Security, risk and compliance Analysis

EU AI Act Compliance in 2026: What the Omnibus Changed and What Is Due Now

The Digital Omnibus on AI moved the high-risk deadlines and left the transparency duties where they were. What matters now is which duties already bind you, which role you hold, and whether your systems produce the records a regulator will ask to see.

For CTOs, CISOs and general counsel deciding what their AI systems must do to be sold or used in the EU, and what has to be built before December 2027.

Published
Reviewed
Reading time
17 min

The short answer

EU AI Act compliance in 2026 means meeting the duties already in force and building the evidence for the duties that Regulation (EU) 2026/1744 postponed. Prohibitions and AI literacy have applied since February 2, 2025, general-purpose model duties since August 2, 2025 and Article 50 transparency since August 2, 2026. High-risk obligations start December 2, 2027 for Annex III systems and August 2, 2028 for AI in regulated products.12

Key takeaways

  • The high-risk dates moved: stand-alone Annex III systems, such as hiring, credit scoring and exam proctoring, now fall under the requirements from December 2, 2027, and AI inside regulated products from August 2, 2028.12
  • Article 50 did not move. Disclosure for systems that talk to people and labeling of deepfakes apply now; generators already on the market before August 2, 2026 have until December 2, 2026 to mark their output in a machine-readable format.29
  • The Act reaches US, UK and Indian companies that place AI systems on the EU market or whose system output is used in the EU, with or without an EU office.1
  • A company that builds a system for its own use is its provider, and a company that turns a general-purpose assistant to a high-risk purpose becomes one. Settle the role of every system before you plan the work.1
  • A high-risk system already on the market before its deadline stays outside the requirements only while its design stays unchanged. For a product that is still being developed, plan to comply.2

Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal on July 24, 2026 and entered into force on July 27.27 It moved the start of the high-risk obligations by 16 months for stand-alone systems and by 12 months for AI built into regulated products, because the harmonized standards, guidance and national authorities those obligations depend on were delayed.2 A compliance plan built before the Omnibus was agreed carries the wrong central date: August 2, 2026 no longer applies to Annex III systems. The transparency duties in Article 50 kept their date and have applied since August 2, 2026.4

This article is engineering guidance: counsel should confirm how any specific system is classified, and nothing here is legal advice.

  • Aug 2, 2026Article 50 transparency duties for chatbots, synthetic content and deepfakes began to apply4
  • Dec 2, 2027High-risk obligations begin for Annex III systems in areas such as employment, credit and education2
  • 7%of total worldwide annual turnover, or €35 million if higher, the maximum fine for a prohibited practice1

EU AI Act deadlines after the Omnibus

Three stages of the Act are already in force, one more deadline falls on December 2, 2026, and the high-risk obligations now start on December 2, 2027 and August 2, 2028.12 The Omnibus set these as fixed dates in the regulation itself.2

DateWhat appliesStatus on September 26, 2026
February 2, 2025Prohibited practices (Article 5) and AI literacy (Article 4)In force
August 2, 2025Obligations for general-purpose AI model providers, governance and the national penalty regimeIn force
August 2, 2026General date of application, including Article 50 transparency and Commission fines for model providers (Article 101)In force
December 2, 2026Machine-readable marking for generators placed on the market before August 2, 2026; new bans on AI that generates non-consensual intimate imagery or child sexual abuse materialNext deadline
August 2, 2027General-purpose models placed on the market before August 2, 2025 must comply; each Member State must have an AI regulatory sandbox runningUnchanged for models; sandbox date moved by the Omnibus
December 2, 2027High-risk requirements for Annex III systems (Chapter III, Sections 1 to 3)Moved from August 2, 2026
August 2, 2028High-risk requirements for AI in products covered by Annex IMoved from August 2, 2027
August 2, 2030High-risk systems intended for public authorities that were on the market before their application dateUnchanged
Dates from Article 113 of the AI Act as amended by Regulation (EU) 2026/1744, and Articles 57 and 111.123

The Omnibus left Articles 9, 12, 13, 14 and 15, the core high-risk requirements, untouched.2 Its other changes that bear on engineering and procurement:

  • AI literacy Article 4 now requires providers and deployers to take measures to support the AI literacy of their staff, and states that no specific level has to be guaranteed for any individual.28
  • Small mid-caps SME relief now extends to small mid-cap enterprises: a simplified technical documentation form, a proportionate quality management system and lower fine caps.23
  • Registration A provider that decides an Annex III system is not high-risk must still register it, with less information than before.27
  • Bias data A new Article 4a allows special categories of personal data to be processed to detect and correct bias, only where strictly necessary and where synthetic or anonymized data cannot do the job.2
  • Cybersecurity A high-risk system that meets the relevant conditions of the Cyber Resilience Act is deemed to meet the cybersecurity requirement in Article 15.2

Does the EU AI Act apply to US, UK and Indian companies?

