Not sure where to start? Answer 3 questions and get a tailored compliance action plan.
What applies to me? →AI Omnibus Regulation (EU AI Act Extension)
Issued by
European Commission
The AI Omnibus is a binding EU regulation that entered into force on 27 July 2026, extending the oversight powers of the AI Office established under the EU AI Act. It applies to providers and deployers of general-purpose AI systems, as well as AI systems embedded within large online platforms and search engines. Covered organizations must maintain robust model governance, conduct provider due diligence, and respond to compliance evidence requests from the AI Office.
Applies To
Overview
The AI Omnibus builds on the foundational EU AI Act framework by granting the AI Office expanded supervisory authority over a defined class of AI systems, including general-purpose AI models and those integrated into very large online platforms and search engines subject to the Digital Services Act. The regulation introduces structured obligations around risk classification, model documentation, and escalation procedures for responding to AI Office inquiries. Enforcement is conducted through the AI Office, which gains direct investigative and remediation powers over in-scope providers, supplementing the national market surveillance authorities already operating under the EU AI Act. Organizations operating at scale in the EU market, particularly those deploying or integrating GPAI models, must establish clear internal governance pathways to handle regulatory contact and produce compliance evidence on demand. The regulation reflects the Commission's intent to close oversight gaps identified during the initial rollout of the EU AI Act, specifically around systemic risks posed by widely deployed foundation models. Non-compliance may trigger investigative proceedings consistent with the enforcement mechanisms outlined in the broader EU AI Act.
Key Requirements
- •Maintain up-to-date model governance documentation for all in-scope general-purpose AI systems and embedded AI components.
- •Conduct and record provider due diligence assessments before deploying or integrating third-party GPAI models into products or services.
- •Classify AI systems according to risk tiers consistent with EU AI Act criteria, with particular attention to GPAI models exhibiting systemic risk indicators.
- •Establish internal escalation procedures capable of responding to AI Office inquiries and producing compliance evidence within required timeframes.
- •Ensure AI systems embedded in large online platforms and search engines are subject to dedicated risk review processes aligned with Digital Services Act obligations.
- •Cooperate with AI Office investigations, including providing access to technical documentation, model cards, and risk assessments upon request.
What Your Organization Must Do
- →Audit all AI systems currently in deployment to determine whether any qualify as general-purpose AI or are embedded in platforms subject to the Digital Services Act, and flag them for enhanced governance treatment.
- →Appoint or designate a responsible internal contact point specifically for AI Office correspondence and evidence requests.
- →Update vendor and provider contracts to require conformity documentation, model cards, and risk classification evidence for any GPAI model procured or integrated.
- →Build and test an internal escalation workflow that can route AI Office inquiries to legal, compliance, and technical teams within a defined response window.
- →Review existing EU AI Act risk classifications to confirm alignment with the extended scope introduced by the AI Omnibus, correcting any gaps in GPAI coverage.
- →Schedule recurring governance reviews for embedded AI components in platform products to capture changes in model version, capability, or risk profile.
Playbook Guidance
Step-by-step implementation guidance for compliance teams.
Frequently Asked Questions
- Does the AI Omnibus apply to companies that deploy third-party GPAI models rather than building their own?
- Yes, the AI Omnibus covers both providers and deployers of general-purpose AI systems. Organizations integrating third-party GPAI models into their products must conduct provider due diligence assessments and maintain supporting documentation, regardless of whether they developed the underlying model.
- How does the AI Omnibus interact with existing EU AI Act obligations for organizations already in compliance?
- The AI Omnibus extends the supervisory authority of the AI Office and closes oversight gaps around GPAI models, so existing EU AI Act compliance programs will need updating. Organizations should audit their current risk classifications and governance documentation to confirm coverage of GPAI systems and embedded AI components.
- Which platforms are brought into scope through the AI Omnibus connection to the Digital Services Act?
- AI systems embedded within very large online platforms and search engines already subject to the Digital Services Act fall under the AI Omnibus. These embedded components require dedicated risk review processes aligned with both regulatory frameworks.
- What triggers an AI Office investigation under the AI Omnibus, and how quickly must organizations respond?
- The AI Office gains direct investigative and remediation powers under the regulation, and can initiate proceedings based on systemic risk indicators or compliance concerns. Organizations must establish internal escalation workflows capable of routing inquiries to legal, compliance, and technical teams within required response timeframes.
- What documentation must organizations produce when the AI Office requests compliance evidence?
- Organizations must be prepared to provide technical documentation, model cards, risk assessments, and records of provider due diligence. Governance documentation for all in-scope GPAI systems should be kept current so it can be produced on demand without delay.
- What are the penalties for non-compliance with the AI Omnibus?
- The regulation does not introduce a standalone penalty regime but instead triggers investigative proceedings consistent with the enforcement mechanisms of the broader EU AI Act. Non-compliant organizations face the same consequences applicable under that framework, which includes remediation orders and potential fines scaled to global turnover.
