Skip to main content

Tag: AI transparency

Have You Heard About the AI Omnibus Regulation? What Changes Compared with the EU Artificial Intelligence Act?

European artificial intelligence regulation is changing again.

At a time when many businesses are still trying to understand how to comply with the European Artificial Intelligence Act, the European Union has approved a new reform known as the AI Omnibus, the Digital Omnibus on AI, or, more informally, the “AI Omnibus Law”.

But is this a completely new law? Does it replace the Artificial Intelligence Act? Have all obligations due to apply in August 2026 been postponed?

The answer is no.

The AI Omnibus does not repeal or replace Regulation (EU) 2024/1689. Its purpose is to amend certain aspects of the AI Act, simplify its implementation, reduce some administrative burdens and adapt certain deadlines to the actual availability of technical standards, guidelines and conformity assessment mechanisms.

What Is Regulation (EU) 2024/1689 on Artificial Intelligence?

Regulation (EU) 2024/1689, commonly known as the Artificial Intelligence Act or AI Act, is the European regulation establishing a common legal framework for the development, placing on the market and use of artificial intelligence systems within the European Union.

It was adopted on 13 June 2024, published in the Official Journal of the European Union on 12 July 2024 and entered into force on 1 August 2024.

Its application was designed to take place gradually.

Among other matters, the AI Act:

  • prohibits certain artificial intelligence practices;
  • classifies certain systems as high-risk AI systems;
  • establishes obligations for providers, deployers, importers and distributors;
  • regulates certain general-purpose artificial intelligence models;
  • imposes transparency requirements for certain AI systems and content;
  • and introduces an obligation to ensure an adequate level of AI literacy.

Not all businesses have the same obligations. Their responsibilities depend, among other factors, on the system being used, its intended purpose, its level of risk and the role performed by the company.

What Is the Digital Omnibus on AI?

The Digital Omnibus on AI is a new European regulation that amends specific aspects of Regulation (EU) 2024/1689.

The European Commission presented its proposal on 19 November 2025 as part of the European regulatory simplification package known as Omnibus VII.

The legislative process subsequently included the following stages:

  • the Council adopted its negotiating position on 13 March 2026;
  • the European Parliament adopted its position on 26 March 2026;
  • Parliament and the Council reached a political agreement on 7 May 2026;
  • the European Parliament approved the final text on 16 June 2026;
  • and the Council gave its final approval on 29 June 2026.

It is therefore not a Spanish law, nor does it replace the AI Act in its entirety.

It is a European regulation that partially amends the existing legal framework.

Its entry into force will take place after publication in the Official Journal of the European Union, under the terms established in the final text.

Main Differences Between the AI Act and the AI Omnibus

1. The AI Act Creates the General Framework; the Omnibus Amends It

Regulation (EU) 2024/1689 remains the principal legal instrument.

It defines what constitutes an AI system, establishes risk categories, allocates responsibilities among the different operators and regulates the applicable legal obligations.

The AI Omnibus does not create a completely new legal system.

Instead, it introduces targeted amendments designed to facilitate the practical implementation of the original Regulation.

A simple way to explain the relationship is:

The AI Act establishes the rules of the game. The AI Omnibus modifies some of those rules, procedures and deadlines.

2. Certain High-Risk AI Obligations Are Postponed

One of the most significant changes concerns the rules applicable to certain high-risk AI systems.

The reform establishes the following latest application dates:

  • 2 December 2027 for certain high-risk systems listed in Annex III, including systems used in areas such as employment, education, critical infrastructure, migration, access to essential services and biometrics.
  • 2 August 2028 for high-risk systems embedded in products governed by the European product safety legislation listed in Annex I, including certain machinery, medical devices and industrial systems.

The purpose is to prevent these obligations from becoming fully enforceable before the necessary harmonised standards, guidelines and implementation tools are available.

However, this change must be interpreted carefully:

the entire AI Act has not been postponed until 2027 or 2028.

3. The August 2026 Obligations Have Not Disappeared

The approval of the AI Omnibus does not mean that 2 August 2026 is no longer an important date.

The transparency obligations under Article 50 remain particularly relevant, including those concerning certain systems that interact directly with individuals, artificially generated or manipulated content, and certain uses of emotion recognition or biometric categorisation.

