Since 2024, 2 August 2026 had been the key date for the European Artificial Intelligence Regulation: the day on which most of its obligations were due to become applicable. That date has now arrived, but with a last-minute change of script.
The so-called Digital Omnibus, approved in extremis by the European institutions, reorganised the timetable just weeks before the deadline. The result has left many companies with the wrong impression: “the AI Act has been postponed”.
That is not the case. One part has been postponed — the rules concerning high-risk systems — while the part affecting the everyday use of AI by any company has been maintained, with all the consequences that entails.
This article, the first in our series on AI Act compliance, explains exactly what has changed, what has been enforceable since 2 August, and what your company should do now.
What is the Digital Omnibus and why did it arrive so late?
The Digital Omnibus is Regulation (EU) 2026/1744 of 8 July 2026, published in the Official Journal on 24 July and in force since 27 July, just six days before the key date.
It is the first major reform of the AI Act before a significant part of its obligations had even started to apply, and its rationale is practical: the harmonised technical standards that were supposed to accompany the high-risk requirements were not ready, and the Commission chose to readjust deadlines and reduce the administrative burden — particularly for SMEs and small mid-cap companies — rather than require the impossible.
The underlying principle is worth remembering: the Omnibus changes the timetable, not the destination.
What has been postponed: high-risk systems
At the heart of the reform is the postponement of the obligations applicable to high-risk AI systems — those listed in Annex III of the Regulation, including recruitment, creditworthiness assessment, biometrics, education, critical infrastructure, essential services, justice and migration, among others.
The requirements that were due to become applicable on 2 August 2026 — risk management, data governance, technical documentation, event logging, human oversight, accuracy, robustness, cybersecurity and conformity assessment — have been deferred until 2 December 2027.
For AI integrated into products already subject to sector-specific regulation — Annex I: machinery, medical devices, toys, etc. — the new deadline is 2 August 2028.
Two points are important to avoid costly mistakes.
First: this is a postponement, not an exemption. The substance of the obligations has not changed, only the date on which they become enforceable. Given the amount of technical work they require, companies would be well advised not to waste the additional time by simply waiting.
Second: the high-risk regime will apply to systems already in operation, not only to those placed on the market from that date onwards. If your company currently uses an Annex III system, the countdown is already running.
What does apply from 2 August: transparency, penalties and supervision
This is what many companies are overlooking. 2 August 2026 remains the general application date of the Regulation, bringing three fully enforceable areas into effect.
First, the transparency obligations under Article 50, which are the most visible to customers, employees and users. In summary: anyone operating chatbots or systems that interact with people must inform them that they are interacting with AI; providers of generative systems must mark synthetic content in a machine-readable format; and anyone disseminating deepfakes or AI-generated text on matters of public interest must disclose this.
The technical marking obligation under Article 50(2) includes a specific transition period for certain systems already on the market, but the industry is already moving in this direction. The clearest example is Anthropic’s announcement that it will incorporate invisible watermarks into texts generated by its Claude models specifically to comply with the European Code of Transparency.
When major providers start marking their content, the question shifts to each company using those systems: are your notices, labels and internal processes up to standard?
We will address this area in the third article in this series, including examples of compliant notices.
Second, the penalty regime and supervisory authorities are now fully operational: Member States have designated their authorities, and fines can reach €35 million or 7% of worldwide annual turnover for the most serious infringements.
The era of voluntary compliance is over.
Third, the areas already in force remain applicable and are reinforced: the prohibited practices under Article 5 — to which the Omnibus adds new prohibitions, notably concerning non-consensual intimate images, applicable from 2 December 2026 — the supervision of general-purpose AI (GPAI) models by a European AI Office with expanded powers, and AI literacy under Article 4.
The wording of the latter obligation has been adjusted by the Omnibus: companies are no longer required to ensure a specific level of competence, but rather to adopt measures that support AI literacy. In practice, it remains an obligation to provide and document appropriate training. We will address this in the fourth article in the series.
What your company should do now: five steps
1. Create an inventory
You cannot comply with what you have not mapped. Identify which AI systems your company uses — including those integrated into third-party tools — and classify them according to their function and risk.
This will be the subject of the second article in this series.
2. Determine your role for each system
The obligations under the AI Act depend on whether you are a provider, deployer, importer or distributor, and the same company may have different roles in relation to different systems.
This analysis must come before any compliance plan.
3. Update your transparency measures
Review notices in chatbots and assistants, the labelling of AI-generated content that you publish, and the consistency between what your policies say and what your teams actually do.
It is the first thing a customer — and an inspector — will see.
4. Document training
Article 4 requires AI literacy measures proportionate to how your staff use AI.
A short training programme, adapted to different employee profiles and properly documented, can meet the obligation while also reducing genuine operational risks.
5. Review contracts with your AI providers
Who is responsible for what? What compliance guarantees are being provided? What information will you receive in order to comply with your own obligations?
If your company integrates third-party model APIs into its products, this point is critical, and we will dedicate a specific article to it.
The timetable at a glance
From 2 August 2026: Article 50 transparency requirements, supervisory authorities and penalties, GPAI supervision and — already applicable beforehand — prohibited practices and AI literacy.
From 2 December 2026: new prohibitions introduced by the Omnibus.
From 2 December 2027: requirements for high-risk systems under Annex III.
From 2 August 2028: AI integrated into regulated products under Annex I.
Conclusion
The Digital Omnibus has given high-risk AI projects more time, but it has left untouched — and already enforceable — everything affecting the everyday use of AI within companies.
The correct reading of the current situation is not “we have until 2027”, but rather “the visible obligations are already in force, and the technical obligations have a fixed deadline”.
Companies that organise their AI inventory, transparency measures and training now will enter 2027 with the work already underway; those that interpret the reform as a pause will be late twice.
At Ferrer-Bonsoms & Sanjurjo, we advise technology companies and businesses using AI throughout the entire AI Act compliance process: system inventories and classification, transparency policies, AI literacy programmes and the review of contracts with AI providers.
If you would like to assess your company’s current position, contact our team.
This article is for informational purposes only and does not constitute legal advice. For an assessment of your specific circumstances, please contact our team.
