← Back to blog
NewsAbout 6 min read

The EU AI Act After the Digital Omnibus: What Actually Applies Now

Published Oct 7, 2026
The EU AI Act After the Digital Omnibus: What Actually Applies Now

A lot of AI Act coverage is still running on a calendar that no longer exists. The Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force on July 27, 2026, and it pushed the heaviest obligations out by more than a year. If you read a compliance guide written before late July, check its dates first. Several widely shared explainers still describe August 2026 as the day high-risk compliance became mandatory, and that has not been the law for months.

Here is the schedule that actually applies.

The corrected timeline

The Act does not switch on all at once, and the Omnibus moved only part of it.

Prohibited AI practices and the AI literacy duty have applied since February 2, 2025. Obligations for providers of general-purpose AI models followed on August 2, 2025, along with governance and penalty provisions. Article 50 transparency rules took effect on August 2, 2026, the same date the Commission's enforcement powers over GPAI providers came online.

The Omnibus left those in place. What it postponed were the high-risk obligations. Stand-alone high-risk systems listed in Annex III, such as AI used in recruitment or credit scoring, now have until December 2, 2027. High-risk systems embedded in products covered by Annex I legislation, spanning medical devices, machinery, and aviation, have until August 2, 2028.

Two more dates sit inside the near term. December 2, 2026 marks the end of the Article 50(2) marking grace period, which covers only generative systems placed on the market before August 2, 2026. That same date brings two new prohibitions into force: AI-generated child sexual abuse material, and non-consensual intimate imagery, commonly described as the nudifier ban.

There is also a date for older models that is worth verifying against the Act's own text before you rely on it. General-purpose AI models placed on the market before August 2, 2025 must be brought into compliance by August 2, 2027.

The delay is real but narrow

It is easy to read "high-risk postponed to 2027" as breathing room. The postponement applies to Chapter III, the high-risk obligations. It does not touch the transparency rules or the GPAI regime, both of which are live.

Law firm commentary is consistent on the interpretation: the Omnibus buys time without reducing the work. A company that treats the deadline as a reason to start later will discover that a conformity assessment does not compress just because the calendar moved.

Does this apply to you

The AI Act follows your output rather than your office address. It reaches you if you place an AI system on the EU market, deploy one inside the EU, or produce output that is used in the EU even when the system runs elsewhere.

Your obligations depend on your role. A provider develops a system or has one developed and puts it on the market under its own name. A deployer uses a system in a professional setting. Importers and distributors bring AI systems into the EU or resell them.

The distinction is not cosmetic. A company that merely uses an AI writing assistant carries far fewer obligations than one that builds a hiring algorithm, sells an AI-enabled medical device, or provides a general-purpose model. Getting the role wrong in either direction is expensive: too loose and you miss obligations, too tight and you spend on conformity work you did not need.

The trap is a deployer becoming a provider without noticing. Under Article 25, that can happen by putting your own brand on a high-risk system, substantially modifying one, or repurposing a system so it becomes high-risk. If you commission a system, build on someone else's model and ship it as your product, or fine-tune a tool for a regulated use, assume you may be the provider until counsel tells you otherwise.

What to have ready

The Act does not literally require an AI policy or an AI register. Without a list of your systems and your role in each, however, you cannot demonstrate which obligations apply to you. That list is the practical starting point, and it feeds everything downstream.

From there, three things are worth having documented today: a check against the prohibited practices, a check against Article 50 transparency for anything that interacts with people or generates synthetic media, and a record of the AI literacy measures you have taken.

Enforcement is arriving unevenly

The Commission has sent more than 30 requests for information to companies on topics ranging from copyright to cybersecurity and safety, which is a preliminary step that can open an investigation. Individual member states are spinning up their own authorities on their own schedules.

Poland's KRiBSI begins handling complaints, inspections, individual opinions, and fines on October 28, 2026. Germany's AI market surveillance act, the KI-MIG, has been in force since July 29, 2026, with the Bundesnetzagentur as the main authority. Where you operate determines when enforcement becomes concrete.

The transparency obligation is already reshaping products

Article 50 is doing visible work. OpenAI announced it will add imperceptible watermarks to text generated by ChatGPT and Codex for users in the EU, to meet the Act's transparency requirements, with the company publishing a technical report on a method it calls textGrain alongside researchers from Penn and Yale. Anthropic made a similar move for Claude some two months earlier, globally rather than regionally.

OpenAI was candid about the limits. Replacing roughly 10 percent of words with synonyms dropped detection from about 92 percent to 66 percent, and short texts, math answers, and translations are harder still. That is why the company is restricting early detector access to vetted researchers.

Read together, the watermarking rollouts and the Omnibus timeline describe where the Act's pressure actually lands right now. Not on high-risk conformity assessments, which have been deferred, but on the marking and disclosure duties that apply to anything generating content in the EU today. That is the part of the law with a live deadline, and it is the part most companies should be working on first.

The gap between the regulation's public reputation and its current operative content is wider than for almost any other tech law. The AI Act is discussed as an existential compliance burden. In practice, for most businesses, the obligations that apply this year are transparency and literacy: tell people when they are interacting with a system, mark synthetic media, and make sure your staff understand what they are using. Those are real but tractable, and they are a different order of effort from a full high-risk conformity assessment.

The honest caveat is that the transparency duties are harder than they sound for anyone shipping generative features. Marking synthetic media requires knowing which bytes your system produced, which is not always obvious once content passes through editing tools and third-party pipelines. The grace period ending in December 2026 will reveal how many providers built that plumbing and how many assumed someone else would.

Related articles