This website will offer limited functionality in this browser. We only support the recent versions of major browsers like Chrome, Firefox, Safari, and Edge.
If you have been tracking the EU AI Act’s implementation timeline over the past two years, you will know that 2 August 2026 was the date most compliance calendars had circled in red. It was the date most of the Act’s substantive obligations, including the high-risk regime, were meant to switch on. It has now come and gone, and the picture it left behind is more interesting, and more complicated, than the one shown in most compliance calendars had.
Here we summarise what’s happened, what’s applicable now, why those inside and outside the EU need to comply, and what in-house teams should do now.
The Digital Omnibus, in brief
Back in November 2025, the Commission tabled the Digital Omnibus on AI, a package of amendments aimed at simplifying parts of the Act. It sat alongside a wider digital omnibus touching the GDPR, the ePrivacy Directive, NIS2 and the Data Act, so this was never focused purely on AI. The headline driver was practical rather than political: member states had been slow to designate their national competent authorities, and the harmonised standards that high-risk compliance depends on were not ready. Regulators were on track to demand conformity against benchmarks that did not yet exist.
Negotiations progressed through two political trilogues, with the session in late April 2026 braking down without agreement. The institutions came back to the table in May, reached a political deal, and the European Parliament formally endorsed the text on 16 June 2026 by a comfortable margin. The Council gave its final sign-off on 29 June 2026, and the amending regulation was published and entered into force shortly after, comfortably ahead of the August deadline. So as of today, the Omnibus is not a proposal – it is law, and it has reshaped the Act’s timetable rather than its architecture:
It did not dismantle the Act’s architecture. The risk-based classification, the prohibited-practices regime, and the general-purpose AI (GPAI) rules all remain intact.
It pushed back the high-risk deadlines. Standalone Annex III high-risk AI systems (covering biometrics, critical infrastructure, education, employment, migration, asylum, and border control) now apply from 2 December 2027 (previously 2 August 2026). High-risk AI embedded in products already subject to EU product safety legislation (Annex I: machinery, toys, lifts, medical devices) moves to 2 August 2028 (previously 2 August 2027).
It added a new prohibition. A fresh Article 5 prohibition covers AI systems built to generate non-consensual intimate imagery (so-called “nudification” tools) and child sexual abuse material. This applies from 2 December 2026.
It extended certain support measures. The Omnibus broadens some SME accommodations to small mid-cap companies, simplifies registration obligations for exempted systems, and introduces an EU-level regulatory sandbox alongside a strengthened role for the Commission and Member States in promoting AI literacy.
What happened on 2 August 2026?
Obligations now live and enforceable
Transparency obligations under Article 50. The Commission’s final Article 50 Guidelines were adopted on 20 July 2026. Anyone deploying chatbots, generating synthetic content, using emotion recognition or biometric categorisation systems, or building tools whose output could be mistaken for human interaction must now meet disclosure requirements. There is no general grace period: Article 50 applies from 2 August 2026. A limited exception exists only for AI systems placed on the market before that date, and only for the machine-readable marking and detection obligation under Article 50(2), which those providers must meet by 2 December 2026. Content generated before 2 August 2026 does not need retrospective labelling.
Enforcement authority. The EU’s AI Office and national market surveillance authorities are now responsible for implementing, supervising, and enforcing the Act. The AI Office holds investigative and sanctioning powers over GPAI model providers: it can issue requests for information, demand access to models and technical documentation, conduct evaluations, require corrective measures (including mitigation, withdrawal, recall, or market restriction), and impose fines.
Monitoring and complaint tools. Three new channels went live: an AI Act Complaint Tool for alleged infringements by providers of AI systems supervised by the AI Office; a Whistleblower Tool for individuals professionally connected to providers to report violations securely and anonymously; and a downstream provider complaints channel for alleged breaches of GPAI model obligations under Articles 53-55.
The Code of Practice on Transparency of AI-generated Content. Published in final form on 10 June 2026 and assessed as adequate by the Commission and AI Board on 9 July 2026, this voluntary code sets practical steps for providers and deployers of generative AI systems to meet Article 50 obligations. It has two sections: Section 1 (providers: marking and detection of AI-generated/manipulated content) and Section 2 (deployers: labelling deepfakes and AI-generated/manipulated text) (see our article on the transparency obligations guidelines here). By end-July 2026, approximately 190 organisations had signed, including major providers (Anthropic, Google, Meta, Microsoft, Mistral, OpenAI) and a growing list of deployers (Getty Images, Iberdrola, Lenovo, Lufthansa). The Code remains open for signature. Adherence is not conclusive evidence of compliance, but signatories may rely on it to demonstrate compliance.
EU icons for AI-generated content. The Commission has created standardised icons that deployers may use to label AI-generated or manipulated content, designed to be clearly perceivable at first exposure and accessible.
GPAI model obligations. Rules on GPAI models have applied since August 2025, and the AI Office’s enforcement powers over them are now active. The GPAI Code of Practice (published on 10 July 2025 and confirmed adequate on 1 August 2025) covers transparency, copyright, and (for the most advanced models with systemic risk) safety and security. Around 21 providers have signed, including Amazon, Anthropic, Google, IBM, Microsoft, Mistral AI, and OpenAI. Providers who placed models on the market before 2 August 2025 have until 2 August 2027 to comply; those placing models on the market after that date must comply now. The Signatory Taskforce, chaired by the AI Office, has met four times in 2026 and is actively overseeing implementation.