Yes, if the company places an AI system or general-purpose AI model on the EU market, or if the output of its AI system is used in the EU, wherever the company is established.1 Article 2(1)(a) covers providers placing systems on the EU market irrespective of where they are located, and Article 2(1)(c) covers providers and deployers in a third country whose system output is used in the Union.1 A US software company selling a product with AI features to European customers is a provider under the first. A credit model run from Virginia or Bengaluru that scores applicants for an EU subsidiary falls within the plain wording of the second.

The UK is outside the EU, so the Act is not UK law, and UK companies are caught through Article 2 on exactly the same terms as US and Indian ones.1 A provider established outside the EU must appoint an authorized representative in the EU, by written mandate, before it makes a high-risk system available there.1 The main exclusions are military, defense and national security uses, systems built solely for scientific research, pre-market research and testing (real-world testing excepted), and open-source systems that are neither high-risk, prohibited nor covered by Article 50.1

Provider or deployer: your role sets your duties

You are the provider of an AI system if you develop it, or have it developed, and place it on the market or put it into service under your own name; you are a deployer if you use an AI system under your authority.1 Putting into service includes supplying a system for your own use, so a bank that builds its own credit-scoring model is its provider as well as its deployer, with the heavier set of duties.1

Exhibit 1What each role must do for a high-risk system

Provider

Builds the system, or has it built, and puts it out under its own name

  • Meets the requirements in Articles 9 to 15
  • Runs a quality management system (Article 17)
  • Keeps the technical documentation for 10 years
  • Completes conformity assessment, CE marking and registration
  • Monitors the system after launch and reports serious incidents
  • Appoints an EU authorized representative if based outside the EU

Deployer

Uses the system under its own authority

  • Uses the system as its instructions for use require
  • Assigns oversight to trained people with authority to act
  • Keeps the input data it controls relevant and representative
  • Keeps the system's logs for at least six months
  • Informs workers before workplace use, and people a high-risk system helps decide about
  • Assesses fundamental rights impact if it is a public body, provides public services, scores credit or prices life and health insurance
Summarized from Articles 16 to 27, 72 and 73 of the AI Act.1

Roles also move. A deployer, distributor or other third party becomes the provider of a high-risk system if it puts its name on the system, makes a substantial modification to it, or changes the intended purpose of any system, including a general-purpose one, so that it becomes high-risk.1 The Omnibus sharpened a procurement duty: the provider of a high-risk system and any third party supplying an AI system, model, tool or component used in it must agree in writing the information and technical access the provider needs to comply, and a breach sits in the 3% fine tier.2 Contracts with model and tool vendors need that clause before the build starts.

Is your system high-risk? An Annex III walkthrough

An AI system is high-risk if it is a safety component of a product regulated under Annex I that needs third-party conformity assessment, or if its intended purpose falls in one of the eight areas listed in Annex III and no exemption in Article 6(3) applies.1 Classification follows the intended purpose the provider states, so the test is run use case by use case.1

Exhibit 2Six questions that classify a system
  1. Is it an AI system?A machine-based system that infers from its input how to generate predictions, content, recommendations or decisions. Language-model applications and agents generally qualify.If no, the Act does not apply.
  2. Is it prohibited?Article 5 bans, among others, harmful manipulation, social scoring, emotion recognition at work or in education, and scraping facial images for recognition databases.If yes, it cannot be sold or used in the EU.
  3. Is it a safety component under Annex I?AI in toys, lifts, medical devices and other products regulated under Annex I, where the product needs third-party conformity assessment.If yes, it is high-risk from August 2, 2028.
  4. Is its purpose listed in Annex III?Check the intended purpose against the eight areas listed below.If no, check Article 50 and stop here.
  5. Does it profile people?Profiling of natural persons, in the sense used by the GDPR.If yes, it is high-risk, with no exemption.
  6. Does an Article 6(3) condition apply?A narrow procedural task; improving the result of a completed human activity; detecting patterns without replacing human assessment; or a preparatory task.If yes, document the assessment and register the system. If no, it is high-risk from December 2, 2027.
Our sequencing of Articles 3, 5 and 6 and Annexes I and III, as amended.12 Sources: [1], [2]
  • 1. Biometrics Remote biometric identification (identity verification excluded), categorization by sensitive attributes, and emotion recognition.
  • 2. Critical infrastructure Safety components in digital infrastructure, road traffic, water, gas, heating and electricity.
  • 3. Education Admission, grading learning outcomes, assigning education levels, and detecting cheating in tests.
  • 4. Employment Targeted job ads, filtering applications and evaluating candidates; decisions on promotion, termination and task allocation; monitoring performance and behavior.
  • 5. Essential services Public benefit eligibility, credit scoring (fraud detection excepted), life and health insurance pricing, and emergency call triage.
  • 6 to 8. Public powers Law enforcement; migration, asylum and border control; and the administration of justice and democratic processes.

