On 27 July 2026, Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force, turning months of political negotiation into binding EU law. For most Flemish and Belgian SMEs, the change is real relief: high-risk obligations move to December 2027, technical documentation gets a simplified SME template, and the AI-literacy duty softens from a guarantee to a best-effort obligation. Here is what actually changed, what did not, and what a 20-50 FTE business should do before the end of 2026.
What is the Digital Omnibus on AI, and why is it law now?
The Digital Omnibus on AI is not a proposal anymore. It was published in the Official Journal on 24 July 2026 and, under its own Article 4, entered into force three days later. It amends three existing regulations at once: the AI Act itself (Regulation (EU) 2024/1689), the civil aviation regulation, and the machinery regulation, which matters if you build or integrate AI into physical equipment. Earlier reporting on this site, including our July piece on the AI Act for Flemish SMEs, covered the *political* agreement reached on 7 May and the Council's final green light on 29 June. Both were negotiating milestones, not law. What changed on 27 July is that the deferrals, the new SME provisions and the new enforcement powers stopped being proposals and became text you can be held to.
One distinction the European Commission's own announcement is careful about, and that most commentary blurs: entry into force and applicability are not the same thing. The amendments became part of the AI Act's text on 27 July. Whether a specific amended provision is already enforceable still depends on which chapter it sits in and the original AI Act timetable for that chapter.
Which AI Act deadlines actually moved?
This is the part vendors and consultancies got loudest about ahead of 2 August 2026, and the part most likely to be wrong in a sales pitch. Here is the corrected picture, based on the Council's press release and the regulation text:
- Deferred to 2 December 2027: the requirements for stand-alone high-risk AI systems under Annex III (Chapter III, Sections 1-3): things like AI used in recruitment, credit scoring or biometric identification.
- Deferred to 2 August 2028: high-risk AI embedded in regulated products, such as machinery, toys or lifts (Annex I).
- Not deferred: applies from 2 August 2026 as originally planned: the Article 50 transparency duties (chatbot and AI-content disclosure), the AI Office's supervisory and enforcement powers, and the general date of application of the AI Act.
- Unchanged and already in force: the prohibited-practices regime since 2 February 2025, and the general-purpose AI (GPAI) provider obligations since 2 August 2025.
- New, and applying from 2 December 2026, not immediately: two new prohibitions on AI-generated non-consensual intimate imagery and CSAM-adjacent material, plus a grace period for machine-readable marking of synthetic content already on the market before 2 August 2026 shortened from the six months first proposed to four, with the new deadline set at 2 December 2026.
- Pushed back a year: the deadline for each member state to have at least one national AI regulatory sandbox operational, now 2 August 2027, alongside a new EU-level sandbox run by the AI Office with priority access for SMEs and start-ups.
The headline claim worth correcting: the AI Act itself was not postponed. Only the sections on high-risk system requirements, operator obligations and notified-body designation were. Everything else, including the parts most SMEs actually touch, arrived on schedule.
What changes for a 20-50 FTE business specifically?
The regulation writes two new size categories into Article 3 of the AI Act: the existing SME definition, and a new small mid-cap (SMC) category covering companies with fewer than 750 employees and under €150 million turnover. Several reliefs that used to apply only to micro-enterprises now extend to SMEs and, in part, to SMCs:
- A simplified technical documentation template for high-risk systems (Article 11(1)), which notified bodies are required to accept rather than demand a bespoke format.
- A quality management system proportionate to company size (Article 17(2)), instead of the same procedural weight expected of a 5,000-person enterprise.

- Priority access to AI regulatory sandboxes (Article 57(3a)), both national and the new EU-level one.
- Capped administrative fines for small mid-caps (Article 99(6a)): the lower of the percentage-of-turnover figure or the fixed amount, not both.
The honest caveat: nearly all of this only bites if your business is a provider placing a high-risk AI system on the market: building or substantially modifying it, not just using someone else's tool. A Flemish accountancy, garage or wholesaler running Microsoft Copilot, a chatbot, or an n8n workflow calling an external API is almost always a deployer, not a provider. For that majority of SMEs, these documentation reliefs are not the part of the Omnibus that matters most day to day: the literacy and transparency duties below are.
Is the AI-literacy duty easier to meet now?
