The AI Act Omnibus Becomes the Legitimacy Test
Donal Casey and Liane Colonna's June 2026 preprint treats the EU Digital Omnibus on AI as more than technical housekeeping. It asks what happens to a rights-based law's legitimacy when political urgency and implementation gaps drive amendment before its core high-risk rules apply.
The question is now concrete. The proposal examined by the paper became Regulation (EU) 2026/1744 and entered into force on July 27, 2026. Legal validity answers whether the amendment is law; the legitimacy test asks whether its process, reasons, trade-offs, institutional capacity, and protection of affected people remain publicly defensible.
The Law Meets Its Update Loop
The paper is The Digital Omnibus on AI, Legislative Legitimacy and the Dynamics of AI Regulation, arXiv:2606.15662v1 [cs.CY], by Donal Casey and Liane Colonna. It was submitted on June 14, 2026, two days before Parliament's final vote and more than a month before publication of the enacted regulation. Its legal object is therefore the Commission proposal, COM(2025) 836, and the accelerated legislative process around it—not the final law as later published.
The timing is the paper's point. Regulation (EU) 2024/1689, the AI Act, entered into force on August 1, 2024 and uses a staggered application schedule. The Commission proposed amendments on November 19, 2025 while harmonised standards, guidance, supervisory capacity, conformity-assessment capacity, and compliance practices were still being assembled. A law designed to create planning certainty was itself placed into a rapid change process before several central duties applied.
The phrase AI Act Omnibus should be used narrowly. It refers to legislative procedure 2025/0359(COD), which began as COM(2025) 836 and became Regulation (EU) 2026/1744. The final regulation amends the AI Act, the civil-aviation regulation, and the machinery regulation. The broader Digital Omnibus proposal, COM(2025) 837, concerning data, data protection, ePrivacy, cybersecurity, and platform rules is a separate legislative file and has its own status.
This makes the paper a useful companion to the site's pages on the EU AI Act, AI governance, and AI change management. Its fresh question is legitimacy under regulatory churn: how a law retains authority when the institution is revising the rules, building the implementation machinery, and asking regulated actors and affected people to plan at the same time.
Current Context
As of August 12, 2026, the legislative status is settled. The Commission proposed COM(2025) 836 on November 19, 2025; Council and Parliament negotiators reached a provisional agreement on May 7, 2026; Parliament approved the text on June 16 by 423 votes to 57, with 174 abstentions; and the Council gave its final approval on June 29. The act was signed on July 8, published in the Official Journal on July 24, and entered into force on July 27 as Regulation (EU) 2026/1744.
Entry into force and application are not synonyms. The AI Act's general application date passed on August 2, 2026. Article 50 transparency duties now apply, subject to a narrow transition until December 2, 2026 for the Article 50(2) marking duty of generative systems placed on the market before August 2. The Commission's enforcement powers for general-purpose AI model obligations also became applicable on August 2.
The final Omnibus fixes later dates for the core high-risk classification, requirements, and operator-duty provisions in Chapter III, Sections 1–3, except Article 6(5): December 2, 2027 for systems classified under Article 6(2) and Annex III, and August 2, 2028 for systems classified under Article 6(1) and Annex I. Those are now enacted dates, not a proposal tied to a future Commission finding about support tools. The new prohibitions concerning specified non-consensual intimate or sexually explicit material and child sexual abuse material apply from December 2, 2026. National AI regulatory sandboxes must be operational by August 2, 2027.
Delay does not create a law-free interval. The AI Act provisions already in application remain in force, and the Act expressly preserves applicable EU data-protection, consumer-protection, product-safety, and more protective worker rules. Organizations still need to identify which law, actor role, use case, and date govern a system; "the high-risk rules were delayed" is not a general exemption from safety, rights, documentation, contract, or sectoral duties.
Legitimacy Is Not Legal Validity
Casey and Colonna analyze the Omnibus through Peter Wahlgren's framework of five rationalities. Political rationality concerns the policy objectives and support that law is meant to mobilize. Legal rationality concerns rule-of-law qualities such as procedure, stability, predictability, and rights. Cultural rationality concerns whether law is intelligible in its social setting and resonates with the expectations of those affected. Operational rationality concerns resources, procedures, supervision, and practical enforceability. Internal rationality concerns coherence, clarity, consistency, and logical fit within the legal system.
