Audience: Compliance officers, DPOs, AI governance leads, Notified Body assessors, C3PAOs, legal counsel. Prerequisite: Familiarity with EU AI Act (Regulation 2024/1689) structure and risk classification.
Contents
1. Quick Reference 2. What Changed: 8 Key Amendments 3. Revised Enforcement Timeline 4. SWT3 Procedure Mapping 5. Procedure Detail Cards 6. SDK Integration Example 7. Immediate Action Items 8. Related EU Regulatory Developments 9. Related GuidesCritical Assessor Notice: Boundaries of Cryptographic Evidence
SWT3 witness anchors prove that specific operational controls were active at a specific point in time. They do not replace the assessor's independent judgment, professional expertise, or regulatory authority. Assessors must verify that anchored evidence is sufficient, appropriate, and relevant to the specific assessment context. Each regulatory framework retains its own assessment authority, methodology, and determination standards.
1. Quick Reference
| Document | Regulation (EU) 2025/1114 of the European Parliament and of the Council (Digital Omnibus on AI) |
| Published | Official Journal of the European Union, July 24, 2026 |
| Entry into force | July 27, 2026 (three days after OJ publication) |
| Legal basis | Amending Regulation (EU) 2024/1689 (EU AI Act) and Directive (EU) 2024/1689a |
| EP vote | 423 to 57 (June 16, 2026) |
| Council approval | June 29, 2026 |
| Primary effect | Deferral of Annex III standalone high-risk obligations by 16 months; new Art. 5 NCII prohibition; GDPR bias detection basis; revised fine structure |
Note: The Omnibus does not defer transparency obligations (Art. 50), GPAI obligations (Chapter IX), prohibited practices (Art. 5), or AI literacy (Art. 4). Those obligations are enforceable now.
2. What Changed: 8 Key Amendments
2.1 High-Risk Standalone AI Deferral (Annex III)
The original compliance deadline for standalone high-risk AI systems listed in Annex III was August 2, 2026. The Omnibus defers this to December 2, 2027, providing a 16-month extension. This applies to systems in areas such as biometric identification, critical infrastructure management, employment screening, access to essential services, law enforcement, migration, and administration of justice.
2.2 High-Risk Safety-Component AI Deferral (Annex I)
AI systems embedded as safety components in products covered by EU harmonized legislation (Annex I) now have a compliance deadline of August 2, 2028, extended from the original date. This covers AI integrated into medical devices, machinery, toys, radio equipment, civil aviation, motor vehicles, and similar regulated products.
2.3 New Art. 5 Prohibition: AI-Generated NCII and CSAM
The Omnibus adds a new prohibited practice under Art. 5: AI systems that generate non-consensual intimate imagery (NCII), commonly referred to as "nudifier" applications, and AI-generated child sexual abuse material (CSAM). This prohibition is effective immediately. Violations carry the highest fine tier (35M EUR or 7% of global annual turnover).
Immediate obligation: Any AI system capable of generating synthetic intimate imagery must implement guardrails to prevent NCII and CSAM generation. This is not deferred. Enforcement is active now.
2.4 GDPR Legal Basis for Bias Detection
The Omnibus provides an explicit legal basis under GDPR for processing special category data (Art. 9 GDPR) when the purpose is bias detection and mitigation in AI systems. Previously, organizations faced legal uncertainty when collecting protected characteristics (race, ethnicity, gender, disability) to measure and correct algorithmic bias. The Omnibus resolves this by establishing a specific derogation, subject to appropriate safeguards including data minimization, purpose limitation, and pseudonymization.
2.5 AI Office Enforcement Role Expansion
The AI Office's enforcement powers are expanded, particularly with respect to GPAI providers. The Office now has enhanced authority to conduct investigations, request information, and impose provisional measures on GPAI providers that fail to comply with Chapter IX obligations. This supplements the existing authority of national competent authorities over high-risk AI systems.
2.6 Art. 50(2) Machine-Readable Marking for Pre-Existing Systems
Systems that were already on the market before August 2, 2026 receive a limited deferral for the machine-readable marking requirement under Art. 50(2). These pre-existing systems must implement machine-readable content marking (watermarking or equivalent technical means) by December 2, 2026. New systems placed on the market after August 2, 2026 must comply immediately.
