The EU AI Act changed substantially in mid-2026, but not in the way most headlines suggest. The Digital Omnibus - endorsed by the European Parliament on 16 June 2026 and given final approval by the Council on 29 June - deferred the high-risk AI obligations from 2 August 2026 to 2 December 2027, while leaving the Article 50 transparency obligations and general-purpose AI (GPAI) enforcement powers on their original 2 August 2026 date.
In short: the deadline that moved is the one fewer organizations were going to hit first; the deadline that held applies to almost everyone running customer-facing AI.
For transformation leaders, this is not a legal-department footnote. AI governance is now a live operating-model question - one where ambition has run well ahead of readiness. In PEX Network's research into the state of business transformation, 70 percent of the 220 professionals surveyed rated AI as "critical" or "very important" to their strategic goals, yet only 43 percent had an AI governance policy in place and 29 percent had none at all. The regulation is arriving into that gap.
What is the Digital Omnibus and what did it change?
The Digital Omnibus is the first substantive amendment package to the AI Act since it entered into force on 1 August 2024. It does three things transformation leaders should track.
First, it defers the heavy high-risk regime. Standalone high-risk systems listed in Annex III - recruitment tools, credit scoring, systems used in education, law enforcement and border control - move from 2 August 2026 to 2 December 2027. AI embedded in already-regulated products under Annex I (medical devices, machinery, lifts) moves to 2 August 2028.
Second, it leaves the transparency regime alone. The Article 50 obligations - telling people when they are interacting with a chatbot, labelling deepfakes, marking AI-generated content - remain enforceable from 2 August 2026.
Third, it adds new prohibitions and reshapes oversight, including a new Article 5 prohibition on AI-generated non-consensual intimate imagery, and expanded supervisory powers for the EU AI Office over GPAI providers.
One procedural caveat matters for planning: the new dates only become legally binding once the Omnibus is published in the Official Journal, which enters into force on the third day after publication. Until that publication lands, the original 2024 timeline is the operative legal baseline. Confirm the final text against the Commission's AI Act page before making compliance decisions.
Which EU AI Act deadlines apply in 2026?
The practical calendar for a transformation programme now reads as two tracks moving at different speeds:
- 2 August 2026 (unchanged): Article 50 transparency obligations become enforceable. GPAI enforcement powers activate. National market surveillance authorities across all 27 member states can investigate and sanction breaches.
- 2 December 2026: Article 50(2) machine-readable marking for generative-AI systems already on the market before August 2026 (a narrow grandfathering window), plus new prohibited practices.
- 2 December 2027: High-risk obligations for standalone Annex III systems.
- 2 August 2028: High-risk obligations for Annex I embedded systems.
The asymmetry is the whole story. A typical enterprise deploying a customer-service chatbot or generating marketing content has a live obligation in 2026. The heavier conformity-assessment and documentation work most people associate with "the AI Act" is now a 2027 problem.
What are the Article 50 obligations for deployers?
Article 50 draws a distinction transformation leaders need to hold clearly: the provider builds the AI system, the deployer uses it under their own authority. You can be both - for different systems - and you carry deployer obligations regardless of whether you built the tool or bought it.
Four obligations sit at the centre. Chatbot and virtual-assistant disclosure under Article 50(1): people must be told they are interacting with AI, at the point of interaction, not buried in terms and conditions. Synthetic-content marking under Article 50(2): AI-generated text, image, audio and video must be marked in machine-readable form. Emotion-recognition and biometric-categorisation notification under Article 50(3). And deepfake disclosure under Article 50(4): content that looks or sounds real must be labelled, even where no deception was intended.
For organizations deploying agentic AI in customer-facing roles, the Commission's draft guidance is specific: the system must identify itself as AI directly, and a platform-applied label does not discharge the deployer's own disclosure duty. Non-compliance carries fines of up to €15 million or 3 percent of global annual turnover, whichever is higher.
Why this is an operating-model problem, not a legal one
The instinct is to route AI Act compliance to legal and move on. The PEX Network data suggests why that fails. When practitioners were asked what would most improve their ability to leverage AI, governance strategy was named by 31 percent - but it sat below training programs (49 percent), data infrastructure (48 percent) and strategic guidance (45 percent).
That ordering is the risk. Article 50 obligations demand named owners, enabled disclosure notices, retained evidence and monitoring - all of which live in the operating model, not the statute book. The report's contributors make the point without reference to regulation at all. As Doug Shannon, an AI and intelligent automation practitioner, puts it: "The ultimate goal is autonomy with accountability, where reasoning behind decisions remains clear and traceable, not lost in the system."
Similarly, Rahul Zende, principal data scientist for enterprise AI strategy at Navy Federal Credit Union, identifies the foundations: "A solid data foundation, strategic thinking and organizational readiness are also key."
Organizations that can't produce disclosure evidence or an audit trail on demand don't have an organizational-readiness problem confined to compliance - they have one that shows up everywhere AI touches the business.
A practical checklist for transformation leaders
Before 2 August 2026, deployers with any customer-facing or content-generating AI should be able to answer yes to the following:
- Inventory: Do we know every AI system in use that interacts with people, generates content, or produces deepfakes or public-interest text - including shadow AI and purchased tools?
- Chatbot disclosure: Does every customer-facing AI identify itself as AI at the point of interaction?
- Content marking. Is AI-generated content marked in machine-readable form, and are deepfakes clearly labelled?
- Ownership: Is there a named owner for each disclosure obligation, with the notice enabled, visible and retained as evidence?
- Provider vs deployer mapping: Have we mapped which obligations we hold as a deployer versus a provider for each system?
- Governance policy: Do we have an AI governance policy at all - given that 29 percent of surveyed organizations still do not?
The organizations best positioned are the ones that were already treating AI governance as part of their operating model rather than a compliance afterthought.
FAQ
Is the EU AI Act delayed?
Partly. The Digital Omnibus deferred high-risk obligations for standalone (Annex III) systems from 2 August 2026 to 2 December 2027, and embedded (Annex I) systems to 2 August 2028. But Article 50 transparency obligations and GPAI enforcement remain on 2 August 2026. Most organizations' nearest deadline did not move.
Who counts as a deployer under the EU AI Act?
A deployer is any organization using an AI system under its own authority, whether it built the system or bought it. Deployers carry their own obligations under Article 50 - for example, ensuring a purchased chatbot discloses that it is AI - independent of the provider's duties.
What are the penalties for breaching Article 50?
Up to €15 million or 3 percent of total global annual turnover, whichever is higher. Enforcement is carried out by national market surveillance authorities in each of the 27 member states.
Does the EU AI Act apply to companies outside the EU?
Yes. The obligations attach to AI systems placed on the EU market or whose output is used in the EU, so a non-EU organization serving EU users can fall within scope without any EU entity.
Where should responsibility for AI Act compliance sit?
The obligations are operational - disclosure, marking, monitoring, evidence retention - so they need named owners inside the operating model, not only legal sign-off. Treating governance as a bolted-on control is the most common readiness gap.