A company using chatbots, virtual assistants, AI-generated images, synthetic voices or manipulated content should therefore not interpret the postponement of certain high-risk obligations as a general suspension of its duties.

4. Certain Administrative Burdens Are Simplified

The AI Omnibus aims to reduce duplication and facilitate compliance.

Its objectives include:

  • simplifying certain documentation requirements;
  • improving coordination between assessments required under different European laws;
  • avoiding duplicated assessments where an AI system is already subject to sector-specific legislation;
  • facilitating compliance for small and medium-sized enterprises;
  • and providing greater clarity regarding the obligations of the different operators.

Simplification does not mean the removal of responsibility.

Businesses will still need to know which tools they use, why they use them, what data they process, who supervises the results and what risks may arise for clients, employees or third parties.

5. Certain Support Measures for Businesses Are Expanded

The AI Act already included specific measures designed to support SMEs.

The reform expands some of those measures and facilitation mechanisms, including measures aimed at small mid-cap companies.

This may lead to more proportionate documentation, regulatory support, controlled testing environments and implementation measures better adapted to the size and resources of the organisation.

However, being an SME or self-employed professional does not create a general exemption from the AI Act.

6. A New Prohibition Concerning Non-Consensual Intimate Content Is Introduced

The agreed text adds an express prohibition relating to AI systems designed to generate non-consensual sexual or intimate material involving identifiable individuals, as well as child sexual abuse material.

This includes so-called AI “nudifier” systems or applications.

The reform therefore demonstrates that the AI Omnibus is not limited to postponing deadlines or simplifying obligations.

It also introduces new prohibitions intended to protect fundamental rights and human dignity.

7. Transitional Rules Are Introduced for Certain Generative AI Systems

The reform provides for transitional arrangements for certain generative AI systems placed on the market or put into service before 2 August 2026.

In particular, it establishes an adaptation period for certain technical obligations relating to the marking and detection of AI-generated content.

This should not be confused with the general obligation to inform individuals when they are interacting directly with certain artificial intelligence systems.

Does the AI Omnibus Benefit Businesses?

In some respects, yes.

It provides additional time for compliance with certain high-risk obligations, reduces some duplication and aims to facilitate adaptation for SMEs and medium-sized businesses.

However, it may also create a false sense of security.

A business may wrongly conclude:

“As Europe has postponed the AI Act, we do not have to do anything until 2027.”

That conclusion would be incorrect.

Prohibited practices, AI literacy requirements, obligations concerning general-purpose AI models and certain transparency requirements follow their own application timetable.

Other laws also continue to apply, including:

  • the General Data Protection Regulation;
  • consumer protection legislation;
  • employment law;
  • intellectual property law;
  • trade secret rules;
  • advertising law;
  • and contractual obligations towards clients and suppliers.

What Should an SME or Self-Employed Professional Do Now?

The first step is not to prepare hundreds of documents.

The first step is to understand how artificial intelligence is actually being used within the business

Once this inventory has been prepared, the company can determine its legal role, the risk level of each use and the measures that must be adopted.

Conclusion

The Digital Omnibus on AI does not replace the European Artificial Intelligence Act.

It amends it.

It introduces new deadlines for certain high-risk systems, simplifies procedures, expands some support measures and adds new prohibitions.

However, it does not suspend the general application of the AI Act or remove the obligations that are already applicable or due to apply in August 2026.

The practical conclusion is clear:

businesses have more time in relation to certain high-risk systems, but they should not postpone their general preparation for compliance with European artificial intelligence legislation.

At Bennet & Rey, we help SMEs, self-employed professionals and companies identify their AI tools, classify their uses, assess their risks and prepare the documentation required to comply with European legislation in a proportionate and understandable way.

The aim is not to stop using artificial intelligence.

The aim is to use it with knowledge, human oversight and legal certainty.

Article 50 of the EU AI Act: transparency is no longer optional

Artificial intelligence is already part of everyday business life. Companies use chatbots on their websites, AI-generated text in marketing, AI images in social media, virtual assistants in customer service, and avatars or synthetic video content in branding and communication.

The problem is that many businesses have focused only on whether the technology works. Far fewer have asked the legal question: does it comply?

That is where Article 50 of the EU AI Act becomes highly relevant. Article 50 sets out transparency obligations for providers and deployers of certain AI systems. In practice, this means that, in some situations, a business must inform people that they are interacting with AI or disclose that content has been artificially generated or manipulated.

