ctipilot.ch

EU AI Act Digital Omnibus (Regulation (EU) 2026/1744)

policy · policy:eu-ai-act-digital-omnibus-2026

Regulation amending the EU AI Act (Regulation (EU) 2024/1689), published in the Official Journal on 24 July 2026 and in force from 27 July 2026, which rewrites Article 113's application-date carve-outs: high-risk obligations for standalone Annex III systems move to 2 December 2027, Annex I embedded high-risk systems to 2 August 2028, and Articles 102-110 apply from 27 July 2026 (EUR-Lex, 2026-07-24).

Aliases: Digital Omnibus on AI, AI Act Omnibus, Regulation (EU) 2026/1744

Coverage timeline
2
first 2026-08-09 → last 2026-08-09
Peak priority
notable
2 notable
Sources cited
9
8 hosts
Sections touched
2
weekly-looking-ahead, weekly-policy
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
0
no mapped behavior yet

Story timeline

  1. 2026-08-092026-W32 looking ahead — items already in motion: a NIS2 law in force in six days, a PAM appliance whose full exploitation detail is due in September, five products that will never be patched, and a federal ISMS deadline five months out
    weekly-looking-aheadW32 outlook — the 15 August Dutch NIS2 clock, WALLIX details due in September, and five products with no fix coming
  2. 2026-08-09The EU AI Act's high-risk obligations were deferred six days before they would have applied — Regulation (EU) 2026/1744 moves Annex III systems to 2 December 2027 and Annex I to 2 August 2028, and the Commission's own Article 113 page still shows the old text
    weekly-policyThe AI Act's 2 August 2026 headline date survived; almost every obligation behind it was carved out and deferred

Where this entity is cited

  • weekly-policy1
  • weekly-looking-ahead1

Source distribution

  • eur-lex.europa.eu2 (22%)
  • ai-act-service-desk.ec.europa.eu1 (11%)
  • cert.ssi.gouv.fr1 (11%)
  • fedlex.admin.ch1 (11%)
  • labs.infoguard.ch1 (11%)
  • ncsc.gov.uk1 (11%)
  • rijksoverheid.nl1 (11%)
  • wallix.com1 (11%)

explore in graph

Entries about EU AI Act Digital Omnibus (Regulation (EU) 2026/1744) (2)

2026-08-09 · view entry permalink →

NOTABLENATOA1

2026-W32 looking ahead — items already in motion: a NIS2 law in force in six days, a PAM appliance whose full exploitation detail is due in September, five products that will never be patched, and a federal ISMS deadline five months out

Items already in motion at the close of ISO week 2026-W32, each with a source and a date. None of these is a prediction.

Dated obligations.

  • 15 August 2026 — the Netherlands' Cyberbeveiligingswet enters into force, together with the companion critical-entities resilience law, imposing registration, duty-of-care, incident-notification and board-accountability duties on more than 8,000 organisations across 18 sectors, with registration in NCSC-NL's national entity register mandatory from that date (Rijksoverheid, 2026-07-07). Relevant to anyone with Dutch entities, suppliers or public-sector counterparts, whose notification behaviour changes on that date.
  • 11 September 2026 — the Cyber Resilience Act's reporting obligations begin, ahead of the regulation's principal obligations in December 2027. 13 September 2026 — ENISA's consultation on the draft EU Managed Security Services certification scheme closes, two days later; providers delivering services under the EU Cybersecurity Reserve would need that certification within two years of the scheme's entry into force, which makes it a procurement gate rather than a voluntary mark. Both were established in prior weekly coverage and neither date has moved.
  • 2 December 2026 — two new prohibited AI practices apply under the AI Act as amended, and 2 December 2027 / 2 August 2028 are the new application dates for high-risk obligations under Annex III and Annex I respectively, following Regulation (EU) 2026/1744 (EUR-Lex, 2026-07-24). Any readiness plan written against 2 August 2026 for Annex III systems is now diarised to the wrong date.
  • 1 January 2027 — Swiss federal administrative units must have built their ISMS. The Informationssicherheitsverordnung requires the administrative units under its Article 2(1)(c) to build their information-security management system within three years of the ordinance's entry into force, and the ordinance entered into force on 1 January 2024 (Fedlex, ISV SR 128.1). Roughly five months remain. The addressee is the federal administration itself; commentary that presents this as a general critical-infrastructure obligation is reading it more broadly than the text supports.

Disclosure and exploitation clocks.

  • September 2026 — full technical details of the WALLIX Bastion authentication bypass are due. WALLIX states that the reporting researchers intend to publish the complete write-up of the CVSS 4.0 base 10.0 flaw that gives an unauthenticated caller full product-administrator control of the appliance — its credential vault and session recordings included — in September (WALLIX, 2026-07-20). Bastion 12.3.7 and 12.4.1 and later are patched, per the CERT-FR advisory that relayed the bulletin (CERT-FR, 2026-08-06). This is a dated window for remediating quietly, not a current threat.
  • Cl0p's Windchill and FlexPLM listings have still not begun. Research re-checked this week found no leak-site listing for that campaign, leaving affected organisations in the interval between exfiltration and publication — the status a prior weekly recorded, unchanged.

