AI
Creating Environments for Effective AI Compliance: The EU Digital Omnibus Case
By Veronica Shiroya
The EU AI Act, adopted in May 2024, became the world's first comprehensive, enforceable law on AI arriving roughly a year and a half after AI tools captured global attention in late 2022. In the time since, AI has worked its way into nearly every sector, and with that spread has come mounting pressure on developers and deployers to get their compliance house in order. As AI capabilities expanded, so too did concerns surrounding safety, transparency, accountability, privacy and fundamental rights, making regulation and compliance increasingly necessary for both AI developers and deployers.
However, the conversation around AI regulation has been far from straightforward. The AI Act has attracted significant debate from industry leaders, policymakers and innovators. Critics argued that the compliance timelines were overly ambitious, particularly given the absence of harmonised standards, technical guidance and established regulatory authorities. Others questioned whether imposing extensive regulatory obligations so early in the technology's lifecycle could hinder innovation, particularly for start-ups and small businesses.
Responding to these concerns, the European Union revisited the AI Act. Following widespread industry feedback regarding the practicality of compliance within the prescribed timelines, the availability of technical standards, the readiness of national authorities, conformity assessment procedures and overlapping sector-specific legislation, the European Parliament agreed to amend several provisions of the AI Act.
In late June 2026, the EU finalized the Digital Omnibus on AI, a targeted amendment to the EU AI Act designed to simplify implementation, reduce duplication, clarify compliance obligations and provide more realistic implementation timelines. The Digital Omnibus is best understood as a corrective layer added to the AI Act. It preserves the Act's risk-based regulatory framework while refining how and when certain obligations apply. Rather than weakening AI regulation, it seeks to make compliance more practical without compromising the protection of health, safety and fundamental rights.
Some of the most significant amendments include:
High-risk AI deadlines are delayed
The headline change is a staggered delay to the timeline for high-risk AI systems:
2 December 2027 — for high-risk AI systems classified under Article 6(2) / Annex III, covering standalone use cases such as biometrics, critical digital infrastructure, education and vocational training, employment, and access to essential private and public services.
2 August 2028 — for high-risk AI systems classified under Article 6(1) / Annex I, meaning AI embedded as a safety component in already-regulated products (medical devices, machinery, radio equipment, and similar categories).
The reasoning is straightforward: the harmonised standards, common specifications, guidance documents, and national competent authorities that businesses need in order to demonstrate compliance simply weren't ready in time. Forcing the original deadlines through would have created uneven enforcement across Member States and pushed compliance costs up without a corresponding gain in safety or trust.
This is the single biggest relief valve in the Omnibus. It gives organizations especially those building or deploying systems in high-stakes sectors like healthcare, employment, education, and critical infrastructure real time to build proper governance frameworks rather than rushing to meet a deadline the ecosystem wasn't ready to support. The extra time is meant to be used, not banked. Standards bodies are still working through the technical specifications, and 18 months can disappear quickly if inventory and classification work doesn't start now.
Transparency for AI-generated content: A shorter-than-expected watermarking grace period
Article 50 of the AI Act requires providers of systems that generate synthetic audio, video, image, or text to ensure their outputs are marked in a machine-readable format and detectable as AI-generated or manipulated. Under the Omnibus, providers of systems already placed on the market before 2 August 2026 get a grace period, but it's shorter than industry initially hoped for: instead of a proposed six-month extension, the final deal grants just three additional months, moving the deadline to 2 December 2026. Systems placed on the market after 2 August 2026 must comply from day one as there's no grandfathering for new entrants.
Organizations should treat 2 August 2026 as a live date regardless. Deployer-side transparency obligations under Article 50 are largely untouched by the Omnibus, and only the narrower provider obligation for pre-existing systems gets the short reprieve.
Why this matters:
Combating misinformation — Watermarks let users and platforms verify whether media such as a deepfake video or a manipulated image was AI-generated, curbing the spread of deceptive content.
Content provenance and trust — Embedded identifiers let media organizations and creators prove authenticity and build audience trust.
IP and traceability — Watermarks tie outputs back to specific models, helping creators enforce copyright and track misuse.
Model accountability — Marking content lets developers and researchers see how, when, and by whom a model is being used in the wild, supporting more responsible deployment.
