Skip to main content

Tag: SMEs

Have You Heard About the AI Omnibus Regulation? What Changes Compared with the EU Artificial Intelligence Act?

European artificial intelligence regulation is changing again.

At a time when many businesses are still trying to understand how to comply with the European Artificial Intelligence Act, the European Union has approved a new reform known as the AI Omnibus, the Digital Omnibus on AI, or, more informally, the “AI Omnibus Law”.

But is this a completely new law? Does it replace the Artificial Intelligence Act? Have all obligations due to apply in August 2026 been postponed?

The answer is no.

The AI Omnibus does not repeal or replace Regulation (EU) 2024/1689. Its purpose is to amend certain aspects of the AI Act, simplify its implementation, reduce some administrative burdens and adapt certain deadlines to the actual availability of technical standards, guidelines and conformity assessment mechanisms.

What Is Regulation (EU) 2024/1689 on Artificial Intelligence?

Regulation (EU) 2024/1689, commonly known as the Artificial Intelligence Act or AI Act, is the European regulation establishing a common legal framework for the development, placing on the market and use of artificial intelligence systems within the European Union.

It was adopted on 13 June 2024, published in the Official Journal of the European Union on 12 July 2024 and entered into force on 1 August 2024.

Its application was designed to take place gradually.

Among other matters, the AI Act:

  • prohibits certain artificial intelligence practices;
  • classifies certain systems as high-risk AI systems;
  • establishes obligations for providers, deployers, importers and distributors;
  • regulates certain general-purpose artificial intelligence models;
  • imposes transparency requirements for certain AI systems and content;
  • and introduces an obligation to ensure an adequate level of AI literacy.

Not all businesses have the same obligations. Their responsibilities depend, among other factors, on the system being used, its intended purpose, its level of risk and the role performed by the company.

What Is the Digital Omnibus on AI?

The Digital Omnibus on AI is a new European regulation that amends specific aspects of Regulation (EU) 2024/1689.

The European Commission presented its proposal on 19 November 2025 as part of the European regulatory simplification package known as Omnibus VII.

The legislative process subsequently included the following stages:

  • the Council adopted its negotiating position on 13 March 2026;
  • the European Parliament adopted its position on 26 March 2026;
  • Parliament and the Council reached a political agreement on 7 May 2026;
  • the European Parliament approved the final text on 16 June 2026;
  • and the Council gave its final approval on 29 June 2026.

It is therefore not a Spanish law, nor does it replace the AI Act in its entirety.

It is a European regulation that partially amends the existing legal framework.

Its entry into force will take place after publication in the Official Journal of the European Union, under the terms established in the final text.

Main Differences Between the AI Act and the AI Omnibus

1. The AI Act Creates the General Framework; the Omnibus Amends It

Regulation (EU) 2024/1689 remains the principal legal instrument.

It defines what constitutes an AI system, establishes risk categories, allocates responsibilities among the different operators and regulates the applicable legal obligations.

The AI Omnibus does not create a completely new legal system.

Instead, it introduces targeted amendments designed to facilitate the practical implementation of the original Regulation.

A simple way to explain the relationship is:

The AI Act establishes the rules of the game. The AI Omnibus modifies some of those rules, procedures and deadlines.

2. Certain High-Risk AI Obligations Are Postponed

One of the most significant changes concerns the rules applicable to certain high-risk AI systems.

The reform establishes the following latest application dates:

  • 2 December 2027 for certain high-risk systems listed in Annex III, including systems used in areas such as employment, education, critical infrastructure, migration, access to essential services and biometrics.
  • 2 August 2028 for high-risk systems embedded in products governed by the European product safety legislation listed in Annex I, including certain machinery, medical devices and industrial systems.

The purpose is to prevent these obligations from becoming fully enforceable before the necessary harmonised standards, guidelines and implementation tools are available.

However, this change must be interpreted carefully:

the entire AI Act has not been postponed until 2027 or 2028.

3. The August 2026 Obligations Have Not Disappeared

The approval of the AI Omnibus does not mean that 2 August 2026 is no longer an important date.