Flaws with no fix coming. Five items from this week's coverage will not be resolved by waiting for a vendor, and each therefore converts into an architecture or lifecycle decision:

  • Tobit TeamDavid — 22 CVEs bounded at "Rollout 524" with no fixed release named, against roughly 12,000 internet-facing instances, and researchers reporting that both they and the coordinating national cyber security centre were left without a vendor response (InfoGuard Labs, 2026-08-07).
  • Flowise — three CVEs assigned days after the vendor announced it is winding down; self-hosted operators own the compensating controls.
  • Zbtlink routers (ENDLESSDOORS) — a factory-shipped root backdoor on twenty models, where the discloser's remediation is device replacement.
  • CPDLC over ATN-B1 — five flaws that are properties of the standard, with CISA recording the remediation category as none-available.
  • Check Point's end-of-support management trains — R80 through R81.10 are listed as affected by this week's unauthenticated management-authentication bypass with no fix on offer.

In development, no date. NCSC UK confirms it is working with international partners on a reference architecture for forensic observability in network appliances, intended to give vendors something concrete to build to (NCSC UK, 2026-07-29). It is not published, and no publication date is stated. Separately, the Metabase SQL-injection zero-day exploited this week still has no CVE identifier assigned, so it will not reach any process that waits for one.

Builds on: 2026-08-09/wallix-bastion-rest-api-unauth-admin-cvss10 · 2026-08-09/teamdavid-tobit-22-cves-unauth-mailbox-takeover-dach · 2026-08-08/flowise-three-cves-vendor-sunset-no-fix-coming · 2026-08-06/endlessdoors-zbtlink-router-factory-shipped-root-backdoor · 2026-08-08/cpdlc-atn-b1-five-protocol-flaws-no-mitigation-available · 2026-08-05/check-point-cve-2026-18574-management-auth-bypass · 2026-08-09/metabase-unauth-sqli-zeroday-exploited-framework-tally

outlook09 Aug 23:45Zmulti-sourceOpen finding ↗

2026-08-09 · view entry permalink →

NOTABLENATOA1

The EU AI Act's high-risk obligations were deferred six days before they would have applied — Regulation (EU) 2026/1744 moves Annex III systems to 2 December 2027 and Annex I to 2 August 2028, and the Commission's own Article 113 page still shows the old text

A compliance function that read the AI Act's headline application date and diarised 2 August 2026 got the right date and the wrong obligation set. Regulation (EU) 2026/1744, the "Digital Omnibus on AI," was published in the Official Journal on 24 July 2026 and entered into force on 27 July, six days before that date, and it rewrites the carve-outs that determine what actually applies.

The amendment is surgical, which is the reason it is easy to misread. It replaces points inside Article 113's third paragraph and leaves the second paragraph — "It shall apply from 2 August 2026" (EUR-Lex, 2024-07-12) — untouched as text, so a reader who stops at that sentence concludes nothing has changed. What changed sits one paragraph below: the amended point now provides that "Chapter III, Sections 1, 2, and 3, with the exception of Article 6(5), shall apply from: (i) 2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III; and (ii) 2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I" (EUR-Lex, 2026-07-24). Annex III is the standalone high-risk list that covers biometrics, employment, education, migration, access to essential services and law enforcement — categories that map directly onto public-administration systems — and those obligations were due on the general date. They are now sixteen months further out. Annex I high-risk systems, embedded as safety components in products already regulated under EU product law, move from 2 August 2027 to 2 August 2028.

Two smaller changes run the other way. A new point provides that "Articles 102 to 110 shall apply from 27 July 2026" — the AI Act's own amendments to sectoral product legislation take effect immediately on the omnibus's entry into force rather than waiting for a later date. And the omnibus inserts two further prohibited practices into Article 5(1), which apply from 2 December 2026 rather than from the February 2025 date that governs the rest of Chapters I and II.

The secondary observation is operationally relevant to anyone whose compliance tooling reads from official web sources rather than from the Official Journal. The European Commission's own AI Act Service Desk explorer page for Article 113, fetched during this run, still displayed the pre-amendment text with the old three-point structure (European Commission — AI Act Service Desk, checked 2026-08-09), sixteen days after the Commission published the amending regulation. No consolidated version reflecting the amendment was available on EUR-Lex either. Any downstream tool, tracker or advisory that sources its dates from those pages is currently serving a timetable that the law has superseded.

Chapter III, Sections 1, 2, and 3, with the exception of Article 6(5), shall apply from: (i) 2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III; and (ii) 2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I;

Articles 102 to 110 shall apply from 27 July 2026.

It shall apply from 2 August 2026.

EUR-Lex / Official Journal of the European Union 2026-07-24
policy09 Aug 23:45Zmulti-sourceOpen finding ↗