Skip to content
EU AI Act Enforcement Begins: What the Digital Omnibus Rollback Really Changes
AI & Automation44 min read

EU AI Act Enforcement Begins: What the Digital Omnibus Rollback Really Changes

Scult Team
44 min read

The EU AI Act's enforcement phase began in August 2026 with real fines and new rules, even as the Digital Omnibus delayed other high-risk obligations.

EU AI Act Enforcement Begins: What the Digital Omnibus Rollback Really Changes

Direct answer: As of 2 August 2026, the EU AI Office has real investigative and enforcement powers under the EU AI Act, including fines up to the higher of EUR 15 million or 3% of global turnover, and the Act's Article 50 transparency and labeling rules are now legally binding — making the EU AI Act the world's first comprehensive AI law with actual teeth. At the same time, the Digital Omnibus (in force since 27 July 2026) pushed the deadlines for high-risk AI system obligations back to December 2027 and August 2028, so Brussels is simultaneously enforcing part of its own law and loosening another part under industry pressure. Any business building, deploying, or selling AI into the EU now has to track two moving targets at once rather than one.

Two Rules, Two Directions, Same Month

Most regulatory stories have a single throughline. This one doesn't, and that's exactly why it's worth understanding closely rather than skimming the headline. On 2 August 2026, the European Commission confirmed it had started enforcing the AI Act's newly binding obligations and the Article 50 transparency requirements — the rules that require AI systems to disclose when content is AI-generated, when a person is interacting with a chatbot rather than a human, and when audio, video, or images have been synthetically created or manipulated. That's the enforcement half of the story, and it's the part that gets attention because it comes with actual penalties attached: the EU AI Office can now investigate, request information, and levy fines reaching the higher of EUR 15 million or 3% of a company's global annual turnover.

The other half of the story happened almost in parallel. The Digital Omnibus, which entered into force on 27 July 2026, followed the Council of the EU's final green light on 29 June 2026 to "simplify and streamline" the AI Act's rules — and one of its central effects was pushing back the compliance deadlines for high-risk AI systems, the category covering things like AI used in hiring, credit scoring, medical devices, and critical infrastructure. Those obligations, originally on a path to bite in 2026 and 2027, are now staggered out to December 2027 and August 2028 depending on which part of the high-risk regime applies.

Put those two facts next to each other and you get a regulator that is, in the same month, turning on real enforcement power for one set of rules while giving industry more runway on another. That's not really a contradiction so much as a reflection of where political pressure has actually landed: transparency and labeling rules are politically popular and relatively cheap for most companies to implement, while full high-risk compliance — conformity assessments, technical documentation, human oversight design — is expensive, slow, and the part industry lobbying has pushed hardest against. Understanding which bucket your AI system falls into is now the single most consequential compliance question a business operating in or selling into the EU can ask itself.

For compliance teams specifically, the practical shift is less about any single new rule and more about a change in posture. Before 2 August 2026, the sensible response to the AI Act was to build a reasonable paper trail and revisit it periodically as guidance evolved. After that date, the same AI system needs to be defensible on demand — not because a specific inspection is scheduled, but because the mechanism for triggering one now exists and is staffed. That's a subtle but real shift in what "good enough" compliance looks like, and it's the reason legal teams that treated the Act as a future problem for most of 2025 are now treating it as a live one running in parallel with everything else on their plate.

Why This Is a Genuinely Different Moment for AI Regulation

The AI Act has had "in force" dates before this one — the ban on prohibited practices, the initial general-purpose AI (GPAI) provider obligations — but those milestones were mostly about documentation, registration, and getting a compliance program on paper. August 2026 is different because it's the first point where the EU AI Office has real investigative and enforcement authority to act on what it finds, not just a deadline for paperwork to exist. That distinction matters enormously for how seriously legal and compliance teams are treating this moment compared with previous ones.

It's also the reason multiple law firms — Wilson Sonsini among them — have been explicit that this is the point at which the EU AI Act becomes, functionally, the world's first enforceable comprehensive AI statute, rather than the world's first comprehensive AI statute on paper. Plenty of jurisdictions have passed AI-related rules before this. Very few have paired a risk-tiered, cross-sectoral framework with a dedicated regulator holding investigative teeth and a fine schedule with real bite. That combination is what makes this a genuine first, and it's why in-house counsel at companies with no EU headquarters at all are still paying close attention — the Act's reach was never limited to companies physically located in the bloc.

