The Practitioner Guide to What Changes, What Stays, and What to Do Before August 2026
The EU AI Act has been in force since 1 August 2024. Its compliance obligations apply in phases: by risk category, by actor type, and by system status. The phased structure was always deliberate. What has changed is that some of those phases are now moving.
In November 2025, the European Commission published the Digital Omnibus, a legislative package that proposes, among other things, to push back the high-risk AI system deadlines that most organisations have been building toward. The proposal is moving fast by EU standards. The Council adopted its position in March 2026. The European Parliament's committees followed days later. The plenary voted its position on 26 March 2026. Trilogue between the three institutions is now formally open, with a target agreement before 2 August 2026.
Nevertheless, the companies will not get a break from what applies on 2 August 2026. The Digital Omnibus targets high-risk system obligations specifically. Transparency rules, penalties, and governance infrastructure apply as scheduled. The direction is clear enough to act on. August 2026 is still the operative deadline.
For a full overview of the regulation, see our EU AI Act summary. For a guide to which systems qualify as high-risk AI, see our dedicated guide.
Where enforcement stands as of March 2026
Fines of up to EUR 35 million or 7% of global annual turnover have been applicable since August 2025. But the investigatory and enforcement powers that allow authorities to act on those fines for most obligations do not apply until 2 August 2026.
TL;DRThe EU AI Act applies in four main phases: prohibited practices (February 2025), GPAI obligations (August 2025), most remaining obligations including transparency rules (August 2026), and high-risk AI in regulated products (August 2027 under the original text, now proposed for August 2028). High-risk AI in Annex III was due August 2026 but is proposed for December 2027 under the Digital Omnibus. Neither proposed deadline is final law yet.
The EU AI Act Timeline: Milestone by Milestone
1 August 2024: Entry into Force
The regulation entered into force. No compliance obligations apply yet, but the clock starts on all phased deadlines.
2 February 2025: Prohibited Practices and AI Literacy
The first live obligations. Prohibited AI practices under Article 5 are banned: social scoring by public authorities, real-time biometric identification in public spaces for law enforcement (with limited exceptions), AI that exploits vulnerabilities to manipulate behaviour, and systems that infer emotions in the workplace or education. Organisations must currently have AI literacy measures in place for staff working with or on AI systems. The Digital Omnibus proposes softening this obligation for most actors. Critically, the training and competency requirements for staff in human-oversight roles for high-risk AI systems are expected to remain. Organisations should not assume AI literacy obligations will disappear: they should differentiate between general workforce literacy (likely softened) and role-specific oversight competence for high-risk deployments (likely retained).
These obligations are in force and are not proposed for delay under the Digital Omnibus. One significant addition is in the pipeline: the Council's negotiating position proposes expanding Article 5 to add an explicit prohibition on AI systems that generate or manipulate non-consensual intimate imagery and child sexual abuse material. The prohibitions are being tightened in this respect, not relaxed.
2 August 2025: GPAI Models and Governance Infrastructure
General-purpose AI model obligations became applicable. Providers of GPAI models must maintain technical documentation, publish a summary of training data content, comply with EU copyright rules, and put in place policies for systemic risk.
The AI Office became fully operational. The penalty regime entered into effect for most infringements (penalties for GPAI obligations are delayed to August 2026). Member States should have designated national competent authorities.
GPAI providers that placed models on the market before 2 August 2025 have until 2 August 2027 to comply: a two-year grace period. New models must comply immediately.
2 August 2026: The Main Application Date
The date the bulk of the EU AI Act becomes enforceable. This is not proposed for delay under the Digital Omnibus. Organisations preparing for August 2026 should continue on that track regardless of how the Digital Omnibus negotiations resolve. The following section covers in detail what applies on this date.
