What happened today — and why it matters this fast
The Digital Omnibus on AI was signed on 8 July, published in the Official Journal on 24 July, and enters into force today — just three days after publication. The compressed timeline is no accident: the regulation itself says it was adopted "as a matter of urgency" because the high-risk AI deadline it amends lands on 2 August — this Sunday.
That means every company deploying AI systems to users in the EU's 450-million-person single market now has six days to meet the first enforceable transparency rules. The clock is already ticking.
The road to today's law was not smooth. The European Commission proposed the Omnibus on 19 November 2025 following industry complaints about the AI Act's administrative burden. Two trilogues — legislative negotiations between the Commission, Parliament and Council — were needed. The first opened in March 2026. The second, in late April, ended without agreement. A provisional deal was finally struck at 4:30 a.m. Brussels time on 7 May, endorsed by the Parliament on 16 June, and given the Council's final green light on 29 June.
The result is a split calendar that affects everyone differently — from the chatbot you talk to tomorrow, to the recruitment algorithm that might screen your next job application, to the medical device that could one day help diagnose you.
The compliance calendar: four dates that matter
Let's translate the legalese into a simple timeline.
2 August 2026 — this Sunday. Article 50 transparency obligations become enforceable. This is the deadline that most immediately affects ordinary people. Three things must happen: first, any AI system interacting with a person — a chatbot, a voice assistant, an automated call centre — must disclose that you are talking to a machine. Second, providers of generative AI must embed machine-readable markers in AI-generated images, audio, video, and text, so that automated tools can detect them. Third, anyone publishing deepfakes — AI-generated content depicting real people in ways that could appear authentic — must label that content visibly as AI-generated.
There is one small grace period: generative AI systems already on the EU market before 2 August get until 2 December to comply with the watermarking requirement. But for new systems launched on or after Sunday, and for the chatbot-disclosure and deepfake-labelling duties, there is no extension.
One honest caveat: the watermarking obligation lands in a technology environment that has not yet settled on a single standard. OpenAI and Google DeepMind jointly announced in May 2026 that ChatGPT image outputs now carry both SynthID pixel-level watermarks and C2PA cryptographic metadata — the dual-layer approach the AI Office recommends. But smaller providers and text-generation companies face a harder question, as TechTimes reported on 21 July. No single watermarking technology currently meets all four statutory requirements simultaneously. The law is ahead of the tools — and that creates real-world compliance risk.
2 December 2026. Two new hard prohibitions take effect, closing a gap the original AI Act left open. First, a ban on AI systems that generate or manipulate non-consensual intimate imagery — the so-called "nudifier" apps that produce realistic nude depictions of real, identifiable individuals. Second, a ban on AI systems that generate child sexual abuse material.
For providers, the prohibition applies where generating such material is the system's intended purpose, or where it is a reasonably foreseeable outcome and the company has not put adequate technical safeguards in place — refusal training, output controls, content filtering. Companies cannot rely on terms-of-service fine print alone; the regulation requires technical barriers at the model or application level. A deployer — the person actually using the system — is caught only when they use it for that prohibited purpose.
The penalty is as serious as it gets under the AI Act: up to €35 million (about $40 million) or 7% of global annual turnover, whichever is higher.
The NCII ban was triggered, in part, by a specific incident: xAI's Grok assistant generated an estimated 3 million sexualised non-consensual images in 11 days. The EU's approach — a supply-side prohibition on the AI capability itself — differs from the American response, which targets the distribution channel through the TAKE IT DOWN Act signed in May 2025. Europe is saying: if your tool can be used to create this harm, you must build the guardrails, or you cannot offer it here.
2 December 2027. This is the big one for companies. The full suite of high-risk AI obligations — risk management systems, technical documentation, data governance, human oversight, third-party conformity assessments, CE marking, and database registration — applies to standalone Annex III systems. These are AI applications used in recruitment screening, credit scoring, law enforcement decision-support, education, border control, and similar sensitive domains. That is roughly 16 months more time than the original August 2026 deadline.
2 August 2028. The same obligations extend to Annex I embedded systems — AI built into regulated products like medical devices, machinery, civil aviation equipment, and lifts.
The deadlines are now fixed calendar dates, not conditional on standards being ready. The Commission had originally proposed tying the deferral to a trigger — the rules would apply once it confirmed that harmonised standards and support tools were available. The final text removed that mechanism. That is good for planning certainty, but it does not guarantee the compliance infrastructure will be ready. Analysis from the Cloud Security Alliance suggests the full suite of approximately 35 harmonised standards from CEN-CENELEC may not be available before December 2026 — giving companies barely 12 months of standards-backed runway, not 18.
What this actually means for you
If you are not a lawyer or a compliance officer, here is the practical version.
