EU AI Act Implementation Status 2026: The Digital Omnibus Is Now Law - Re-Baseline Your Plans

On 22 June 2026 we published a guide to the Digital Omnibus on AI which said, correctly at the time, that the deal was not yet law and that you should keep planning against 2 August 2026.
That position has now changed.
The Digital Omnibus on AI - Regulation (EU) 2026/1744 - was published in the Official Journal of the European Union on 24 July 2026 and entered into force on 27 July 2026, three days after publication. It is the first formal set of amendments to the EU AI Act since the Act was adopted in June 2024.
If you built a compliance plan against the old dates, it needs re-baselining. This post sets out the corrected EU AI Act implementation timeline: what still binds on 2 August 2026, what moved to 2027 and 2028, and what is genuinely new in the law as of this week.
How the Omnibus became law
The legislative path matters because it explains why so much published guidance is out of date.
The Commission tabled the proposal on 19 November 2025. A first trilogue on 28 April 2026 ended without agreement. The institutions returned to the table and reached a provisional political agreement on 6 May 2026, confirmed by Member State representatives in the Council on 13 May. The European Parliament formally endorsed the text on 16 June 2026, the Council gave its final green light on 29 June, and the act was signed on 8 July. Publication in the Official Journal followed on 24 July, with entry into force on 27 July 2026 - six days before the original high-risk deadline.
The timing was deliberate. The whole point was to get the deferral on the statute book before 2 August 2026, so that organisations were not briefly bound by obligations everyone knew were about to be postponed.
EU AI Act implementation timeline 2026 to 2028
| Date | What applies | Status |
|---|---|---|
| 1 Aug 2024 | AI Act enters into force (Article 113) | In force |
| 2 Feb 2025 | Article 5 prohibitions; Article 4 AI literacy | In force |
| 2 Aug 2025 | GPAI model obligations (Articles 51-56); AI Office operational | In force |
| 2 Aug 2026 | Article 50 transparency obligations; Article 99 and Article 101 penalty provisions become operative | Unchanged |
| 2 Dec 2026 | Article 50(2) marking grace period ends for pre-existing systems; new nudifier/CSAM prohibition transitional period ends | New |
| 2 Aug 2027 | Member State deadline to establish at least one AI regulatory sandbox (Article 57) | Deferred |
| 2 Dec 2027 | Stand-alone Annex III high-risk obligations apply | Deferred |
| 2 Aug 2028 | Annex I embedded high-risk obligations apply | Deferred |
What moved
Stand-alone Annex III high-risk systems now have until 2 December 2027. This covers the use cases most people think of when they think "high-risk AI": recruitment and employment tools, credit scoring, education, law enforcement, border control and critical infrastructure. The previous date was 2 August 2026. That is roughly sixteen additional months.
AI embedded as a safety component in Annex I regulated products now has until 2 August 2028. Medical devices, machinery, vehicles and toys fall here. The previous date was 2 August 2027.
One detail deserves emphasis. The Commission's original proposal contained a conditional trigger - the delay would have been tied to the availability of harmonised standards. The final agreed text replaced that mechanism with fixed dates. In practice this means there is no built-in contingency if the standards work slips again. The 2027 and 2028 dates are not provisional.
The regulatory sandbox deadline also moved. Member States now have until 2 August 2027, rather than 2 August 2026, to establish at least one AI regulatory sandbox under Article 57. The AI Office may additionally run an EU-level sandbox for systems covered by Article 75(1), with priority access for SMEs, start-ups and small mid-cap enterprises.
What did not move: 2 August 2026 is still a live date
This is the part that gets lost in headlines about the delay. Article 50 transparency obligations apply from 2 August 2026 and were not deferred.
Article 50 requires you to:
- disclose to a person that they are interacting with an AI system;
- mark synthetic audio, image, video and text output in a machine-readable format;
- notify people subject to emotion recognition or biometric categorisation systems;
- disclose deepfakes and AI-generated text published on matters of public interest.
There is one narrow grace period, and it is narrower than most summaries suggest. Only the Article 50(2) machine-readable marking duty, and only for systems placed on the market before 2 August 2026, is deferred to 2 December 2026. Systems placed on the market on or after 2 August 2026 must comply from 2 August 2026. Every other Article 50 duty - including the duty to tell users they are talking to an AI - is unaffected.
The penalty machinery also switches on. Article 99 (penalties applied by Member States) and Article 101 (fines imposed directly by the Commission through the AI Office on GPAI model providers) become operative on 2 August 2026. Article 50 breaches sit in the tier of up to €15 million or 3% of worldwide annual turnover, whichever is higher.
And the obligations already in force stay in force: the Article 5 prohibitions and Article 4 AI literacy duty since 2 February 2025, and the GPAI model obligations in Articles 51-56 since 2 August 2025.
What is genuinely new
The Omnibus is not only a postponement. Several substantive changes took effect on 27 July 2026.
A new prohibition on nudifiers and CSAM
Article 5 now prohibits AI systems that generate or manipulate non-consensual intimate images, video or audio, and child sexual abuse material. This was introduced at the European Parliament's initiative during trilogue negotiations and did not appear in the Commission's original text. A transitional period runs to 2 December 2026.
Read the scope carefully, because it is broader than an intent test. For providers, the prohibition reaches beyond systems intended for such use. It catches any system where such generation is a reasonably foreseeable and reproducible outcome without significant technical modification, and where the system lacks reasonable and adequate technical safeguards to reliably prevent it.
The practical consequence - and this is interpretation rather than statutory text - is that providers of general-purpose image and video generation tools now carry an affirmative duty to assess foreseeable misuse at design and deployment stage, and to be able to show the safeguards they put in place. "We did not build it for that" is no longer a sufficient answer.
Article 4 AI literacy, softened
