Search pages, courses, and articles
The Digital Omnibus, Regulation (EU) 2026/1744, entered into force on 27 July 2026. Annex III now applies from 2 December 2027; Annex I from 2 August 2028. Article 4 was reworded and new Article 5 prohibitions apply from 2 December 2026.
The Digital Omnibus, published on 24 July 2026 and in force since 27 July 2026, is the single most important regulatory change to the EU AI Act since adoption. It moved Annex III standalone high-risk obligations from 2 August 2026 to 2 December 2027, a 16-month shift that materially changes 2026 compliance scoping for every deployer. Annex I embedded high-risk (medical devices, machinery) moved to 2 August 2028. Critically, Article 4 AI literacy and the Article 5 prohibitions stay live, both applying since 2 February 2025. Article 4 now reads take measures to support the development of AI literacy and expressly does not require guaranteeing any individual's level, and the Omnibus added new Article 5 prohibitions that apply from 2 December 2026. SME relief was also extended to small mid-caps (SMCs) for the first time.
The Digital Omnibus, Regulation (EU) 2026/1744, was published on 24 July 2026 and entered into force on 27 July 2026. Annex III standalone systems now apply from 2 December 2027, Annex I embedded systems from 2 August 2028. Article 4 literacy and the Article 5 prohibitions stay live: Article 4 was reworded to require measures that support the development of AI literacy, and the new Article 5 prohibitions apply from 2 December 2026.
Read articleA practical 10-step compliance checklist for the EU AI Act. From AI inventory to ongoing monitoring: everything your business needs before the 2 December 2027 high-risk deadline.
Read articleRecruitment AI, CV screening, performance scoring, promotion and termination AI, gig allocation, and worker monitoring all sit in Annex III(4) high-risk territory under the EU AI Act. This guide covers what HR teams need to do under Article 26, when an Article 27 FRIA is required, and how to scope a 90-day HR AI compliance ramp.
Read articleHealthcare AI sits at the intersection of two regimes: the EU AI Act + sectoral product law (MDR / IVDR). This guide covers Annex I embedded high-risk classification, the dual conformity assessment route, Article 73 incident reporting on top of MDR vigilance, and the 2 August 2028 deadline post-Omnibus.
Read articleCredit-scoring AI is one of the few use cases that REQUIRES an Article 27 FRIA under the EU AI Act. This guide covers Annex III(5)(b) classification, the FRIA process, GDPR Article 22 automated-decision rights, the Consumer Credit Directive interaction, and the 2 December 2027 deadline.
Read articleArticle 27 requires certain deployers of high-risk AI systems to run a fundamental rights impact assessment (FRIA) before deployment. Who's actually in scope is narrower than most read it. This guide covers the 6 things a FRIA must cover, how it differs from a GDPR DPIA, the notification step, and how to scope your first FRIA without over-engineering it.
Read articleMore topics
5-minute scored assessment across People, Tools, Compliance, and Infrastructure. See where you sit on this topic in operational terms.