For a business that has spent the last couple of years treating AI Act compliance as a "get to it eventually" item, August 2026 is the point where that posture stops being defensible. Not because every company will be investigated immediately — enforcement bandwidth is finite, and the AI Office will inevitably prioritize the most visible, highest-risk cases first — but because the legal exposure is no longer theoretical. A regulator with the power to investigate and fine is a different risk category than a regulator with a rulebook and no way to act on it.

What the AI Office Can Actually Do Now

The practical shift is about capability, not just calendar dates. Before this enforcement phase began, the EU AI Office's role leaned heavily toward guidance, codes of practice, and coordination with national authorities. Its investigative and enforcement powers under the Act now let it request information directly from providers and deployers of general-purpose AI models, investigate suspected non-compliance, and — where it finds a violation — impose fines calculated against the higher-of-two-numbers formula regulators favor specifically because it scales with company size rather than letting a flat fine become a rounding error for the largest AI labs.

Reporting on the buildout behind this enforcement capacity has pointed to the AI Office adding roughly three dozen new staff — figures cited put it around 38 — specifically to build out the investigation and enforcement function ahead of this phase, which is itself a signal of intent. A regulator doesn't generally staff up an enforcement unit unless it plans to use it. That hiring also suggests where early enforcement attention is likely to land first: general-purpose AI model providers, given that GPAI obligations were the first substantive compliance layer to come into force and the AI Office holds direct oversight of that category at the EU level rather than deferring entirely to national market surveillance authorities.

Importantly, enforcement here isn't purely reactive. The Act gives the AI Office standing to request technical documentation and model evaluation information from GPAI providers as a matter of course, not only after a complaint or an incident. That's a meaningfully more proactive posture than most companies are used to from privacy regulators, where investigations have historically tended to follow a breach or a specific complaint. Compliance-as-paperwork was arguably a defensible posture when the main risk was an occasional audit; compliance-as-standing-obligation is the more accurate frame now.

None of this is unfamiliar territory for teams that have already lived through data protection enforcement maturing from paper compliance into active investigations over the past several years. The AI Office's build-out echoes a similar trajectory: a regulator that starts by publishing guidance and coordinating with industry, then gradually shifts toward requesting evidence, then acting on what it finds. Businesses that treated an earlier compliance program as a template rather than a one-off exercise tend to be better positioned to adapt that same institutional muscle to AI Act obligations, rather than standing up a parallel compliance function completely from scratch under time pressure.

The Digital Omnibus: Simplification, or a Rollback Under Pressure?

It's worth being precise about what the Digital Omnibus actually changed, because "simplification" and "delay" aren't quite the same thing, even though they're being used somewhat interchangeably in coverage of this update. The Council of the EU's own framing on 29 June 2026 was about simplifying and streamlining rules — language that suggests procedural relief rather than a substantive rollback. In practice, though, the most consequential change for most businesses is a straightforward deadline push: high-risk AI system obligations, which were on a path to apply broadly across 2026 and 2027, now apply on a staggered basis running through December 2027 for one part of the high-risk regime and August 2028 for another.

That gap — between "simplification" as the political framing and "delay" as the operational reality — is exactly the tension flagged by law firms tracking this closely, including Gibson Dunn's analysis of the Omnibus agreement. Whether you read the Digital Omnibus as sensible regulatory sequencing (giving companies more realistic runway to build genuinely robust high-risk compliance programs instead of rushing brittle ones) or as industry successfully lobbying to soften a law that was about to bite depends partly on which side of the compliance cost you're standing on. Both readings are defensible, and neither is really "wrong" — they're just different vantage points on the same underlying fact: the obligations that would have been hardest and most expensive to meet on the original timeline got more time, while the obligations that were cheaper and more visible to consumers did not.

What's genuinely useful to take from this, regardless of which framing you find more persuasive, is that the delay is targeted rather than blanket. It applies specifically to the high-risk system category — not to GPAI transparency obligations, not to the prohibited-practices ban, and not to Article 50's labeling and disclosure requirements. A company that assumed "the EU pushed back AI Act deadlines" meant blanket relief across the board would be working from a costly misreading of what actually happened.