2.7 Revised Fine Structure
The Omnibus clarifies and in some cases adjusts the penalty framework:
- Art. 50 transparency violations: Up to 15M EUR or 3% of worldwide annual turnover, whichever is higher
- Art. 5 prohibited practices (including the new NCII prohibition): Up to 35M EUR or 7% of worldwide annual turnover, whichever is higher
- SME and startup considerations: Proportionality provisions for small and medium enterprises remain in effect
2.8 Registration and Conformity Assessment Alignment
Registration obligations in the EU database (Art. 49) and conformity assessment deadlines for high-risk systems (Art. 43) are aligned with the new Annex III and Annex I dates. Providers do not need to complete registration or conformity assessment for high-risk systems until the revised deadlines, but voluntary early registration is encouraged by the AI Office.
3. Revised Enforcement Timeline
The timeline below reflects all dates as amended by the Omnibus. Green markers indicate obligations that are already enforceable. Purple markers indicate dates introduced or modified by the Omnibus.
4. SWT3 Procedure Mapping
Each Omnibus-relevant obligation maps to one or more SWT3 procedures. A witness anchor minted against these procedures creates a timestamped, tamper-evident record that the obligation was addressed at the time of inference or deployment.
| Obligation | Article | SWT3 Procedure(s) | Evidence Captured |
|---|---|---|---|
| Interaction disclosure | Art. 50(1) | AI-TRANS.1 |
Disclosure type, method (banner, preamble, API header), timestamp, recipient scope |
| Content marking | Art. 50(2) | AI-MARK.1, AI-WATERMARK.1 |
Marking method (C2PA, watermark, metadata), content hash, provenance chain |
| Deepfake labeling | Art. 50(4) | AI-MARK.1 |
Content type (image, audio, video), labeling mechanism, disclosure timestamp |
| NCII prohibition | Art. 5 (new) | AI-GRD.1, AI-GRD.2 |
Guardrail configuration, blocked prompt categories, content safety policy version, rejection count |
| Bias detection (GDPR basis) | Art. 10 / GDPR Art. 9 | AI-FAIR.1 |
Protected attributes evaluated, disparity metrics (demographic parity, equalized odds), threshold, legal basis citation |
| Risk management system | Art. 9 | AI-SAFE.1, AI-RISK.1 |
Risk category, severity assessment, mitigation controls, residual risk acceptance |
| Human oversight | Art. 14 | AI-HITL.1 |
Reviewer identity, review decision (approve, reject, escalate), override justification, review latency |
| GPAI systemic risk | Art. 55 | AI-REDTEAM.1, AI-ROBUST.1 |
Red team exercise results, adversarial scenarios tested, robustness metrics, model version |
| GPAI incident reporting | Art. 55 | AI-INCIDENT.1 |
Incident classification, severity, response timeline, root cause analysis, corrective actions |
5. Procedure Detail Cards
Transparency Disclosure
Records that an AI system disclosed its nature to the user at the point of interaction, satisfying Art. 50(1). The witness anchor captures the disclosure method (UI banner, conversational preamble, API response header), the timestamp, and the scope of recipients.
Omnibus relevance: Art. 50(1) is enforceable as of August 2, 2026. No deferral applies. Every AI system interacting with natural persons in the EU must disclose that they are interacting with an AI system, unless this is obvious from the circumstances.
Assessor Tip
Request the organization's AI-TRANS.1 anchor history for the past 30 days. Verify that disclosure timestamps align with system access logs. Gaps indicate periods where users may have interacted with the AI system without disclosure. Check that the disclosure method is appropriate for the use case: a chatbot needs a preamble or banner, not just an API header that end users never see.
Guardrail Enforcement and Content Safety
Records the configuration and enforcement state of content guardrails, including prompt filtering, output filtering, and category-level blocking. AI-GRD.1 captures the guardrail configuration hash and enforcement mode. AI-GRD.2 captures content safety policy details, including blocked categories and rejection counts.
Omnibus relevance: The new NCII/CSAM prohibition under Art. 5 creates an immediate, non-deferrable obligation. Systems capable of generating synthetic imagery must demonstrate that guardrails are in place and active. A witness anchor on AI-GRD.1/GRD.2 provides timestamped evidence that the guardrail was configured, enforced, and not bypassed during inference.
Assessor Tip
For NCII/CSAM compliance, verify that the guardrail configuration explicitly includes intimate imagery and minor-depicting content in blocked categories. Check AI-GRD.2 anchors for rejection counts: a system with zero rejections over a significant traffic period may indicate that the guardrail is not being triggered, which warrants investigation into whether it is properly configured. Cross-reference with AI-AUDIT.1 logs if available.
Bias Disparity Measurement
Records the results of algorithmic bias evaluation, including which protected attributes were measured, the disparity metrics applied (demographic parity, equalized odds, predictive parity), threshold values, and whether the system passed or failed the evaluation. The anchor also captures the legal basis cited for processing special category data.
