The AI Digital Omnibus, published in June, introduces significant amendments to the AI Act with the aim of simplifying its implementation, reducing the administrative burden on businesses, and adjusting the compliance timetable.
Although the AI Act already provided for a phased implementation schedule, the absence of harmonised technical standards has prompted the European legislator to reconsider that timeline. The result is a more complex, but also more realistic, compliance calendar, under which some obligations remain subject to their original deadlines, while others have been postponed until 2027 and 2028.
In this article, we examine what has changed, what remains unchanged, the obligations that apply at each stage of the implementation timetable, and the new requirements introduced by the AI Digital Omnibus.
1. Small Mid-Cap Enterprises
Until now, the AI Act provided tailored measures for small and medium-sized enterprises (SMEs) but did not address the situation of businesses that had grown beyond the SME thresholds while still facing many of the same compliance challenges.
These companies often experience faster growth, innovation, and capitalisation than SMEs, yet continue to face comparable administrative burdens. To address this gap, the European legislator has introduced a new category of small mid-cap enterprises, granting them the same regulatory support measures previously reserved for SMEs, thereby ensuring that administrative requirements do not hinder their continued growth.
As a result, small mid-cap enterprises will now benefit from the following measures, which were previously available only to SMEs:
- Simplified technical documentation. These companies may use the simplified template to provide the technical documentation required under Annex IV of the AI Act.
- Proportional quality management systems. The implementation of the quality management system must be proportionate to the size of the provider's organisation. However, the Regulation makes clear that this principle of proportionality does not reduce the required level of rigour or the degree of protection necessary to ensure that high-risk AI systems comply with the AI Act.
- Priority access to regulatory sandboxes. The AI Office is empowered to establish EU-wide regulatory sandboxes for specific AI systems under its supervision. SMEs and small mid-cap enterprises will receive priority access to these controlled testing environments.
- Proportionate administrative fines. For these businesses, administrative fines imposed for breaches of general obligations or for providing incorrect information will be calculated using either the percentage of annual turnover or the fixed monetary amount specified in the AI Act, with the lower of the two amounts always applying. Importantly, this benefit does not extend to fines imposed for engaging in prohibited AI practices under Article 5 of the AI Act. Furthermore, Member States are required to take into account the interests and economic viability of small mid-cap enterprises when establishing and applying their national penalty regimes.
In practice, this means that if your business has grown beyond the SME definition, you will no longer be forced directly into the regulatory framework applicable to large companies. Instead, the new simplification measures provide additional support to help your business transition smoothly and meet its compliance obligations under the AI Act.
2. New Prohibited AI Practices Under Article 5 of the AI Act
The AI Act simplification package expands Article 5 by introducing two new categories of prohibited AI practices aimed at addressing the risks associated with AI-generated intimate imagery (deepfake nudification) and the use of generative AI to create child sexual abuse material (CSAM).
Specifically, the following prohibitions have been added:
- Non-consensual intimate content. The placing on the market, putting into service, or use of AI systems that generate or manipulate realistic images, videos, or audio depicting the intimate parts of an identifiable person, or portraying that person engaging in sexually explicit activities, without their free and explicit consent, is prohibited.
- Child sexual abuse material (CSAM). The use of AI systems to generate or manipulate child sexual abuse material is prohibited.
The Regulation also clarifies the circumstances in which an operator will be deemed to have infringed these prohibitions:
- For providers, the prohibition applies where the AI system is specifically designed to generate such material, or where its design makes such outputs reasonably foreseeable and reproducible, and the provider has failed to implement reasonable technical safeguards to prevent them.
- For deployers, the prohibition applies only where the AI system is intentionally used to generate or manipulate the prohibited material.
The Regulation also establishes several important exclusions to these prohibitions:
- Technical enhancements. A modification will not be regarded as prohibited manipulation where it merely improves existing content without increasing the exposure of intimate body parts or altering the sexual nature of the depicted activity. Examples include adjusting brightness, changing the background, or adding a text caption.
