
Blog
The EU AI Act: What the Digital Omnibus Changed and What It Didn’t


Colleen Baehrend
Director, Legal AI Solutions
On 29 June 2026, the Digital Omnibus package was approved resulting in targeted amendments to the EU AI Act. Most significantly, the Omnibus postponed the compliance deadline for certain high-risk AI systems to December 2027 (the category relevant to legal, HR, and similar tools), softened the AI literacy obligation and introduced a grace period until December 2026 for watermarking AI-generated content.
The extension on high-risk AI, while welcome, is only part of the picture. Several obligations are already active, including transparency requirements for AI-generated content that took effect this August. Organisations using AI today should focus on using the additional time to build or strengthen the governance foundations that the AI Act in full force will require.
What’s in Force and What’s Coming
The AI Act has been rolling out in phases since it took effect on 1 August 2024. The timeline following adoption of the Digital Omnibus is as follows:
February 2025
Prohibited Practices and AI Literacy. Specific AI uses became prohibited under the AI Act including systems that use subliminal manipulation, social scoring or real-time remote biometric identification in publicly accessible spaces for law enforcement, subject to narrow exceptions.
The AI literacy obligation also took effect requiring organisations that have deployed AI to support AI literacy among staff working with those tools. The original requirement was to “ensure” a sufficient level of literacy. The Omnibus softened the requirement: now organisations are only required to “support the development of” it.
August 2025
General Purpose AI Model Obligations. Providers of AI models became subject to new obligations covering transparency, training data and copyright compliance. These sit primarily with the provider rather than the organisations deploying their tools.
August 2026
Transparency Obligations. Providers of AI systems that interact directly with people (such as chatbots, voice assistants, AI agents) must disclose that users are engaging with AI.
In addition, for AI systems released after 2 August 2026, AI-generated output must be watermarked in a machine-readable format such that it can be detected as artificially generated or manipulated.
AI-generated text or deepfakes published to inform the public on matters of public interest (such as legal or regulatory commentary, industry analysis, public alerts) must be labelled as AI-generated, unless a person has substantively reviewed it first.
December 2026
Watermarking Grace Period Ends. Providers whose AI systems were already on the market before 2 August 2026 have until 2 December 2026 to comply with the watermarking and machine-readable detection requirements.
December 2027
High-Risk AI Obligations. For high-risk AI systems used in areas like legal, HR, and other regulated business functions, the full compliance infrastructure will come into force, including risk management, data governance, technical documentation, audit logging, human oversight and conformity assessments. AI built into physical products, like medical devices, follows a separate, later deadline.
The Road to December 2027
The 16-month extension for high-risk AI obligations is genuine relief. However, the underlying obligations have not changed and the time is best used building the governance foundations that will be required in December 2027.
- Inventory every AI tool in use. Not just the ones IT has officially procured, but all of the tools that employees are using, including tools adopted informally outside of standard procurement process. The AI Act’s obligations apply to all actively used tools, not just approved ones.
- Classify each tool against the AI Act’s risk tiers. For tools touching legal interpretation, document analysis, or anything influencing advice to clients, the classification question deserves active attention. Annex III’s “administration of justice” category is broader than it might initially appear, and the risk tier a tool falls into determines the full set of obligations that will apply by December 2027.
- Build audit trail infrastructure. The AI Act requires automatic logging of high-risk system use: inputs, outputs, user actions and timestamps, retained for at least six months. Many general-purpose AI tools do not provide this kind of log by default. Building that infrastructure takes time and should not be left until 2027.
There is also a less obvious benefit. The audit requirements in effect are a forcing mechanism for the kind of AI usage visibility that most organisations currently lack. This infrastructure can help organisations understand how AI is being used, by whom and for what purpose, in ways that support both governance and client transparency.
- Ensure human oversight is meaningful. Effective oversight under the AI Act requires more than simply a human reviewing AI output. It requires that reviewers understand the system’s limitations, are able to interpret its outputs, can override them without friction and, critically, that workflow design actively counteracts automation bias. In practice, this means it should not be easier to accept AI output than to question it. That is a design requirement and it is worth considering whether current tools support it.
- Develop an AI literacy programme. The obligation to support AI literacy among those working with AI tools is already in force. In practice, this means ensuring employees understand what the AI tools they use actually do, where their outputs can be relied upon and where human judgement is needed. A documented programme covering the tools in use, the roles involved, and the specific risks in a legal context satisfies the regulatory requirement and provides the foundation for a firm-wide AI policy.
- Create a framework for evaluating AI tools. As the AI tech landscape grows, organisations will face a steady stream of new tools and vendors. A detailed evaluation framework covering classification, data residency, oversight capabilities and vendor compliance applied at the point of procurement ensures compliance is built in from the start.
For organisations outside the EU, the AI Act’s reach is broader than it might appear. It applies wherever an AI system’s output is used within the EU. This means non-EU organisations with EU clients or EU-facing tools may fall within its scope. Organisations in that position should seek advice on whether and how the AI Act applies to them.
The Digital Omnibus has given organisations a buffer zone, but not a reason to wait. The most valuable use of that additional time is to build the governance foundations the AI Act will ultimately require: visibility into the tools being used, consistent evaluation of new AI technologies, meaningful human oversight, appropriate auditability and an AI literacy programme that evolves alongside the technology.
For legal organisations in particular, those considerations should increasingly form part of the technology-selection process. The question is no longer simply whether an AI tool can perform a task well. Firms also need to understand where their information goes, how the system uses it, what controls and records are available, and whether the technology can support their own governance and regulatory obligations over time.
This post is for informational purposes only and does not constitute legal advice.
Discover why firms are turning to NetDocuments AI and the industry’s first the Legal Context Graph, which connects matters, documents, people and communications in real time.
Share
Check out these other resources
-

- Blog
Why Legal AI Adoption Stalls Before it Starts
Betsy Parker AI Adoption Expert, NetDocuments Moving from scattered experimentation to…
-

- Blog
AI in the Legal Industry: How will AI affect lawyers?
The introduction of no-code tools and AI-powered solutions has revolutionized the…
-

- Blog
Gartner Says Legal Tech Budgets Will Double. Here Is What Firms Should Spend It On.
Kathleen Hogan Legal Innovation Partner, NetDocuments Gartner’s latest prediction landed last…
-

- Blog
10 Signs That Your Law Firm Needs a DMS
How do you know when it’s time to level up your…


