EU AI Act 2026 News Today: What Changed, What Still Applies, and How to Stay Compliant
The Digital Omnibus reshaped the EU AI Act timeline in July 2026. Here is what changed, what still applies now, and the compliance steps that matter most.

EU AI Act 2026 News Today: What Changed, What Still Applies, and How to Stay Compliant
The most consequential EU AI Act 2026 news today is that the regulation's timeline has been formally amended, but not paused. The EU AI Act is the European Union's horizontal law governing artificial intelligence, classifying systems by risk — prohibited, high-risk, limited-risk, and minimal-risk — and attaching obligations accordingly. In July 2026, the Digital Omnibus amendments were published in the Official Journal and entered into force, deferring the heaviest high-risk compliance deadlines while leaving prohibitions, general-purpose AI rules, and transparency duties on their original schedule. That combination has created widespread confusion, and the practical risk right now is that organisations assume everything moved when the obligations most likely to affect them did not.
Quick Answer: The Digital Omnibus, published in the Official Journal on 24 July 2026 and effective 27 July 2026, defers high-risk AI obligations to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I products. Prohibitions, GPAI rules, and Article 50 transparency duties from 2 August 2026 remain unchanged.
Building Compliance Into the Product: How WebPeak Supports AI Act Readiness
Most AI Act obligations end up being product requirements rather than legal paperwork: an AI interaction notice in the chat interface, machine-readable marking on generated media, logging that survives an audit, and a human-review path that actually exists in the code. Delivering that means touching the application layer, the data layer, and ongoing upkeep together — which is why compliance work so often pairs Next JS web development for the user-facing notices with website maintenance and support for the documentation and monitoring that regulators expect to see maintained over time. Organisations planning this can explore the wider capabilities of WebPeak, whose teams work internationally across AI implementation and web engineering.
What Exactly Did the Digital Omnibus Change?
The amendments are targeted, and reading them precisely saves a great deal of wasted effort. Two deadline shifts matter most. Obligations for standalone high-risk AI systems listed in Annex III — covering areas such as employment, education, creditworthiness, essential services, and certain law enforcement uses — now apply from 2 December 2027 rather than 2 August 2026. Obligations for AI embedded in products already governed by EU sectoral product legislation under Annex I move to 2 August 2028.
What did not move is equally important. The Article 5 prohibitions on unacceptable practices, such as social scoring and certain manipulative or exploitative systems, have applied since February 2025 and remain fully enforceable. General-purpose AI model obligations, in force since August 2025, continue as scheduled. Article 50 transparency duties apply from 2 August 2026, with one narrow accommodation: systems already placed on the market before that date have until 2 December 2026 to meet machine-readable marking requirements. A separate new prohibition on AI-generated non-consensual intimate material applies from 2 December 2026. The correct summary is therefore "deferral of the heaviest conformity work, continuation of everything about deception, prohibition, and disclosure."
Your Compliance Priorities in Order, Given the Revised Timeline
- Confirm you are not operating a prohibited practice. This has been enforceable since February 2025 and carries the highest penalties. Review any system that scores, profiles, or infers emotion in sensitive contexts.
- Ship your Article 50 transparency notices now. Chatbots and voice agents need a clear AI notice; synthetic image, audio, and video output needs marking. This deadline was 2 August 2026 and has already arrived.
- Close the machine-readable marking gap by 2 December 2026. If your generative system was live before August 2026, this is your remaining window for embedded provenance metadata.
- Complete AI literacy obligations. Staff operating AI systems need appropriate training. This is inexpensive, has been in effect since February 2025, and is frequently overlooked.
- Classify your systems against Annex III and Annex I. Do this in 2026 even though the deadlines moved, because classification determines the scope of every later obligation.
- Build the high-risk evidence base gradually. Risk management, data governance, technical documentation, logging, and human oversight for a December 2027 deadline should start well before 2027 begins.
The deferral is genuinely useful breathing room, but treating it as permission to stop work is the error most likely to cause a scramble in 2027. Classification and documentation are the slow parts.
