

Stand-alone high-risk systems listed in Annex III apply from 2 December 2027. High-risk AI embedded in products regulated under Annex I applies from 2 August 2028. Both were originally due earlier.

Did the Omnibus delay Article 50 transparency rules?

No. Article 50 has applied since 2 August 2026. The only extension is for providers of generative AI systems placed on the market before that date, who have until 2 December 2026 to meet the machine-readable marking duty in Article 50(2).

Is AI literacy still a legal requirement?

Yes. Article 4 still requires providers and deployers to take measures to support the AI literacy of their staff. It no longer implies that any specific level must be guaranteed for each person.

Is a law firm’s legal research tool a high-risk AI system?

Generally not. Annex III point 8(a) covers AI used by or on behalf of a judicial authority, or in a similar way in alternative dispute resolution. A tool a firm uses for its own client work does not meet that description. Hiring tools used by the firm can be high-risk under point 4.

What is the maximum fine under the EU AI Act?

Up to EUR 35 million or 7 per cent of worldwide annual turnover, whichever is higher, for prohibited practices. Most other breaches carry up to EUR 15 million or 3 per cent.

Sources

Want analysis like this in your inbox? Subscribe to Legal Desire Insider. Lawyers and firms who want to publish their own commentary can do so through Publish with Legal Desire.

LEGAL DESIRE NEWSLETTER

Where the legal industry reads first.

Enjoyed this article? Get the biggest legal industry updates, deals, appointments, insights and expert interviews in your inbox, free.

No spam. Unsubscribe anytime.

From Legal Desire

Is your firm the one being cited, or the one being skipped?

We ran the test. On several everyday legal questions, software companies are answering and law firms are not. We help firms fix that, and we build the technology behind the practice.

Anuj Kumar
Founder and Editor-in-Chief