2 December 2027: Proposed New Deadline for Annex III High-Risk AI
Under the Digital Omnibus proposal, as supported by both the Council (13 March 2026) and the Parliament committees (18 March 2026), the obligations for standalone high-risk AI systems listed in Annex III would apply from 2 December 2027, approximately 16 months after the original August 2026 date. Annex III covers AI used in biometrics, education, employment, access to essential services, law enforcement, migration, and administration of justice.
Both Parliament and Council have formally adopted their positions. Trilogue is now open. The deadline of 2 December 2027 reflects the agreed positions of both institutions, though the final text may still be amended in trilogue. If the Digital Omnibus is not formally adopted before 2 August 2026, the original deadline stands.
2 August 2028: Proposed New Deadline for Annex I High-Risk AI
High-risk AI systems embedded in regulated products under Annex I (medical devices under the MDR, machinery, vehicles, in vitro diagnostic devices) were originally due to comply by 2 August 2027. The Digital Omnibus proposes pushing this to 2 August 2028, one year later than the previous deadline. For more on conformity assessment for these systems, see our EU AI Act conformity assessment guide.
31 December 2030: Large-Scale IT Systems
AI systems that are components of large-scale IT systems listed in Annex X must be brought into compliance by 31 December 2030. These systems have the longest transition period given their embedded nature and cross-border governance complexity.
What Applies on 2 August 2026
TL;DR2 August 2026 is the main application date for the EU AI Act. Transparency obligations under Article 50, enforcement powers, GPAI penalties, and the majority of governance provisions all apply from this date. Existing high-risk AI systems placed on the market before 2 August 2026 are grandfathered and exempt from the new obligations, unless they undergo significant design changes after that date. The Digital Omnibus does not change this date.
August 2026 is not a soft target. The obligations below apply regardless of how the Digital Omnibus negotiations conclude.
| What applies from 2 August 2026 | Who it affects |
|---|---|
| Transparency obligations (Article 50): AI systems that interact with humans must disclose they are AI. AI-generated content (audio, image, video, text) must be machine-readable marked. Deepfakes and AI-generated text published to inform the public on matters of public interest must also carry a visible label. Emotion recognition systems must notify users. | Providers and deployers of chatbots, generative AI tools, emotion recognition systems, synthetic media systems |
| Enforcement powers for most obligations: national market surveillance authorities gain full investigatory and enforcement powers | All actors in the AI supply chain operating in the EU |
| Penalty regime fully active for GPAI: fines for GPAI model obligations now enforceable (the penalty regime for most other obligations has been active since August 2025) | Providers of general-purpose AI models |
| AI regulatory sandboxes: Member States must have established at least one per country | Organisations wanting to test innovative AI under regulatory supervision |
| Measures in support of innovation apply: SME-specific provisions, regulatory flexibility tools become operational | SMEs, startups, and academic institutions developing AI systems |
| Operators of pre-2026 high-risk AI systems must comply if significant design changes occur: existing Annex III systems are grandfathered unless significantly redesigned | Deployers and providers who modify existing high-risk AI systems |
The AI-generated content marking deadline: an important nuance
For AI systems that generate synthetic audio, images, video, or text and are already on the market before 2 August 2026, the Digital Omnibus proposes an extended deadline for machine-readable content marking (Article 50(2)). The Council proposes 2 February 2027. The Parliament adopted 2 November 2026 at its plenary vote on 26 March 2026. The final date will be settled in trilogue. For new systems launched after 2 August 2026, the marking obligation applies immediately from launch.
What Has Been Pushed and Why
TL;DRThe high-risk AI obligations, conformity assessments, technical documentation, quality management systems, CE marking, EU database registration, are proposed for delay under the Digital Omnibus. The reason is infrastructure: harmonised standards, Commission guidance, and national enforcement capacity are not ready. The Commission, Council, and Parliament committees have all agreed on the direction. The specific dates are still being negotiated.