The transparency obligations under Article 50 remain particularly relevant, including those concerning certain systems that interact directly with individuals, artificially generated or manipulated content, and certain uses of emotion recognition or biometric categorisation.

A company using chatbots, virtual assistants, AI-generated images, synthetic voices or manipulated content should therefore not interpret the postponement of certain high-risk obligations as a general suspension of its duties.

4. Certain Administrative Burdens Are Simplified

The AI Omnibus aims to reduce duplication and facilitate compliance.

Its objectives include:

  • simplifying certain documentation requirements;
  • improving coordination between assessments required under different European laws;
  • avoiding duplicated assessments where an AI system is already subject to sector-specific legislation;
  • facilitating compliance for small and medium-sized enterprises;
  • and providing greater clarity regarding the obligations of the different operators.

Simplification does not mean the removal of responsibility.

Businesses will still need to know which tools they use, why they use them, what data they process, who supervises the results and what risks may arise for clients, employees or third parties.

5. Certain Support Measures for Businesses Are Expanded

The AI Act already included specific measures designed to support SMEs.

The reform expands some of those measures and facilitation mechanisms, including measures aimed at small mid-cap companies.

This may lead to more proportionate documentation, regulatory support, controlled testing environments and implementation measures better adapted to the size and resources of the organisation.

However, being an SME or self-employed professional does not create a general exemption from the AI Act.

6. A New Prohibition Concerning Non-Consensual Intimate Content Is Introduced

The agreed text adds an express prohibition relating to AI systems designed to generate non-consensual sexual or intimate material involving identifiable individuals, as well as child sexual abuse material.

This includes so-called AI “nudifier” systems or applications.

The reform therefore demonstrates that the AI Omnibus is not limited to postponing deadlines or simplifying obligations.

It also introduces new prohibitions intended to protect fundamental rights and human dignity.

7. Transitional Rules Are Introduced for Certain Generative AI Systems

The reform provides for transitional arrangements for certain generative AI systems placed on the market or put into service before 2 August 2026.

In particular, it establishes an adaptation period for certain technical obligations relating to the marking and detection of AI-generated content.

This should not be confused with the general obligation to inform individuals when they are interacting directly with certain artificial intelligence systems.

Does the AI Omnibus Benefit Businesses?

In some respects, yes.

It provides additional time for compliance with certain high-risk obligations, reduces some duplication and aims to facilitate adaptation for SMEs and medium-sized businesses.

However, it may also create a false sense of security.

A business may wrongly conclude:

“As Europe has postponed the AI Act, we do not have to do anything until 2027.”

That conclusion would be incorrect.

Prohibited practices, AI literacy requirements, obligations concerning general-purpose AI models and certain transparency requirements follow their own application timetable.

Other laws also continue to apply, including:

  • the General Data Protection Regulation;
  • consumer protection legislation;
  • employment law;
  • intellectual property law;
  • trade secret rules;
  • advertising law;
  • and contractual obligations towards clients and suppliers.

What Should an SME or Self-Employed Professional Do Now?

The first step is not to prepare hundreds of documents.

The first step is to understand how artificial intelligence is actually being used within the business

Once this inventory has been prepared, the company can determine its legal role, the risk level of each use and the measures that must be adopted.

Conclusion

The Digital Omnibus on AI does not replace the European Artificial Intelligence Act.

It amends it.

It introduces new deadlines for certain high-risk systems, simplifies procedures, expands some support measures and adds new prohibitions.

However, it does not suspend the general application of the AI Act or remove the obligations that are already applicable or due to apply in August 2026.

The practical conclusion is clear:

businesses have more time in relation to certain high-risk systems, but they should not postpone their general preparation for compliance with European artificial intelligence legislation.

At Bennet & Rey, we help SMEs, self-employed professionals and companies identify their AI tools, classify their uses, assess their risks and prepare the documentation required to comply with European legislation in a proportionate and understandable way.

The aim is not to stop using artificial intelligence.

The aim is to use it with knowledge, human oversight and legal certainty.

