Contact

Policy

EU AI Act: high-risk rules delayed, transparency duties already live

The Digital Omnibus delayed the heaviest AI Act obligations, but disclosure and labelling duties have applied since 2 August 2026.

A person stands where a glass walkway splits in a dark hall: one path leads to an open, lit doorway, the other to a closed gate with scaffolding still going up behind it.

On 2 August 2026 the transparency chapter of the EU's AI Act began to apply. Providers of chatbots, AI agents and other systems that deal directly with people in the EU must now make sure users know they are dealing with AI, unless that is obvious, and providers of generative tools must mark what those tools produce. Organisations that publish deepfakes, or AI-generated text meant to inform the public on matters of public interest, must label it. The heaviest obligations in the Act, the requirements for high-risk systems, did not arrive on that date.

They were pushed back by Regulation (EU) 2026/1744, known as the Digital Omnibus on AI. It was published in the Official Journal on 24 July 2026 and entered into force on 27 July, less than a week before the Act's general application date of 2 August. Stand-alone high-risk systems in areas such as employment, education and critical infrastructure now face their obligations from 2 December 2027. AI that forms part of regulated products listed in Annex I of the Act has until 2 August 2028.

The result is a split timetable that is easy to misread. The delay is adopted law, not a proposal, but it covers a specific set of obligations. For teams shipping conversational or generative features into Europe the compliance work is current, while teams building high-risk systems have gained time without gaining certainty about the technical standards they will be measured against.

How the AI Act is built, and what the omnibus changed

The AI Act, Regulation (EU) 2024/1689, entered into force on 1 August 2024 and has been switched on in stages. The ban on prohibited practices and the AI literacy duty came first, on 2 February 2025. Governance rules and the obligations for general-purpose AI models followed on 2 August 2025. The Commission describes the Act as applicable from 2 August 2026, with exceptions.

The Act sorts AI by risk. A short list of practices is banned outright. High-risk systems carry the heaviest duties: risk assessment and mitigation, high-quality datasets, activity logging, detailed documentation, clear information for deployers, human oversight, and robustness, cybersecurity and accuracy. A third tier carries transparency duties only, and the Commission says most AI systems currently used in the EU fall into a minimal-risk tier with no specific rules.

High-risk status arrives by two routes. Annex III lists sensitive uses of stand-alone systems, including biometrics, critical infrastructure, education, employment, migration, asylum and border control. Annex I covers AI inside products that are already governed by EU product legislation. The omnibus reflects that overlap: alongside the AI Act, it also amends the Machinery Regulation and the Basic Aviation Regulation.

The omnibus took less than eight months from proposal to adoption. The Commission adopted its proposal on 19 November 2025, political agreement followed on 7 May 2026, and the regulation itself is dated 8 July 2026. According to an analysis by Hunton Andrews Kurth, the proposal answered practical problems: delays in designating national authorities and conformity assessment bodies, and the absence of harmonised standards and other compliance tools for high-risk systems. The new high-risk dates are set as calendar dates, and the recitals say the Commission should have compliance support measures in place in good time to avoid further delays.

What applies now: Article 50 in practice

Article 50 splits its duties between providers, who develop systems and place them on the market, and deployers, who use them. Providers of systems that interact directly with people must design them so that users are told they are dealing with AI, unless that is already obvious. The Commission's guidance on the article judges obviousness from the point of view of a reasonably well-informed, observant and circumspect person, and expects disclosure from the start of the first interaction.

The Commission names chatbots, AI agents and avatars as examples, and its test turns on a system built for genuine two-way exchange with people rather than one that merely collects data or returns automated responses. Nothing in those criteria is limited to text, so a voice agent that holds a real conversation appears to be covered as much as a chatbot. Providers of generative systems carry a second duty: outputs must be marked in a machine-readable format and be detectable as artificially generated or manipulated. The marking duty does not extend to functions that only assist with standard editing.

Deployers carry three duties of their own. They must inform people who are exposed to emotion recognition or biometric categorisation systems. They must disclose deepfakes clearly, at first exposure at the latest, although deepfakes in artistic, creative, satirical or fictional work can be flagged in a way that does not spoil the work. And they must label AI-generated or manipulated text published to inform the public on matters of public interest, unless it has gone through human review or editorial control.

According to the Commission, fines for breaching these duties can reach 15 million euros or 3 per cent of total worldwide turnover for the preceding financial year. Enforcement sits mainly with national market surveillance authorities, with a limited role for the AI Office where general-purpose AI is involved.

The grace period and the voluntary code

One concession applies. Providers whose generative systems were already on the market before 2 August 2026 have until 2 December 2026 to add machine-readable marking; the regulation describes this as a four-month transitional period. It is narrow. It does not cover disclosure to people interacting with AI, it does not cover deployers' labelling duties, and it does nothing for a system placed on the market after 2 August.

To make marking and labelling workable, the Commission published a voluntary Code of Practice on 10 June 2026. Its first section deals with marking and detection and is aimed chiefly at providers of generative AI; its second deals with labelling and is aimed at deployers. The Commission first reported about 190 signatories on 31 July; by 16 September its published count for the two sections had risen to 95 signatories for marking and detection and 192 for labelling, and it said both it and the AI Board had assessed the code as adequate.