The original EU AI Act set August 2026 as the date for full compliance by providers and deployers of high-risk AI systems listed in Annex III. For Annex I systems embedded in regulated products, the date was August 2027. The Digital Omnibus proposes changing both. It is important to note that the Omnibus is not purely a simplification package: it also tightens certain provisions. New prohibitions are being added, data protection requirements in some areas are being debated in a more restrictive direction, and the enforcement architecture is being refined. The net effect is a more workable framework, not a weaker one.
Why?
The Commission's stated rationale is the absence of the compliance infrastructure the Act assumed would be ready. Harmonised standards from CEN-CENELEC are delayed. Commission guidance on high-risk classification was expected in February 2026 but has not been finalised. Guidance on serious incident reporting, originally expected in August 2025, has no confirmed publication date. Only 8 of 27 Member States have designated single points of contact for enforcement. The pool of formally designated notified bodies under the EU AI Act remains very small.
The delay is a practical acknowledgement: enforcing obligations when the compliance tools and enforcement infrastructure are both incomplete is not viable. It does not mean the obligations are weakening.
| Obligation | Original deadline | Proposed new deadline (Digital Omnibus) | Status |
|---|---|---|---|
| Conformity assessment, technical documentation, QMS, CE marking, EU database registration: Annex III standalone high-risk AI | 2 August 2026 | 2 December 2027 | Proposed. Parliament and Council aligned. Trilogue ongoing. |
| Same obligations for Annex I high-risk AI embedded in regulated products | 2 August 2027 | 2 August 2028 | Proposed. Same legislative process. |
| Machine-readable marking of AI-generated content (systems on market before 2 Aug 2026) | 2 August 2026 | 2 November 2026 (Parliament) or 2 February 2027 (Council) | Disagreement between Parliament and Council. To be resolved in trilogue. |
| GPAI models on market before 2 August 2025: grace period to comply | 2 August 2027 | Unchanged: 2 August 2027 | No change proposed. |
The critical caveat: the Digital Omnibus has not yet been formally adopted as law. Both the Parliament and the Council have adopted their positions and trilogue is open. The target is agreement by May 2026. If the final text is not adopted before 2 August 2026, the original deadlines apply. The Parliament adopted its position at plenary on 26 March 2026. Both institutions have moved quickly. For businesses: August 2026 is a build deadline, not a watch list item.
Other Digital Omnibus Changes That Affect Compliance Planning
Registration under Article 6(3): self-assessment obligations changing
Under the current AI Act, providers who determine that a system listed in Annex III is not high-risk under Article 6(3) must register that determination in the EU database. The Commission proposes removing this registration duty entirely. The Council's position is more conservative: it wants lighter registration requirements rather than outright removal, and it wants to reinstate the obligation to register where providers self-assess their system as non-high-risk. This is directly relevant to compliance planning: organisations that have structured their classification decisions around the current registration obligation should review those assumptions. The outcome will determine how much public accountability attaches to self-assessments, and how much scrutiny they face from market surveillance authorities.
Sensitive data for bias mitigation: a live data protection dispute
One of the most actively contested elements of the Omnibus is the legal standard for processing special categories of personal data for bias detection and correction in AI systems. The Commission proposed relaxing the standard from "strictly necessary" to "necessary" and extending the permission to a broader set of actors beyond high-risk AI systems. The Council and Parliament have both pushed back, reinstating the "strictly necessary" standard and narrowing the scope. This is not a settled question. The final outcome will directly affect how organisations structure their bias-mitigation workflows and what legal bases they rely on under the GDPR. Organisations processing sensitive data for bias detection purposes should document strict necessity now and should not assume the Commission's more permissive position will prevail.
Proportionality extended to small mid-caps
The Digital Omnibus proposes extending the SME-style proportionality provisions currently in the AI Act to small mid-cap enterprises (SMCs): companies with up to 750 employees and up to EUR 150 million in annual turnover. This means simplified technical documentation requirements and capped penalties for a significantly larger group of organisations than currently benefit from those provisions. Companies that currently sit just above SME thresholds should assess whether they would qualify as SMCs and what that would mean for their compliance planning.
