The EU AI Act in 2026: What Applies Now, What Was Delayed, and What It Means for You

The EU AI Act now runs on two clocks. One is already ticking: prohibited practices, general-purpose AI (GPAI) rules, AI Office enforcement, and chatbot and deepfake transparency. The other was reset. Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. If you read “delay” as “pause,” you will miss live obligations. This guide separates what binds you today from what you can schedule.

Quick Takeaways

  • Live now: Article 5 prohibitions, AI literacy, GPAI model duties, Article 50 transparency, and AI Office enforcement.
  • Delayed: Stand-alone Annex III high-risk systems move to 2 December 2027, and Annex I product-embedded systems move to 2 August 2028.
  • Next hard date: 2 December 2026. Machine-readable marking for legacy generative systems and the new nudifier/CSAM ban both land that day.
  • Fines: up to €35M or 7% of global turnover for prohibited practices. GPAI providers face AI Office enforcement with fines up to 3% of worldwide turnover.

EU AI Act Timeline (as of October 4, 2026)

Date Obligation Status
2 Feb 2025 Article 5 bans; Article 4 AI literacy In force
2 Aug 2025 GPAI model obligations (Arts. 51–55) In force
2 Aug 2026 Article 50 transparency; AI Office GPAI enforcement In force
2 Dec 2026 Marking for legacy generative systems; nudifier/CSAM ban Upcoming
2 Aug 2027 National regulatory sandboxes (moved from 2026) Delayed
2 Dec 2027 Annex III high-risk obligations Delayed
2 Aug 2028 Annex I high-risk obligations Delayed

What the Digital Omnibus Actually Changed

The legislative path

The Parliament and Council reached political agreement on 7 May 2026. Parliament endorsed it on 16 June and the Council adopted it on 29 June. The fast track was deliberate. Lawmakers split the AI Omnibus from the wider package so the new deadlines would take effect before the original 2 August 2026 date.

Why high-risk rules slipped

The cause was infrastructure, not politics. National authorities and harmonized technical standards were not ready. The compliance logic itself, covering risk management, documentation, human oversight, and post-market monitoring, is unchanged.

Grandfathering nuance

Annex III systems placed on the EU market before the new date fall under the requirements only if they are substantially modified afterward. Treat any major retraining or feature expansion as a potential compliance trigger.

Other amendments

  • AI literacy softened. Organizations now need to adopt measures that support staff AI literacy. They no longer have to guarantee a specific level.
  • SME relief widened. Relief extends to small mid-caps, and machinery gets a carve-out.
  • AI Office powers expanded. The AI Office gains tools for investigations, on-site inspections, binding commitments, and fines.

What Applies Right Now

Prohibited practices (Article 5)

These have applied since February 2, 2025. Social scoring, manipulative techniques, and untargeted facial-image scraping are banned. The Omnibus did not touch them.

GPAI model obligations

Providers of general-purpose models have faced duties since August 2, 2025. The final GPAI Code of Practice of 10 July 2025 serves as the practical guide. Since 2 August 2026, the AI Office can enforce them with penalties.

GPAI Duty Applies To Practical Output
Technical documentation All GPAI providers Model card, training and evaluation details
Copyright policy All GPAI providers Documented opt-out and TDM handling
Training-data summary All GPAI providers Public summary using the EU template
Adversarial testing and evaluations Systemic-risk models (>10²⁵ FLOPs presumption) Red-team reports, eval logs
Incident reporting and cybersecurity Systemic-risk models Serious-incident notifications to the AI Office

Article 50 transparency

Article 50 has applied since 2 August 2026. It splits duties between providers and deployers.

Article 50 Duty Who What You Must Do
50(1) Interaction disclosure Provider Tell users they are talking to an AI, unless obvious
50(2) Machine-readable marking Provider Mark synthetic audio, image, video, and text as AI-generated
50(3) Emotion/biometric notice Deployer Inform exposed people
50(4) Deepfake and public-interest text labeling Deployer Disclose manipulated content

Generative systems placed on the market before 2 August 2026 get a short grace period. The watermarking duty applies to them from 2 December 2026. New systems get no grace.

What’s Coming on December 2, 2026

Two items need action this quarter.