For large companies outside the public sector, the exposure sits mostly in areas 4 and 5: recruiting tools, workforce analytics, lending and insurance pricing.1 A provider relying on Article 6(3) must document its reasoning before launch, produce it on request and register the system.12 For areas 2 to 8, conformity assessment is internal control with no notified body, so your own evidence is the whole case.1

What Article 50 requires today

Article 50 has applied since August 2, 2026 and requires disclosure whenever people interact with an AI system or see content it generated or manipulated; for most companies it is the part of the Act due now.45

Article 50 duties in force now

  • Providers of systems that interact directly with people tell them they are dealing with an AI system, unless that is obvious to a reasonably well-informed person (Article 50(1)).
  • Providers of systems that generate synthetic audio, images, video or text mark the output in a machine-readable format so it can be detected as artificially generated (Article 50(2)). Systems on the market before August 2, 2026 have until December 2, 2026.
  • Deployers of emotion recognition or biometric categorization systems inform the people exposed to them (Article 50(3)).
  • Deployers disclose deepfakes, and disclose AI-generated text published to inform the public on matters of public interest unless a person reviewed it and holds editorial responsibility (Article 50(4)).
  • The information is given clearly, at the latest at the first interaction or exposure, and meets accessibility requirements (Article 50(5)).

The other Article 50 duties took effect on August 2, 2026 with no grace period.9 The final Code of Practice on Transparency of AI-generated Content, published June 10, 2026, covers marking and detection for providers and labeling for deployers; about 190 companies and organizations had signed it by the end of July 2026.6 Under the Commission's guidelines, signing the code is one way to show compliance with the marking and labeling duties; a company that does not sign must show equivalently adequate means.5 In engineering terms: a disclosure component in every conversational surface, a marking step in every generation pipeline, and a detection check in release testing.

The high-risk requirements, mapped to what engineering builds

Each high-risk requirement in Articles 9 to 15 turns into a specific artifact an engineering team produces and keeps current, and a regulator's first request will be for those artifacts.1 Built into the delivery pipeline, they cost little to maintain; reconstructed a month before an audit, they cost a great deal and prove less.

RequirementWhat the Act asks forWhat the engineering team produces
Risk management (Article 9)A continuous process across the lifecycle; testing against prior defined metrics and probabilistic thresholdsA risk register tied to the intended purpose and foreseeable misuse; release gates in CI that fail when a metric crosses its threshold
Data governance (Article 10)Documented practices for training, validation and test data, including examination for bias and data gapsDataset records with origin, collection purpose, labeling method and known gaps; bias tests by affected group; for systems that train no model, the same for test data only
Technical documentation (Article 11, Annex IV)A technical file that shows compliance, kept for 10 yearsArchitecture, component and model inventory, design choices, evaluation method and the post-market monitoring plan, versioned with the system
Record-keeping (Articles 12, 19, 26)Automatic logging of events over the system's lifetime; logs kept at least six monthsStructured traces of inputs, retrieved context, outputs, tool calls, model and prompt versions and human overrides, with a retention policy
Transparency to deployers (Article 13)Instructions for use, including accuracy metrics, known limitations, oversight measures and how to collect logsInstructions for use maintained as a release artifact, matched to each deployed version
Human oversight (Article 14)People able to understand, monitor, override and reverse the output, and to halt the system safelyReview queues, override controls, a stop control that leaves the system in a safe state, and screens that show sources and confidence
Accuracy, robustness and cybersecurity (Article 15)Declared accuracy metrics; resilience to errors and feedback loops; defenses against data poisoning, model poisoning, adversarial inputs and confidentiality attacksAn evaluation suite with the declared metrics, fallback paths, drift monitoring, and red-team results that include prompt injection
Our mapping of the high-risk requirements to engineering deliverables. Article references are to the AI Act as amended.12

Around those seven requirements sit the provider's process duties: a quality management system, conformity assessment, the EU declaration of conformity, CE marking, registration and monitoring after launch.1 The post-market monitoring plan is now part of the technical documentation, and the Commission owes a template for it by September 2, 2027.2 Serious incidents must be reported within 15 days of awareness, two days for a widespread infringement or serious disruption of critical infrastructure, and 10 days for a death.1 Those clocks need an on-call runbook written before launch. In the systems we build, the trace, the evaluation gate and the override queue ship in the first release, and our AI development teams generate the technical file from the pipeline itself.

