The EU’s AI rulebook changed again. Here is what companies must follow now
The European Union’s AI rulebook has not been delayed as a whole. Instead, its compliance calendar has been split: transparency duties are applying now, while some requirements for high-risk systems have moved to later dates.
The change follows the Digital Omnibus on AI, which entered into force across the EU on July 27, 2026. The amended framework gives companies more time for specified high-risk obligations while preserving rules covering transparency, prohibited practices, general-purpose AI and enforcement.
What changed on July 27
For high-risk AI systems listed in Annex III—including systems used in areas such as employment, education, law enforcement, migration and access to essential services—the main obligations now begin on December 2, 2027.
High-risk AI embedded in regulated physical products covered by Annex I, such as certain machinery, toys and lifts, has a later deadline: August 2, 2028.
Those dates replace the earlier timetable for the specified categories. They do not remove other duties that are already in force or now applying.
What started on August 2
Transparency obligations under Article 50 began applying on August 2, 2026. The European Commission says the rules are intended to help people recognize when they are interacting with AI or when content has been generated or altered by AI.
In covered circumstances, providers must design systems to inform users when they are directly interacting with AI. Providers must also use machine-readable marking to enable detection of AI-generated or manipulated content, subject to the regulation’s transition rules and exceptions.
Deployers—the organizations using an AI system—have separate responsibilities. They must inform people when they are exposed to covered deepfakes, certain AI-generated content on matters of public interest when there has been no human review or editorial control, and emotion-recognition or biometric-categorization systems.
The rules do not mean that every chatbot exchange, image, video or publication automatically requires the same notice. Coverage depends on the type of system, the role of the organization, the content involved and the exceptions in the regulation.
What remains prohibited or enforceable
The revised framework preserves prohibitions on AI systems that generate non-consensual sexually explicit or intimate content and child sexual abuse material. Under the implementation timeline, those specified prohibitions begin applying on December 2, 2026.
December 2, 2026 is also the transition deadline under Article 50(2) for certain providers of AI systems, including some general-purpose AI systems that generate synthetic content and were already placed on the market before August 2, 2026.
The Digital Omnibus expands the European AI Office’s oversight of certain AI systems, including systems built on general-purpose models and systems embedded in large online platforms and search engines. The Associated Press reported that the office is adding staff to monitor major AI firms, giving the rules practical reach beyond companies headquartered in the EU.
General-purpose AI obligations began applying in 2025 and remain part of the framework. A postponed high-risk deadline therefore does not create a compliance pause.
Who needs to pay attention
Companies should first identify whether they are acting as a provider, a deployer or both. A software company developing an AI tool may be a provider, while a retailer, employer, school, publisher or platform using that tool may be a deployer.
Companies based outside the EU should also assess their exposure. The framework can matter when products, models or AI-generated content are supplied to people in the European market. That means U.S. and other non-EU firms serving European users may need to review the same disclosure, labeling and governance questions as EU-based businesses.
A practical compliance checklist
- Inventory AI systems, models and synthetic-media tools used or offered in Europe.
- Classify each system and identify whether the organization is a provider, deployer or both.
- Review user notices for covered AI interaction, deepfakes, public-interest content and biometric or emotion-recognition use.
- Verify machine-readable marking and content-labeling capabilities, including applicable transition rules.
- Document exceptions, human review and editorial-control processes.
- Update compliance calendars for December 2, 2026; December 2, 2027; and August 2, 2028.
The practical consequence is not less regulation but a more staggered schedule. Companies must track several live obligations at once: transparency and enforcement for applicable rules now, specified prohibitions and a synthetic-content transition milestone on December 2, 2026, and different high-risk deadlines in 2027 and 2028.
Sources
- Regulation (EU) 2026/1744 — Digital Omnibus on AI, EUR-Lex
- Transparency obligations guidance — European Commission
- EU AI Act implementation timeline — AI Act Service Desk
- EU begins crackdown on AI risks — Associated Press
Look for updates to this story
Discover more from Interactive News
Subscribe to get the latest posts sent to your email.