EU AI Act August 2026: the compliance checklist after the Digital Omnibus

eu ai act august 2026 the compliance checklist after the digital omnibus

On 27 July 2026, six days before the deadline most enterprises had been working towards, Regulation (EU) 2026/1744 entered into force and moved the AI Act’s high-risk obligations by sixteen months.

The August 2026 date did not disappear. It now applies to something different from what most published checklists assume. Transparency obligations under Article 50 became enforceable on 2 August 2026 and were not deferred. High-risk obligations under Annex III now apply from 2 December 2027, and Annex I from 2 August 2028.

That distinction matters commercially. The obligations that bite today are the ones almost every organisation already triggers: customer-facing assistants, generated images and text, synthetic voice. The obligations that were postponed are the ones only a minority of organisations trigger at all. Most compliance programmes are pointed at the wrong half.

This article sets out what applies today, what moved, what did not, and what to do with the time the deferral bought you. For the underlying risk-based structure, see our explainer on the EU AI Act and on risk-based classification.

image

What the Digital Omnibus changed about the EU AI Act

Regulation (EU) 2026/1744, the Digital Omnibus on AI, was adopted on 8 July 2026, published in the Official Journal on 24 July 2026, and entered into force on 27 July 2026. It amends the AI Act itself, so these are not guidelines or interpretation. They are the law.

Five changes matter for enterprises:

  • Annex III standalone high-risk systems move from 2 August 2026 to 2 December 2027. This covers recruitment, credit scoring, education, essential services and law enforcement uses.
  • Annex I high-risk systems embedded in regulated products move from 2 August 2027 to 2 August 2028.
  • AI regulatory sandboxes must be operational in every member state by 2 August 2027 rather than 2 August 2026.
  • Two new prohibitions were added to Article 5: AI systems that generate or manipulate child sexual abuse material, and systems that generate non-consensual intimate imagery of identifiable people. Both apply from 2 December 2026. The test is asymmetric: providers are caught where generation is the intended purpose or a reasonably foreseeable and reproducible outcome without significant technical modification, while deployers are caught only on deliberate use.
  • The definition of a safety component was narrowed. The operative text now turns on whether a component is intended to prevent or mitigate risks to health and safety, and the accompanying recital states that systems used purely for user assistance, performance optimisation, service efficiency, automation, convenience or non-safety-related quality control do not qualify. This pulls a meaningful number of industrial systems out of the high-risk category entirely.

Two further changes are worth knowing. Small and medium enterprises and small mid-caps get simplified technical documentation, quality management obligations proportionate to organisation size, and priority access to sandboxes. The mitigated penalty rule already existed for SMEs and is now extended to small mid-caps. And Article 4, on AI literacy, was rewritten, which is covered separately below because it is the change with the most direct consequences for how organisations train staff.

The new dates are unconditional. The earlier proposal tied them to the readiness of harmonised standards; that trigger was removed. Changing them again would require a full legislative procedure.

eu ai act updated timeline
The AI Act timeline as it stands after Regulation (EU) 2026/1744. Transparency did not move; high-risk did.

What applies right now: Article 50 transparency

Article 50 became enforceable on 2 August 2026 and was left untouched by the Omnibus. It contains four obligations, and they land on different parties.

1. Tell people they are talking to an AI

Providers of AI systems that interact directly with people must design and build them so users are informed they are dealing with an AI system, unless that is obvious to a reasonably well-informed person in the circumstances. In practice this covers every customer-facing chatbot, voice assistant and support agent on your estate, including ones embedded in software you bought rather than built.

2. Mark synthetic content in a machine-readable format

Providers of systems that generate synthetic audio, image, video or text must mark the output in a machine-readable format and make it detectable as artificially generated or manipulated. This is a technical requirement, not a visible watermark or a disclaimer in the caption. Systems already on the market before 2 August 2026 have a grace period until 2 December 2026, which is the nearest real deadline on the calendar for most organisations.

3. Disclose deepfakes

Deployers of systems producing deepfake image, audio or video content must disclose that the content has been artificially generated or manipulated. There are exceptions for evidently artistic, creative, satirical and fictional works, where the disclosure can be lighter and must not spoil the work.

4. Disclose emotion recognition and biometric categorisation

Deployers of emotion recognition or biometric categorisation systems must inform the people exposed to them. Note that emotion recognition in the workplace and in education is not a transparency question at all: it is prohibited outright under Article 5, and has been since February 2025, unless it is used for medical or safety reasons.

A fifth obligation catches AI-generated text published to inform the public on matters of public interest, which must be disclosed unless a human has taken editorial responsibility for it. Any organisation publishing AI-assisted content on regulated or public-interest topics should read that one closely.