Enforcement: What It Looks Like in Practice
TL;DRThe EU AI Act's enforcement framework became partially operational in August 2025 and becomes fully operational in August 2026. Penalties are tiered by infringement type. National market surveillance authorities are the primary enforcement actors for most provisions. The AI Office handles GPAI. Enforcement infrastructure is uneven across Member States, but that is changing, and it does not make the fines theoretical.
The penalty regime under the EU AI Act has three tiers:
| Infringement type | Maximum fine |
|---|---|
| Prohibited AI practices (Article 5): e.g. social scoring, real-time biometric ID, manipulation of vulnerable groups | EUR 35 million or 7% of global annual turnover |
| Most other obligations (including high-risk AI requirements, GPAI model obligations, transparency duties) | EUR 15 million or 3% of global annual turnover |
| Supplying incorrect information to authorities | EUR 7.5 million or 1% of global annual turnover |
Who enforces it
National market surveillance authorities are the primary enforcement actors. Only 8 of 27 Member States have designated one as of March 2026. Italy is the first to have passed a national AI law, in September 2025. Most Member States are still building their enforcement infrastructure.
The AI Office, now fully operational, supervises GPAI model obligations and systemic risk assessments. The Commission's Digital Omnibus proposal would give the AI Office exclusive competence over AI systems built on GPAI models. The Council has pushed back: its negotiating position retains national authority competence for product-safety systems, critical infrastructure, law enforcement, financial services, and justice. The final split of competence will be settled in trilogue.
What enforcement looks like now
Fines for prohibited practices have been applicable since August 2025. Full enforcement powers for most obligations apply from August 2026. Capacity is uneven across Member States, but that does not make the obligations optional. Expect enforcement to begin with visible cases and escalate, as it did under GDPR.
The GDPR analogy is instructive but imperfect. AI obligations are more technically complex than data protection obligations, and enforcement authorities will need specialist knowledge and tooling that takes time to develop. There is also a coordination question: where GPAI models are used across multiple Member States, enforcement competence may lie primarily with the AI Office rather than national authorities. This will generate jurisdictional questions that will not be resolved quickly. For organisations building AI governance programmes, the enforcement trajectory should inform the priority sequence, not the binary question of whether enforcement is real.
What Organisations Should Do Now
TL;DRThe delay in high-risk AI deadlines does not eliminate the work required. Classification, governance, documentation, and vendor assessment do not depend on which deadline applies. Organisations that treat the Digital Omnibus as a reason to slow down are misreading the situation. The work that needs to be done is the same regardless of whether obligations apply in August 2026 or December 2027.
Your compliance calendar, regardless of how the Digital Omnibus resolves:
- Audit prohibited practices immediately. These have been in force since February 2025 and carry the maximum fines. If your organisation uses AI for employee monitoring, social benefit decisions, or law enforcement purposes, these obligations are live.
- Classify all AI systems against the Annex III taxonomy. This work does not depend on which deadline applies. You cannot assess compliance risk without knowing which category your systems fall into. Our high-risk AI guide covers the classification framework.
- Prepare for August 2026 transparency obligations. Article 50 applies from 2 August 2026 and is not proposed for delay. AI systems interacting with people must disclose they are AI. Generative AI outputs must be marked. Emotion recognition systems must notify users. These are the obligations to build toward immediately.
- Build governance infrastructure regardless of high-risk deadline. Quality management systems, risk management processes, and technical documentation take time to develop. The December 2027 deadline gives more time for formal certification. It does not reduce the documentation work. Our ISO 42001 guide covers the governance framework that aligns most directly with AI Act requirements.
- Apply AI Act requirements to vendor assessments now. If you deploy third-party AI systems in high-risk use cases, your deployer obligations are already in scope. The vendor assessment process should include AI Act compliance verification as a standard checkpoint.