The authors' central interpretive claim is that the Omnibus responds to one legitimacy dilemma and creates another. It addresses doubts about whether the AI Act can be implemented in a fast-moving technical and geopolitical environment, but does so by prioritizing political and operational rationalities over legal and cultural ones. Their conclusion that the reform sits near the margins of the legitimacy sphere is a scholarly judgment, not a court ruling.
Four questions should therefore remain separate:
- Legal validity: was the rule enacted by the competent institutions and is it in force?
- Legislative legitimacy: were the reasons, process, trade-offs, participation, and institutional design publicly defensible?
- Compliance: does a named actor satisfy the provisions applicable to a named system and use on a named date?
- Safety and rights protection: are risks actually controlled, monitored, contestable, and remediable in operation?
A valid regulation can remain contested; a legitimate process does not guarantee compliance; and compliance with one regulation does not establish that a deployment is safe, fair, necessary, or lawful under every other applicable regime. This is why the affected person's perspective cannot be reduced to whether a vendor found the rule easy to implement.
Three Races
The paper identifies three dynamics pushing the EU toward revision. The race for AI regulation is the competition to define rules, institutions, and global expectations. The authors argue that speed helped produce a complex legal system before all of its supporting standards, guidance, and oversight mechanisms were ready.
The race for AI dominance is economic and geopolitical. After the AI Act's adoption, pressure intensified around whether Europe could compete with the United States and China in investment, infrastructure, development, and deployment. In the paper's account, competitiveness moved from one policy objective among several toward a justification for reopening the law.
The race for regulatory connection is the pacing problem: law must remain meaningfully connected not only to changing technology but also to changing uses, institutions, interests, and social values. Connection is not the same as matching industry speed. Sometimes legal stability is the condition that lets authorities, firms, workers, and the public build expectations and demand evidence.
From Proposal to Final Law
The paper groups the Commission proposal into four families: linking some dates to implementation support; simplifying documentation, registration, and AI-literacy rules; centralizing specified supervision in the AI Office; and expanding sandboxes while clarifying overlap with other EU legislation. That taxonomy remains useful, but the final regulation is not identical to the proposal the paper analyzed.
The enacted text makes several material choices:
- Fixed high-risk dates. It replaces the proposal's availability-triggered timing mechanism with December 2, 2027 and August 2, 2028 dates for the two high-risk routes.
- A revised but retained AI-literacy duty. Providers and deployers must take measures to support development of AI literacy among staff and others using systems on their behalf, while the text says they need not guarantee a specific individual's level. Commission and Member State support supplements that organizational duty.
- Registration retained, disclosure narrowed. The Commission proposal would have removed registration for an Annex III system that its provider classifies as non-high-risk under Article 6(3). The EDPB and EDPS opposed that change. The final act keeps Article 49(2) registration but deletes two Annex VIII fields: the short grounds for the non-high-risk conclusion and the Member States where the system is available.
- Bias processing broadened with conditions. New Article 4a permits exceptional processing of special-category personal data when strictly necessary for bias detection and correction. It requires necessity, reuse limits, privacy and security measures, documented access, no third-party transfer or access, deletion, and a recorded explanation. Paragraph 2 expressly says the extension to other systems does not itself create a duty to conduct bias detection and correction.
- Supervision and experimentation changed. The act expands specified AI Office powers, permits an EU-level sandbox for systems within its supervision, requires data-protection-authority involvement where relevant, extends some SME treatment to small mid-cap companies, and broadens routes for real-world testing.
- New prohibitions and sectoral changes. It adds the December 2026 prohibitions for specified intimate-content and child-sexual-abuse-material practices, revises treatment of machinery and other product regimes, and amends the Machinery Regulation as well as the AI Act and civil-aviation rules.
This legislative delta is part of the legitimacy evidence. Consultation and negotiation did not merely ratify the Commission draft; some contested duties were preserved or reframed, while other accountability information and high-risk timelines were reduced or deferred. A serious assessment compares proposal, negotiated text, final act, and implementation rather than treating "the Omnibus" as one unchanging object.
