August 10, 2026, (Inside AI) — The European Union's regulatory landscape for physical AI just underwent a structural shift. On 27 July 2026, the "Digital Omnibus on AI" entered into force, fundamentally recalibrating how AI-enabled products like robots, autonomous machines, and industrial equipment gain market access. The new regulation, officially Regulation (EU) 2026/1744, amends the AI Act, the Aviation Regulation, and the Machinery Regulation to streamline overlapping requirements.
The AI Omnibus is not merely a delay in enforcement. It is a strategic realignment that shifts physical AI governance toward sector-specific product laws, with the AI Act adding targeted safeguards through delegated acts rather than creating parallel regimes. This matters because an AI error in a physical system can cause real-world harm: unwanted movements, unsafe interactions, and dangerous decisions. The EU's focus remains on risks to physical safety, cybersecurity, privacy, and fundamental rights.
High-Risk Deadlines Stretch to 2028
The Omnibus introduces a staggered compliance timetable that gives industry breathing room. High-risk AI obligations are now differentiated: stand-alone systems under Annex III of the AI Act, such as those used in biometrics or critical infrastructure, must comply by 2 December 2027. For product-embedded high-risk AI, where the system is a safety component like an AI-based collision avoidance function, the deadline extends to 2 August 2028.
Near-term deadlines remain. Providers must implement content transparency measures, including watermarking under Article 50, by 2 December 2026. On the same date, a new ban takes effect on AI systems that generate or manipulate non-consensual intimate content or child sexual abuse material. These dates are firm.
Benedikt Rohrssen, a partner at Taylor Wessing who advises global manufacturers on EU AI compliance, notes the structural change: "For robotics and other 'physical AI,' the AI Omnibus is more than a delay; it is a structural realignment. Physical AI, starting with industrial AI embedded in machinery, will increasingly be governed by sectoral product law, with the AI Act adding targeted safeguards by delegated and implementing acts rather than creating duplicate regimes."
Cybersecurity Overlaps Remain Intact
The AI Omnibus does not displace the Cyber Resilience Act (CRA). Manufacturers must align AI Act readiness with the CRA's cybersecurity requirements and timeline. Incident and vulnerability reporting under the CRA begins on 11 September 2026, with full application on 11 December 2027. The European Union Agency for Cybersecurity's Single Reporting Platform will be operational by that date, requiring notifications within strict 24-hour, 72-hour, and 14-day windows.
For industrial AI, the path forward involves sectoral conformity assessment. The Machinery Regulation will incorporate AI-related health and safety requirements through future delegated acts, as outlined in Recital 47 of the Omnibus. This means one cybersecurity-by-design stack, sectoral conformity as the default for physical AI, and a staged plan to meet high-risk, transparency, and governance duties on the new timeline.
Rohrssen emphasizes the need for early action: "In short, design should be made now for convergence of the different laws: one cybersecurity-by-design stack, sectoral conformity as the default for physical AI, and a staged plan to meet high-risk, transparency and governance duties on the new timeline."
Two governance elements stand out. Providers must register AI systems in the EU database for high-risk AI even if they consider them out of scope, strengthening supervisory oversight. Additionally, the "strict necessity" standard is reinstated for processing special categories of personal data to detect and correct bias, tightening the use of sensitive data in model governance.
The AI Office's competence is refined for supervising general-purpose AI models where both the model and downstream system come from the same entity. National authorities retain oversight in areas like law enforcement and financial services. The Omnibus also mandates Commission guidance to help operators comply with high-risk requirements while minimizing administrative burden.
Products other than machinery, such as toys and lifts listed in Annex I of the AI Act, remain fully subject to both product-specific laws and the AI Act. The compromise text is still subject to formal adoption later in 2026, but the direction is clear: the EU is moving toward a sector-led compliance model that regulates AI risks embedded in different products without lowering the bar on safety and rights.