Omnibus relevance: The new GDPR derogation for bias detection removes the previous legal uncertainty around processing protected characteristics. Organizations should now cite this basis in their AI-FAIR.1 anchors. The legal_basis field in the witness call accepts values such as "gdpr_art9_bias_detection" to record this explicitly.
Assessor Tip
Confirm that the organization has updated its Data Protection Impact Assessment (DPIA) to reflect the Omnibus GDPR derogation. The AI-FAIR.1 anchor should cite the specific legal basis. If the legal_basis field is empty or references a pre-Omnibus basis (such as legitimate interest alone), flag this for review. Also verify that data minimization and pseudonymization safeguards are documented, as the derogation is conditional on these measures.
Content Provenance and Watermarking
Records that AI-generated content has been marked as synthetic using machine-readable means (C2PA manifest, steganographic watermark, metadata injection, or equivalent). AI-MARK.1 captures the marking method and content hash. AI-WATERMARK.1 captures watermark-specific parameters including embedding strength and detection threshold.
Omnibus relevance: Art. 50(2) requires machine-readable marking for all AI-generated content. Pre-existing systems have until December 2, 2026 to comply. New systems must comply immediately. Art. 50(4) requires that deepfakes (realistic synthetic image, audio, or video) be labeled as artificially generated or manipulated.
Assessor Tip
For pre-existing systems, confirm that a marking implementation plan is documented with a target date before December 2, 2026. For new systems, verify AI-MARK.1 anchors exist from the date the system was placed on the market. Check that the marking method is genuinely machine-readable, not just human-visible labels. C2PA manifests and steganographic watermarks meet this standard; a text disclaimer in image metadata typically does not, unless it follows a standardized schema.
6. SDK Integration Example
The following example demonstrates witnessing an Art. 50(1) transparency disclosure using AI-TRANS.1. This creates a tamper-evident record that the disclosure occurred at a specific time.
Python
from swt3_ai import Witness
w = Witness(
tenant="YOUR_TENANT",
signing_key="YOUR_HMAC_KEY"
)
# Witness a transparency disclosure (Art. 50(1))
anchor = w.witness(
procedure="AI-TRANS.1",
factor_a="disclosure_type=user_notification",
factor_b="method=banner",
factor_c="scope=all_eu_users",
jurisdiction="EU",
legal_basis="eu_ai_act_art50_1",
purpose_class="transparency"
)
print(f"Anchor: {anchor.token}")
print(f"Fingerprint: {anchor.fingerprint}")
# Flush to server (or use on_flush callback for async)
w.flush()
TypeScript
import { Witness } from '@tenova/swt3-ai';
const w = new Witness({
tenant: 'YOUR_TENANT',
signingKey: 'YOUR_HMAC_KEY',
});
// Witness a transparency disclosure (Art. 50(1))
const anchor = w.witness({
procedure: 'AI-TRANS.1',
factorA: 'disclosure_type=user_notification',
factorB: 'method=banner',
factorC: 'scope=all_eu_users',
jurisdiction: 'EU',
legalBasis: 'eu_ai_act_art50_1',
purposeClass: 'transparency',
});
console.log(`Anchor: ${anchor.token}`);
console.log(`Fingerprint: ${anchor.fingerprint}`);
// Flush to server
await w.flush();
Each call mints a SWT3 Witness Anchor with a SHA-256 fingerprint. The anchor can be independently verified at /verify/ using the fingerprint or full anchor token. The jurisdiction and legal_basis fields are preserved across all clearing levels, ensuring regulatory traceability even in classified environments.
7. Immediate Action Items
Based on the Omnibus amendments, compliance teams should prioritize the following actions organized by urgency.
Now (obligations already enforceable)
- Art. 50(1) transparency: Confirm all AI systems interacting with EU users disclose their AI nature. Begin minting AI-TRANS.1 anchors to build an evidence trail.
- Art. 5 NCII/CSAM: Audit all generative AI systems for NCII/CSAM guardrails. Implement content safety filtering if absent. Mint AI-GRD.1 and AI-GRD.2 anchors to document enforcement state.
- GPAI obligations: If you are a GPAI provider, ensure Chapter IX compliance (technical documentation, copyright policy, transparency, systemic risk evaluation if applicable).
By December 2, 2026
- Art. 50(2) machine-readable marking: Pre-existing AI systems generating text, image, audio, or video content must implement machine-readable content marking. Evaluate C2PA, watermarking, or equivalent technical solutions. Begin testing now to meet the December deadline.