Providers, Deployers, and the GPAI Layer: Who's Actually on the Hook

The AI Act's obligations don't fall on "AI companies" as an undifferentiated group — they're structured around specific roles, and which role you occupy for a given AI system changes what you're actually required to do. A provider is the entity that develops an AI system or has one developed and places it on the market under its own name — the party responsible for conformity assessments, technical documentation, and registering high-risk systems. A deployer is the entity using an AI system under its own authority in the course of a professional activity — generally facing lighter but still real obligations, such as ensuring human oversight, using the system according to its instructions, and in some cases informing the people affected by its use. The same company can be a provider for one system and a deployer for another it merely licenses and uses internally, which is exactly the kind of nuance that trips up businesses trying to self-assess their obligations without mapping each AI system individually. Our glossary breaks down terms like these — provider, deployer, GPAI, conformity assessment — in plain language if the vocabulary itself is part of what's slowing down a compliance review.

General-purpose AI models sit in their own category because of how broadly they get reused downstream — a single foundation model can end up embedded in thousands of other companies' products, each of which becomes a deployer of that underlying model even if it never touches the model's training data. GPAI providers face documentation and transparency obligations toward downstream users regardless of what those users eventually build, and providers of GPAI models with systemic risk — the largest, most capable models — face additional obligations around risk assessment and incident reporting. Signing the EU's voluntary GPAI Code of Practice isn't a legal requirement, but it functions as a practical safe harbor: providers that sign and follow it get a presumption of conformity with several of the Act's GPAI obligations, which is a meaningfully easier path than demonstrating compliance from scratch through direct evidence.

Article 50 is where most consumer-facing businesses actually feel this law day to day, regardless of whether they think of themselves as "an AI company" at all. If your product includes a chatbot, it generally needs to disclose that a user is talking to an AI rather than a human, unless that's already obvious from the context. If your product generates or manipulates images, audio, or video in a way that could pass as authentic, that content generally needs to be marked as AI-generated or manipulated — the "watermarking" obligation referenced constantly in AI Act coverage this year. These are the obligations that became binding on 2 August 2026 and were not touched by the Digital Omnibus delay, which is exactly why they're the part of this story getting the most immediate compliance attention even though high-risk systems carry the heavier long-term burden.

Germany's Answer: KI-MIG and a Named Enforcer

Because the AI Act is an EU regulation, its substantive obligations are the same across every member state — but enforcement infrastructure is a national matter, and each member state has had to build or designate the authorities that will actually do the market surveillance and conformity assessment work on the ground. Germany moved early and specifically. The Bundestag passed the AI Market Surveillance and Innovation Promotion Act — KI-MIG, in the German abbreviation — on 11 June 2026, and it took effect on 29 July 2026, just ahead of the EU-wide enforcement phase.

KI-MIG's most concrete contribution is naming names: it designates the Bundesnetzagentur (BNetzA) — Germany's federal network agency, which already regulates telecoms, energy, and postal markets — as the national market surveillance authority for the AI Act, and DAkkS (the German national accreditation body) as the notifying body responsible for conformity assessment procedures. That's a meaningful clarification for any business operating in Germany, because it answers a question that otherwise sits unresolved in a lot of member states even now: which specific agency do you actually deal with if you need a conformity assessment, or if you're the subject of a market surveillance inquiry? Germany answered that question months before enforcement began in earnest, which is itself informative about how seriously German industry and regulators are treating implementation relative to some of their EU peers.

It's worth being precise that KI-MIG is primarily an enforcement-infrastructure law rather than a source of new substantive obligations layered on top of the AI Act itself. It doesn't invent new categories of prohibited AI use or new disclosure requirements beyond what the EU regulation already sets out — it builds the domestic machinery (naming the regulator, setting out national procedural and penalty details within the ranges the EU regulation allows) that lets the AI Act's existing obligations actually get enforced inside Germany. For a business already tracking AI Act compliance at the EU level, KI-MIG changes who you'd hear from in Germany specifically, more than it changes what you have to do.

France's INESIA and the Long Tail of National Implementation

France took a different but complementary path. Its National Institute for the Evaluation and Security of AI — INESIA — was established back in February 2025, well before this year's enforcement milestone, specifically to coordinate the country's implementation of the AI Act across the various national bodies that touch AI oversight. Rather than a single new law analogous to Germany's KI-MIG, France's approach has run through a longer sequence of implementing decrees tied to its 2024 SREN Law (the law on securing and regulating the digital space), with that decree process continuing through 2025 and into 2026.

