"The AI Act deadlines have been postponed — can we slow down?" It's the question many Italian SMEs are asking after the Digital Omnibus. The short answer is: no. The Digital Omnibus — Regulation (EU) 2026/1744, in force since 27 July 2026 — postponed only part of the obligations, those on high-risk systems, leaving everything already applicable today unchanged. Transparency included.

What the Digital Omnibus is

The Digital Omnibus is a package of targeted amendments to Regulation (EU) 2024/1689 (the EU AI Act). It was published in the Official Journal of the European Union on 24 July 2026 and entered into force on 27 July 2026, six days before the original 2 August 2026 deadline.

The key point is what it doesn't touch: it does not reopen the risk categories, does not change the penalty framework, does not alter the logic of the Regulation. It acts on a single front — the application dates for high-risk systems — and makes them unconditional (no longer tied to the availability of standards). The stated reason is practical: the European harmonised standards (CEN and CENELEC) and the conformity-assessment infrastructure would not have been ready for 2 August 2026.

The only postponed deadlines: high-risk

The deferral concerns exclusively the obligations on high-risk systems, on two distinct tracks:

Obligation Previous deadline New deadline
"Stand-alone" high-risk systems (Annex III) 2 August 2026 2 December 2027
High-risk systems embedded in regulated products (Annex I) 2 August 2027 2 August 2028

Annex III covers "stand-alone" high-risk uses — for example AI in recruitment, in access to credit or to essential services. Annex I concerns AI embedded in products already subject to conformity assessment (machinery, medical devices and the like). If your company builds or uses one of these systems, you have more time — but not less work.

What did NOT change (and applies right now)

Here lies the dangerous misconception. Most of the AI Act is already in force and the Digital Omnibus did not touch it:

  • 2 February 2025 — the bans on unacceptable-risk practices (Art. 5) and the AI literacy obligation (Art. 4) are operational.
  • 2 August 2025 — the obligations for general-purpose AI models (GPAI), governance and the penalty framework apply.
  • 2 August 2026 — the transparency obligations of Art. 50 apply: disclosing that a chatbot is an AI system, marking generated or manipulated content, flagging deepfakes. As of today it is already a live obligation.

The Digital Omnibus also added two new prohibited practices to Art. 5 — systems that generate non-consensual intimate imagery and child sexual abuse material — with a transitional period until 2 December 2026. In other words: the direction of the Regulation is not loosening; in some points it tightens.

The Regulation's penalties are also unchanged: up to €35 million or 7% of total worldwide annual turnover for the most serious infringements. Postponing the high-risk deadline does not move the obligations already applicable by a single day.

AI literacy: softened, not abolished

One nuance deserves attention. The Digital Omnibus eased the wording of the AI literacy obligation (Art. 4): providers and deployers must now support the development of AI literacy among their staff, rather than ensure a sufficient level of competence. The obligation remains in force since 2 February 2025 and remains substantive: whoever uses AI in a company must understand what they are using, with what limits and risks. In practice, a documented training programme is still the right answer.

And in Italy: Law 132/2025

The national framework does not change with the Omnibus. Law No. 132 of 23 September 2025 is the Italian law adapting the legal order to the AI Act: it assigns market surveillance to the ACN (National Cybersecurity Agency), with powers of inspection even without notice and sanctioning powers, and to AgID the notification and supervision functions over conformity-assessment bodies. It is a framework law: several operational aspects will be defined by implementing decrees. For an SME the message is concrete: in Italy, the enforcement counterparts are already identified.

What an SME should do now

The deferral is an opportunity, not a pause. The operational sequence does not change:

  1. Inventory — list every AI system in use, in-house or third-party.
  2. Risk classification — prohibited, high, limited or minimal. This is the step that tells you which deadlines actually apply to you.
  3. Transparency now — if you use chatbots, generate content, or publish AI-produced images/text, the Art. 50 obligations already apply today.
  4. Literacy — train whoever uses AI and document the training.
  5. High-risk: prepare, don't defer — if you have Annex III or Annex I systems, use the extra time for technical documentation, human oversight and data governance, not to shelve the topic.

Where to start

The Digital Omnibus makes it even more important to know where you stand: which of your systems are already subject to live obligations and which benefit from the deferral. An independent gap assessment turns confusion over dates into a plan with priorities, owners and real deadlines — and it saves you both from running on empty and from discovering too late an obligation that was already in force.