EU AI Act guide · updated 3 August 2026
August 2, 2026 after the Omnibus: what is actually enforceable now
Six days before the most anticipated deadline in AI regulation, the law changed. On 27 July 2026 the Digital Omnibus on AI (Regulation (EU) 2026/1744) entered into force and moved the high-risk obligations that were due on 2 August 2026 to 2 December 2027 (Annex III) and 2 August 2028(AI embedded in Annex I regulated products). Most of the compliance content published this year — vendor sites, law-firm alerts, this page's own earlier version — was written for the old timeline. Here is what is actually true now.
What is enforceable today
- Since 2 February 2025 — the Article 5 prohibitions: manipulative techniques, social scoring, untargeted facial-image scraping, emotion recognition at work and school, and the other banned practices.
- Since 2 August 2025 — duties for general-purpose AI model providers (Articles 53/55) and the governance structure around the AI Office.
- Since 2 August 2026 (now)— Article 50 transparency duties: telling users they are interacting with AI, labelling deepfakes and synthetic content, disclosing emotion recognition and biometric categorisation. Also now live: the Commission's penalty powers over GPAI providers, and national market-surveillance authorities' ability to investigate and fine breaches of everything already applicable. Both Article 50 and GPAI breaches sit in the €15M / 3% tier.
What the Omnibus changed
- Annex III high-risk → 2 December 2027. Risk management, data governance, Annex IV technical documentation, logging, human oversight, conformity assessment and registration for providers; Article 26 duties for deployers.
- Annex I embedded high-risk → 2 August 2028. AI as a safety component of regulated products — medical devices, machinery, vehicles and the rest.
- Fixed dates, not conditions. The proposed standards-availability trigger was deleted in the final text. These dates do not move if standards are late.
- A new prohibition, from 2 December 2026.AI systems that generate or manipulate non-consensual intimate imagery of identifiable persons (“nudifiers”) and CSAM join Article 5 — drafted to reach systems where such misuse is reasonably foreseeable and reproducible in the absence of reasonable, proportionate and effective safeguards, not only purpose-built tools. Revised machine-readable content-marking provisions apply from the same date.
Who should act this quarter anyway
- Everyone shipping AI-facing features — chatbots, image and text generation, voice agents, emotion recognition. Article 50 duties are live now, they are the cheapest obligations in the Act to satisfy, and they are the easiest for an authority to verify from the outside: a regulator can check your chatbot's disclosure from their own desk.
- Anyone near generative imagery — the December 2026 prohibition is drafted around misuse that is foreseeable and not prevented by effective safeguards. If your product can be used to undress real people and your safeguards would not stop it, the question is no longer reputational.
- Providers and deployers of Annex III candidates — recruitment, credit scoring, insurance pricing, education, essential services, biometrics. December 2027 is sixteen months to do work that consultancies quote six to twelve months for: oversight design, logging, data governance, Annex IV documentation, conformity assessment. Companies that started GDPR work when the date was announced had a calm 2018; the ones that waited did not.
- Anyone being asked for proof— procurement questionnaires, enterprise customers and investors have not read the Omnibus. They are asking for your classification records today, and “the deadline moved” is not an answer to “which of your systems are high-risk?”
The sane response, updated
- Inventory every AI system you build, embed or deploy — including vendor tools in HR, finance and support.
- Classify each one against Article 5 (including the December addition), Annex III and Article 50 — and record which application date governs each verdict. That record is what makes the postponement usable.
- Fix Article 50 first. It is enforceable now, visible from outside, and usually days of work, not months — the Transparency Toolkit has paste-ready disclosure texts and the evidence checklist.
- Plan high-risk conformity backwards from December 2027 — for genuine Annex III systems, the runway is the opportunity to do in-house, at software prices, what a panicked 2027 will pay consultancy prices for.
Classify a system against the post-Omnibus timeline — free, 10 minutes
The free AnnexWise assessment classifies a system in about 10 minutes — risk tier, open obligations and a gap report, with article references throughout. It runs in your browser; answers never leave your device.
Run the free assessment →The Omnibus is also a lesson about compliance content itself: the law moved on a Monday and most of the internet's AI Act advice became wrong overnight. Every AnnexWise verdict is stamped with the rule-set version and legal-state date it was produced under, and the rule-set changelog records publicly what changed and when. A classification you cannot date is a classification you cannot trust.
Frequently asked questions
Did the Omnibus delay the whole EU AI Act?
No. The Digital Omnibus on AI (Regulation (EU) 2026/1744, in force 27 July 2026) postponed one part of the Act: the high-risk regime, moving Annex III systems to 2 December 2027 and Annex I embedded systems to 2 August 2028. Everything else stayed on schedule — prohibitions banned since February 2025, GPAI duties since August 2025, and Article 50 transparency duties plus enforcement powers from 2 August 2026. The Omnibus also added a new prohibition on AI-generated non-consensual intimate imagery, applying from 2 December 2026.
Are the new high-risk dates conditional on standards being ready?
No. The Commission's original proposal linked the start of high-risk obligations to a decision confirming that standards and support tools were available. The co-legislators dropped that mechanism: 2 December 2027 (Annex III) and 2 August 2028 (Annex I) are fixed calendar dates. Do not plan on a further slip.
We're not an EU company — are we affected?
Very likely, if your AI touches the EU. The Act applies extraterritorially: to any provider placing an AI system on the EU market and to providers and deployers whose system's output is used in the EU (Article 2). This is the same reach that made GDPR a de facto global standard, and the Omnibus did not narrow it.
High-risk moved to 2027 — can we park this until then?
Only after classifying. You cannot know whether the postponement helps you until each system is mapped: chatbots, synthetic media and emotion-recognition features carry Article 50 duties that are enforceable today; anything touching intimate-imagery generation faces a prohibition in December 2026; and a genuine high-risk verdict means conformity work that realistically consumes the sixteen-month runway. The delay is breathing room for the prepared, not amnesty.
Where does your AI system actually stand?
The free AnnexWise assessment classifies a system in about 10 minutes — risk tier, open obligations and a gap report, with article references throughout. It runs in your browser; answers never leave your device.
Run the free assessment →Keep reading
AnnexWise is compliance software, not a law firm; this guide is general information about Regulation (EU) 2024/1689, not legal advice for your situation. Verdict logic is documented on the methodology page; the people behind it are on the about page.