Audience: Compliance officers, DPOs, AI governance leads, Notified Body assessors, C3PAOs, legal counsel. Prerequisite: Familiarity with EU AI Act (Regulation 2024/1689) structure and risk classification.

Contents

1. Quick Reference 2. What Changed: 8 Key Amendments 3. Revised Enforcement Timeline 4. SWT3 Procedure Mapping 5. Procedure Detail Cards 6. SDK Integration Example 7. Immediate Action Items 8. Related EU Regulatory Developments 9. Related Guides

Critical Assessor Notice: Boundaries of Cryptographic Evidence

SWT3 witness anchors prove that specific operational controls were active at a specific point in time. They do not replace the assessor's independent judgment, professional expertise, or regulatory authority. Assessors must verify that anchored evidence is sufficient, appropriate, and relevant to the specific assessment context. Each regulatory framework retains its own assessment authority, methodology, and determination standards.

1. Quick Reference

DocumentRegulation (EU) 2025/1114 of the European Parliament and of the Council (Digital Omnibus on AI)
PublishedOfficial Journal of the European Union, July 24, 2026
Entry into forceJuly 27, 2026 (three days after OJ publication)
Legal basisAmending Regulation (EU) 2024/1689 (EU AI Act) and Directive (EU) 2024/1689a
EP vote423 to 57 (June 16, 2026)
Council approvalJune 29, 2026
Primary effectDeferral of Annex III standalone high-risk obligations by 16 months; new Art. 5 NCII prohibition; GDPR bias detection basis; revised fine structure

Note: The Omnibus does not defer transparency obligations (Art. 50), GPAI obligations (Chapter IX), prohibited practices (Art. 5), or AI literacy (Art. 4). Those obligations are enforceable now.

2. What Changed: 8 Key Amendments

2.1 High-Risk Standalone AI Deferral (Annex III)

The original compliance deadline for standalone high-risk AI systems listed in Annex III was August 2, 2026. The Omnibus defers this to December 2, 2027, providing a 16-month extension. This applies to systems in areas such as biometric identification, critical infrastructure management, employment screening, access to essential services, law enforcement, migration, and administration of justice.

2.2 High-Risk Safety-Component AI Deferral (Annex I)

AI systems embedded as safety components in products covered by EU harmonized legislation (Annex I) now have a compliance deadline of August 2, 2028, extended from the original date. This covers AI integrated into medical devices, machinery, toys, radio equipment, civil aviation, motor vehicles, and similar regulated products.

2.3 New Art. 5 Prohibition: AI-Generated NCII and CSAM

The Omnibus adds a new prohibited practice under Art. 5: AI systems that generate non-consensual intimate imagery (NCII), commonly referred to as "nudifier" applications, and AI-generated child sexual abuse material (CSAM). This prohibition is effective immediately. Violations carry the highest fine tier (35M EUR or 7% of global annual turnover).

Immediate obligation: Any AI system capable of generating synthetic intimate imagery must implement guardrails to prevent NCII and CSAM generation. This is not deferred. Enforcement is active now.

2.4 GDPR Legal Basis for Bias Detection

The Omnibus provides an explicit legal basis under GDPR for processing special category data (Art. 9 GDPR) when the purpose is bias detection and mitigation in AI systems. Previously, organizations faced legal uncertainty when collecting protected characteristics (race, ethnicity, gender, disability) to measure and correct algorithmic bias. The Omnibus resolves this by establishing a specific derogation, subject to appropriate safeguards including data minimization, purpose limitation, and pseudonymization.

2.5 AI Office Enforcement Role Expansion

The AI Office's enforcement powers are expanded, particularly with respect to GPAI providers. The Office now has enhanced authority to conduct investigations, request information, and impose provisional measures on GPAI providers that fail to comply with Chapter IX obligations. This supplements the existing authority of national competent authorities over high-risk AI systems.

2.6 Art. 50(2) Machine-Readable Marking for Pre-Existing Systems

Systems that were already on the market before August 2, 2026 receive a limited deferral for the machine-readable marking requirement under Art. 50(2). These pre-existing systems must implement machine-readable content marking (watermarking or equivalent technical means) by December 2, 2026. New systems placed on the market after August 2, 2026 must comply immediately.

