EU AI Act — what changed in 2026
The first substantive amendments since the Act was adopted in 2024. High-risk deadlines slipped considerably; transparency obligations did not.
1 · What happened
The Digital Omnibus on AI reached provisional trilogue agreement on 7 May 2026, was approved by the European Parliament on 16 June 2026, and was expected in the Official Journal during July 2026, entering into force three days after publication. It is a targeted amendment package, not a reopening of the Act: the risk-tier architecture, the provider/deployer split and the penalty regime all survive.
2 · The revised timeline
| Date | Obligation | Status |
|---|---|---|
| 1 Aug 2024 | AI Act enters into force | unchanged |
| 2 Feb 2025 | Prohibited practices (Art. 5) + AI literacy (Art. 4) | unchanged |
| 2 Aug 2025 | GPAI model obligations; governance; penalties regime | unchanged |
| 2 Aug 2026 | Transparency obligations (Art. 50) apply | unchanged — this did NOT move |
| 2 Dec 2026 | New Art. 5 prohibitions (NCII, CSAM); Art. 50(2) marking for systems already on the market | new / transitional |
| 2 Aug 2027 | National regulatory sandboxes | delayed from 2 Aug 2026 |
| 2 Dec 2027 | Annex III high-risk obligations (employment, credit, education, essential services…) | delayed from 2 Aug 2026 |
| 2 Aug 2028 | Annex I high-risk — AI embedded in regulated products | delayed from 2 Aug 2027 |
3 · The substantive changes
High-risk deadlines pushed back
Annex III use-based high-risk obligations moved from 2 August 2026 to 2 December 2027 — a 16-month deferral. Annex I product-embedded high-risk moved from 2 August 2027 to 2 August 2028. The stated reason is the difficulty of operationalising testing, documentation and third-party assessment, including the absence of harmonised standards.
Two new prohibited practices
Article 5 gains prohibitions on AI systems generating or manipulating non-consensual intimate imagery of identifiable people, and on AI-generated child sexual abuse material. Providers are liable where such generation is the intended purpose or a reasonably foreseeable outcome absent adequate safeguards; deployers only where they use the system intentionally for the prohibited purpose. Applies from 2 December 2026.
New Article 4a — special category data for bias detection
The Act now expressly permits processing special-category data to detect and correct bias, subject to cumulative safeguards: no viable alternative (synthetic or anonymised data first), technical reuse limits, strict access control, no onward transmission, deletion once corrected, and documented justification. This directly addresses the long-standing tension between GDPR Article 9 and fairness testing.
AI literacy softened
Article 4 changes from a duty to "ensure" AI literacy to a duty to "take measures to support the development of" it — a materially less prescriptive standard.
Registration and documentation simplified
Providers who self-assess a system as not high-risk get a lighter registration path, with parts of Annex VIII removed. High-risk registration itself survives intact.
"Safety component" narrowed
Systems used purely for assistance, optimisation, efficiency or quality control fall outside high-risk classification unless failure could endanger health or safety — trimming some over-inclusive classifications.
Stronger duties up the supply chain
Article 25 now requires upstream providers to give downstream providers technical documentation sufficient to assess Article 16 compliance, disclose known limitations and failure modes, and grant targeted technical access for testing. Breach carries fines up to €15M or 3% of worldwide turnover.
AI Office gains direct supervision
The Commission’s AI Office takes exclusive competence over AI systems built on general-purpose models where the model and system share a provider, and over systems integrated into very large online platforms and search engines under the DSA — with power to run pre-market assessments.
4 · Article 50 — the transparency regime
Article 50 applied from 2 August 2026 and was not pushed back with the high-risk rules. It is the layer most organisations actually touch, because it applies to ordinary generative AI use rather than to a narrow high-risk list.
Disclose AI interaction
People must be told they are interacting with an AI system — unless that is already obvious to a "reasonably well-informed, observant and circumspect" person. This is the chatbot rule.
Mark synthetic content
Audio, image, video and text output must be marked as artificially generated or manipulated in a machine-readable format, effective, interoperable, robust and reliable as far as technically feasible. Does not apply to assistive editing that does not substantially alter the input.
Disclose deepfakes
Artificially generated or manipulated image, audio or video resembling real people, places or events must be disclosed as such. Artistic, creative, satirical or fictional works are exempt from the full duty provided the existence of manipulation is disclosed appropriately.
Disclose AI-generated text on public-interest matters
Text published to inform the public on matters of public interest must be disclosed as AI-generated — unless it underwent human editorial review and a person or organisation holds editorial responsibility.
Inform on emotion recognition / biometric categorisation
People exposed to these systems must be informed, and the processing must independently satisfy the GDPR.
Law-enforcement systems authorised to detect, prevent, investigate or prosecute criminal offences are exempt, unless the system is publicly accessible for reporting crime.
5 · The Code of Practice on transparency of AI-generated content
Published in final form on 10 June 2026 after a consultation opened in September 2025 and a first draft in December 2025, timed to the 2 August 2026 application of Article 50. Roughly 190 organisations had signed by late July 2026.
- Section 1 — providers: how to mark and make detectable AI-generated audio, image, video and text in machine-readable form.
- Section 2 — deployers: how to label deepfakes and AI-generated publications on matters of public interest.
6 · What this means in practice
- Do not stand down your high-risk programme. December 2027 is a reprieve, not a repeal, and conformity assessment work takes longer than the extension.
- Transparency is live now. If you deploy a chatbot, generate synthetic media, or publish AI-written content on public-interest topics, the duties already apply.
- Article 4a is genuinely useful. It gives a clearer basis for the bias testing that GDPR Art. 9 made awkward — but the safeguards are cumulative, not a menu.
- Prohibitions never moved. Article 5 has applied since February 2025, and now grows on 2 December 2026.
Sources
- European Commission AI Act Service Desk — Article 50
- European Commission — Code of Practice on transparency of AI-generated content
- Regulation (EU) 2024/1689 — consolidated text on EUR-Lex
Stated as at August 2026. Amendment dates depend on Official Journal publication — confirm against the consolidated text before relying on any deadline operationally.
Test yourself
Five questions on what is above, with every option explained. Your score is kept in this browser and shown on your dashboard, and saved to your account if you are signed in.
Under the Digital Omnibus amendments, which AI Act deadline did NOT move?
- AAnnex III high-risk obligations, covering employment and credit.
- BArt. 50 transparency obligations, still applying from 2 August 2026.
- CNational regulatory sandboxes, originally due from 2 August 2026.
- DAnnex I high-risk obligations for AI embedded in regulated products.