EU AI Act enforcement starts as high-risk rules move back
The Digital Omnibus on AI has entered into force, giving companies serving the EU market a binding compliance calendar under the EU AI Act. Article 50 transparency rules become enforceable on August 2, 2026, requiring chatbot disclosure, synthetic content marking, deepfake labeling, and notices for emotion recognition or biometric categorization systems. The European AI Office also gains penalty powers over general-purpose AI model providers on the same date, including for obligations that have applied since August 2025.
The Omnibus delays the Act’s most demanding high-risk AI requirements. Mandatory conformity assessments, CE marking, and technical documentation for stand-alone high-risk systems move to December 2, 2027, while AI embedded in regulated products such as medical devices and industrial machinery moves to August 2, 2028. The delay reflects unfinished harmonized European standards from CEN/CENELEC, which are needed to support the self-certification pathway for many Annex III systems.
Enforcement is likely to be uneven across member states. National authorities handle Article 50 oversight, while only approximately ten member states show advanced public implementation as of mid-2026. GPAI supervision is centralized at the European AI Office, whose remit now also covers AI systems based on general-purpose models developed within the same business group.
Organizations with EU exposure are expected to prioritize AI inventories, Article 50 disclosures, GPAI documentation and copyright policies, and preparation for high-risk conformity assessments rather than treating the extended deadlines as a pause.