The practical effect for a business operating in France is less about a single bright-line date and more about an ongoing, incremental buildout of the regulatory and institutional apparatus around AI oversight — INESIA acting as the coordinating body across what would otherwise be a scattered set of sector regulators, and the SREN Law's decrees filling in operational detail as they're finalized. If Germany's approach reads as "name the enforcer early and clearly," France's reads as "build the coordinating institution early and let the operational detail accumulate." Both get to broadly the same place — a functioning national enforcement apparatus behind the EU-level rules — by different institutional routes, which is a useful reminder that "the EU AI Act" is not one uniform experience across member states even though the underlying regulation is identical text everywhere.

How the Rest of the World Is Actually Watching This

None of this happens in a vacuum, and one of the more interesting parts of 2026's AI regulation story is how differently other major economies are positioning themselves relative to the EU's approach — not adopting it, largely, but defining themselves in explicit contrast to it.

In the United States, there's no direct EU AI Act obligation for most companies, but federal policy has moved deliberately in the opposite direction. An executive order from December 2025 (EO 14365) and a March 2026 National Policy Framework both explicitly favor "minimally burdensome" AI standards — language that reads, and is widely understood by firms like Morgan Lewis and Baker Botts tracking this, as a direct positioning against the EU's binding, risk-tiered model. American companies with EU exposure still have to comply with the Act regardless of what Washington prefers domestically, which creates a genuinely awkward position for multinationals: build to the stricter EU standard everywhere for consistency, or maintain two different compliance postures depending on market. Washington's own preemption fight with individual states over AI law is a related but distinct story in its own right, driven by different pressures entirely.

The UK isn't an EU member and has no direct AI Act obligation either, but the Act reaches UK companies anyway wherever they're affecting EU markets — a UK-based provider selling an AI product into the EU doesn't get to opt out just because the UK itself hasn't legislated a domestic equivalent. Absent its own comprehensive AI statute, the UK is instead leaning on existing frameworks: UK GDPR, the Data (Use and Access) Act 2025, and a patchwork of sector regulators — the ICO for data protection, Ofcom for communications and online safety, the FCA for financial services, and the MHRA for medical devices — each handling AI-related risk within their existing sectoral remit rather than under one unified AI law.

Australia is charting its own course rather than importing the EU's model wholesale, developing what's being called "Australian Standards for AI" following an announcement from Prime Minister Albanese in July 2026. That's a meaningfully different regulatory philosophy from the EU's binding, risk-tiered statute — closer to a standards-based approach than a hard-law one, at least based on what's been publicly signaled so far.

For the UAE, Dubai, and China, there isn't distinct regional-specific reporting tying them into this particular enforcement-and-rollback story the way there is for the jurisdictions above. That's worth saying plainly rather than glossing over: China's AI governance runs through a different structural model entirely — sectoral measures led by the Cyberspace Administration of China rather than a single risk-tiered statute like the EU's — which makes a direct comparison to "how is China responding to the EU AI Act's enforcement phase" somewhat of a category mismatch rather than a gap in reporting. The UAE and Dubai's AI governance approach, meanwhile, simply doesn't have prominent public reporting connecting it to this specific August 2026 milestone at the time of writing.

What This Actually Means If You Build or Ship AI Into Europe

Strip away the political framing on both the enforcement phase and the Digital Omnibus, and the practical task in front of any business with EU exposure is the same one it's always been, just with a firmer deadline attached to part of it: know exactly which AI systems you provide or deploy, know which regulatory bucket each one falls into, and know which obligations are due now versus which ones you've genuinely been given more runway on.

That starts with an honest classification exercise. Is a given system a prohibited practice (already unlawful, full stop), a high-risk system (now on the delayed Digital Omnibus timeline), a GPAI model or a product built on one (subject to transparency obligations that were not delayed), or something that only triggers Article 50's disclosure and labeling requirements because it involves a chatbot or synthetic media? Most businesses will find they have more than one answer across their AI footprint, which is exactly why a system-by-system inventory beats a single company-wide compliance statement.

From there, the sequencing matters. Article 50 disclosure and GPAI transparency obligations are live now, which makes them the near-term priority regardless of what else is on a compliance roadmap — a chatbot that doesn't disclose it's a chatbot is a live compliance gap today, not a future one. High-risk system compliance — conformity assessments, technical documentation, human oversight design — has more runway under the Digital Omnibus timeline, but "more runway" is not the same as "no urgency," particularly because conformity assessment processes for genuinely high-risk systems tend to take real calendar time to do properly, the same way a security review can't be meaningfully compressed by adding more people at the last minute.