Breaching Article 50 sits in the second penalty tier: up to 15 million euro or 3% of total worldwide annual turnover, whichever is higher. For SMEs it is whichever is lower.

which ai act obligations apply to you
Which obligations apply to you today. The main line is already enforceable; only the last branch has a deadline in the future.

What didn’t change in the EU AI Act

The deferral was narrow. Everything below has been in force for months or years and remains fully enforceable.

The original Article 5 prohibitions have applied since 2 February 2025. Social scoring, untargeted facial image scraping, exploitative manipulation and the rest of the list are simply illegal. Emotion inference is prohibited specifically in the workplace and in education, and only there, with a carve-out for medical or safety reasons. Elsewhere it is a transparency obligation rather than a ban. There is no transition period and no grandfathering for this tier, and it carries the highest penalty: up to 35 million euro or 7% of total worldwide annual turnover.

General-purpose AI model obligations have applied since 2 August 2025. Separately, the Commission’s power to fine GPAI providers under Article 101 became applicable on 2 August 2026, which means enforcement against model providers is now live rather than theoretical.

The extraterritorial reach is unchanged. The Act applies to providers placing AI systems on the EU market wherever they are established, to deployers established in the EU, and to providers and deployers outside the EU where the output of the system is used in the EU. A Dutch company using a US model provider does not escape the Act, and neither does the provider. The three-tier penalty structure is unchanged as well, and is set out in the FAQ below.

The AI literacy rewrite in the EU AI Act

Article 4 changed on 27 July 2026, and the change is easy to misread in both directions.

The original text required providers and deployers to “ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf”.

The amended text requires them to “take measures to support the development of” that level, and adds that the article “does not require providers or deployers to guarantee any specific level of AI literacy of any individual”.

That is a shift from an obligation of result to an obligation of means. The requirement did not disappear; it is still binding and still enforceable. What changed is the compliance test. You are no longer judged on whether your staff are demonstrably competent. You are judged on whether you took measures, which means the evidence trail is now the compliance artefact.

The practical consequence is counterintuitive. Ad-hoc enablement, a lunch session, a shared prompt library, is harder to defend than it was, because there is nothing to point at. A structured programme with attendance records, dated materials and a defined curriculum is now the cheapest way to satisfy Article 4. The Commission’s referenced frameworks are AILit and DigComp 3.0.

What to do with sixteen extra months

The honest read is that sixteen months is less generous than it sounds, for three reasons.

First, the work is longer than the extension. A conformity assessment is not a document you write in a quarter. It rests on a risk management system that has been running long enough to produce evidence, on data governance documentation covering provenance and bias mitigation, on logging that has been capturing traceable records, and on a post-market monitoring plan with actual data in it. Organisations that start in mid-2027 will be assembling artefacts retroactively, which is both more expensive and less defensible.

Second, harmonised standards are still not final. When they land, they will define what “sufficient” means in practice, and anything built against a guess will need revisiting. Building the underlying capability now and mapping it to standards later is cheaper than the reverse.

Third, the deferral changed nothing about commercial reality. Enterprise procurement, public tenders and investor due diligence already ask for AI governance evidence, and they do not wait for regulatory deadlines. A vendor risk assessment arriving from a customer is not something you can defer to December 2027.

The one genuinely useful thing to do with the extra time is re-classification. The narrowed safety component definition means systems you previously scoped as high-risk may no longer be. Quality control, performance optimisation and user assistance functions are now outside the definition unless failure endangers health or safety. Re-running that classification is the highest-value hour you can spend on the AI Act this quarter, because it can remove entire workstreams from your programme.

The 90-day checklist to comply with the EU AI Act

Ten steps, in order, aimed at the obligations that are actually enforceable today. Most organisations can complete the first six in a fortnight.

  • Inventory every AI system in use, including features inside software you bought rather than built. Shadow AI and embedded vendor features are where the Article 50 exposure usually sits.
  • Flag every system that interacts with people or generates content. That is your Article 50 population.
  • Check the disclosure on every customer-facing assistant. Users must be told they are dealing with an AI unless it is obvious from context.
  • Check machine-readable marking on every system that generates audio, image, video or text. Anything already live before 2 August 2026 must be compliant by 2 December 2026.
  • Check deepfake and emotion recognition disclosures where relevant, and confirm you are not running a prohibited emotion recognition use in the workplace or in education.
  • Re-run your Article 5 screen against the two prohibitions added by the Omnibus, which apply from 2 December 2026.
  • Re-classify your systems against the narrowed safety component definition. Remove anything that no longer qualifies as high-risk from the programme.
  • Document your AI literacy measures. Curriculum, dates, attendance, materials. The evidence is the artefact, not the outcome.
  • Put the remaining high-risk work on a schedule that ends well before 2 December 2027, not on it.
  • Name an accountable owner and set a review date. The dates in this article have moved once already.