Signing the code is voluntary, and not signing it is not a breach. The Commission says organisations that stay outside it must show compliance with the marking and labelling duties by other adequate means, and may face more requests for information. What an adequacy assessment offers is a recognised way to show how an organisation meets its duties, which matters once national authorities begin asking questions. Signatories are also to be invited into two task forces due to launch in September 2026 to share practice on implementation.

The delay is real, but it covers the high-risk rules; the duty to tell people they are talking to a machine already applies.

What else the omnibus did

The delay drew the headlines, but the regulation changes more than dates. It adds a new prohibited practice, bringing the Commission's count to nine: AI systems that generate non-consensual sexually explicit or intimate content, or child sexual abuse material, of which so-called nudification apps are the clearest example. The text aims at realistic depictions of an identifiable person made without that person's explicit consent. The ban applies from 2 December 2026.

It widens the AI Office's reach. The Office holds enforcement powers over general-purpose models, including requesting technical documentation, evaluating models, requiring corrective measures and imposing fines. The omnibus gives it exclusive competence, with some exceptions, over AI systems built on a general-purpose model where the model and the system come from the same provider or the same corporate group.

Smaller firms get some relief. The option to provide technical documentation in simplified form, already available to SMEs, is extended to small mid-cap companies, and the simplified route to a quality management system, previously limited to microenterprises, is opened to all SMEs. The AI literacy duty is recast so that providers and deployers must take measures to support the literacy of their staff, rather than reach a guaranteed level. Member States must have at least one national regulatory sandbox operating by 2 August 2027, and the AI Office may set up a sandbox at EU level.

Not every change is a relaxation. The regulation sets out a specific legal basis for processing special categories of personal data to detect and correct bias, available only where strictly necessary and subject to safeguards, which Hunton Andrews Kurth describes as restoring a stricter standard. It also keeps a registration requirement, in simplified form, for systems in listed high-risk areas that providers assess as not being high-risk, and providers must still document that assessment before placing such systems on the market.

What is disputed or still unknown

The largest open question is standards. Harmonised standards are meant to turn the high-risk requirements into testable engineering practice, and their absence was one reason for the delay. The regulation does not link the new dates to the standards being ready, so a further slip in standards would not move the deadlines by itself. Organisations therefore face the possibility of reaching December 2027 with incomplete standards, which remains a developing issue.

Enforcement readiness is an open question. National authorities now carry the main responsibility for Article 50, yet the late designation of those authorities was itself one of the problems the omnibus set out to address. How consistently they will read the obviousness test, or the editorial-control exception for public-interest text, will only become clear as cases arise.

Several boundaries are untested. It is not settled where assistive editing ends and generation begins, when a synthetic voice or avatar becomes a deepfake, or how much human review is enough to lift the labelling duty. The Commission's guidance and the Code of Practice offer interpretations, but only authorities and, eventually, courts can settle them. The task forces that bring code signatories together on implementation were only due to launch in September 2026.

There is also a scope question around the new prohibition. The ban targets AI systems that generate non-consensual intimate content or child sexual abuse material, and the Commission's own example is nudification apps built for that purpose. How authorities will treat general image, video and audio tools that can be misused in the same way, and what safeguards they will expect from their providers, has not yet been tested.

What this means for organisations running AI in operations

For teams that run chatbots, voice agents, generative content tools or decision-support systems in real operations, the split timetable points to a clear order of work. The transparency items are overdue if they are not already done; the high-risk items are a programme for roughly the next 15 months, not a task to leave until late 2027.

  • Inventory every system that interacts with people in the EU, including phone lines and assistants embedded in apps, and decide for each whether its AI nature is obvious; where there is doubt, disclose from the start of the first interaction.
  • Establish who is provider and who is deployer for each generative feature, since marking falls on providers and labelling on deployers, and write that split into vendor contracts.
  • If a generative system was on the EU market before 2 August 2026, schedule machine-readable marking before 2 December 2026; anything placed on the market from 2 August 2026 onwards needed it from launch.
  • Treat the high-risk delay as build time: put risk management, logging, documentation and human oversight in place for employment, education, critical infrastructure and similar uses ahead of 2 December 2027, and for Annex I products ahead of 2 August 2028.
  • Review AI literacy measures, bias-testing data practices and any not-high-risk self-assessments against the amended text rather than the 2024 version.
  • Track harmonised standards and national authority guidance, and weigh whether signing the Code of Practice gives a defensible way to evidence Article 50 compliance.

Sources

  1. Official publication: Digital Omnibus on AI Act and related sectorial legislationEU Law Live · 24 July 2026
  2. EU Digital Omnibus on AI Enters Into ForceHunton Andrews Kurth (Privacy & Cybersecurity Law Blog) · 28 July 2026
  3. Commission publishes Code of Practice on marking and labelling AI-generated contentEuropean Commission · 10 June 2026
  4. AI Act | Shaping Europe's digital future (policy page and application timeline)European Commission · 3 August 2026
  5. Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026 (Digital Omnibus on AI)Official Journal of the European Union (EUR-Lex) · 24 July 2026
  6. Transparency obligations under Article 50 of the AI Act (FAQ)European Commission · 24 July 2026
  7. Strong backing for the Code of Practice on Transparency of AI-generated ContentEuropean Commission · 16 September 2026