How the EU AI Act treats AI agents

An AI agent is an AI system under the Act, which has no separate category for agents, so it is classified by its intended purpose like any other system.1 A customer service agent that talks to people carries the Article 50(1) disclosure duty today. An agent that screens candidates or decides on credit is an Annex III system, and if it profiles the people it assesses, no Article 6(3) exemption is available.1 A company that connects a general-purpose assistant to its hiring workflow has changed that system's intended purpose and becomes its provider.1

The high-risk requirements map closely onto agent architecture. Article 14's stop control is the agent's kill switch. Article 12's logs are its step-by-step traces. Article 15's duty to resist attempts to alter a system's use or outputs is where prompt injection through the documents and emails an agent reads belongs, and its feedback-loop rule is relevant to agents that learn from their own memory.1 Our guide to AI agent guardrails maps these controls in detail. Supervision depends on who built the agent: if a model provider builds an agent on its own general-purpose model, the AI Office supervises it in most cases; an agent your company builds on a third-party model stays with national authorities.2

EU AI Act penalties

Fines reach €35 million or 7% of total worldwide annual turnover, whichever is higher, for prohibited practices, and €15 million or 3% for most other breaches, including Article 50.1 The penalty regime has applied since August 2, 2025, and Member States set the detailed rules.1

BreachMaximum fineArticle
Prohibited practices€35 million or 7% of total worldwide annual turnover, whichever is higher99(3)
Obligations of providers, deployers, importers, distributors and authorized representatives; Article 50 transparency€15 million or 3%, whichever is higher99(4)
Incorrect, incomplete or misleading information given to authorities or notified bodies€7.5 million or 1%, whichever is higher99(5)
General-purpose AI model providers, fined by the Commission€15 million or 3%, whichever is higher101
SMEs (all tiers) and small mid-caps (the 3% and 1% tiers)Whichever of the two amounts is lower99(6), 99(6a)
Penalty tiers in Articles 99 and 101, with the small mid-cap cap added by the Omnibus.12

Authorities weigh gravity, duration, the people affected, company size and cooperation.1 Until December 2, 2027, the live exposure for most enterprises is the prohibitions and Article 50.

An EU AI Act readiness plan in five workstreams

Readiness takes five workstreams, run in this order because each depends on the one before.

  1. Inventory and classify List every AI system you build, buy or embed, including agents and AI features in vendor products. Record your role, the intended purpose, the Annex III area and any Article 6(3) reasoning; counsel signs off the classification.
  2. Close what is already due Screen every system against Article 5, including the two bans that apply from December 2, 2026. Ship Article 50 disclosure and output marking, and record the AI literacy measures you run for staff.
  3. Put the evidence in the pipeline Generate traces, evaluation results against declared thresholds and dataset records from the system on every release, so the technical file stays current.
  4. Design oversight and incident response Build the override, review and stop controls; name the people who hold oversight and train them; write the serious-incident runbook against the 15-day, 10-day and two-day clocks.
  5. Fix contracts and change control Write information and access terms into supplier contracts. Record for every release whether it is a significant change, and pre-determine the retraining you will assess at conformity assessment. Appoint an EU authorized representative if you provide high-risk systems from outside the EU.

The Omnibus bought time for high-risk systems. A company that uses the next 14 months to build traces, evaluation gates, oversight controls and supplier terms into its delivery pipeline will reach December 2027 with the technical file written by its own systems. A company that waits will write that file by hand, under a deadline, for a system it can no longer freeze.

Questions leaders ask

Has the EU AI Act high-risk deadline been delayed?

Yes. Regulation (EU) 2026/1744 moved the high-risk obligations for Annex III systems from August 2, 2026 to December 2, 2027, and for AI in products covered by Annex I from August 2, 2027 to August 2, 2028.2 It entered into force on July 27, 2026, and the dates are fixed in the text. The prohibitions, the general-purpose model duties and Article 50 transparency kept their original dates.24

Does the EU AI Act apply to US companies?