Legitimacy Is Not Only Operability
The paper does not claim that every amendment is illegitimate. It argues more narrowly that purposive reconnection to institutional capacity and technical reality can fall near the margins of legislative legitimacy when competitiveness and burden reduction crowd out rights, participation, stability, and legal coherence. The final law partly changes the object of that critique, but not the question.
That warning travels beyond Europe. AI governance will be revised while institutions are still building standards, guidance, expertise, and enforcement practice. Regulated actors will seek certainty; affected people will seek protection and remedy; regulators will face resource limits. "Simplification" names an objective, not who gains, who waits, or where risk moves.
The crucial question is not "is the rule simple?" It is "simple for whom, at whose risk, and with what loss of enforceable memory?"
That is also a safety question. Deferring Chapter III's core high-risk sections can give organizations time to use stable standards and guidance. It also postpones the AI Act duties in those sections concerning risk management, data governance, technical documentation, logging, information for deployers, human oversight, accuracy, robustness, cybersecurity, and operator responsibilities. The public-interest question is whether the interval comes with bridge controls and enforceable oversight under other law, or whether deployment continues while preparation is mistaken for protection.
Failure Modes
Status laundering. A company, consultant, or agency treats a proposal, political agreement, press release, voluntary code, guideline, or draft standard as if it were the binding rule. The inverse failure is just as serious: treating a future application date as if the enacted duty did not exist or require preparation.
Application-date flattening. "The AI Act applies" and "the high-risk rules were delayed" are both too broad. Different chapters, articles, system categories, legacy provisions, actor roles, and enforcement powers follow different dates. A compliance claim without an article and date is not auditable.
Simplification asymmetry. Administrative burden is measured for providers while burdens shifted to workers, students, patients, migrants, consumers, journalists, public servants, supervisory bodies, and complaint systems remain invisible. Cost reduction is not a complete impact assessment.
Deadline deferral without bridge controls. Missing standards helped justify delay, but a later date does not manage risks already present. Inventory, classification, documented risk assessment, testing, logging, incident response, meaningful human review, and procurement controls should not wait merely because one legal section does.
Centralisation without capacity or appeal. Reinforcing the AI Office can reduce fragmentation for systems within its competence. Authority without staffing, technical access, published procedures, coordination with independent data-protection authorities, complaint handling, and review paths can instead create a larger bottleneck.
Registration without reasons. The final act preserves registration for self-assessed non-high-risk Annex III systems, but removes the short grounds field from the registration record. The underlying assessment must still be documented and available to national authorities on request. Governance weakens if the public can see the conclusion but not enough reasoning to contest it.
Scope drift by sectoral handoff. Moving machinery and other product-embedded AI toward sectoral safety routes may reduce duplicate assessment. It can also make AI-specific risks harder to see if sectoral authorities, notified bodies, or public records cannot connect model behavior to product-safety evidence.
Governance Standard
Any AI-law simplification package should publish a legitimacy ledger: a versioned record of what is delayed, narrowed, transferred, clarified, preserved, or strengthened; the evidence and policy objective for each change; who receives administrative relief; which affected groups assume additional risk or procedural burden; and which rights baseline remains applicable.
The ledger should contain six linked records:
- Status and duty map: CELEX or ELI identifier, legal force, article, actor, system category, original text, proposal, negotiated change, final text, application date, transition, and responsible authority.
- Evidence map: implementation problem, consultation record, impact evidence, standards or guidance gap, competing evidence, assumptions, and unresolved uncertainty.
- Distributional map: benefits and burdens for providers, deployers, regulators, workers, consumers, children, migrants, disabled people, and other affected groups rather than one aggregate compliance-cost estimate.
- Safety bridge: controls that operate before delayed duties apply—inventory and classification, testing, impact and risk assessment, logs, human-oversight design, incident and complaint routes, procurement conditions, monitoring, rollback, and an accountable owner.
- Capacity map: staffing, expertise, powers, coordination, resources, and appeal routes for the AI Office, national competent and market-surveillance authorities, data-protection authorities, notified bodies, and sandboxes.
- Public-memory map: what is registered, withheld, redacted, corrected, retained, searchable, machine-readable, and contestable, with a changelog linking every update to the operative legal version.
Regulators and institutions should treat the amendment as a change-control event. Standards mappings, conformity routes, procurement clauses, impact-assessment templates, system inventories, training, incident procedures, public notices, and evidence-retention schedules all need revalidation. A changed deadline should produce a named bridge-control owner and review cadence, not a blank space in the assurance case.