  1. Legacy marking deadline. If your generative product shipped before August 2, bake metadata or watermarking into outputs now.
  2. New Article 5 bans. AI systems that generate non-consensual intimate imagery or AI-generated child sexual abuse material become prohibited on 2 December 2026, in the tier carrying fines up to €35M or 7% of global turnover. There is no exemption for systems already on the market. A safe harbor exists for systems with effective preventive safeguards. Document your safeguards before the deadline.

What Was Delayed: High-Risk AI

Annex III covers recruitment tools, credit scoring, law enforcement, education, and border control. These systems now have until 2 December 2027. Annex I systems, such as medical devices, radio equipment, and toys, have until 2 August 2028.

Do not shelve the work. Classification still follows Article 6, and the Commission published draft classification guidelines on 19 May 2026. Agents deserve special attention. If a deployer uses an agent in a way the provider did not intend, the deployer may become the provider of a high-risk system.

Penalty Structure

Violation Maximum Fine
Prohibited practices (Art. 5) €35M or 7% of global turnover
Most other obligations, including GPAI and Art. 50 €15M or 3%
Misleading information to authorities €7.5M or 1%

Implementation: Build a Compliance Triage Script

Start with an inventory. This Python script flags each system against the dates above. Adapt the area list to your own legal review.

from dataclasses import dataclass
from datetime import date

ANNEX_III_AREAS = {
    "employment", "education", "credit_scoring", "law_enforcement",
    "border_control", "essential_services", "critical_infrastructure",
}

@dataclass
class AISystem:
    name: str
    use_area: str
    talks_to_users: bool
    generates_media_or_text: bool
    launched_before_2026_08_02: bool
    intimate_imagery_capable: bool = False

def triage(s: AISystem) -> list[tuple[str, date]]:
    flags = []
    if s.use_area in ANNEX_III_AREAS:
        flags.append(("High-risk candidate (Annex III)", date(2027, 12, 2)))
    if s.talks_to_users:
        flags.append(("Art. 50(1) disclosure", date(2026, 8, 2)))
    if s.generates_media_or_text:
        deadline = date(2026, 12, 2) if s.launched_before_2026_08_02 else date(2026, 8, 2)
        flags.append(("Art. 50(2) machine-readable marking", deadline))
    if s.intimate_imagery_capable:
        flags.append(("Possible Art. 5 ban: document safeguards", date(2026, 12, 2)))
    return flags

inventory = [
    AISystem("HR resume ranker", "employment", False, False, True),
    AISystem("Support chatbot", "customer_service", True, True, False),
]
for system in inventory:
    print(system.name, triage(system))

For chatbots, add the disclosure at the interface and API layer. Set temperature 0 on the disclosure template so the wording stays stable:

DISCLOSURE = "You are chatting with an AI assistant, not a human."

def wrap_response(text: str, first_turn: bool) -> dict:
    return {
        "disclosure": DISCLOSURE if first_turn else None,
        "content": text,
        "metadata": {"ai_generated": True},  # machine-readable flag for Art. 50(2)
    }

Real-World Scenarios

HR SaaS vendor (Annex III provider). Your resume-screening product is a high-risk candidate. You have until December 2027, but harmonized standards are still arriving through late 2026 and 2027. Start classification, data governance, and logging now.

Customer-support chatbot (Art. 50 provider). Disclosure obligations have applied since August 2. Audit every entry point, including voice and messaging channels.

Image-generation startup (legacy system). You launched before August 2026. Ship invisible watermarking and metadata by December 2, 2026.

Foundation-model lab (GPAI provider). Maintain documentation, a copyright policy, and a training-data summary. If you exceed the 10²⁵ FLOPs presumption, add evaluations and incident reporting.

Enterprise deploying third-party models. You are a deployer. Label deepfakes, inform people exposed to emotion recognition, and confirm your vendor’s marking works.