Article 4 of the AI Act was rewritten in full. The old text required providers and deployers to "ensure" a sufficient level of AI literacy among staff. The new text requires them to take measures to support the development of AI literacy, a deliberately softer standard, and adds a sentence that removes any doubt: this obligation does not require guaranteeing any individual's specific level of literacy. Because Article 4 sits in Chapter I of the AI Act, which has applied since 2 February 2025, the softened wording took effect immediately on 27 July 2026, with no deferral.
Our practitioner read: this does not mean skipping staff training. A documented AI-use policy, which tools staff may use, on what data, who signs off on outputs, remains the least expensive way to satisfy both this duty and the overlapping GDPR expectations around automated processing. What the rewrite removes is the theoretical exposure of a single undertrained employee triggering a compliance failure. That is a real reduction in liability, not a paperwork gesture.
Who enforces this in Belgium, and does it change anything for you?
Belgium designated the BIPT (Belgian Institute for Postal Services and Telecommunications) as its lead market surveillance authority, with FOD Economie coordinating. Belgium missed its own original August 2025 institutional deadline, and enforcement capacity has continued to build through 2026 rather than arriving fully formed.
The Omnibus adds a second layer above BIPT: from 2 August 2026, the AI Office gains exclusive supervisory and enforcement competence, but only over two narrow categories: AI systems built on a general-purpose AI model by the same provider (or the same corporate group), and systems that are, or are embedded in, a very large online platform or search engine under the DSA. Those powers are modelled on antitrust enforcement: on-site inspections, the ability to seal premises during an inspection, and periodic penalty payments of up to 5% of average daily turnover.
For a typical Flemish SME buying and deploying third-party AI tools, not training its own foundation model, not operating a very large platform: BIPT remains the relevant authority, and BIPT's own capacity is still catching up. The practical read: enforcement risk today is lower than the urgency implied by pre-August compliance-consultancy marketing. The duties that are simple, low-cost and genuinely due now are the Article 50 transparency labelling and a basic AI-literacy policy, not a full high-risk audit most SMEs do not need until December 2027 at the earliest.
What should a Flemish SME actually do before year-end?
A short, honest checklist, in priority order:
- If you run a chatbot or generate synthetic content for customers, confirm users are told they are interacting with AI. Article 50 transparency was not deferred and applies now.
- If any AI tool you provide generates synthetic audio, image, video or text and was already on the market before 2 August 2026, machine-readable content marking is due 2 December 2026, a four-month window, not the six originally planned.
- Write a one-page internal AI-use policy: approved tools, permitted data, who signs off. It costs an afternoon and satisfies Article 4's "measures to support literacy" standard.
- If your product could generate non-consensual intimate imagery, document your technical safeguards now: the new prohibition takes effect 2 December 2026, and "reasonably foreseeable and reproducible without significant modification" is the test that will be applied to your design choices.
- Do not pay for a full "high-risk AI Act audit" unless you are actually placing an Annex III system on the market. For most SMEs that clock has not started; it starts 2 December 2027.
- Use the kmo-portefeuille training subsidy, still funding AI training at 30% (small) or 20% (medium), capped at €7,500 per year, to formalise the literacy measures Article 4 now expects, rather than treating them as an afterthought.
For a structured, article-by-article view of where your organisation stands, see our AI Act checklist for SMEs; where AI Act obligations intersect with subsidy planning, our AI subsidy overview for SMEs links the two together. If your systems edge toward the high-risk categories, our earlier breakdown of the high-risk deadline walks through the classification test in more depth.
The overall shift the Digital Omnibus makes is not simplification in the sense of "less regulation": it adds two new prohibitions, a new legal basis for processing sensitive data for bias correction, and a genuinely new enforcement apparatus at EU level. What it simplifies is the part that fell hardest on smaller companies: documentation format, proportionality of process, and the literacy standard. Knowing which category your obligations fall into, and which deadline actually applies to you: is now worth more than a blanket compliance retainer.
If your obligations point to building something rather than writing a policy, AI consultancy for Flemish SMEs shows how we scope it at fixed prices.
Our AI Act Check (€950 fixed) gives you your risk classification, obligations and a concrete to-do list within one week — including what you can safely ignore.
See the AI Act Check →