Fines for the Misuse of AI: What Self-Employed Professionals and SMEs Need to Know

Artificial intelligence is already part of the day-to-day operations of many businesses.

Self-employed professionals, retailers, professional firms and small and medium-sized enterprises use tools such as ChatGPT, Microsoft Copilot and other AI systems to draft documents, respond to enquiries, prepare marketing campaigns, analyse information and improve internal processes.

Using these tools is not, in itself, unlawful.

However, the professional use of artificial intelligence is not free from legal obligations. The European Union Artificial Intelligence Act establishes a system of responsibilities and penalties that may also apply to self-employed professionals and SMEs.

The key question is not simply whether a business uses artificial intelligence. It is how the technology is used, for what purpose and what consequences it may have for clients, employees, job applicants or consumers.

Can an SME be fined for using artificial intelligence?

Yes.

A self-employed professional or an SME may fall within the scope of the EU AI Act when using an AI system as part of its professional or commercial activity.

The Regulation uses the term “deployer” to describe a natural or legal person who uses an AI system under their authority, except where the system is used in the course of a personal, non-professional activity.

This means that a business does not need to have developed its own artificial intelligence system in order to assume legal responsibilities.

It may be sufficient for the business to use an AI tool to make decisions, screen job applicants, assess employees, classify customers, generate content or provide services.

Not all uses of artificial intelligence, however, carry the same level of risk.

The EU AI Act follows a risk-based approach. The most demanding obligations apply to prohibited AI practices and systems classified as high-risk.

When does the EU AI Act apply?

The Regulation is being introduced progressively.

The general provisions and prohibitions relating to certain AI practices began to apply on 2 February 2025.

The rules concerning penalties began to apply on 2 August 2025.

Most of the Regulation will become fully applicable from 2 August 2026, although some specific provisions are subject to different implementation dates.

Businesses should therefore not wait until the last moment to review how artificial intelligence is being used within their organisations.

What fines does the EU AI Act establish?

The Regulation provides for three principal levels of administrative fines.

1. Prohibited AI practices

Breaching the prohibition on certain artificial intelligence practices may lead to fines of up to:

€35 million or 7% of the company’s total worldwide annual turnover.

Prohibited practices include, in certain circumstances, AI systems that manipulate human behaviour, exploit people’s vulnerabilities, carry out certain forms of social scoring or use prohibited biometric technologies.

2. Breaches of other obligations under the Regulation

Failure to comply with other obligations applicable to providers, deployers, importers, distributors or notified bodies may lead to fines of up to:

€15 million or 3% of total worldwide annual turnover.

This category may include breaches connected with high-risk AI systems, transparency, documentation, human oversight or cooperation with the competent authorities.

3. Providing incorrect, incomplete or misleading information

Providing incorrect, incomplete or misleading information to the relevant authorities or notified bodies may lead to fines of up to:

€7.5 million or 1.5% of total worldwide annual turnover.

Do the same maximum amounts apply to SMEs?

The Regulation expressly takes account of the position of small and medium-sized enterprises, including start-ups.

Where the infringing business is an SME, the maximum fine in each category is the lower of:

  • the fixed monetary amount established in the Regulation; or
  • the relevant percentage of the business’s annual turnover.

For example, if a small business has an annual turnover of €500,000, the percentage-based maximums would be:

  • up to €35,000 for a prohibited AI practice: 7%;
  • up to €15,000 for other infringements: 3%;
  • up to €7,500 for providing incorrect, incomplete or misleading information: 1.5%.

This does not mean that these amounts will automatically be imposed.

The competent authority must consider the circumstances of the individual case and ensure that any penalty is effective, proportionate and dissuasive.

Relevant factors may include:

  • the nature and seriousness of the infringement;
  • its duration;
  • the number of people affected;
  • the damage caused;
  • whether the conduct was intentional or negligent;
  • the measures taken to correct the infringement;
  • the level of cooperation with the authorities;
  • any previous infringements;
  • and the financial capacity of the business.

Can the use of ChatGPT lead to a fine?

Using ChatGPT, Copilot or another generative AI tool does not, by itself, constitute an infringement.