If you would rather not run this internally, our EU AI Act assessment produces the inventory, the classification and the gap analysis in a fixed scope.

Obligations by role

RequirementProviderDeployerImporter or distributorApplies from
Article 5 prohibitionsMandatoryMandatoryMandatory2 Feb 2025 (2 new bans 2 Dec 2026)
Article 4 AI literacy measuresMandatoryMandatoryRecommended2 Feb 2025, amended 27 Jul 2026
Article 50 transparencyDisclosure and markingDeepfake and biometric noticeVerify provider compliance2 Aug 2026 (legacy marking 2 Dec 2026)
Risk management (Art. 9)MandatoryNot applicableVerify provider compliance2 Dec 2027 (Annex III)
Technical documentation (Art. 11)MandatoryKeep instructionsVerify provider compliance2 Dec 2027 (Annex III)
Human oversight (Art. 14)Design inImplementNot applicable2 Dec 2027 (Annex III)
EU database registration (Art. 49)MandatoryPublic bodies onlyNot applicable2 Dec 2027 (Annex III)
Post-market monitoring (Art. 72)MandatoryMonitor useReport incidents2 Dec 2027 (Annex III)

Conclusion

The Digital Omnibus did not weaken the AI Act. It rebalanced it, and in doing so it separated the organisations that built a compliance plan around a date from those that built one around their actual systems.

If your programme was scoped to Annex III, you now have sixteen more months and a narrower scope, and the sensible response is to re-classify rather than to relax. If your programme was scoped to a date, it is pointed at the wrong obligations, because the ones enforceable today are the transparency requirements that almost every organisation triggers and that most compliance plans treat as a footnote.

The nearest real deadline is 2 December 2026, when the marking grace period ends for generative systems already on the market. That is roughly a quarter away. If you want a second opinion on where your organisation actually stands, an EU AI Act assessment is the fastest route to an answer you can defend.

Frequently Asked Questions (FAQ)

Was the August 2026 AI Act deadline cancelled?

No. It was split. Article 50 transparency obligations and the Commission’s power to fine general-purpose AI providers under Article 101 both took effect on 2 August 2026 as originally scheduled. Only the high-risk obligations were deferred: Annex III standalone systems to 2 December 2027 and Annex I embedded systems to 2 August 2028, under Regulation (EU) 2026/1744.

Do I still need to do anything about high-risk AI systems?

Yes, for two reasons. Conformity assessment depends on evidence that has to accumulate over time, including risk management records, data governance documentation and post-market monitoring data, so starting in 2027 means assembling it retroactively. And the narrowed safety component definition means some systems previously scoped as high-risk no longer are, which is worth confirming before you spend another quarter on them.

Is AI literacy training still mandatory?

Article 4 still binds every provider and deployer, but the obligation changed on 27 July 2026 from ensuring a sufficient level of AI literacy to taking measures to support its development. It explicitly does not require guaranteeing any specific level for any individual. In practice the compliance test is now documentary: you need to show what you did, not prove what your staff know.

What is a Fundamental Rights Impact Assessment (FRIA)?

A FRIA is a mandatory assessment for certain deployers of high-risk AI systems, specifically public bodies and private entities providing essential public services such as banking or insurance. It requires the deployer to assess how the AI’s use will affect the fundamental rights of the people involved before the system is put into use.

Does the EU AI Act apply to companies outside Europe?

Yes. It applies to any provider placing an AI system on the EU market or putting it into service in the EU regardless of where the provider is established, to deployers established in the EU, and to providers and deployers in third countries where the output produced by the system is used in the EU.

Are open-source AI models exempt?

Partly, and less than most people assume. The Act provides exemptions for models released under free and open-source licences provided they are not placed on the market as part of a high-risk system and do not qualify as general-purpose AI models with systemic risk. Article 50 transparency obligations still apply to output generated with an open-source model, so open-source status is not a compliance shield.

What are the penalties?

Three tiers. Up to 35 million euro or 7% of total worldwide annual turnover for breaching the Article 5 prohibitions. Up to 15 million euro or 3% for most other obligations, including Article 50 transparency and the high-risk requirements. Up to 7.5 million euro or 1% for supplying incorrect, incomplete or misleading information to notified bodies or national competent authorities. In each case the higher figure applies, except for SMEs and start-ups where the lower applies.

Add DataNorth AI to your Google favorites