Revised EU AI Act Compliance Timeline at a Glance
| Date | Obligation | Who It Affects | Status |
|---|---|---|---|
| 2 February 2025 | Prohibited practices and AI literacy duties | All providers and deployers | In force, unchanged |
| 2 August 2025 | General-purpose AI model obligations, governance and penalties | GPAI model providers | In force, unchanged |
| 2 August 2026 | Article 50 transparency obligations apply | Chatbots, voice agents, synthetic media | In force now |
| 2 December 2026 | Machine-readable marking for pre-existing systems; new prohibition on non-consensual intimate imagery | Generative AI already on the market | Upcoming deadline |
| 2 December 2027 | Annex III standalone high-risk obligations | HR, credit, education, essential services AI | Deferred from August 2026 |
| 2 August 2028 | Annex I embedded high-risk obligations | AI inside regulated products | Deferred from August 2027 |
Verified Facts and Practical Analysis of What This Means
The documented record is clear on the essentials: the Digital Omnibus amendments to the AI Act were published in the Official Journal on 24 July 2026 and became effective on 27 July 2026, deferring Annex III high-risk obligations to 2 December 2027 and Annex I obligations to 2 August 2028, while leaving Article 5 prohibitions, GPAI obligations, and the 2 August 2026 transparency regime in place. The four-month extension to 2 December 2026 for watermarking systems already on the market, and the new prohibition on AI-generated non-consensual intimate material from the same date, are equally part of the enacted text.
Beyond the legal text, the useful contribution is analysis rather than invented figures. In practice, the deferral changes sequencing far more than substance: the conformity assessment, technical documentation, and post-market monitoring work required for high-risk systems takes several quarters to assemble, so organisations that pause entirely will face the same crunch a year later with less market guidance available, not more. The teams handling this well are using the extra time for the unglamorous foundation — an accurate inventory of every AI system in use, its risk classification, its data sources, and its named human owner. That inventory also does double duty operationally, because AI system registers overlap heavily with the asset registers used in cybersecurity governance, and maintaining one register rather than two is markedly cheaper.
Key Takeaways
- The Digital Omnibus took effect on 27 July 2026 and deferred high-risk deadlines without pausing the AI Act.
- Annex III high-risk obligations now apply from 2 December 2027; Annex I embedded systems from 2 August 2028.
- Article 50 transparency obligations applied from 2 August 2026 and are enforceable today.
- Pre-existing generative systems have until 2 December 2026 to meet machine-readable marking requirements.
- A new prohibition on AI-generated non-consensual intimate material applies from 2 December 2026.
Frequently Asked Questions
Was the EU AI Act delayed or cancelled in 2026?
Neither. It was amended. The Digital Omnibus, effective 27 July 2026, deferred high-risk compliance deadlines to December 2027 and August 2028. Prohibited practices, general-purpose AI obligations, and transparency requirements all remain in force on their original timelines and are actively enforceable.
What EU AI Act obligations apply to my business right now?
As of today, the prohibitions on unacceptable practices, AI literacy duties for staff, general-purpose AI model obligations if you provide such models, and Article 50 transparency requirements for chatbots and synthetic media all apply. High-risk conformity obligations are the part that has been deferred.
Do I still need to label AI-generated images and video?
Yes. Article 50 transparency obligations have applied since 2 August 2026. The only accommodation is for systems already on the market before that date, which have until 2 December 2026 to implement machine-readable marking. Visible labelling expectations were not deferred.
Which AI systems count as high-risk under the Act?
Broadly, Annex III covers standalone systems used in employment decisions, education access, creditworthiness, essential public and private services, biometrics, and certain law enforcement and migration contexts. Annex I covers AI embedded in products already regulated by EU sectoral product safety legislation.
Should I stop compliance work because of the deferral?
No. Classification, data governance, documentation, and post-market monitoring take several quarters to build properly. Use 2026 to complete your AI system inventory and risk classification, because those outputs determine every subsequent obligation and cannot be produced quickly in late 2027.
Conclusion
The single insight to carry away is that the Digital Omnibus moved the deadline for proving compliance, not the deadline for behaving compliantly — prohibitions and transparency duties are live today, and the December 2026 marking deadline is the next real cliff. Organisations that read the news as a general reprieve are mismeasuring their own exposure. Your next step should be a one-page AI system inventory: every AI tool in use, what it decides or generates, its Annex classification, and the named person accountable for it. That document is the foundation for every obligation between now and 2028, and it is the first thing a regulator will ask to see.
Related articles
Artificial IntelligenceAudio Books on Artificial Intelligence: The Best Way to Learn AI on the Go
Discover the best audio books on artificial intelligence, how to choose the right one for your level, and why listening beats reading for busy learners.
Artificial IntelligenceMaryville University Master of Science in Artificial Intelligence Online Cost: A Complete Breakdown
Understand the Maryville University Master of Science in Artificial Intelligence online cost, how per-credit tuition works, hidden fees, and how to calculate total spend.
Artificial IntelligenceMahjong Artificial Intelligence: How AI Learned to Beat the World's Hardest Tile Game
Mahjong artificial intelligence solves hidden information, four-player dynamics, and luck. Here is how systems like Suphx work and how to use AI to improve your play.
