What already applies, what was postponed, and what to do next
The EU's “Digital Omnibus” pushed the high-risk deadlines further out — and has now been formally adopted. But the next milestone is imminent: on 2 August 2026 the Article 50 transparency and labelling obligations take effect. This guide separates what is binding already, what is about to land, and what you have more time for.
Last updated: July 2026 — not legal advice
The EU AI Act (Regulation (EU) 2024/1689) has been in force since August 2024 and applies in phases. The “Digital Omnibus” — the reform package that significantly delays the obligations for high-risk AI — has now been formally adopted: Parliament approved it on 16 June 2026, the Council on 29 June 2026, with publication in the EU Official Journal expected in July. The key point: this is not the all-clear. Several duties are binding already, and on 2 August 2026 the next milestone lands with the Article 50 transparency obligations — affecting every company that runs chatbots or generative AI.
The AI Act does not land all at once — it phases in. With the Omnibus formally adopted, the roadmap looks like this:
Transitional rule for marking: generative AI systems already on the market before 2 August 2026 have until 2 December 2026 to implement machine-readable marking of their outputs. All other Article 50 obligations apply from 2 August 2026 without deferral.
The AI Act does not regulate “AI” as a blanket category — it regulates by risk. Which class your system falls into determines your obligations:
The AI Act distinguishes between the “provider” (who develops an AI system or places it on the market under their own name) and the “deployer” (who uses an AI system in a professional capacity). Most mid-market companies are deployers — and often underestimate that this role carries duties too. But adapt a system substantially, or pass it on under your own brand, and you can become a provider yourself.
Establish your role per system first — it drives the entire set of obligations. When in doubt, for instance when fine-tuning or white-labelling third-party models, check early whether you cross over into being a provider.
Yes, as a deployer. Even if you only use AI rather than build it, the AI-literacy duty and transparency rules apply. On top of that, using such cloud tools overlaps with the GDPR the moment personal data flows into your prompts.
Neither fully scrapped nor entirely postponed. The Digital Omnibus moves the high-risk obligations to 2027/2028 but leaves the existing bans, GPAI rules and literacy duties untouched. The delay was formally adopted at the end of June 2026 — and the Article 50 transparency obligations arrive as planned on 2 August 2026.
The Article 50 transparency obligations: chatbots must disclose that they are AI, generative systems must mark their outputs in a machine-readable way, and deepfakes as well as AI-generated text on matters of public interest must be visibly labelled. The only exception: generative systems already on the market before the deadline have until 2 December 2026 for the machine-readable marking.
For prohibited practices, up to EUR 35 million or 7% of global annual turnover. For breaches of other obligations, up to EUR 15 million or 3%. For supplying incorrect information to authorities, up to EUR 7.5 million or 1%.
No. Building risk management, documentation and data governance takes months. The extended deadline is a buffer, not a reason to defer — and most of the work pays into GDPR and IT security anyway.
They interlock. As soon as AI processes personal data, both apply. A clean GDPR foundation — legal basis, data minimisation, data-subject rights — is often half the battle for AI Act conformity. Our GDPR-compliant-AI guide complements this overview.
We map your AI landscape into the risk classes, clarify your role as provider or deployer, and show which steps matter now — GDPR-compliant and without the hype.
Or start with our structured AI potential and compliance analysis.
Go to the AI readiness analysis