For vendors and deployers, "AI Act compliant" is too broad to audit. A defensible claim names the organization and actor role, exact system and version, intended use, jurisdiction, applicable article, application date, conformity route, evidence retained, exceptions relied on, other applicable law, reviewer, and claim expiry. See the site's Claim Hygiene Protocol, governance-document revalidation, and compliance calendar.
The Spiralist rule is this: legislative simplification is legitimate only when the reduction in paperwork does not become a reduction in evidence, remedy, or responsibility.
Source Discipline
This page treats Casey and Colonna's work as a 20-page, single-version arXiv preprint and a legal-governance argument. It does not empirically measure public acceptance, implementation costs, safety outcomes, regulatory capacity, or the distribution of views among affected groups. Because it predates the final vote and Official Journal text, it is evidence about the proposal and a legitimacy framework, not the current wording of EU law.
EU sources have different authority. Regulation (EU) 2024/1689 is the original AI Act; Regulation (EU) 2026/1744 is the amending act now in force. COM(2025) 836, its staff working document, the EDPB-EDPS opinion, negotiation texts, and institutional press releases explain history and positions but do not override the Official Journal text. Commission guidelines and the AI Act Service Desk assist interpretation and implementation; they are not amendments. Where a consolidated display or explainer lags, read the two regulations together.
Dates are part of the legal claim. Proposal, political agreement, institutional approval, signature, publication, entry into force, and application are separate events. So are August 2, 2026 for Article 50 and specified enforcement powers; December 2, 2026 for the narrow marking transition and new prohibitions; December 2, 2027 for Annex III high-risk sections; and August 2, 2028 for Annex I high-risk sections.
The final-text comparison also matters. The EDPB and EDPS criticized the proposal's planned deletion of registration for self-assessed non-high-risk systems and asked that provider/deployer responsibility for AI literacy remain. The final act preserved both in revised form. That does not prove the whole process legitimate or resolve every rights concern; it shows why proposal criticism, enacted text, and later enforcement should be evaluated as different evidence.
This is a sourced governance analysis, not legal advice. A real compliance decision should use the authentic language version, current amendments, sectoral and national law, authoritative guidance, and qualified counsel for the specific system and actor.
Related Pages
- EU AI Act
- AI Governance
- AI Regulatory Sandboxes
- AI Audits and Third-Party Assurance
- AI Post-Market Monitoring
- AI System Inventory
- AI Change Management
- Human Oversight of AI Systems
- Notice and Appeal
- Transparency and Public Registers
- Compliance Calendar
- The AI Audit Becomes the Compliance Interface
- The Regulatory Sandbox Becomes the Exception Machine
- The AI Register Becomes Public Memory
- The Governance Document Becomes a Revalidation Problem
Sources
- Donal Casey and Liane Colonna, The Digital Omnibus on AI, Legislative Legitimacy and the Dynamics of AI Regulation, arXiv:2606.15662v1 [cs.CY], submitted June 14, 2026; PDF; reviewed August 12, 2026.
- EUR-Lex, Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026, Official Journal publication July 24, 2026, entry into force July 27, 2026; reviewed August 12, 2026. This is the authoritative final Omnibus text used for amendment language and dates.
- EUR-Lex, Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence, the original AI Act baseline; reviewed August 12, 2026.
- European Commission, AI Omnibus enters into force, July 27, 2026, and AI Act Service Desk, Frequently Asked Questions, current implementation and enforcement timeline; reviewed August 12, 2026.
- European Commission, Guidelines on transparency obligations for providers and deployers of AI systems, July 20, 2026, and Article 50 questions and answers; reviewed August 12, 2026.
- European Commission, COM(2025) 836 final and SWD(2025) 836 final, proposal and supporting analysis, November 19, 2025; reviewed August 12, 2026.
- European Data Protection Board and European Data Protection Supervisor, Joint Opinion 1/2026 on the Digital Omnibus on AI proposal, adopted January 20, 2026; reviewed August 12, 2026.
- European Parliament, AI Act: EP approves simplification measures and "nudifier" app ban, June 16, 2026, and Council of the European Union, final approval, June 29, 2026; reviewed August 12, 2026.