Skip to content

Blog

AI Act deadlines after the AI Omnibus: what already applies from 2026 and what is postponed

With the AI Omnibus the AI Act calendar changes: transparency for chatbots and generated content applies from 2 August 2026, the rules on high risk arrive later. What this means for a management system or a portal with an AI feature inside.

Martina Biscuola

From 2 August 2026 the AI Act, the European regulation on artificial intelligence, applies the transparency rules of Article 50: chatbots recognisable as machines and generated content that can be identified. With the AI Omnibus, in force since 27 July 2026, the rules on high risk are postponed to 2 December 2027 (Annex III) and to 2 August 2028 (Annex I).

The dates come from the news of the entry into force and from the AI Act Service Desk timeline, both from the European Commission. The examples concern a management system, a portal or an app with an AI feature inside: an assistant that answers customers, a model that sorts documents or job applications. It is a technical reading of the calendar: on a specific case, the opinion comes from a lawyer.

What is the AI Omnibus?

It is the amendment to the AI Act that entered into force across the whole Union on 27 July 2026. The Commission had proposed it on 19 November 2025, within the digital omnibus package, and according to its page on the AI Act the political agreement came on 7 May 2026. For the full text the Commission refers to EUR-Lex, from the news of the entry into force.

In the calendar the Omnibus pushes back the rules on high-risk systems. It also simplifies some obligations, partly for smaller companies.

What already applies from 2 August 2026?

The transparency rules of Article 50 apply, and from that date enforcement starts, at national and European level. According to the Commission’s Service Desk, from that day most of the AI Act’s rules apply and enforcement of the rules in force begins. Among the areas covered by enforcement are general-purpose AI models, the prohibitions and transparency.

For software being written now, this means that features that talk to people or produce content must be designed with these rules already built in.

Does a company chatbot have to say it is an AI?

Yes. According to the Commission’s page, people using a system such as a chatbot must know they are interacting with a machine. This also applies to the assistant on a website that answers customers.

In software it is an interface choice: where the notice appears, in what words, whether it stays visible for the whole conversation or only at the start, what happens when the conversation passes to a person. These are decisions to write into the requirements, together with the screens.

Does AI-generated content have to be labelled?

Yes, in different ways depending on the content. Providers of generative AI must make generated content identifiable; deep fakes and texts published to inform the public on matters of public interest must be labelled clearly and visibly. The Commission has published guidelines on the transparency obligations and a code of practice, voluntary, on marking generated content.

For some providers of systems that generate synthetic content, already on the market before 2 August 2026, the Service Desk indicates a transitional deadline of 2 December 2026 to comply with Article 50(2). From the same date the new prohibitions apply to systems that generate non-consensual sexual deepfakes and child sexual abuse material.

What is postponed with the Omnibus?

The rules on high-risk systems are postponed. According to the Commission’s news, those for Annex III systems apply from 2 December 2027. Those for high-risk AI built into physical products in Annex I, such as machinery, toys and lifts, from 2 August 2028.

Software that ranks CVs falls under the first calendar; a high-risk AI component inside a machine that a company builds and sells, under the second.

The postponement is time to prepare, not an exemption. A contract signed today for software built in phases may still be running when the rules on high risk start to apply.

Which AI systems are high risk?

They are those used in the cases the regulation lists. The Commission’s page mentions several, including AI tools for recruiting and managing workers, such as software that ranks CVs, those that give access to essential private and public services, such as credit scoring that denies a loan, and safety components in critical infrastructure.

Use matters more than technique. A model that sorts customer emails by topic and one that discards job applications before a person reads them can be built in the same way and sit in two different boxes.

What do the rules on high risk require?

The regulation requires that a high-risk Annex III system, from 2 December 2027 and before going on the market, has what the Commission describes as follows:

  • risk assessment and mitigation;
  • quality data;
  • logging of activity, for traceability;
  • detailed documentation;
  • clear information for whoever uses it, the deployer;
  • human oversight measures;
  • robustness, cybersecurity and accuracy.

Many of these items are built inside the software. Activity logs are written in the code. Human oversight is a flow: who sees the model’s proposal, who confirms it, where the record of the confirmation is kept. Documentation is written while the system is being built.

What was already in force before the Omnibus?

From 2 February 2025 the general provisions apply, that is the definitions and AI literacy, and the prohibitions. From 2 August 2025 the rules for general-purpose AI (GPAI) and governance apply. The dates are in the Service Desk timeline.

The Omnibus has intervened on AI literacy: according to the Commission’s news it has simplified the requirement that previously applied to companies, and the Commission and the Member States will have a stronger role in promoting it.

What changes for SMEs and small mid-caps?

Some measures previously reserved for SMEs are extended to small mid-caps (SMCs). According to the Commission’s page, these include simplified technical documentation requirements. The Omnibus also simplifies the obligation to register exempted AI systems in the EU database.

What should you ask the supplier before signing?

It is worth having the answer to these questions in writing:

  • who decides whether the feature falls within the high-risk cases, and with what written reasoning;
  • who keeps the documentation and the activity logs that the rules on high risk require, and where they are if one day you change supplier;
  • how the software tells users that they are talking to an AI or that they are reading generated content.

The answers can go into the scope of the work, next to the integrations and the screens, and into the contract.

How do you prepare for the AI Act deadlines?

With a list: the AI features the software should have, and for each one what it decides, who sees its result, what it produces. Next to each item, the date that concerns it: 2 August 2026 for transparency, 2 December 2027 or 2 August 2028 for high risk.

dotenv writes custom software, and Neurally is the AI company we founded. On the custom software page we explain how we build a project, from analysis to release with the documentation, and who keeps the source code and documentation: whoever paid for the work, even if one day they change supplier. That is the part that concerns the second question above.

If it is too early to talk about it, you can write the list yourself and compare it with the Service Desk timeline.

A similar problem, in your company?