The legal risk arises when a business uses artificial intelligence without appropriate safeguards or for purposes that may affect the rights of other people.

Examples may include:

  • entering clients’ personal data or confidential information into an AI system without first assessing the risks;
  • using AI to select or reject job applicants without sufficient human oversight;
  • assessing employee performance or behaviour through automated systems;
  • publishing AI-generated or manipulated images, videos or audio without complying with applicable transparency obligations;
  • making significant decisions solely on the basis of AI-generated output;
  • using tools that produce discriminatory or biased results;
  • or allowing staff to use AI systems without training or internal guidance.

Other legislation may also apply alongside the EU AI Act, including the General Data Protection Regulation, employment law, consumer protection law, intellectual property law and professional duties of confidentiality.

AI literacy is also a legal obligation

The EU AI Act requires providers and deployers of AI systems to take measures to ensure that the people using those systems on their behalf have a sufficient level of AI literacy.

This does not necessarily mean turning every member of staff into a technical expert.

It means ensuring that employees understand, according to their roles:

  • which AI tools they are permitted to use;
  • what information they must not enter;
  • the limitations of the system;
  • when AI-generated output must be reviewed;
  • what risks may arise;
  • and when human intervention is required.

Allowing employees to use AI without any training, policy or supervision may expose a business to unnecessary legal and operational risks.

What should an SME do now?

The first step is not to prohibit artificial intelligence.

It is to understand how AI is actually being used within the organisation.

Many businesses believe that they do not use AI in any significant way, while their employees may already be using it to summarise documents, draft emails, review CVs, prepare quotations, generate images or respond to client enquiries.

An initial review should include the following measures.

1. Identify the AI tools being used

The business should know which artificial intelligence systems are used by its employees, collaborators and external service providers.

2. Determine how they are being used

Using AI to improve the wording of a document does not create the same level of risk as using it to select employees or decide whether a customer should receive a service.

3. Assess the level of risk

The business should determine whether the system falls within a prohibited practice, a high-risk system, a system subject to transparency duties or a lower-risk use.

4. Review the information entered into the system

It is important to determine whether employees are entering personal data, confidential information, trade secrets or client documents into AI tools.

5. Establish human oversight

AI-generated outputs should not be accepted automatically, particularly where they may have legal, financial or personal consequences.

6. Train employees

Staff should receive clear and proportionate guidance on the authorised use of artificial intelligence.

7. Adopt an internal AI policy

An internal policy can establish which tools are authorised, for which purposes they may be used and which safeguards must be followed.

Compliance without preventing innovation

The EU Artificial Intelligence Act is not intended to prevent businesses from using this technology.

Its purpose is to promote artificial intelligence that is safe, transparent and respectful of fundamental rights.

For self-employed professionals and SMEs, compliance does not have to become a disproportionate burden. The measures adopted should reflect the size of the business, the nature of its activity and the actual risks created by the AI systems it uses.

However, ignoring the legislation or assuming that a practice must be acceptable because “everyone is using AI” may lead to legal, reputational and financial consequences.

The best form of prevention is to review current AI use, identify the risks and establish clear internal rules before a problem arises.

How can Bennet & Rey help?

Bennet & Rey offers a legal AI compliance assessment and internal policy service for SMEs and professional firms.

The service may include:

  • identifying the AI tools currently used within the business;
  • analysing their purposes and legal risks;
  • reviewing the use of personal data and confidential information;
  • classifying AI systems according to their level of risk;
  • preparing an internal AI use policy;
  • establishing human oversight procedures;
  • drafting clauses for employees, collaborators and suppliers;
  • and recommending appropriate AI literacy and training measures.

The objective is not to prevent a business from using artificial intelligence, but to help it use AI safely, proportionately and in a way that reflects its actual activities.

Every organisation uses artificial intelligence differently. The first step should therefore be an individual assessment to determine which measures are genuinely necessary.

Does your business use artificial intelligence, and are you unsure whether it complies with the new rules?

Contact Bennet & Rey to request an AI compliance assessment.