Back to blog

EU AI Act Omnibus 2026: What Changed and What Fashion Teams Must Do

· Last updated:
EU AI Act Omnibus 2026: What Changed and What Fashion Teams Must Do

The EU AI Omnibus entered into force in August 2026, amending the original AI Act in ways that directly affect every fashion brand and retailer operating recommendation engines, personalisation layers, and generative design tools in the European market. The amendments did not soften the regulation; they restructured its timeline and clarified deployer obligations in ways that make earlier assumptions about your compliance roadmap unreliable. If your team built a plan around the original schedule, you need to revisit it now.

Key takeaways

  • The EU AI Omnibus entered into force in August 2026, amending the AI Act's compliance calendar and deployer obligations.
  • Deadline shifts represent additional preparation time, not a reprieve — enforcement expectations remain in place.
  • Fashion recommendation, personalisation, and generative design systems each carry distinct obligations depending on how they are classified under the risk framework.
  • Deployers — not only providers — carry affirmative duties under the amended text, including transparency measures visible to end users.
  • Brands operating at scale, such as those running multi-market e-commerce platforms, face the most immediate compliance surface.

What is the EU AI Omnibus and why does it matter for fashion?

The EU AI Act established a risk-tiered framework for artificial intelligence systems placed on or put into service in the European Union. The Omnibus package — a legislative instrument amending several existing texts simultaneously — revised specific provisions of that framework, including the phased application dates that governed when different categories of obligation would become enforceable.

Fashion's exposure to the AI Act is broader than many compliance teams initially assumed. As Taylor Wessing's sector analysis notes, the industry deploys AI across a wide range of functions: product recommendation, dynamic pricing, demand forecasting, virtual try-on, and increasingly, generative tools for design and content. Each of these sits somewhere in the Act's risk classification structure, and the Omnibus changes where some of them land on the enforcement timeline.

The Act's architecture distinguishes between providers (those who develop or place an AI system on the market) and deployers (those who use an AI system in a professional context). A fashion retailer using a third-party recommendation engine is a deployer. A brand that has built its own personalisation model and makes it available to wholesale partners is a provider. Many large fashion groups are both simultaneously, and the Omnibus sharpened the obligations that apply to each role.

Which deadlines moved and which did not?

The original AI Act established a phased application schedule: prohibited practices provisions applied first, followed by obligations for general-purpose AI models, then high-risk system requirements, and finally the full framework. The Omnibus adjusted several of these dates.

For employers and technology providers, the Morgan Lewis analysis published in June 2026 makes the operative point clearly: the deadline changes represent additional preparation time, not a reprieve. Supervisory authorities are expected to apply the substantive standards from the original schedule even where formal enforcement dates have shifted. The practical consequence for fashion teams is that a delayed deadline does not delay the work.

The provisions that did not move are the ones most immediately relevant to fashion AI:

  • Prohibited practices — including certain forms of subliminal manipulation and real-time biometric categorisation — remain on the original timeline.
  • Transparency obligations for certain AI-generated content — including AI-generated product imagery and synthetic model photography — were not deferred.
  • General-purpose AI model obligations — which affect brands that fine-tune or deploy foundation models for design generation or customer-facing chat — remain substantively in place.

What shifted, in several cases, were the formal notification and registration deadlines for high-risk systems that are not yet subject to active supervisory review. Your legal counsel should map your specific system inventory against the amended schedule rather than relying on a summary.

How does the risk classification apply to fashion AI systems?

The AI Act's risk tiers — unacceptable, high, limited, and minimal — determine which obligations attach to a given system. Fashion AI deployments span all four, and the classification is not always intuitive.

Recommendation and personalisation engines

Product recommendation systems — the engines that surface items based on browsing history, purchase behaviour, or inferred preferences — are generally classified as limited-risk or minimal-risk under the Act's current framework, provided they do not exploit psychological vulnerabilities or target protected characteristics in ways that cause harm. The primary obligation at this tier is transparency: users must be informed, in a clear and accessible way, that they are interacting with or being influenced by an AI system.

This sounds straightforward, but implementation is not. A disclosure buried in a privacy policy does not satisfy the transparency requirement. The obligation is contextual — it must be legible at the point of interaction. For a fashion e-commerce platform, that means visible, plain-language disclosure at the point where personalised results are surfaced, not only in the terms of service.

Zalando, which operates one of Europe's largest fashion platforms across 29 markets and is actively building agentic AI capabilities, sits squarely in the deployer category for the recommendation and personalisation systems it runs. At its scale — connecting tens of millions of active customers with thousands of brands — the transparency and documentation obligations are non-trivial to implement consistently across markets and interfaces.

Generative design and content systems

Generative AI tools used to produce product imagery, design concepts, or marketing content carry specific labelling obligations under the Act. AI-generated synthetic content — including photorealistic product shots that do not depict real garments or real people — must be marked as machine-generated in a way that is detectable by users and, in some cases, machine-readable.

For fashion brands that have moved toward AI-generated lookbooks, virtual model photography, or AI-assisted print and pattern design, this obligation is immediate. The White & Case alert published in August 2026 confirms that the EU AI Omnibus entered into force that month, and the synthetic content provisions were part of the framework it amended rather than deferred.