A living AI system register is worth building now regardless of which deadline applies to which system — not a one-time spreadsheet assembled for a launch review, but a document that gets updated every time a new AI feature ships or an existing one changes scope. It should record what each system actually does, which risk tier it falls into, which specific obligations apply, and when each one is due. Static documentation drafted once and never revisited is exactly the kind of gap an investigation tends to surface first, because it signals that compliance was treated as a one-time event rather than an ongoing discipline — and a regulator with real investigative power, as the AI Office now has, is far more likely to notice that gap than a regulator that only ever reviewed paperwork on request.

If your AI systems involve any kind of autonomous decision-making or agent-like behavior — approving a transaction, triaging a support ticket, taking an action rather than just generating text for a human to review — the classification question gets more consequential, not less, because autonomy is exactly the kind of design choice that can push a system from a lighter compliance category into a heavier one depending on what it's actually allowed to do without a human in the loop. That's a question worth resolving at the architecture stage, which is the same discipline we bring to AI agent and automation work generally — scoping precisely what a system is authorized to do, and building the disclosure and oversight hooks in from the start rather than retrofitting them once a regulator asks. Getting that scoping wrong isn't just a compliance risk in the EU specifically; it's the same excessive-agency problem that shows up in security reviews everywhere an AI system has more reach than its actual task requires.

For businesses across regulated sectors — healthcare, financial services, education, employment — the stakes compound further, since AI Act high-risk classification overlaps heavily with sectors that already carry their own regulatory obligations; our industries pages cover how AI-related compliance priorities differ across some of the sectors we build for, which is worth a look if your AI footprint sits inside one of the sectors the Act treats most seriously by default. And if the honest answer to "do we actually know our full AI compliance obligation across every system we've shipped" is uncertain, that uncertainty itself is the thing worth resolving first — a full compliance review that maps every AI system against its actual regulatory bucket is a more useful starting point than reacting piecemeal to whichever obligation happens to be in the news that month.

The Practical Takeaway

August 2026 didn't simplify the EU AI Act story, even though "simplify" was the word Brussels used for one half of it. It made the law real in one direction — enforceable, with a regulator that can investigate and fine — while making it slower in another, for the specific category of obligations that were always going to be the most expensive to meet. Treating those as one undifferentiated update, rather than two separate and partially contradictory ones, is the single most common mistake a business can make reading this moment from the outside. The safer posture is the boring one: classify every AI system you touch, track the two timelines separately, and treat the obligations that are already binding — Article 50 disclosure, GPAI transparency — as due now, regardless of how much runway the high-risk category bought everyone else.

What Businesses Actually Want to Know About the EU AI Act's Enforcement Phase

Are you ready for the August 2026 deadline?

This question is really a self-check disguised as a deadline reminder, and the honest way to answer it is to break "ready" into pieces rather than treat it as one yes-or-no. Being ready means you've inventoried every AI system you provide or deploy, classified each one against the Act's risk tiers, and confirmed which obligations are already binding versus which ones the Digital Omnibus pushed out. If your chatbots and any AI-generated media already disclose themselves under Article 50, and you know whether any of your systems count as general-purpose AI models with transparency duties attached, you're in reasonable shape for what's live right now. If you haven't done that classification exercise at all, "ready" isn't really the right word for where you stand — the more useful next step is a structured compliance review that maps your actual AI footprint against the Act's categories, rather than trying to answer the readiness question from memory.

Is their product considered high-risk or a prohibited practice under the Act?

The Act sorts AI systems into a small number of tiers, and getting the classification right is the single most consequential compliance decision a business makes. Prohibited practices are the narrowest and harshest category — things like certain manipulative or exploitative AI techniques, some forms of social scoring, and specific biometric uses — and they're banned outright regardless of safeguards; there's no compliance path for a prohibited practice, only removal. High-risk systems are a much broader category covering AI used in contexts like employment decisions, credit and lending, medical devices, and critical infrastructure, and they carry substantive obligations rather than an outright ban. Most commercial AI products fall into neither extreme — they sit in the lighter-touch categories covering general-purpose models or Article 50 disclosure duties. Determining which bucket a specific product falls into requires mapping its actual use case against the Act's annexes, not guessing from the product's general category or industry.

Which obligations specifically apply to their product?