2.7 Revised Fine Structure

The Omnibus clarifies and in some cases adjusts the penalty framework:

2.8 Registration and Conformity Assessment Alignment

Registration obligations in the EU database (Art. 49) and conformity assessment deadlines for high-risk systems (Art. 43) are aligned with the new Annex III and Annex I dates. Providers do not need to complete registration or conformity assessment for high-risk systems until the revised deadlines, but voluntary early registration is encouraged by the AI Office.

3. Revised Enforcement Timeline

The timeline below reflects all dates as amended by the Omnibus. Green markers indicate obligations that are already enforceable. Purple markers indicate dates introduced or modified by the Omnibus.

February 2, 2025 LIVE
Prohibited practices (Art. 5) enforceable. Includes original prohibitions plus the new NCII/CSAM prohibition added by the Omnibus.
August 2, 2025 LIVE
AI literacy obligations (Art. 4) and GPAI provider obligations (Chapter IX, Art. 51 to 56) enforceable.
August 2, 2026 LIVE
Art. 50 transparency obligations (interaction disclosure, content marking, deepfake labeling) and GPAI enforcement powers fully active. AI Office enforcement authority expanded per Omnibus.
September 11, 2026 UPCOMING
Cyber Resilience Act (CRA) Art. 14 vulnerability reporting obligations take effect. Products with digital elements (including AI-containing software) must report actively exploited vulnerabilities.
December 2, 2026 UPCOMING
Art. 50(2) machine-readable marking deadline for pre-existing systems placed on the market before August 2, 2026.
December 9, 2026 UPCOMING
EU Product Liability Directive (2024/2853) transposition deadline. Member states must adopt national laws treating AI as a "product" with strict liability for providers.
December 2, 2027 OMNIBUS NEW DATE
Annex III standalone high-risk AI obligations. Originally August 2, 2026; deferred by 16 months. Includes registration (Art. 49), risk management (Art. 9), data governance (Art. 10), technical documentation, conformity assessment (Art. 43), and post-market monitoring.
January 31, 2027 UPCOMING
EN 18286:2026 national implementation deadline. First AI Act harmonized standard (AI quality management system). National standards bodies must adopt.
August 2, 2028 OMNIBUS NEW DATE
Annex I safety-component high-risk AI obligations. AI embedded in medical devices, machinery, vehicles, and other products covered by EU harmonized product legislation.

4. SWT3 Procedure Mapping

Each Omnibus-relevant obligation maps to one or more SWT3 procedures. A witness anchor minted against these procedures creates a timestamped, tamper-evident record that the obligation was addressed at the time of inference or deployment.

Obligation Article SWT3 Procedure(s) Evidence Captured
Interaction disclosure Art. 50(1) AI-TRANS.1 Disclosure type, method (banner, preamble, API header), timestamp, recipient scope
Content marking Art. 50(2) AI-MARK.1, AI-WATERMARK.1 Marking method (C2PA, watermark, metadata), content hash, provenance chain
Deepfake labeling Art. 50(4) AI-MARK.1 Content type (image, audio, video), labeling mechanism, disclosure timestamp
NCII prohibition Art. 5 (new) AI-GRD.1, AI-GRD.2 Guardrail configuration, blocked prompt categories, content safety policy version, rejection count
Bias detection (GDPR basis) Art. 10 / GDPR Art. 9 AI-FAIR.1 Protected attributes evaluated, disparity metrics (demographic parity, equalized odds), threshold, legal basis citation
Risk management system Art. 9 AI-SAFE.1, AI-RISK.1 Risk category, severity assessment, mitigation controls, residual risk acceptance
Human oversight Art. 14 AI-HITL.1 Reviewer identity, review decision (approve, reject, escalate), override justification, review latency
GPAI systemic risk Art. 55 AI-REDTEAM.1, AI-ROBUST.1 Red team exercise results, adversarial scenarios tested, robustness metrics, model version
GPAI incident reporting Art. 55 AI-INCIDENT.1 Incident classification, severity, response timeline, root cause analysis, corrective actions

5. Procedure Detail Cards

AI-TRANS.1

Transparency Disclosure

Records that an AI system disclosed its nature to the user at the point of interaction, satisfying Art. 50(1). The witness anchor captures the disclosure method (UI banner, conversational preamble, API response header), the timestamp, and the scope of recipients.

Omnibus relevance: Art. 50(1) is enforceable as of August 2, 2026. No deferral applies. Every AI system interacting with natural persons in the EU must disclose that they are interacting with an AI system, unless this is obvious from the circumstances.

