The AI Omnibus Explained: Europe Gives Business More Time on High-Risk AIEurope has kept the core of its AI law and simplified how it lands. For businesses, the result is a clearer, more realistic runway.

“A targeted simplification of the AI rulebook while preserving strong safeguards for people's safety and fundamental rights.”
It is rare for a major piece of European law to be adjusted before its biggest obligations even arrive. But that is exactly what happened to the EU AI Act this year — and the way it happened says a lot about how Europe is trying to balance protection with practicality.
The change came through the AI Omnibus, part of a wider digital simplification package the European Commission proposed on 19 November 2025. After negotiations between the European Parliament and member states, a political agreement was reached on 7 May 2026. Parliament gave its final approval on 16 June, the Council followed on 29 June, and the Commission confirmed in July that the AI Omnibus had entered into force.
The headline is more time. The detail is more interesting. Here is what the Omnibus changed, why it was needed, and what Irish businesses should do with the breathing space.
What Changed: The New Timeline
The EU AI Act sorts AI systems by risk. At the top sit a small number of banned practices. Below them is the category that carries the heaviest obligations: high-risk AI. These are systems used in sensitive areas such as recruitment, education, access to credit, critical infrastructure and public services, as well as AI built into regulated products.
Under the original timetable, many of these high-risk rules were due to apply in August 2026. The Omnibus moves them back. According to the Commission, rules for stand-alone high-risk AI systems listed in Annex III of the Act now apply from 2 December 2027. Rules for high-risk AI embedded in physical products covered by Annex I — the Commission's examples include machinery, toys and lifts — apply from 2 August 2028.
The rest of the Act's structure stays in place. The bans on unacceptable practices still apply. The rules for general-purpose AI models still apply, and the Commission's enforcement powers over them came into application in August 2026. The transparency duties around chatbots and deepfakes are also now enforceable.
Why Europe Hit Pause on the Hardest Part
The main reason for the delay is simple: high-risk compliance depends on detailed technical standards, and those standards needed more time. Businesses cannot build good compliance processes against rules that are not yet fully defined.
The political agreement itself acknowledged that meeting the AI Act's requirements takes significant work. Companies have to set up risk management systems, data governance, human oversight, record keeping and quality management. Doing that properly takes months, sometimes years, especially for smaller firms without large legal teams.
The Commission describes the Omnibus as a targeted simplification that delivers a lighter rulebook while preserving strong safeguards for people's safety and fundamental rights. In other words, the goal was not to water down protections but to make sure they arrive in a form businesses can actually implement.
For Europe's AI ambitions, that matters. A law that is clear, workable and properly supported by standards is far more likely to build trust — and far less likely to push innovation elsewhere — than one rushed into force before anyone knows how to comply.
New Protections Added Along the Way
The Omnibus was not only about delay. Negotiators also used it to strengthen the law in one area that had become a clear and growing harm.
The agreement adds a ban on so-called nudifier apps — tools that use AI to create fake intimate images of real people without their consent. It is a narrow, targeted change, but a meaningful one, and it shows the Act can respond quickly to real-world misuse.
Negotiators also adjusted the timing of some technical watermarking requirements for AI-generated content, giving providers more time to put reliable marking methods in place. The broader principle — that people should be able to tell when content has been created by AI — remains firmly part of the law.
Taken together, the changes show a rulebook that is being refined in light of experience, which is how good regulation is supposed to work.
What Irish Businesses Should Do With the Extra Time
The biggest risk now is treating the new dates as a reason to do nothing. December 2027 is closer than it sounds, and the companies that use the runway well will be in a much stronger position than those that leave it late.
A sensible first step is to map where AI is used across the business and identify anything that could fall into a high-risk category. Recruitment tools, credit scoring, and systems that affect access to services are obvious places to look. For manufacturers, AI built into products is the area to watch for 2028.
Next, talk to suppliers. Many Irish organisations use AI built by someone else. Understanding what those providers are doing to prepare — and what documentation they will supply — takes a large part of the burden off in-house teams.
Finally, there is support closer to home. Ireland's Regulation of Artificial Intelligence Act 2026 came into force on 31 July, and the new AI Office of Ireland has a stated role in promoting AI innovation and literacy as well as coordinating supervision. Its power to establish regulatory sandboxes could give Irish innovators a supported place to test high-risk systems well before the deadlines arrive.
How It Fits the Bigger Picture
The AI Omnibus did not happen in isolation. It sits inside a wider push by the European Commission to simplify digital rules and reduce paperwork for businesses, particularly smaller companies that have found the growing volume of EU technology law hard to keep up with.
That wider agenda reflects a clear shift in tone in Brussels over the past year. The focus has moved towards making European rules easier to follow, so that companies spend less time decoding legislation and more time building products. The AI Omnibus is one of the first concrete results of that approach.
Crucially, the changes were made through the normal legislative process. The Commission proposed them, the European Parliament and the Council negotiated them, and both institutions formally approved the final text before it entered into force. That gives businesses legal certainty: the new dates are now written into law, not just promised.
For Ireland, the timing works well. The national Regulation of Artificial Intelligence Act 2026 came into force on 31 July, just as the Omnibus took effect at EU level. Irish organisations now have both a settled European timetable and a national framework to work within, which makes planning far simpler than it was even six months ago.
There is also a lesson here for how Europe regulates new technology. Setting firm principles early, then adjusting the detail as standards and experience develop, is a sensible way to handle something moving as fast as AI. It gives people protections now while leaving room to get the practical rules right.
Businesses that begin preparing now will find the new dates far easier to meet. Early work on inventories, supplier conversations and staff training costs little, builds confidence and turns a future legal deadline into an ordinary part of good management.
The Bottom Line
The AI Omnibus is a sign of a law that is maturing, not retreating. Europe has kept the core protections of the AI Act, added a new ban where real harm was emerging, and given businesses realistic dates for the most demanding rules: 2 December 2027 for stand-alone high-risk AI and 2 August 2028 for AI built into products. For Irish companies, the extra time is an opportunity to prepare properly — mapping AI use, working with suppliers and using the new national supports — so that when the rules arrive, compliance is already part of how they build.
AI & Innovation Pulse is an independent Irish digital title covering artificial intelligence and innovation. Every piece is written in-house, editorially independent, and verified.