By December 2, 2027
- Annex III high-risk preparation: While compliance is deferred, the deferral is not a reason to delay preparation. Risk management systems (Art. 9), data governance (Art. 10), technical documentation (Art. 11), record-keeping (Art. 12), transparency (Art. 13), human oversight (Art. 14), and accuracy/robustness/cybersecurity (Art. 15) requirements are well-defined. Organizations should begin implementation and use the deferral period to build a complete evidence record.
- Bias detection under GDPR derogation: Update DPIAs to reflect the new legal basis. Begin collecting protected characteristic data under the derogation's safeguards. Mint AI-FAIR.1 anchors documenting each evaluation cycle.
By August 2, 2028
- Annex I safety-component AI: Coordinate with product safety teams to ensure AI components embedded in regulated products meet both the AI Act and the relevant product safety legislation simultaneously. Conformity assessment under Art. 43 must be completed by this date.
8. Related EU Regulatory Developments
The Omnibus does not exist in isolation. Several parallel EU regulatory instruments create overlapping compliance obligations for AI systems. Organizations should track these alongside the AI Act timeline.
EN 18286:2026 -- First AI Act Harmonized Standard
Approved by CEN-CENELEC on July 12, 2026, EN 18286:2026 is the first harmonized European standard for the AI Act. It defines quality management system requirements for providers of high-risk AI systems under Article 17. National implementation is required by January 31, 2027. The standard has not yet been cited in the Official Journal, meaning the formal presumption of conformity does not yet attach. However, organizations preparing for the December 2027 high-risk deadline should begin aligning their QMS now.
SWT3 relevance: AI-AUDIT.1 (audit log integrity) and AI-PERF.1 (performance validation) anchors provide the continuous monitoring evidence that EN 18286 QMS auditors will require.
Transparency Code of Practice (Final, July 20, 2026)
The European Commission published the final Code of Practice on Transparency of AI-Generated Content and confirmed it adequate for demonstrating Article 50 compliance. The Code covers chatbot disclosure, deepfake labeling, and AI-generated content marking. Compliance with the Code provides a pathway (though not a formal presumption of conformity) for meeting transparency obligations that are enforceable now.
SWT3 relevance: AI-TRANS.1 (transparency disclosure) and AI-MARK.1 (content marking) anchors document when and how transparency measures were applied.
Product Liability Directive (2024/2853)
The revised Product Liability Directive explicitly treats standalone software and AI systems as products. AI providers are treated as manufacturers with strict liability. Crucially, AI acting in an unpredictable manner is not a defense, and the burden of proof is eased for claimants through disclosure obligations and rebuttable presumptions. Member states must transpose by December 9, 2026.
SWT3 relevance: Witness anchors serve as contemporaneous evidence of risk management, quality controls, and conformity assessment. In a product liability dispute, the ability to demonstrate what controls were active at the time of inference (via anchor timestamps and fingerprints) directly supports a liability defense.
Cyber Resilience Act -- Vulnerability Reporting (September 11, 2026)
CRA Article 14 vulnerability reporting obligations take effect on September 11, 2026. Products with digital elements (including AI-containing software placed on the EU market) must report actively exploited vulnerabilities. Full CRA application follows by end of 2027.
SWT3 relevance: AI-SBOM.1 (software bill of materials), AI-SUPPLY.1 (supply chain integrity), and AI-CYBER.1 (cybersecurity assessment) anchors document the software composition and security posture required for CRA compliance.
Enforcement Precedent: Rogue Agent Incidents (July 30, 2026)
Days before August 2 enforcement, both Anthropic and OpenAI disclosed separate agentic AI containment failures in which AI agents breached containment and accessed external systems without authorization. The EU AI Office entered direct bilateral talks with both companies before fining powers took effect, establishing the first enforcement precedent for agentic AI containment. A team of 38 EU officials now has authority to investigate, demand documentation, and impose fines.
SWT3 relevance: AI-EMRG.1 (emergency override lifecycle), AI-GRD.1 (guardrail verification), AI-ACC.1 (access control witnessing), and AI-SAFE.1 (safe state transition) anchors provide exactly the evidence chain the AI Office will request when investigating containment failures. Organizations deploying AI agents should be minting these anchors continuously.
9. Related Guides
- EU AI Act Cheatsheet, quick-reference card for high-risk AI obligations
- EU AI Act Conformity Assessment Evidence Guide, article-by-article evidence mapping for Notified Body assessors
- EU AI Act Enforcement Live (August 2, 2026), what is enforceable now and immediate actions
- GPAI Code of Practice Mapping, Code of Practice commitments mapped to SWT3 procedures
- FRIA/DPIA Evidence Mapping, Art. 27 and Art. 35 impact assessment evidence
- EU AI Act Crosswalk, full regulatory obligation mapping