The Digital Omnibus is now in force: what actually changes for SMB AI governance
The Digital Omnibus officially entered into force in late July 2026. What was conditional is now settled, and a new prohibition appears. Here is what it means for French SMBs and mid-sized companies.
Since July 27, 2026, the Digital Omnibus is no longer a hypothesis. Published in the Official Journal of the European Union on July 24, it entered into force three days later. What had been presented since June as "pending Council adoption" is now settled. For business owners who followed this file with reasonable skepticism, the question is no longer whether the delay will happen, but what to do now that it has been confirmed.
The text sets two deadlines. Stand-alone high-risk systems under Annex III, recruitment, credit, biometrics, education, shift from August 2, 2026 to December 2, 2027. For AI embedded in already-regulated products, medical devices, industrial machinery, the delay runs to August 2028. What does not change deserves equal attention: Article 50 transparency obligations, in force since August 2, 2026, general-purpose model rules since August 2025, Article 5 prohibitions since February 2025. The text also introduces something that is not a relaxation at all, an explicit ban on tools generating non-consensual intimate images and child sexual abuse material.
In my recent conversations with business owners, I see the same misreading as after the June vote. Many treat this confirmation as good news that justifies waiting. It is the opposite. The real compliance risk for a French SMB in 2026 does not come from Annex III, it comes from the CNIL. Recruitment is explicitly listed among its priority control themes for 2026, with a stated focus on AI-driven CV screening and candidate scoring. That oversight has no moratorium and no extra delay. It applies now to any company processing candidate data, regardless of size.
This is a pattern I see across most of my engagements. Companies follow European news closely, and miss that their immediate risk is national. An SMB using an ATS with automated scoring, an HR chatbot, or an AI screening tool must document that processing today, independent of any delay to 2027 or 2028. Confusing the European timeline with CNIL priorities is a costly mistake.
This is exactly what the Inventory step of the IMPACT method covers, in week one: mapping actual AI usage, HR included, before asking which text applies on which deadline. A company that does not know what tools its HR teams actually use can neither answer a CNIL inspection nor prepare for 2027. The Digital Omnibus clarified a European calendar. It clarified nothing about what happens inside the tools your teams are using this week. A five-business-day diagnostic shows you exactly where you stand.
Let's take action
Ready to structure your AI transformation?
Free 30-minute diagnostic to identify your top priorities and estimate concrete ROI for your organization.
Book my free diagnostic →Related articles

The Digital Omnibus is now in force: what actually changes for SMB AI governance
The Digital Omnibus officially entered into force in late July 2026. What was conditional is now settled, and a new prohibition appears. Here is what it means for French SMBs and mid-sized companies.

Are your AI vendor contracts compliant? What the DPA needs to cover
The absence of a data processing agreement with an AI publisher puts a company in immediate GDPR violation. A governance risk rarely checked, unlike the tool's usage itself.

The three real barriers to AI in SMBs, and they aren't the ones you think
Data misuse, lack of skills, difficulty finding a use case: Bpifrance Le Lab ranks the real barriers to AI adoption. Team resistance only comes after.