- Realistic representations. The prohibition applies only to realistic depictions of a person's face, voice, or body that could credibly be perceived as real. It expressly excludes cartoons, artistic representations, and physically impossible depictions.
- Medical diagnosis and treatment. AI applications used for legitimate medical purposes, such as mammograms or anatomical simulations for diagnosis or treatment, fall outside the scope of these prohibitions.
- Informed and explicit consent. The prohibition does not apply where the identifiable person has given their informed and explicit consent, for example in the context of virtual try-on technologies.
These new prohibited AI practices under Article 5 will become applicable on 2 December 2026.
3. The Role of AI Literacy
Article 4 of the AI Act already required both providers and deployers to ensure that their staff possessed an adequate level of AI literacy. Under the original wording, this amounted to an obligation of result, requiring organisations to guarantee that their personnel achieved a sufficient level of AI literacy.
The AI Digital Omnibus retains the obligation to promote AI literacy but changes its nature. Rather than requiring organisations to guarantee a particular outcome, it introduces an obligation of means, requiring providers and deployers to take reasonable measures to support the development of AI literacy among their personnel.
In addition, the amendments require the European Commission and the Member States to support providers and deployers—particularly SMEs—by publishing practical examples of how to comply with this obligation through a single information platform.
In other words, AI literacy shifts from being an obligation to guarantee a specific level of competence to an obligation to implement reasonable support measures, with the emphasis placed on continuous learning and the ongoing development of AI skills.
4. New Powers for the AI Office
Another key pillar of the simplification package is the strengthening of the role of the European AI Office, the Commission body responsible for overseeing the enforcement of the AI Act.
- Exclusive Supervisory Competence
The AI Office is granted exclusive responsibility for supervising compliance with the AI Act in the following cases:
- General-purpose AI (GPAI) models and systems, where both the model and the AI system have been developed by the same provider or by companies belonging to the same corporate group.
- Very Large Online Platforms (VLOPs) and Very Large Online Search Engines (VLOSEs), where AI systems constitute, or are integrated into, services designated under the Digital Services Act (DSA).
- New Investigative and Enforcement Powers
To carry out its supervisory role, the AI Office is granted powers equivalent to those of a market surveillance authority, including:
- Inspections. The AI Office may enter business premises, inspect books and records, examine data, obtain copies of documents, and request oral or written explanations from staff. Where access is refused, national authorities are required to provide assistance.
- Requests for information. The Office may require operators to provide documents or information through legally binding decisions. Failure to comply may result in administrative fines.
- Access to AI systems. The Office may require operators to grant direct access to their AI systems and provide explanations regarding their operation and functionality.
- Experts and auditors. The AI Office is empowered to appoint independent experts and auditors to assist with investigations.
- Power to Impose Direct Sanctions
The AI Office is also empowered to determine infringements of the AI Act and impose both administrative fines and periodic penalty payments. These periodic penalty payments may amount to up to 5% of the operator's average daily worldwide turnover in the preceding financial year and are intended to compel companies to submit to inspections, comply with requests for information, or fulfil legally binding commitments.
- Promoting Innovation Through EU Regulatory Sandboxes
The AI Office may establish EU-wide regulatory sandboxes for AI systems falling within its supervisory remit. These controlled testing environments must provide priority access to SMEs, start-ups, and small mid-cap enterprises, enabling them to develop and test innovative AI systems under regulatory supervision.
- Resources
The amendments also require the European Commission to provide the AI Office with adequate human, financial, and technical resources, including permanent staff with sufficient technical expertise, so that it can carry out its enforcement responsibilities effectively through a highly qualified and permanent workforce.
5. New Compliance Timeline
The simplification of the AI Act, introduced through the AI Digital Omnibus, revises the implementation timetable to allow operators and national authorities more time to adapt from both a technical and organisational perspective.
- Extended Deadlines for High-Risk AI Systems
Due to delays in the development of harmonised technical standards and the establishment of national governance frameworks, the compliance deadlines for high-risk AI systems have been extended.
- Annex III high-risk AI systems (sector-specific applications). Compliance with the requirements relating to risk management, data governance, and technical documentation has been postponed from 2 August 2026 to 2 December 2027.