The AI literacy obligation survives but in a lighter form. Article 4 now requires providers and deployers to take measures supporting AI literacy among staff and others operating systems on their behalf. It no longer demands that organisations guarantee a "sufficient level" of literacy for each individual. No specific outcome is required.
Two caveats. First, deployers of high-risk AI systems remain subject to the more specific competence and training duties in Article 26(2). Second, softer does not mean absent: the practical reading is that you should document training and awareness programmes, but you do not need to certify individual competence.
Bias detection, widened but still strict
The legal basis for processing special categories of personal data for bias detection and correction previously applied only to providers of high-risk systems. It now extends to providers and deployers of all AI systems and models.
The co-legislators did, however, reinstate the "strict necessity" threshold, reversing the Commission's proposal to lower it to a simple necessity test. That aligns with the approach recommended by the EDPB and EDPS in Joint Opinion 1/2026. Wider gateway, same height of bar.
Sectoral overlap and a narrower "safety component"
For AI embedded in products already covered by EU sectoral safety legislation, the Omnibus introduces mechanisms to avoid double regulation:
- AI embedded in products governed by the Machinery Regulation is excluded from the direct scope of the AI Act's high-risk rules. The Commission may instead adopt delegated acts under the Machinery Regulation imposing AI-specific health and safety requirements.
- The Commission is empowered to limit the application of specific AI Act requirements where sectoral legislation already imposes equivalent obligations.
- The definition of "safety component" is narrowed. AI used solely for non-safety aspects - user assistance, performance optimisation, service efficiency, automation or convenience, or quality control - does not become high-risk merely by being embedded in a regulated product, unless its failure or malfunction would endanger health and safety.
If you classified a product as high-risk purely because an AI feature sat inside a regulated device, that classification is worth revisiting.
Article 6(3) registration, simplified but not removed
If you self-assess a nominally Annex III system as not high-risk under Article 6(3), the obligation to register it in the EU database remains. What changed is that the Annex VIII information requirements have been simplified.
The documentation duty is unchanged in substance: you must document the Article 6(3) assessment before placing the system on the market or putting it into service, and national competent authorities may request that assessment.
A stronger AI Office
The Omnibus clarifies and reinforces the AI Office's supervisory role. It now has exclusive competence over AI systems built on general-purpose AI models where the model and the system come from the same provider, and over AI systems integrated into VLOPs and VLOSEs under the Digital Services Act. National authorities remain competent for law enforcement, border management, judicial authorities and financial institutions.
The AI Office also gains real enforcement tools: powers to conduct investigations and on-site inspections, to accept binding commitments, and to impose fines.
Support extended to small mid-caps
Regulatory support measures, including priority sandbox access, now reach small mid-cap enterprises. This closes a gap that previously stripped support from growing companies the moment they crossed SME thresholds.
What to do in the next 90 days
- Re-baseline your plan against the corrected dates. Anything scheduled to land by 2 August 2026 for high-risk purposes can be re-sequenced - deliberately, with a new target date recorded, not quietly dropped.
- Treat Article 50 as this quarter's deliverable. Inventory every customer-facing surface: chatbots, voice agents, AI-drafted copy, synthetic images, generated video. Confirm disclosure is present and check whether each system was placed on the market before or after 2 August 2026, because that determines whether the marking grace period to 2 December 2026 applies.
- Run the nudifier/CSAM assessment now if you provide image or video generation. The transitional period ends 2 December 2026, and the standard is foreseeability plus adequate safeguards, not intent.
- Revisit Annex I classifications in light of the narrowed "safety component" definition and the Machinery Regulation carve-out.
- Keep building the high-risk artefacts. Sixteen months sounds generous until you try to assemble a risk management file, an Annex IV technical file and a working quality management system from a standing start.
The honest read
This is a deferral, not a dismantling. The risk-based architecture, the governance structure and the core obligations are unchanged. Only the clock moved.
That distinction matters because the temptation now is to bank the time rather than use it. The readiness evidence argues against that. A 2026 EU AI Act readiness report found that 78% of enterprises had taken no meaningful steps toward AI Act compliance, 83% had no formal inventory of their AI systems, 74% had no designated internal owner for AI compliance, and 61% had no process for producing the technical documentation high-risk systems require. Those are survey findings from a private report rather than official EU figures, but the direction is consistent with what the delay itself signals: implementation was visibly off track.
An organisation with no AI inventory and no named owner does not need sixteen months of runway. It needs to start. The deferral makes a proper job possible; it does not make the job smaller.
This post is general information about the EU AI Act as at 30 July 2026, not legal advice. For the primary texts, see the AI Act, Regulation (EU) 2026/1744, the Commission's Article 50 transparency FAQ, its guidelines on transparency for AI-generated content, and the AI Act policy page.
Related reading

Harmonised Standards and Presumption of Conformity Under the EU AI Act: A Plain-English Guide to Articles 40 and 41
What "presumption of conformity" actually buys you under Articles 40 and 41, why the CEN-CENELEC standards are delayed, and what high-risk AI providers must do right now.

EU AI Act Article 9: A Plain-English Guide to the Risk Management System for High-Risk AI
Article 9 of the EU AI Act requires a continuous, lifecycle-wide risk management system for every high-risk AI system. Here's exactly what that means and how to build one.

Article 22 EU AI Act: The Plain-English Guide to Authorised Representatives for Non-EU Providers
If you build high-risk AI outside the EU and want to sell into the EU market, Article 22 requires you to appoint an EU authorised representative by written mandate - before you go live. Here's exactly what that means.