Obligations by Role

Role Already Binding Next Date
GPAI provider Arts. 51–55; AI Office enforcement None new
Generative-AI provider (new systems) Art. 50(1)–(2) None new
Generative-AI provider (legacy) Art. 50(1) 2 Dec 2026 (marking)
Annex III provider Prohibitions, literacy 2 Dec 2027
Deployer Prohibitions, literacy, Art. 50(3)–(4) 2 Dec 2027 (high-risk)

Your Q4 2026 Checklist

  1. Build an AI system inventory with owners and vendors.
  2. Classify each system under Article 6.
  3. Add chatbot disclosures and content marking.
  4. Audit products for nudifier or CSAM misuse risk, and record safeguards.
  5. Document an AI literacy program, scaled to your staff and context.
  6. Request GPAI documentation from your model vendors.

FAQ

Did the Digital Omnibus delay the entire EU AI Act?

No. It postpones only part of the high-risk obligations. Prohibitions, literacy, GPAI duties, and Article 50 transparency continue on their original schedules.

When do high-risk AI rules now apply?

Stand-alone Annex III systems must comply by 2 December 2027. Systems embedded in regulated products under Annex I must comply by 2 August 2028.

Is AI Act enforcement active today?

Yes. The Commission and AI Office can now investigate and fine GPAI providers, with penalties up to €15 million or 3% of worldwide turnover. Prohibited-practice violations carry higher fines of up to €35M or 7%.

What new AI uses are banned?

The Omnibus bans using AI to generate or manipulate child sexual abuse material and to create non-consensual intimate content depicting identifiable people. Both bans apply from 2 December 2026.

Hot this week

Android 17: What’s New and Which Phones Get It

Android 17 is live: App Bubbles, location indicators, app memory limits. See which Pixel, Samsung, OnePlus and Xiaomi phones get it. Check yours now.

Android Developer Verification Explained: What Changes for Sideloading

Android developer verification is live. See how the 24-hour advanced flow works, what ADB skips, and how to keep sideloading safely. Read the guide.

Windows 11 Versions Explained: 24H2, 25H2, 26H1, and What’s Next

Windows 11 versions 24H2, 25H2, 26H1 and 26H2 compared. See build numbers, support dates, the Arm split and what 27H2 brings. Check your version now.

Windows 10 End of Support and ESU: Dates, Options, and What to Do

Windows 10 reached end of support on October 14, 2025. Since then, home PCs have stayed patched only through the one-year consumer Extended Security Updates (ESU) program, which stops on October 13, 2026.

Check and Update Your Secure Boot Certificates: A Step-by-Step Guide

Secure Boot certificates from 2011 are expiring. Check your status and update Windows and Linux with our step-by-step guide.

Topics

Android 17: What’s New and Which Phones Get It

Android 17 is live: App Bubbles, location indicators, app memory limits. See which Pixel, Samsung, OnePlus and Xiaomi phones get it. Check yours now.

Android Developer Verification Explained: What Changes for Sideloading

Android developer verification is live. See how the 24-hour advanced flow works, what ADB skips, and how to keep sideloading safely. Read the guide.

Windows 11 Versions Explained: 24H2, 25H2, 26H1, and What’s Next

Windows 11 versions 24H2, 25H2, 26H1 and 26H2 compared. See build numbers, support dates, the Arm split and what 27H2 brings. Check your version now.

Windows 10 End of Support and ESU: Dates, Options, and What to Do

Windows 10 reached end of support on October 14, 2025. Since then, home PCs have stayed patched only through the one-year consumer Extended Security Updates (ESU) program, which stops on October 13, 2026.

Check and Update Your Secure Boot Certificates: A Step-by-Step Guide

Secure Boot certificates from 2011 are expiring. Check your status and update Windows and Linux with our step-by-step guide.

Windows Secure Boot Certificates Expire October 19, 2026: What You Need to Do

The Windows Production PCA 2011 certificate expires Oct 19, 2026. Check your status, deploy Windows UEFI CA 2023, and avoid boot-level risk. Read the fix.

USB-C Power Delivery for Makers: Powering Projects From Any Charger

Learn how to power your electronics projects with USB-C Power Delivery. Get wiring, trigger boards, and code for 5V–20V builds. Start building now.

Best Soldering Irons for Beginners in 2026: Pinecil, Hakko, and More

Compare the best soldering irons for beginners in 2026, from the Pinecil V2 to the Hakko FX-888DX. See specs, prices, and picks. Find your first iron now.

Related Articles

Popular Categories