HR and workforce AI

The Omnibus amendments also touched provisions relevant to AI used in workforce contexts — scheduling, performance monitoring, and candidate screening. Fashion's large retail and logistics workforce makes this relevant for groups operating at scale. The Morgan Lewis analysis specifically addresses this dimension: the message for HR technology deployers is that the additional preparation time is not a reprieve.

What must a fashion AI team action before the next enforcement date?

The following steps reflect the obligations most clearly in force under the amended framework. They are not a substitute for legal advice specific to your system inventory and jurisdictional exposure.

1. Audit your AI system inventory

Map every AI system your organisation deploys — including those provided by third parties — against the Act's risk tiers. The classification determines which obligations apply and on what timeline. Pay particular attention to systems that interact directly with consumers, systems that process biometric or sensitive personal data, and systems used in employment decisions.

2. Confirm your role: provider, deployer, or both

The Omnibus clarified that deployers carry affirmative obligations, not merely pass-through responsibilities from providers. If you are using a third-party recommendation engine, you are responsible for ensuring the transparency disclosures it generates meet the Act's requirements. If you have fine-tuned a general-purpose model on your own data, you may carry provider obligations as well.

3. Implement point-of-interaction transparency for consumer-facing AI

For recommendation and personalisation systems, draft and deploy disclosures that are visible at the point where AI-influenced results are presented to users. Test these against the Act's plain-language requirement — the standard is whether a typical user would understand that AI is shaping what they see.

4. Label AI-generated content

For any synthetic imagery, AI-generated design assets, or machine-produced marketing content, implement the required labelling. Work with your creative and technology teams to establish a workflow that applies labels at the point of generation rather than as a post-production step.

5. Establish a documentation and monitoring regime

High-risk systems require ongoing monitoring, incident logging, and documentation of the human oversight measures in place. Even for limited-risk systems, maintaining records of system purpose, training data provenance, and performance monitoring will be expected by supervisory authorities conducting reviews.

6. Review third-party contracts

The Act places obligations on deployers that cannot be fully discharged by contractual delegation to providers. Review your agreements with AI vendors to confirm that the information and cooperation you need to meet your own obligations — including access to technical documentation and incident notification — is contractually secured.

What remains unsettled?

Several questions are not yet resolved by the Omnibus text or by supervisory guidance:

  • Classification of hybrid systems. Many fashion AI deployments combine recommendation logic, content generation, and dynamic pricing in a single interface. Whether such systems are classified by their most impactful component or assessed as a whole is not definitively answered.
  • Scope of the synthetic content obligation. It is not yet clear whether AI-assisted editing of real photography — rather than fully synthetic generation — triggers the same labelling requirements as fully generated content.
  • Interaction with the Digital Product Passport. The Digital Product Passport framework, which requires structured product data across the supply chain, intersects with AI systems that generate or manage product information. How the two regimes interact in practice — particularly for AI-generated product descriptions and material certifications — is still being worked out.
  • Enforcement priorities. National market surveillance authorities have discretion in how they allocate enforcement resources. Early enforcement actions will signal which sectors and system types attract priority attention.

The Taylor Wessing analysis of the Act's application to fashion, published in late 2024, remains a useful baseline for understanding how the risk classification framework applies to the industry's characteristic AI use cases, even as the Omnibus has since shifted some of the timeline.

FAQ

What is the EU AI Omnibus? The EU AI Omnibus is a legislative package that entered into force in 2026, amending the original EU AI Act. It adjusted certain compliance deadlines and clarified the obligations of deployers — organisations that use AI systems built by others — alongside those of providers.

Does the Omnibus reduce compliance obligations for fashion brands? No. Some formal notification deadlines shifted, but the substantive obligations — transparency disclosures, content labelling, documentation, and human oversight — remain in place. Supervisory authorities have indicated they expect compliance with the substantive standards regardless of adjusted formal dates.

What counts as a deployer under the AI Act? A deployer is any organisation that uses an AI system in a professional context. A fashion retailer running a third-party recommendation engine, a brand using an AI content generation tool, or a logistics operator using AI-assisted scheduling are all deployers and carry affirmative obligations under the Act.

Are product recommendation engines high-risk under the AI Act? Generally, no — most product recommendation systems fall into the limited-risk or minimal-risk tiers, provided they do not exploit psychological vulnerabilities or process sensitive personal data in ways that cause harm. The primary obligation at these tiers is transparency: users must be informed that AI is shaping what they see.

What must fashion brands do about AI-generated imagery? AI-generated product imagery and synthetic content must be labelled as machine-generated in a way that is legible to users. The obligation applies at the point of publication, not only in metadata. Brands should establish generation-time labelling workflows rather than relying on post-production tagging.

How does the AI Act interact with GDPR for personalisation systems? The two frameworks apply in parallel. GDPR governs the lawful basis for processing personal data used to train or operate a personalisation system; the AI Act governs the transparency and oversight obligations that apply to the system itself. Compliance with one does not discharge obligations under the other.

Further reading

Share this article:

EU AI Act Omnibus 2026: Fashion Compliance Guide