AI Regulatory Sandboxes are delayed and expanded
The Omnibus also resets the sandbox timeline and broadens who benefits from it:
Deadline extended — Member States now have until 2 August 2027 (up from 2 August 2026) to stand up at least one national AI regulatory sandbox.
EU-level sandbox — The AI Office may establish a Union-level sandbox for systems that fall under its own competence.
Priority access — SMEs, start-ups, and small mid-cap enterprises get priority placement.
Greater consistency — The Omnibus clarifies how national authorities should cooperate with each other and how sandbox governance should work in practice.
Inside a sandbox, participating organizations can validate AI systems under realistic conditions, surface technical, legal, ethical, and governance risks early, test mitigation measures, get direct feedback from competent authorities, sharpen their documentation and compliance evidence, and generally prepare for conformity assessment and market entry before the stakes get higher.
AI Literacy Obligation Is Softened
The original Act required developers and deployers to ensure "a sufficient level of AI literacy" among staff. The Omnibus loosens the phrasing: providers and deployers must now "take measures to support the development of AI literacy" among staff and authorized persons operating AI systems on their behalf. The shift in language matters. The amended text acknowledges that a rigid literacy mandate isn't realistic for every organization, SMEs in particular, and reframes AI literacy as a strategic priority rather than a box-ticking compliance burden.
AI literacy is a strategic investment that enables organizations to maximize the benefits of AI while managing its risks. Employees with a strong understanding of AI can critically evaluate model outputs, interpret data-driven insights, and automate repetitive tasks, allowing them to focus on higher-value and more strategic work. At the same time, AI literacy strengthens risk management by helping staff recognize the limitations, biases and ethical implications of AI systems, reducing the likelihood of operational failures, reputational harm and non-compliance with data protection and other regulatory requirements. A workforce that understands AI is also more likely to identify opportunities for experimentation and innovation, accelerating the development of new products, services and business processes.
Bias Detection and Correction
The Omnibus expands the legal basis for processing special categories of personal data (health data, biometric data, or data revealing race or sexual orientation) where strictly necessary to detect and correct bias in AI systems. This extends to deployers and providers of other AI systems and models more broadly, though always subject to safeguards. In practice, this closes a gap that had made bias auditing legally awkward under GDPR's stricter rules on sensitive data, while keeping the "strictly necessary" threshold in place to prevent overreach.
The Bigger Picture
Of all the changes in the Digital Omnibus, the deadline extensions are the clearest signal of intent. They tell Member States and the industry itself that regulators are willing to sequence enforcement with actual readiness, rather than enforcing a timeline the ecosystem can't yet support. That's especially significant for SMEs building AI tools, who rarely have the compliance infrastructure of a large enterprise behind them.
The logical next step is for countries to build the enabling environments that make regulatory compliance achievable from the outset. Several African countries, including South Africa, Nigeria, Rwanda, Ghana, and Mauritius, have established regulatory sandboxes focused primarily on fintech innovations. These sandboxes are typically administered by central banks because of the highly regulated nature of financial products and services. However, there is a growing need to expand this model by establishing cross-sector regulatory sandboxes that allow innovators to safely test a broader range of emerging digital technologies including AI, digital public infrastructure, blockchain, and other frontier technologies under regulatory oversight. Kenya offers a useful example of what that looks like in practice. The Communications Authority of Kenya (CAK), the country's ICT regulator, runs an Emerging Technologies Regulatory Sandbox that gives innovators a controlled environment to test novel digital communication products, services and business models that may fall outside existing regulatory frameworks. The sandbox is designed to foster direct collaboration between innovators and the regulator rather than leaving companies to interpret rules in isolation. CAK has opened applications for innovators, entrepreneurs, technology companies, and researchers to join the sandbox for the 2026/2027 financial year, with the stated goals of fostering innovation, promoting market growth, and strengthening consumer protection.
That kind of timely release of the infrastructure, sandboxes, phased timelines, and direct regulator engagement is what makes mandatory compliance workable rather than just aspirational. The EU's Digital Omnibus buys time on paper, but time only translates into real compliance readiness if it's matched by the standards, guidance, and support structures organizations actually need to act on it. Countries that build those structures early, as Kenya is doing through CAK's sandbox, are the ones best positioned to turn a regulatory deadline into a genuine compliance milestone rather than another deferred crisis.