EU AI Act — what changed in 2026

The first substantive amendments since the Act was adopted in 2024. High-risk deadlines slipped considerably; transparency obligations did not.

1 · What happened

The Digital Omnibus on AI reached provisional trilogue agreement on 7 May 2026, was approved by the European Parliament on 16 June 2026, and was expected in the Official Journal during July 2026, entering into force three days after publication. It is a targeted amendment package, not a reopening of the Act: the risk-tier architecture, the provider/deployer split and the penalty regime all survive.

2 · The revised timeline

Date Obligation Status
1 Aug 2024 AI Act enters into force unchanged
2 Feb 2025 Prohibited practices (Art. 5) + AI literacy (Art. 4) unchanged
2 Aug 2025 GPAI model obligations; governance; penalties regime unchanged
2 Aug 2026 Transparency obligations (Art. 50) apply unchanged — this did NOT move
2 Dec 2026 New Art. 5 prohibitions (NCII, CSAM); Art. 50(2) marking for systems already on the market new / transitional
2 Aug 2027 National regulatory sandboxes delayed from 2 Aug 2026
2 Dec 2027 Annex III high-risk obligations (employment, credit, education, essential services…) delayed from 2 Aug 2026
2 Aug 2028 Annex I high-risk — AI embedded in regulated products delayed from 2 Aug 2027

3 · The substantive changes

High-risk deadlines pushed back

Annex III use-based high-risk obligations moved from 2 August 2026 to 2 December 2027 — a 16-month deferral. Annex I product-embedded high-risk moved from 2 August 2027 to 2 August 2028. The stated reason is the difficulty of operationalising testing, documentation and third-party assessment, including the absence of harmonised standards.

Two new prohibited practices

Article 5 gains prohibitions on AI systems generating or manipulating non-consensual intimate imagery of identifiable people, and on AI-generated child sexual abuse material. Providers are liable where such generation is the intended purpose or a reasonably foreseeable outcome absent adequate safeguards; deployers only where they use the system intentionally for the prohibited purpose. Applies from 2 December 2026.

New Article 4a — special category data for bias detection

The Act now expressly permits processing special-category data to detect and correct bias, subject to cumulative safeguards: no viable alternative (synthetic or anonymised data first), technical reuse limits, strict access control, no onward transmission, deletion once corrected, and documented justification. This directly addresses the long-standing tension between GDPR Article 9 and fairness testing.

AI literacy softened

Article 4 changes from a duty to "ensure" AI literacy to a duty to "take measures to support the development of" it — a materially less prescriptive standard.

Registration and documentation simplified

Providers who self-assess a system as not high-risk get a lighter registration path, with parts of Annex VIII removed. High-risk registration itself survives intact.

"Safety component" narrowed

Systems used purely for assistance, optimisation, efficiency or quality control fall outside high-risk classification unless failure could endanger health or safety — trimming some over-inclusive classifications.

Stronger duties up the supply chain

Article 25 now requires upstream providers to give downstream providers technical documentation sufficient to assess Article 16 compliance, disclose known limitations and failure modes, and grant targeted technical access for testing. Breach carries fines up to €15M or 3% of worldwide turnover.

AI Office gains direct supervision

The Commission’s AI Office takes exclusive competence over AI systems built on general-purpose models where the model and system share a provider, and over systems integrated into very large online platforms and search engines under the DSA — with power to run pre-market assessments.

4 · Article 50 — the transparency regime

Article 50 applied from 2 August 2026 and was not pushed back with the high-risk rules. It is the layer most organisations actually touch, because it applies to ordinary generative AI use rather than to a narrow high-risk list.

Provider

Disclose AI interaction

People must be told they are interacting with an AI system — unless that is already obvious to a "reasonably well-informed, observant and circumspect" person. This is the chatbot rule.

Provider

Mark synthetic content

Audio, image, video and text output must be marked as artificially generated or manipulated in a machine-readable format, effective, interoperable, robust and reliable as far as technically feasible. Does not apply to assistive editing that does not substantially alter the input.

Deployer

Disclose deepfakes

Artificially generated or manipulated image, audio or video resembling real people, places or events must be disclosed as such. Artistic, creative, satirical or fictional works are exempt from the full duty provided the existence of manipulation is disclosed appropriately.

Deployer

Disclose AI-generated text on public-interest matters

Text published to inform the public on matters of public interest must be disclosed as AI-generated — unless it underwent human editorial review and a person or organisation holds editorial responsibility.

Deployer

Inform on emotion recognition / biometric categorisation

People exposed to these systems must be informed, and the processing must independently satisfy the GDPR.

Law-enforcement systems authorised to detect, prevent, investigate or prosecute criminal offences are exempt, unless the system is publicly accessible for reporting crime.

5 · The Code of Practice on transparency of AI-generated content

Published in final form on 10 June 2026 after a consultation opened in September 2025 and a first draft in December 2025, timed to the 2 August 2026 application of Article 50. Roughly 190 organisations had signed by late July 2026.

6 · What this means in practice

Sources

Stated as at August 2026. Amendment dates depend on Official Journal publication — confirm against the consolidated text before relying on any deadline operationally.

Test yourself

Five questions on what is above, with every option explained. Your score is kept in this browser and shown on your dashboard, and saved to your account if you are signed in.

Quick check: the 2026 AI Act amendments1 / 5 · score 0

Under the Digital Omnibus amendments, which AI Act deadline did NOT move?

Study the whole syllabus free

Reference notes for all 13 competencies, 305 exam-style questions, flashcards and full-length timed mocks. Sign in with Google to save your progress across devices — which stores your email address and display name. See what is kept, and how to delete it.

Start studying free →