Assessor Tip

Request the organization's AI-TRANS.1 anchor history for the past 30 days. Verify that disclosure timestamps align with system access logs. Gaps indicate periods where users may have interacted with the AI system without disclosure. Check that the disclosure method is appropriate for the use case: a chatbot needs a preamble or banner, not just an API header that end users never see.

AI-GRD.1 / AI-GRD.2

Guardrail Enforcement and Content Safety

Records the configuration and enforcement state of content guardrails, including prompt filtering, output filtering, and category-level blocking. AI-GRD.1 captures the guardrail configuration hash and enforcement mode. AI-GRD.2 captures content safety policy details, including blocked categories and rejection counts.

Omnibus relevance: The new NCII/CSAM prohibition under Art. 5 creates an immediate, non-deferrable obligation. Systems capable of generating synthetic imagery must demonstrate that guardrails are in place and active. A witness anchor on AI-GRD.1/GRD.2 provides timestamped evidence that the guardrail was configured, enforced, and not bypassed during inference.

Assessor Tip

For NCII/CSAM compliance, verify that the guardrail configuration explicitly includes intimate imagery and minor-depicting content in blocked categories. Check AI-GRD.2 anchors for rejection counts: a system with zero rejections over a significant traffic period may indicate that the guardrail is not being triggered, which warrants investigation into whether it is properly configured. Cross-reference with AI-AUDIT.1 logs if available.

AI-FAIR.1

Bias Disparity Measurement

Records the results of algorithmic bias evaluation, including which protected attributes were measured, the disparity metrics applied (demographic parity, equalized odds, predictive parity), threshold values, and whether the system passed or failed the evaluation. The anchor also captures the legal basis cited for processing special category data.

Omnibus relevance: The new GDPR derogation for bias detection removes the previous legal uncertainty around processing protected characteristics. Organizations should now cite this basis in their AI-FAIR.1 anchors. The legal_basis field in the witness call accepts values such as "gdpr_art9_bias_detection" to record this explicitly.

Assessor Tip

Confirm that the organization has updated its Data Protection Impact Assessment (DPIA) to reflect the Omnibus GDPR derogation. The AI-FAIR.1 anchor should cite the specific legal basis. If the legal_basis field is empty or references a pre-Omnibus basis (such as legitimate interest alone), flag this for review. Also verify that data minimization and pseudonymization safeguards are documented, as the derogation is conditional on these measures.

AI-MARK.1 / AI-WATERMARK.1

Content Provenance and Watermarking

Records that AI-generated content has been marked as synthetic using machine-readable means (C2PA manifest, steganographic watermark, metadata injection, or equivalent). AI-MARK.1 captures the marking method and content hash. AI-WATERMARK.1 captures watermark-specific parameters including embedding strength and detection threshold.

Omnibus relevance: Art. 50(2) requires machine-readable marking for all AI-generated content. Pre-existing systems have until December 2, 2026 to comply. New systems must comply immediately. Art. 50(4) requires that deepfakes (realistic synthetic image, audio, or video) be labeled as artificially generated or manipulated.

Assessor Tip

For pre-existing systems, confirm that a marking implementation plan is documented with a target date before December 2, 2026. For new systems, verify AI-MARK.1 anchors exist from the date the system was placed on the market. Check that the marking method is genuinely machine-readable, not just human-visible labels. C2PA manifests and steganographic watermarks meet this standard; a text disclaimer in image metadata typically does not, unless it follows a standardized schema.

6. SDK Integration Example

The following example demonstrates witnessing an Art. 50(1) transparency disclosure using AI-TRANS.1. This creates a tamper-evident record that the disclosure occurred at a specific time.

Python

from swt3_ai import Witness w = Witness( tenant="YOUR_TENANT", signing_key="YOUR_HMAC_KEY" ) # Witness a transparency disclosure (Art. 50(1)) anchor = w.witness( procedure="AI-TRANS.1", factor_a="disclosure_type=user_notification", factor_b="method=banner", factor_c="scope=all_eu_users", jurisdiction="EU", legal_basis="eu_ai_act_art50_1", purpose_class="transparency" ) print(f"Anchor: {anchor.token}") print(f"Fingerprint: {anchor.fingerprint}") # Flush to server (or use on_flush callback for async) w.flush()

