Legal_Clarification

Corvus_AI_Legal_Clarification_EN Legal Clarification

The EU’s Digital Omnibus on AI introduces targeted amendments to Regulation (EU) 2024/1689, aiming to clarify and streamline the implementation of the EU AI Act. This legal clarification outlines the key changes, their practical implications, and the issues organisations should monitor when preparing for compliance.

Amendments to Regulation (EU) 2024/1689 (EU AI Act) Introduced by the Digital Omnibus on AI

Corvus AI | Legal Digest

1. Purpose of This Clarification

This clarification has been prepared by Corvus AI for informational purposes and describes the content of the regulation amending Regulation (EU) 2024/1689 on artificial intelligence (the "AI Act"), known as the Digital Omnibus on AI. The text has been agreed by the European Parliament (approval of 16 June 2026) and the Council of the European Union (final approval of 29 June 2026), was signed on 8 July 2026, and is pending publication in the Official Journal of the European Union.

Until official publication and entry into force (as a general rule, on the third day following publication), the AI Act continues to apply in its original version. This clarification is based on the final agreed text and does not account for any technical or editorial refinements that may still be introduced before publication.

This material does not constitute legal advice and should not be relied upon as a basis for decision-making without reference to the source text following its official publication and/or consultation with lawyers specialising in EU AI law.

2. Expansion of the List of Prohibited Practices (Art. 5 AI Act)

The regulation adds a new category to the closed list of prohibited AI practices: it prohibits placing on the market, putting into service, and using AI systems intended to generate or manipulate images or other content of an intimate nature without the consent of the person depicted, as well as material constituting child sexual abuse material (CSAM), including cases where the system lacks adequate safeguards preventing the generation of such content.

Providers of systems potentially falling within this category are granted a transitional period until 2 December 2026 to bring their systems into compliance (implementing refusal mechanisms, output controls, content filtering).

Legal characterisation: this is a substantive provision, not a technical deferral of a pre-existing requirement — prior to the entry into force of this regulation, the AI Act contained no such prohibition as a standalone category.

3. Deferral of Application Deadlines for High-Risk AI Systems (Art. 6, Annexes I and III)

The deadlines set out in Art. 113 of the AI Act are amended as follows:

For high-risk AI systems listed in Annex III (including systems used in employment, education, critical infrastructure, law enforcement, and creditworthiness assessment) — from 2 August 2026 to 2 December 2027.

For AI systems constituting safety components of products falling under EU harmonisation legislation listed in Annex I (in particular, medical devices, toys) — from 2 August 2027 to 2 August 2028.

The deferral is due to the unavailability of the harmonised standards on the basis of which providers demonstrate conformity with the requirements of Chapter III, Section 2 of the AI Act. The substantive content of the obligations (risk management system, technical documentation, human oversight requirements, data quality requirements, and other requirements under Chapter III, Section 2) remains unchanged.

4. Transparency Obligations (Art. 50 AI Act)

The general rule on the application of transparency obligations from 2 August 2026 remains unchanged, including the obligation to inform natural persons that they are interacting with an AI system (Art. 50(1), (3), (4)).

The obligation to mark and ensure the technical detectability of content generated or substantially altered by AI (Art. 50(2)) is treated separately: for systems placed on the market before 2 August 2026, a transitional period until 2 December 2026 applies. For systems placed on the market after that date, no deferral applies, and the requirement takes effect on the general date of 2 August 2026.

5. Registration Obligation in the EU Database (Art. 49 AI Act)

The proposal to exempt providers of systems self-classified as non-high-risk under the derogation criteria (Art. 6(3)) from the obligation to register in the EU's public database was not adopted during negotiations. The registration obligation remains in full force with respect to the relevant subjects, although the scope of information to be disclosed has been simplified.

6. AI Literacy Obligation (Art. 4 AI Act)

The wording of this obligation has been amended: instead of requiring providers and deployers to ensure "a sufficient level of AI literacy" among staff and other persons acting on their behalf, the amended text establishes an obligation to support the development of such literacy. From a legal drafting standpoint, this represents a shift from an obligation of result to an obligation of best efforts.

7. Processing of Special Categories of Personal Data for Bias Detection and Correction (Art. 10(5) AI Act)

The category of subjects entitled to process special categories of personal data (within the meaning of Art. 9 GDPR) for the purpose of detecting and correcting bias in AI systems has been expanded: previously reserved exclusively for providers of high-risk systems, this right now extends to providers and deployers of any AI systems and models.

The condition governing the permissibility of such processing — "strict necessity," subject to appropriate safeguards (pseudonymisation, access restrictions, technical and organisational protective measures) — remains unchanged; the proposal to lower this threshold to a simple necessity test was not incorporated into the final text.

8. Delimitation of Competence Between the AI Office and National Supervisory Authorities (Art. 70, 74–75 AI Act)

The European AI Office is granted exclusive competence over AI systems built on general-purpose AI (GPAI) models in cases where the model and the system are developed by the same undertaking, as well as over AI systems embedded in intermediary services regulated under Regulation (EU) 2022/2065 (Digital Services Act).

This rule does not extend to high-risk systems listed in Annex I or to certain categories of systems under Annex III (in particular, those related to critical infrastructure and law enforcement), where competence remains with national supervisory authorities. A legal basis for mandatory cooperation between the AI Office and national authorities has been established.

9. Proportionality of Penalties for Small Mid-Cap Enterprises (Art. 99 AI Act)

The mechanism capping the amount of administrative fines, previously applicable only to small and medium-sized enterprises (SMEs) within the meaning of Commission Recommendation 2003/361/EC, has been extended to Small Mid-Cap (SMC) enterprises. Such entities are required to pay the lower of two amounts — a percentage of annual global turnover or a fixed sum — whereas larger organisations remain subject to the higher of the two amounts.

10. Interaction with the Machinery Regulation (Regulation (EU) 2023/1230)

Products falling under the Machinery Regulation have been moved from Section A to Section B of Annex I to the AI Act. The legal consequence of this change is that the high-risk requirements under Chapter III, Section 2 of the AI Act no longer apply directly to AI systems embedded in such products.

At the same time, the European Commission is empowered to adopt delegated acts under the Machinery Regulation itself to establish AI-specific safety requirements applicable to this category of products. Other products falling under Section A of Annex I (medical devices, toys, etc.) continue to be governed by the AI Act without change.

11. Summary Table of Deadlines


Date


Legal Effect


2 August 2026


General transparency obligations (Art. 50, excluding paragraph 2 for systems placed on the market before this date)


2 December 2026


(a) AI-content marking requirement for systems placed on the market before 2 Aug 2026; (b) technical safeguards under the new Art. 5 prohibition (CSAM / non-consensual content)


2 August 2027


Deadline for the establishment of regulatory sandboxes by Member State competent authorities


2 December 2027


Application of Chapter III, Section 2 requirements to high-risk systems under Annex III


2 August 2028


Application of Chapter III, Section 2 requirements to high-risk systems under Annex I

12. Concluding Remarks

This clarification reflects the content of the act as agreed by the EU institutions and does not replace the text to be published in the Official Journal of the European Union. Corvus AI recommends that organisations engaged in the development, placing on the market, or use of AI systems within the EU conduct (or update) a legal compliance assessment (gap analysis) once the act is officially published, in light of the revised deadlines and substantive requirements.

For questions concerning the application of these amendments to a specific AI system or business model, consultation with Corvus AI specialists or other lawyers specialising in EU AI regulation is recommended.

This material has been prepared for informational purposes only, does not constitute legal advice, and does not create an attorney-client relationship between Corvus AI and any person who reviews this text.

© Corvus AI

logo