Yes, when a US company places an AI system or general-purpose AI model on the EU market, or when its AI system's output is used in the EU, even with no EU office.1 A US provider of a high-risk system must also appoint an authorized representative in the EU by written mandate before making the system available there.1 Purely domestic US use with no EU output is outside the Act's scope.1

Does the EU AI Act apply to the UK?

Not as UK law, because the UK is outside the EU. UK companies are covered on the same terms as any company outside the EU: when they place AI systems on the EU market or when their system's output is used in the EU.1 A UK lender scoring EU applicants, or a UK software company selling an AI product to EU customers, should plan as if the Act applies in full.

What does Article 50 of the EU AI Act require?

Article 50 requires providers to tell people when they are interacting with an AI system and to mark synthetic audio, images, video and text in a machine-readable format. Deployers must disclose deepfakes, AI-generated public-interest text without editorial review, and the use of emotion recognition or biometric categorization.1 It has applied since August 2, 2026; generators on the market before that date have until December 2, 2026 to add marking.2

Is AI literacy still mandatory under the EU AI Act?

Yes, in a lighter form. Since the Omnibus, Article 4 requires providers and deployers to take measures to support the AI literacy of their staff and others operating AI on their behalf, and it states that no specific level has to be guaranteed for any individual.2 The Commission and Member States now have their own duty to support companies, and the Commission must publish practical examples.23

What are the fines for breaking the EU AI Act?

Up to €35 million or 7% of total worldwide annual turnover, whichever is higher, for prohibited practices; up to €15 million or 3% for most other obligations, including Article 50; and up to €7.5 million or 1% for misleading information given to authorities.1 SMEs pay the lower of the two amounts, and the Omnibus extended that cap to small mid-caps for the lower two tiers.2

Sources

  1. Regulation (EU) 2024/1689 (Artificial Intelligence Act)Official Journal of the European Union, July 12, 2024
  2. Regulation (EU) 2026/1744 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 (Digital Omnibus on AI)Official Journal of the European Union, July 24, 2026
  3. AI Omnibus enters into forceEuropean Commission, July 27, 2026
  4. AI ActEuropean Commission, Shaping Europe's digital future
  5. Guidelines on transparency obligations for providers and deployers of certain AI systemsEuropean Commission, July 2026
  6. Code of Practice on Transparency of AI-generated ContentEuropean Commission, final code published June 10, 2026
  7. EU Digital Omnibus on AI Enters Into ForceHunton Andrews Kurth, Privacy and Cybersecurity Law Blog, July 28, 2026
  8. EU AI Act Omnibus Agreement: Postponed High-Risk Deadlines and Other Key ChangesGibson Dunn, May 27, 2026
  9. EU AI Act unpacked #34: The final Digital Omnibus on AIFreshfields, July 10, 2026

Written by DigyAi Engineering from the systems we build and run. Every figure links to its public source, and every link and figure was checked on September 26, 2026. No client data appears in our insights.

Read next

All insights
  • An AI agent on its own tower reads web pages, email and tool text from an island outside; every action it plans passes through a lit policy engine, which lets calls to the company's systems through and stops a call to send data out at a lowered barrier. A kill switch is wired to the agent at the front.

    Security, risk and compliance Guide

    AI Agent Security: The Threat Model and Controls a CISO Should Require

    For CISOs and security architects deciding whether an AI agent is safe to connect to production systems, company data and customers.

    16 min read

  • An AI agent's road runs into a policy hall that classes every action, and reads and reversible changes run on their own. The irreversible road alone leaves the plinth, across a bridge to the outside world, and a lit gate holds it until a named person beside it approves.

    AI agents Playbook

    AI Agent Guardrails: 8 Controls That Hold Up in Production

    For CTOs and CISOs deciding what an AI agent may do on its own before it touches customers, money or production.

    13 min read

  • Your own cases, stored in a golden-set archive, run through your system to a release gate whose board shows every segment against a threshold its owner signed in advance; one segment falls short and the gate holds, then the rerun clears the line and the release crosses a bridge to production.

    LLM and RAG engineering Guide

    LLM and AI Agent Evaluation: How to Prove a System Is Ready to Ship

    For CTOs, heads of AI and risk owners deciding whether an LLM application, RAG system or AI agent is ready to leave the pilot, and what evidence should back that decision.

    16 min read

Get in touch

Tell us what you are building.

Write it as big as you imagine it.