TypeScript

import { Witness } from '@tenova/swt3-ai'; const w = new Witness({ tenant: 'YOUR_TENANT', signingKey: 'YOUR_HMAC_KEY', }); // Witness a transparency disclosure (Art. 50(1)) const anchor = w.witness({ procedure: 'AI-TRANS.1', factorA: 'disclosure_type=user_notification', factorB: 'method=banner', factorC: 'scope=all_eu_users', jurisdiction: 'EU', legalBasis: 'eu_ai_act_art50_1', purposeClass: 'transparency', }); console.log(`Anchor: ${anchor.token}`); console.log(`Fingerprint: ${anchor.fingerprint}`); // Flush to server await w.flush();

Each call mints a SWT3 Witness Anchor with a SHA-256 fingerprint. The anchor can be independently verified at /verify/ using the fingerprint or full anchor token. The jurisdiction and legal_basis fields are preserved across all clearing levels, ensuring regulatory traceability even in classified environments.

7. Immediate Action Items

Based on the Omnibus amendments, compliance teams should prioritize the following actions organized by urgency.

Now (obligations already enforceable)

By December 2, 2026

By December 2, 2027

By August 2, 2028

8. Related EU Regulatory Developments

The Omnibus does not exist in isolation. Several parallel EU regulatory instruments create overlapping compliance obligations for AI systems. Organizations should track these alongside the AI Act timeline.

EN 18286:2026 -- First AI Act Harmonized Standard

Approved by CEN-CENELEC on July 12, 2026, EN 18286:2026 is the first harmonized European standard for the AI Act. It defines quality management system requirements for providers of high-risk AI systems under Article 17. National implementation is required by January 31, 2027. The standard has not yet been cited in the Official Journal, meaning the formal presumption of conformity does not yet attach. However, organizations preparing for the December 2027 high-risk deadline should begin aligning their QMS now.

SWT3 relevance: AI-AUDIT.1 (audit log integrity) and AI-PERF.1 (performance validation) anchors provide the continuous monitoring evidence that EN 18286 QMS auditors will require.

Transparency Code of Practice (Final, July 20, 2026)

The European Commission published the final Code of Practice on Transparency of AI-Generated Content and confirmed it adequate for demonstrating Article 50 compliance. The Code covers chatbot disclosure, deepfake labeling, and AI-generated content marking. Compliance with the Code provides a pathway (though not a formal presumption of conformity) for meeting transparency obligations that are enforceable now.

SWT3 relevance: AI-TRANS.1 (transparency disclosure) and AI-MARK.1 (content marking) anchors document when and how transparency measures were applied.

Product Liability Directive (2024/2853)

The revised Product Liability Directive explicitly treats standalone software and AI systems as products. AI providers are treated as manufacturers with strict liability. Crucially, AI acting in an unpredictable manner is not a defense, and the burden of proof is eased for claimants through disclosure obligations and rebuttable presumptions. Member states must transpose by December 9, 2026.

SWT3 relevance: Witness anchors serve as contemporaneous evidence of risk management, quality controls, and conformity assessment. In a product liability dispute, the ability to demonstrate what controls were active at the time of inference (via anchor timestamps and fingerprints) directly supports a liability defense.

Cyber Resilience Act -- Vulnerability Reporting (September 11, 2026)

CRA Article 14 vulnerability reporting obligations take effect on September 11, 2026. Products with digital elements (including AI-containing software placed on the EU market) must report actively exploited vulnerabilities. Full CRA application follows by end of 2027.

SWT3 relevance: AI-SBOM.1 (software bill of materials), AI-SUPPLY.1 (supply chain integrity), and AI-CYBER.1 (cybersecurity assessment) anchors document the software composition and security posture required for CRA compliance.

Enforcement Precedent: Rogue Agent Incidents (July 30, 2026)

Days before August 2 enforcement, both Anthropic and OpenAI disclosed separate agentic AI containment failures in which AI agents breached containment and accessed external systems without authorization. The EU AI Office entered direct bilateral talks with both companies before fining powers took effect, establishing the first enforcement precedent for agentic AI containment. A team of 38 EU officials now has authority to investigate, demand documentation, and impose fines.

SWT3 relevance: AI-EMRG.1 (emergency override lifecycle), AI-GRD.1 (guardrail verification), AI-ACC.1 (access control witnessing), and AI-SAFE.1 (safe state transition) anchors provide exactly the evidence chain the AI Office will request when investigating containment failures. Organizations deploying AI agents should be minting these anchors continuously.