- Annex I high-risk AI systems (regulated products). The compliance deadline for AI systems incorporated into regulated products such as toys, machinery, and similar products has been postponed from 2 August 2027 to 2 August 2028.
- Alignment with the Machinery Regulation. The sector-specific rules governing the integration of AI requirements into machinery legislation must be fully applicable by 2 August 2028.
- Deadlines for Regulatory Support and Innovation
- Regulatory sandboxes. Member States now have until 2 August 2027—one year later than originally planned—to establish at least one operational national regulatory sandbox.
- Obligations That Remain Applicable from 2 August 2026
Several key obligations remain subject to the original implementation date of 2 August 2026, including:
- General application of the AI Act. The harmonised rules governing the placing on the market and putting into service of AI systems enter into force, particularly for systems that do not fall within the high-risk category.
- Transparency obligations (Article 50). Providers must comply with the transparency requirements applicable to AI systems that interact with natural persons (such as chatbots), emotion recognition systems, and biometric categorisation systems.
- Supervisory infrastructure. National supervisory authorities and conformity assessment bodies must be fully operational and capable of carrying out their regulatory functions.
- AI literacy. Providers and deployers become subject to the obligation to adopt reasonable measures to support the development of AI literacy among their personnel.
- Obligations Applicable from 2 December 2026
The following additional obligations will apply from 2 December 2026:
- New prohibited AI practices (Article 5). The new prohibitions concerning AI systems used to generate non-consensual intimate content ("deepfake nudification") and child sexual abuse material (CSAM) become fully applicable.
- Pre-existing AI-generated content systems. Providers of AI systems that generate text, images, audio, or video and that were already placed on the market before August 2026 must comply by this date with the technical marking requirements requiring AI-generated content to be identifiable in a machine-readable format.
- Obligations Applicable from 2 December 2027 and 2 August 2028 for High-Risk AI Systems
The most significant amendment introduced by the AI Digital Omnibus concerns the implementation timetable for high-risk AI systems. Rather than applying from 2 August 2026, the relevant obligations will now apply as follows:
- 2 December 2027, for Annex III high-risk AI systems used in specific sectors such as education, employment, and other high-risk application areas.
- 2 August 2028, for Annex I high-risk AI systems incorporated into regulated products such as toys, lifts, medical devices, radio equipment, and other products subject to EU product safety legislation.
How Does the AI Act Simplification Affect Your E-commerce?
Having reviewed the five major changes introduced by the AI Digital Omnibus, it is worth considering what these amendments mean in practice for the operation of your e-commerce.
- If your e-commerce business has grown beyond SME status. If your business no longer meets the definition of an SME and now falls within the new category of a small mid-cap enterprise, you will not automatically be subject to the full regulatory regime applicable to large companies. Instead, you can continue to benefit from simplified technical documentation and the more proportionate system of administrative fines.
- If you use generative AI on your e-commerce website. If you use AI tools to generate product images, virtual try-on experiences, promotional videos, or chatbot content, you must ensure that all AI-generated content is appropriately marked from 2 August 2026 onwards. In addition, AI-generated content that was already available before that date must comply with the machine-readable marking requirements by 2 December 2026.
- If your employees use AI. You are no longer required to guarantee that your workforce reaches a particular level of AI literacy. However, you must adopt reasonable measures to support their ongoing training and development in the use of artificial intelligence.
- If your e-commerce business (or the marketplace on which you sell) is a very large online platform. If your business operates as a Very Large Online Platform (VLOP) under the Digital Services Act (DSA), you should be aware that AI Act supervision and DSA enforcement will become more closely coordinated between the European Commission and the AI Office.
Conclusion
The simplification of the AI Act provides businesses with more time to prepare, a more proportionate compliance framework based on company size, and new prohibited AI practices.
Your e-commerce business may have been given additional time to comply, but it has not been given fewer obligations. If you already use artificial intelligence on your website, there is no reason to wait until the new deadlines arrive. Start preparing now with Lawwwing and ensure your business is ready for the AI Act from day one.