EU AI Act 2026: the deadlines after the Omnibus

The second of August 2026 was meant to be the day the EU AI Act started to bite, with risk files and sign-offs due for every company using AI in hiring, credit or education. A regulation called the Digital Omnibus on AI changed that date for the heaviest rules, and it entered into force on 27 July 2026 after publication in the Official Journal three days earlier.12 Most of the confusion now comes from the rules that did not move.
The guide below walks through what the Omnibus changed, which dates still stand in 2026 and what a business that uses Claude or ChatGPT at work should do in the next twelve months. Every date below comes from the Commission, the AI Act Service Desk or the regulation itself, since the law firm summaries written before July disagree with each other in places.
What is the EU AI Act, in one paragraph?
The EU AI Act, formally Regulation (EU) 2024/1689, entered into force on 1 August 2024 and sorts AI systems into four risk levels with different duties for each.3 Banned practices such as social scoring or manipulation that exploits a child's vulnerability may not exist at all. High-risk systems, for example AI that ranks job applicants or scores credit, carry the paperwork. Limited-risk systems such as chatbots must tell people they are talking to a machine, while minimal-risk systems like spam filters carry no duties at all.
Nine out of ten uses we see at European companies land in the last two groups. A team that drafts proposals in Claude or summarises meetings in ChatGPT is a deployer, meaning the business that uses a system, and not a provider that builds one. The heavy obligations sit with the provider.
What did the AI Act Omnibus change in 2026?
Regulation (EU) 2026/1744 of 8 July 2026 is the Omnibus, and it amends the AI Act in six places that matter to a normal business.12
| Rule | Old date | Date after the Omnibus |
|---|---|---|
| High-risk systems in Annex III (hiring, credit, education) | 2 August 2026 | 2 December 2027 |
| High-risk AI inside regulated products (Annex I) | 2 August 2027 | 2 August 2028 |
| Marking of AI-generated content, systems already on the market | 2 August 2026 | 2 December 2026 |
| Ban on non-consensual intimate imagery and child abuse material | not in the law | 2 December 2026 |
| National regulatory sandboxes | 2 August 2026 | 2 August 2027 |
| Chatbot disclosure and the other Article 50 duties | 2 August 2026 | 2 August 2026, unchanged |
High-risk rules move to December 2027
Stand-alone high-risk systems under Annex III, meaning AI used for biometrics, critical infrastructure, education, employment, migration, law enforcement and the courts, now have to comply from 2 December 2027.4 A recruitment firm in Lyon that screens CVs with an AI tool went from one week of runway in late July to about sixteen months, which buys time for the risk file without removing it.
AI in regulated products moves to August 2028
AI built into products that already fall under EU product law, such as medical devices, machinery or toys, now complies from 2 August 2028.4 A Dutch machine builder that adds a vision system to a packaging line gets one more year for its technical file and CE marking.
Content marking keeps a short grace period
Providers of systems that generate synthetic audio, images, video or text must mark the output in a machine-readable way. Systems placed on the market from 2 August 2026 comply at once, while systems already on the market before that date have until 2 December 2026.5 A marketing team that publishes AI images every week should ask its image supplier now how the marking works. The supplier carries the duty, while the team is the one that notices when the mark is missing.
A new ban from December 2026
A new prohibition in the Omnibus covers AI systems that generate non-consensual sexually explicit or intimate content, or child sexual abuse material, from 2 December 2026.24 Nobody reading this runs such a tool, although the ban matters for any platform that lets users upload and edit photos of real people.
Relief extends to small mid-caps
Some measures once reserved for SMEs now also apply to small mid-caps. The Commission defines those as companies with fewer than 750 employees and a turnover of at most 150 million euros or a balance sheet of at most 129 million euros.26 A logistics group in Hamburg with 600 staff gets simpler technical documentation and more proportionate quality management if it ever builds a high-risk system.
AI literacy becomes softer but stays
Article 4 used to say that providers and deployers must ensure a sufficient level of AI literacy among their staff. After the Omnibus they must take measures that support AI literacy, without guaranteeing a set competence level for each person, and the Commission and member states take a larger role in promoting it.25 Deployers of high-risk systems still carry their own training duties under Article 26, so the softer wording helps an office team and not an HR team that scores candidates.
Which EU AI Act duties still apply in 2026?
Three duties apply to almost every business that uses AI, whatever the Omnibus moved.
Chatbot disclosure from 2 August 2026. If you build or brand a customer service bot, a sales assistant on your website or an agent that answers support email yourself, you are usually its provider under Article 50(1) and must tell people at the first contact that they are dealing with AI.57 If you buy a finished bot, check that the supplier does it, and label deepfakes yourself under Article 50(4). A line at the foot of the page is too weak. Write one sentence at the top of the chat, such as "You are chatting with an AI assistant, type human to reach a colleague", and test that the human route works on a Friday afternoon.
Banned practices since 2 February 2025. Social scoring, manipulation of vulnerable people and emotion recognition at work have been banned since February 2025, and the Omnibus did not touch them.8 For most offices the ban is irrelevant, although a staff wellbeing tool that reads facial expressions in video calls falls straight inside it.
Measures for AI literacy. The duty is softer, still it sits in the law, and a regulator who looks into a complaint will ask what training people had before they got a licence.5 One documented training session per role, with a date and a list of names, answers that question.
Fines stay where they were
Using a banned practice can cost up to 35 million euros or 7 per cent of worldwide annual turnover, and most other breaches cap at 15 million euros or 3 per cent.3 SMEs and start-ups pay the lower of the two amounts, which makes the ceiling proportionate without making it small.