- Monitor the Digital Omnibus legislative progress closely. Trilogue negotiations between the Parliament, Council, and Commission will determine the final dates. If the Omnibus is not adopted before 2 August 2026, the original deadlines apply. The Parliament voted on 26 March 2026. Trilogue is now open. The Cypriot Presidency is targeting a final agreement by May 2026.
- Review Article 6(3) classification decisions. The Omnibus proposes changes to registration obligations for systems self-assessed as non-high-risk. Re-inventory your Annex III systems, document your classification reasoning, and track how the trilogue resolves the Commission vs Council disagreement on registration. Self-assessments that are underdocumented today will be harder to defend regardless of which position prevails.
- Audit bias-mitigation workflows for sensitive data processing. If your organisation processes special categories of personal data for bias detection or correction in AI systems, document strict necessity now. The Commission's proposal to relax the standard has not been accepted by either the Council or Parliament. Do not plan on the basis that the standard is changing.
- Differentiate AI literacy obligations by role. The general AI literacy obligation for the workforce is being softened. Training and competence requirements for staff in human-oversight roles for high-risk AI systems are expected to remain. Update training programmes accordingly: broad awareness training may become lighter, but role-specific oversight competence for high-risk deployments should be treated as a firm obligation.
How Whisperly Supports EU AI Act Compliance
The EU AI Act is live, being amended, and will be enforced. A spreadsheet of deadlines is not enough. Whisperly's AI governance platform maps your AI systems to their applicable obligations across the current timeline and the Digital Omnibus scenarios, generates the documentation structure required for conformity assessment, and tracks QMS compliance across your AI portfolio.
For organisations deploying third-party AI systems and managing vendor due diligence, the vendor assessment capability provides a framework for verifying provider compliance before systems enter your environment.
Further Reading on Whisperly
Questions & Answers
Has the EU AI Act August 2026 deadline been delayed?+
The 2 August 2026 date itself has not been delayed. The Digital Omnibus proposes delaying specific obligations: primarily the conformity assessment and documentation requirements for Annex III high-risk AI systems, from August 2026 to December 2027. Transparency obligations, enforcement powers, and GPAI penalties all apply from 2 August 2026 as originally scheduled. Both Parliament and Council have formally adopted their positions and trilogue negotiations are now open. Until the Digital Omnibus is formally adopted as law, the original timeline remains in force.
What EU AI Act obligations apply right now?+
Two sets of obligations are currently live. Since 2 February 2025, prohibited AI practices are banned and AI literacy requirements apply. Since 2 August 2025, GPAI model obligations are in force (for new models; existing models have until August 2027). The penalty regime for most infringements has also been active since August 2025, though full enforcement powers for most obligations do not apply until August 2026. For a complete breakdown, see our EU AI Act summary.
What is the Digital Omnibus and what does it change?+
The Digital Omnibus is a European Commission legislative package published in November 2025. In relation to the EU AI Act, it proposes extending the deadline for high-risk AI system obligations from August 2026 to December 2027 (for Annex III systems) and from August 2027 to August 2028 (for Annex I systems embedded in regulated products). Both the EU Council and the European Parliament have formally adopted their positions and agreed on the general direction, though the final text will be settled in trilogue. For more on the AI Act background, see our EU AI Act summary.
When does EU AI Act enforcement start?+
Enforcement of prohibited practice fines has been technically applicable since August 2025. Full enforcement powers, including market surveillance, corrective orders, and the full penalty regime for most obligations, apply from 2 August 2026. National competent authorities are expected to be operational by that date. As of March 2026, most Member States are still building that infrastructure.
Does the delay in high-risk AI obligations mean I do not need to prepare?+
No. Classification, risk management, governance documentation, and technical architecture decisions do not depend on which compliance deadline applies. A system classified as high-risk and requiring conformity assessment needs the same documentation and governance infrastructure whether the deadline is August 2026 or December 2027. Starting later means compressed timelines, not eliminated work. For detailed guidance, see our conformity assessment guide.
Reviewed by: Tamara Zavisic, AI Governance Consultant