EU AI Act delays leave key disclosure duties intact
The EU Digital Omnibus on AI is expected to enter into force during the second half of July, 2026, changing parts of the EU AI Act without removing near-term compliance risk. Some of the law’s hardest deadlines were pushed back by about sixteen months, but transparency and disclosure obligations affecting many AI products still apply from August 2, 2026.
Standalone high-risk systems moved from August 2, 2026 to December 2, 2027, while product-embedded systems moved from August 2, 2027 to August 2, 2028. The package also softens AI literacy requirements and extends some smaller-company breaks to mid-sized firms. High-risk systems already on the market can keep the benefit of the extension only until they are significantly changed, including through retraining or changes in purpose.
GDPR obligations remain a central source of exposure for US companies processing data from people in the EU. European supervisory authorities are also coordinating more closely on transparency and disclosure issues, increasing the risk that a problem identified in one Member State spreads across markets. Data provenance is emerging as another focus, with scrutiny on web scraping, anonymization claims, and whether companies documented a legal basis before training began.