Who supervises the AI Act in your country
Every member state must name at least one market surveillance authority and one notifying authority under Article 70 of the regulation.3 Some countries give the lead to a telecoms or digital regulator and leave fundamental rights questions to the data protection authority. A French company and a Swedish company may therefore answer to different offices for the same tool. Check your own government's list before you assume the data protection authority is the only one who can call.
Where Claude and Anthropic stand under the AI Act
Anthropic, the company that builds Claude, is a provider of a general-purpose AI model, meaning a large model that can be used for many tasks, in the same group as OpenAI. The rules for these providers have applied since 2 August 2025, and the AI Office gets its full enforcement powers from 2 August 2026.8 Anthropic said in July 2025 that it would sign the EU's General-Purpose AI Code of Practice, the voluntary rulebook the Commission published for these providers.9
For you as a deployer, the provider side matters through three concrete choices:
- Buy a paid business plan. Anthropic states that Team and Enterprise do not train models on your content by default, while the consumer plans work on an opt-out.10
- Keep the data processing agreement on file. Anthropic's DPA, including the Standard Contractual Clauses for transfers out of the EU, is part of the Commercial Terms, so accepting those terms means accepting the DPA.11
- Decide where data may live. Claude Team and Enterprise store data in the US, while Amazon Bedrock offers Claude through an EU cross-region profile that keeps requests inside European regions such as Frankfurt, Ireland, Paris and Stockholm.1213
The transfer question belongs to the GDPR more than to the AI Act, and we cover it in GDPR and American AI tools.
What should European businesses do in the next twelve months?
Five steps cover what most companies with 20 to 500 staff need, and the first one takes an afternoon.
- List every AI tool in use. Ask each team what they use, not only what IT bought, and write down for each tool what goes in, what comes out, who decides and where the data is stored. A 40-person agency usually finds six tools, two of them on private accounts.
- Write an AI policy. One page on approved tools, forbidden data and who owns the rules beats twenty pages nobody opens. Our AI policy template gives you the structure to copy.
- Train people before they get a licence. Two hours per role, with a date and the attendance list saved, covers the literacy measures and makes the tools useful at the same time.
- Put the disclosure line into every chatbot. Web chat, support email and voice agents all count, and the owner of each one should confirm the change in writing before 2 August 2026 passes unnoticed.
- Flag anything that touches hiring, credit or education. If a tool on your list ranks people, start the risk file now, because December 2027 is closer than a procurement cycle.
A Claude rollout through satori-launch covers step three for €560 per user from eight users, with the accounts, a webinar and a full-day workshop in one fixed price. The legal risk file for a high-risk system is not something we write, and a company in that group needs a lawyer next to us. All satori. prices are fixed and exclude VAT.
The short version
Brussels backed off on timing and kept the substance. High-risk rules now start on 2 December 2027, while chatbot disclosure and the enforcement powers of the AI Office start on 2 August 2026. Literacy measures have applied since February 2025, now in a softer form. The breathing room is there for doing the work properly, not for waiting.
List every AI tool your company used last month in a spreadsheet with four columns, namely tool, team, data that goes in and account type. In thirty minutes you have the inventory that every later step depends on, and you will probably find the one private account that should not be there.
Sources
Footnotes
-
European Union (2026). Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026 (Digital Omnibus on AI). EUR-Lex. https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng ↩ ↩2
-
European Commission (2026). AI Omnibus enters into force. Shaping Europe's digital future. https://digital-strategy.ec.europa.eu/en/news/ai-omnibus-enters-force ↩ ↩2 ↩3 ↩4 ↩5
-
European Union (2024). Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). EUR-Lex. https://eur-lex.europa.eu/eli/reg/2024/1689/oj ↩ ↩2 ↩3
-
European Commission (2026). Timeline for the implementation of the EU AI Act. AI Act Service Desk. https://ai-act-service-desk.ec.europa.eu/en/ai-act/timeline/timeline-implementation-eu-ai-act ↩ ↩2 ↩3
-
Lewis Silkin (2026). The Digital Omnibus on AI enters into force today. https://www.lewissilkin.com/insights/2026/07/27/the-digital-omnibus-on-ai-enters-into-force-today-102nedo ↩ ↩2 ↩3 ↩4
-
European Commission (2025). Commission Recommendation (EU) 2025/1099 on the definition of small mid-cap enterprises. EUR-Lex. https://eur-lex.europa.eu/eli/reco/2025/1099/oj/eng ↩
-
European Commission (2026). Article 50: Transparency obligations for providers and deployers of certain AI systems. AI Act Service Desk. https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-50 ↩
-
European Commission (2026). Regulatory framework for AI. Shaping Europe's digital future. https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai ↩ ↩2
-
Anthropic (2025). Anthropic to sign the EU Code of Practice. https://www.anthropic.com/news/eu-code-practice ↩
-
Anthropic (2026). Plans and Pricing. https://claude.com/pricing ↩
-
Anthropic (2026). How do I view and sign your Data Processing Addendum (DPA)? Anthropic Privacy Center. https://privacy.claude.com/en/articles/7996862-how-do-i-view-and-sign-your-data-processing-addendum-dpa ↩
-
Anthropic (2026). Where are your servers located? Do you host your models on EU servers? Anthropic Privacy Center. https://privacy.claude.com/en/articles/7996890-where-are-your-servers-located-do-you-host-your-models-on-eu-servers ↩
-
Amazon Web Services (2026). Regional availability of models in Amazon Bedrock. https://docs.aws.amazon.com/bedrock/latest/userguide/models-region-compatibility.html ↩