You will know when you are talking to a bot. From Sunday, any company deploying an AI chatbot or voice assistant in the EU must tell you. This is not a hypothetical concern — approximately 78% of organisations had taken no meaningful compliance steps this spring, and more than half could not produce a basic inventory of the AI systems they run, according to analysis by Ontrac Solutions. Enforcement will be uneven, but the obligation is now law.
Deepfakes should be labelled. If you see a video of a politician, a celebrity, or someone you know doing or saying something that seems off, there is now a legal requirement for the publisher to label it as AI-generated. That does not create a watermark police force — but it creates liability for those who knowingly skip the label.
Nudifier apps are on borrowed time. From December, an AI tool that can strip clothing from a photo of a real person cannot legally be offered in the EU — unless the provider has built documented technical safeguards that reliably prevent that output. Researchers and victim advocates have consistently described this harm as one that "overwhelmingly targets women and girls" and produces "severe and lasting effects" on victims. The EU's ban is the first AI-specific legislative response to it.
Your job applications and credit checks get more oversight — but later. The recruitment algorithm that screens your CV, the credit model that decides your loan, the border-control system that flags your passport — all of these will face mandatory risk assessments, human oversight, and conformity testing. But not until December 2027. For now, those systems continue operating under existing data protection and non-discrimination law, without the AI Act's dedicated high-risk framework.
The EU AI Office becomes a super-regulator. Under the Omnibus, the Brussels-based AI Office — headed by Director Lucilla Sioli — gains exclusive supervisory powers over AI systems built on general-purpose AI models (when the same company develops both the model and the application) and AI integrated into very large online platforms under the Digital Services Act. This centralises enforcement to avoid 27 member states producing 27 different interpretations — a concern industry groups have raised repeatedly.
What did not change — and why it matters
The Omnibus is often described as "delaying the AI Act," but that shorthand is misleading. Several major tracks were left untouched.
The Article 5 prohibitions — the AI Act's hard bans on social scoring by public authorities, subliminal manipulation, and real-time biometric identification in public spaces — have been in force since 2 February 2025 and are unchanged. General-purpose AI model obligations — transparency on training data, energy consumption, and systemic risk assessments for the largest frontier models — have applied since 2 August 2025, with penalty enforcement powers activating this Sunday. And the AI literacy requirement under Article 4, which asks providers and deployers to take measures to support AI literacy among staff, has been softened from an outcome obligation to a process one — but it has been in force since February 2025.
One structural addition worth noting: the Omnibus introduces a new classification category for agentic AI (AIH 0401) — AI systems that autonomously plan, invoke tools, and execute multi-step actions. The original AI Act did not define AI agents as a distinct legal category, but the proliferation of such systems — ones that can book flights, write code, or manage workflows on their own — created pressure for a distinct regulatory pathway. The new framework preserves the Act's existing three-layer compliance architecture: prohibitions, transparency, and high-risk domain obligations, all applying in parallel depending on what the agent does.
Is the infrastructure actually ready?
This is the question compliance guides do not always answer plainly: the deadlines are law, but the tools to meet them may not be.
The notified body shortage is the most concrete problem. Notified bodies are the third-party organisations that conduct conformity assessments for high-risk AI systems. As of March 2026, "very few bodies have been fully designated specifically for AI Act conformity assessment," according to EyreAct's analysis. Timelines from initial engagement to certification range from 9 to 24 months — meaning companies that wait until 2027 to begin may find the queue already full.
As one compliance observer put it: "Organisations that treat the new date as permission to stop are likely to face the same readiness crunch in 2027 that the legislators have just postponed."
The penalty framework has not changed: violations of the Article 5 prohibitions carry fines of up to €35 million or 7% of global turnover. Violations of transparency and high-risk obligations carry fines up to €15 million (about $17 million) or 3% of global turnover. And the AI Act applies to any company whose AI output reaches EU users, regardless of where the company is headquartered — the same extraterritorial logic as the GDPR.
I run a small e‑shop in the Czech Republic and use a chatbot. What do I need to do by Sunday?
If you deploy a chatbot that interacts with customers, you must ensure it discloses that it is AI — not a human. If you use a third‑party provider (like a widget from an external company), the obligation falls on the provider, but you should verify they are compliant. If you built it yourself, the disclosure requirement is yours. The rule applies from 2 August 2026.
Does the nudifier ban mean I can't use AI image tools at all?
No. The ban targets systems whose intended purpose — or reasonably foreseeable outcome — is realistic non‑consensual intimate imagery of identifiable people. General‑purpose image generators, try‑on apps for clothing, and medical imaging tools are not affected, provided they have adequate safeguards. Cartoonish or physically impossible depictions fall outside the ban.
What happens if a US company ignores the EU AI Act?
The AI Act applies to any company whose AI system's output is used by people inside the EU — regardless of where the company is incorporated or where its servers are. The penalty framework is the same for everyone: up to €35 million or 7% of global annual turnover for the most serious violations. Enforcement begins this Sunday for transparency rules and December for the new prohibitions.