What the Digital Omnibus actually did
The Digital Omnibus on AI — formally Regulation (EU) 2026/1744 — was signed on 8 July 2026, published in the Official Journal on 24 July and entered into force on 27 July 2026. As Legal Desire reported for the legal sector, this is not a repeal of the AI Act and it is not a pause. It is a re-timing, a scope adjustment and — in one specific area — a tightening.
The headline change is the calendar. The original AI Act asked companies to be ready for high-risk obligations far sooner than most of them could realistically manage. The Omnibus formally deferred those dates.
| Date | What applies from that day |
|---|---|
| 2 February 2025 | Prohibitions on unacceptable-risk AI practices, plus employee AI literacy duties — already in force |
| 27 July 2026 | Digital Omnibus on AI enters into force |
| 2 August 2026 | Article 50 transparency obligations become enforceable, including provider marking of synthetic content and deployer deepfake/public-interest text disclosures |
| 2 December 2026 | Four-month marking grace period for pre-existing generative AI systems ends; new bans on non-consensual intimate deepfakes and CSAM generators start |
| 2 December 2027 | New compliance start date for Annex III stand-alone high-risk systems (recruitment, credit scoring, AI used in courts) |
| 2 August 2028 | New compliance start date for Annex I product-embedded high-risk systems |
Read that table twice, because the middle rows matter more than the bottom ones. Most commentary focuses on 2027 and 2028. The obligations that are now applicable and subject to enforcement came into force in August 2026.
What is already binding — and it is not nothing
Article 50 transparency is the part of the AI Act that ordinary people meet first. Under Article 50 of Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744, the obligations split by role. Providers of AI systems intended to interact directly with natural persons must design and develop those systems so the person is informed that they are interacting with AI, unless it is obvious from the circumstances; a customer-facing chatbot should therefore disclose itself at first interaction. Providers that generate synthetic audio, image, video or text content must ensure the output is marked in a machine-readable and detectable way. Deployers have narrower duties: to disclose when they deploy an AI system generating or manipulating image, audio or video content into a deepfake, and to disclose AI-generated or manipulated text published to inform the public on matters of public interest, unless human review with editorial responsibility applies. National market surveillance authorities and the EU AI Office are enforcing this now, not in 2028.
For a law firm, that translates into concrete steps. A customer-facing chatbot must be selected or configured so it discloses itself at first interaction. Generated imagery in marketing is not automatically a deployer disclosure duty under Article 50 unless it is a deepfake; however, the underlying provider’s machine-readable labels should not be removed, and advertising, professional conduct or client-protection rules may still require a higher transparency standard. If the firm publishes AI-generated text for public-interest purposes, the deployer text-disclosure rules apply; routine client correspondence and internal drafting do not automatically trigger Article 50 client disclosure.
The prohibitions from February 2025 are untouched: social scoring, manipulative techniques, untargeted scraping of facial images. The AI literacy duty under Article 4 also remains, though the Omnibus shifted its emphasis towards supportive measures rather than treating it as a strict per-employee compliance burden. In practice, providers and deployers should be able to show that the people using these tools understand what they do; guidance and training count, paperwork alone does not.
Why most legal tools were never high-risk
This is the quiet good news buried in the Omnibus. Legal research platforms, contract review assistants and drafting copilots are not automatically high-risk simply because they are used in a law firm. They are not listed in Annex III as a category. For ordinary general-purpose legal AI applications, the heaviest obligations sit with the model providers who put them on the European market — not with the firm that subscribes to them. However, a system used in the administration of justice, or in another Annex III use, may be classified differently. The classification follows the intended use, not the label “legal tech”.
What remains with the firm is the deployer role: knowing which systems you use, for what, and being able to explain that to a client or a regulator. That is a documentation exercise, not an engineering one.
The penalty numbers are unchanged
The general penalty structure in Article 99 of Regulation (EU) 2024/1689, as amended, is the same as before. Breaches of the prohibited-practice rules can cost up to €35 million or 7% of annual global turnover, whichever is higher. Breaches of high-risk and transparency obligations carry up to €15 million or 3%. The Digital Omnibus did not announce changes to those headline ceilings. For a ten-person firm in Central Europe, those ceilings are academic — but the reputational cost of a client discovering, from a competitor, that a chatbot was pretending to be a trainee solicitor is not.
And the AI Act never replaced the GDPR. Data protection rules on client confidentiality, lawful basis and processor contracts apply to AI tools exactly as they apply to any other software. The Omnibus did not touch them.
What a small firm can do this month
None of this requires a compliance department. An inventory of every AI tool in use — including the ones people bought on personal cards — a short note on what each one does with client data, and a clear line in client communications about when a human is and is not in the loop, will cover most of the practical exposure. Vendor contracts deserve a second look: the model provider carries the heaviest AI Act load, and it is reasonable to ask them to say so in writing.
For everyone else in Europe — the teacher grading with an assistant, the freelancer generating images, the parent whose teenager chats with a bot — the August 2026 date is the one that matters. Labelling is no longer a promise. It is a rule, and it is the reason AI-generated material you encounter online should increasingly say so.
A longer runway to 2027 is not the same as an empty one.
Our lawyers use an AI drafting assistant. Do we have to tell clients about it?
Article 50 does not impose a blanket duty on every AI user to tell the client that AI assisted internal drafting. The direct-interaction disclosure duty falls on providers of AI systems intended to interact with people; deployer disclosure duties cover deepfakes and AI-generated public-interest text. A lawyer using a drafting tool internally, with a human reviewing and taking responsibility for the result, is not automatically a client-disclosure trigger under Article 50. Professional-conduct and confidentiality rules may still apply, so check those separately.
What exactly ends on 2 December 2026?
Two things. The four-month transition grace period for pre-existing generative AI systems already on the market before the new rules, during which they must implement machine-readable marking, expires. And the new explicit bans on AI systems generating non-consensual sexual deepfakes and child sexual abuse material take effect.
Does the postponed high-risk deadline mean nothing applies to us until 2027?
No. The prohibitions on unacceptable-risk AI and the AI literacy duties have applied since February 2025, and Article 50 transparency obligations have been enforceable since 2 August 2026. Only the Annex III and Annex I high-risk compliance dates moved.