What does Article 50 actually require?

Article 50 is not a general rule for every internal use of AI. It is more targeted. It applies to certain AI systems and certain outputs.

Under the official text, Article 50 covers, among other things:

  • AI systems intended to interact directly with natural persons, unless it is obvious that the person is interacting with AI.
  • AI systems generating synthetic audio, image, video or text content, whose outputs must be marked in a machine-readable and detectable way as artificially generated or manipulated, subject to the limits set out in the Regulation.
  • Deployers of emotion recognition systems or biometric categorisation systems, who must inform exposed individuals of the operation of the system.
  • Deployers of AI systems generating or manipulating deepfake image, audio or video

    In short: if your company uses AI in a way that affects how users perceive content or interaction, transparency may no longer be optional.

    Why should businesses care?

    Many companies assume that if an agency built the chatbot, a SaaS tool generated the content, or a tech provider installed the system, the legal side must already be covered.

    That assumption is risky.

    The AI provider may be focused on functionality. Your marketing agency may be focused on conversion. Your general accountant may not be advising on the EU AI Act at all. Yet your company may still be the one exposed if the use of AI is not transparent enough. content, who must disclose that the content has been artificially generated or manipulated, with a softer rule for clearly artistic, creative, satirical or fictional works.

    The legal risk is not only theoretical. It is operational and reputational. A competitor, customer, employee or authority may eventually ask a very simple question:

    How are you using AI, and have you informed users properly?

    If the answer is vague, improvised or undocumented, the business is exposed.

    What kind of businesses may be affected?

    Article 50 may be relevant if your business:

    • uses a chatbot or AI assistant on its website;
    • uses AI-generated content in customer-facing communications;
    • publishes AI-created or AI-manipulated images or videos;
    • uses avatars or synthetic spokesperson videos;
    • relies on AI-generated text in public-facing information;
    • deploys deepfake-style content;
    • uses emotion recognition or biometric categorisation systems.

    Not every business will be affected in the same way. But many businesses already use AI in customer-facing environments without having reviewed the legal transparency angle.

    What are the fines for non-compliance?

    This is the part that gets attention — and understandably so.

    Under Article 99 of the EU AI Act, non-compliance with Article 50 transparency obligations may be subject to administrative fines of up to EUR 15,000,000 or, if the offender is an undertaking, up to 3% of its total worldwide annual turnover for the preceding financial year, whichever is higher.

    The Regulation also makes clear that, in the case of SMEs, including start-ups, the fine is capped at the lower of the relevant percentage or amount. It further states that penalties must be effective, proportionate and dissuasive, while taking into account the interests of SMEs and their economic viability.

So the correct message is not “every SME will be fined millions”. That would be legally sloppy and commercially unhelpful.

The correct message is this:

Non-compliance can be costly, and businesses should not wait for a complaint, inspection or challenge before checking whether their AI use is transparent enough.

When does this matter?

The AI Act provides that the Regulation applies from 2 August 2026, subject to certain exceptions for different parts of the Regulation.

That means businesses already using AI should not leave this until the last minute. Transparency issues are often not difficult to identify, but they do require a proper legal review.

The real issue: evidence of diligence

In practice, one of the most important questions is not simply whether a company made a mistake.

It is whether the company can show that it acted seriously and diligently.

A business that has reviewed its systems, identified where Article 50 may apply,

documented its use of AI and adopted a reasonable action plan is in a very different position from a business that has done nothing at all.

That is why legal review matters.

AI compliance is not about panic

The goal is not to scare businesses away from AI.

The goal is to use AI properly, transparently and with legal awareness.

Most companies do not need panic. They need clarity.

They need to know what applies, what does not, and what practical steps they should take now.

How Bennet & Rey can help

At Bennet & Rey, we help businesses, entrepreneurs and SMEs review their use of AI from a legal perspective.

Final thought

Article 50 of the EU AI Act sends a clear message: if your business uses certain AI systems, transparency is not optional.

If you use chatbots, avatars, AI-generated content or other customer-facing AI tools, now is the time to ask the legal question — not later.

Because the real risk is not just the fine.

The real risk is discovering too late that your AI was visible to everyone except your legal review.

If you have any quesions, please let us know. At Bennet & Rey we are here to help you.