Penalties. The penalty framework has applied since 2 August 2025. Non-compliance with Article 5 prohibitions carries fines of up to €35 million or 7% of total worldwide annual turnover (whichever is higher). Other operator obligations attract up to €15 million or 3% of worldwide turnover. Supplying incorrect or misleading information to regulators can result in fines of up to €7.5 million or 1% of worldwide turnover. For SMEs, the lower of the two amounts applies; for all other companies, the higher. The Commission can fine GPAI providers up to €15 million or 3% of worldwide turnover.
What was pushed back
Annex III high-risk systems: 2 December 2027 (previously 2 August 2026). Sixteen months of additional runway for standalone high-risk use cases including recruitment, credit scoring, education, migration, and biometrics.
Annex I product-embedded high-risk AI: 2 August 2028 (previously 2 August 2027). An additional twelve months for high-risk AI built into products subject to existing EU product safety regulation.
New obligations arriving on 2 December 2026
Two items have been added:
The new Article 5 prohibition on AI systems generating non-consensual intimate imagery and CSAM.
The machine-readable marking and detection obligation under Article 50(2) for AI systems placed on the market before 2 August 2026. Providers of those legacy systems must embed detectable marks in synthetic audio, image, and video output by this date. You may have recently read that Anthropic is embedding imperceptible watermarks into text and files generated by Claude – this is a direct result of the Act’s transparency requirements.
Why this matters even if you sit outside the EU
We get asked a version of this question constantly, usually by a US client with a UK subsidiary or a UK business selling into Europe: does any of this actually touch us? The Act’s scope reaches providers placing systems on the EU market and deployers whose output affects people in the EU, regardless of where the provider is headquartered. If your organisation is a US tech company routing product into Europe, or a UK business with EU-facing tooling, this is not a spectator sport. The Act is deliberately broad in its application, covering:
Providers placing AI systems on the EU market or putting them into service, regardless of where the provider is established.
Providers placing GPAI models on the EU market, irrespective of establishment.
Deployers located within the EU.
Providers and deployers in third countries where the output produced by the AI system is used in the EU.
Importers, distributors, and product manufacturers placing AI systems on the EU market under their name or trademark.
If your organisation sells AI-enabled products or services into the EU, if your output reaches EU-based individuals, or if you are a link in the supply chain of an AI system deployed in the single market, the Act applies to you. The extraterritorial reach echoes the GDPR’s approach, and the enforcement infrastructure behind it is now active.
The UK position
The UK has opted for a principles-based, regulator-led model rather than standalone AI legislation. Existing regulators (the ICO, Ofcom, the FCA, the CMA) are expected to interpret and apply AI within their respective remits, guided by a pro-innovation framework. The Data (Use and Access) Act 2025 (which received Royal Assent on 19 June 2025) amends but does not replace the UK GDPR, DPA 2018, and PECR. The ICO has confirmed that AI using personal data falls within the UK data protection regime and is reviewing its AI guidance in light of the Act.
For organisations with both UK and EU exposure, this means the EU AI Act is, for now, the most prescriptive and detailed rulebook in the market and the one most likely to set the baseline for global compliance programmes, much as the GDPR did for data protection.
What should in-house teams be doing now?
Key actions now include:
Complete your AI inventory and role mapping. Confirm which AI systems your organisation provides, deploys, imports, or distributes. Map each to the relevant AI Act role (provider, deployer, importer, distributor, product manufacturer). The obligations differ materially by role, and procurement and supplier contracts should clearly allocate responsibility.
Map Article 50 use cases now. Transparency obligations are live. Identify every system that interacts with individuals in ways covered by Article 50: chatbots, synthetic content generators, emotion recognition tools, biometric categorisation, deepfake generators, and AI-generated text published on matters of public interest without human editorial oversight. Document whether disclosure, marking, and labelling obligations apply and confirm that your systems meet them.
Engage with the Transparency Code (or build an equivalent case). The Code of Practice on Transparency remains open for signature and offers a practical route to demonstrating Article 50 compliance. If signing is not appropriate for your organisation, you will need to demonstrate compliance through alternative adequate means and should document that reasoning now.
Audit your GPAI model supply chain. If you use third-party GPAI models (from providers like OpenAI, Google, Anthropic, or Mistral), confirm their GPAI Code status and understand the downstream obligations that flow to you as a deployer or integrator. If you provide GPAI models, confirm your own compliance position and, for models with systemic risk, your notification and safety framework obligations.
Prepare for 2 December 2026. Two hard deadlines land: the new Article 5 prohibition on non-consensual intimate imagery and CSAM, and the Article 50(2) marking obligation for pre-August 2026 systems. Audit your generative AI tools and supply chain for compliance with both.
Do not discard your high-risk compliance work. Sixteen months sounds generous, but conformity assessments, technical documentation, risk management systems, and (eventually) CE marking processes take time to build properly. The harmonised standards this work depends on are still being finalised. Organisations that maintain momentum through the extension will be in a materially better position than those that pause and attempt to restart in late 2027.
Update governance policies and acceptable-use frameworks. AI governance policies, product development standards, and acceptable-use policies should reflect the current state of the law, including the new prohibition and the live transparency obligations. These are living documents that need updating as guidance develops.
Establish an audit trail for regulator engagement. The AI Office’s enforcement powers include requests for information and access to documentation. Ensure that technical documentation, risk assessments, testing records, and compliance decisions are preserved and retrievable. The whistleblower and complaint channels create an additional pathway for regulatory scrutiny.
Coordinate across functions. AI Act compliance is not a task for the privacy team alone. Effective implementation requires coordination across data protection, cybersecurity, product safety, employment, procurement, marketing, and (for financial services firms) regulatory affairs. Establish clear internal ownership and escalation paths.
Monitor guidance and standards. The Commission, AI Office, and AI Board are actively publishing guidelines, codes, and implementation support.