This follows directly from classification, and it's why skipping straight to "what do we need to do" without first answering "what are we" tends to produce incomplete compliance work. A prohibited practice has one obligation: stop. A high-risk system carries the heaviest load — conformity assessment, technical documentation, risk management, human oversight design, and registration — now staggered across the Digital Omnibus's December 2027 and August 2028 timeline depending on which high-risk sub-category applies. A general-purpose AI model carries documentation and transparency obligations toward downstream users, with extra risk-assessment duties for the largest, most capable models. A product that's none of the above but includes a chatbot or generates synthetic media still owes Article 50 disclosure, which is already binding. The practical answer is always specific to the product, never a blanket statement about "AI obligations" as a category.

How does the EU regulator ensure enforcement and what business risks may arise?

The EU AI Office enforces primarily through information-request and investigation powers that took on real teeth starting 2 August 2026 — it can request technical documentation and evaluation data from providers, investigate suspected non-compliance, and, where it finds a violation, impose fines reaching the higher of EUR 15 million or 3% of global annual turnover. For high-risk systems specifically, national market surveillance authorities, like Germany's BNetzA, play a parallel enforcement role at the member-state level. The business risks that follow aren't limited to the fine itself: an investigation can force disclosure of internal technical documentation, require product changes or withdrawal from the EU market, and generate reputational damage that outlasts whatever the financial penalty turns out to be. For a company with meaningful EU revenue, the market-access risk of a serious finding is often a bigger practical concern than the headline fine figure.

What measures should be implemented to ensure regulatory compliance?

The foundational measure is a complete, current inventory of every AI system the business provides or deploys, each one mapped against the Act's risk tiers rather than assessed as a single company-wide posture. From there, the specific measures follow the classification: documented risk management and human oversight processes for anything high-risk, transparency documentation for general-purpose models, and disclosure mechanisms — a chatbot notice, a synthetic-media label — for anything triggering Article 50. Underneath all of that, a business needs an internal owner for AI compliance who tracks regulatory changes like the Digital Omnibus as they happen, since a compliance program built once and left static is exactly the kind of thing that becomes quietly out of date within a single regulatory cycle. Building these hooks into a system's architecture from the start, rather than retrofitting them after the fact, is consistently the cheaper and more durable path.

What are the key deadlines and the optimal strategy to establish compliance?

Two dates matter most right now: 2 August 2026, when Article 50 transparency and disclosure obligations and GPAI provider duties became binding, and the Digital Omnibus's staggered high-risk timeline running to December 2027 for standalone high-risk systems and August 2028 for high-risk systems embedded in regulated products. The optimal strategy treats these as sequential priorities rather than one combined deadline: close any Article 50 or GPAI gaps immediately, since those obligations carry no additional runway, and use the extra time the Digital Omnibus bought on high-risk compliance to build a genuinely robust program rather than treating the later deadline as permission to delay starting. Conformity assessments and human-oversight design for real high-risk systems take substantial calendar time to do well, so "we have until 2027 or 2028" is a reason to start deliberately now, not a reason to wait. Our methodology page covers how we typically sequence a compliance-driven build against exactly this kind of staggered regulatory timeline.

What powers does the EU AI Office have to investigate and enforce the AI Act?

As of 2 August 2026, the AI Office can request information and technical documentation directly from providers and deployers — with particular direct oversight over general-purpose AI models — investigate suspected violations, and impose fines up to the higher of EUR 15 million or 3% of global annual turnover where it finds non-compliance. This is a meaningfully more proactive posture than a complaint-driven enforcement model: the Office can request documentation and evaluation data from GPAI providers as a matter of standing oversight, not only after something goes visibly wrong. Reporting on the buildout behind this shift has pointed to the Office adding roughly 38 new staff specifically to grow its investigation and enforcement capacity ahead of this phase, which is a reasonable signal that early enforcement attention is likely to concentrate on general-purpose AI model providers first, given the Office's direct jurisdiction there relative to high-risk systems, which lean more heavily on national market surveillance authorities.

What changed under the Digital Omnibus agreement reached by Council and Parliament?

The Council of the EU gave its final green light on 29 June 2026 to what was framed as simplifying and streamlining the AI Act's rules, and the Digital Omnibus that resulted entered into force on 27 July 2026. Its most consequential practical effect was pushing back the compliance timeline for high-risk AI system obligations — the most expensive and operationally demanding part of the Act for most businesses — to December 2027 and August 2028 depending on the specific high-risk category involved. It's worth being precise that this was a targeted delay to one part of the Act's obligations, not a general rollback: prohibited practices, GPAI transparency duties, and Article 50 disclosure requirements were untouched and remained on their original binding schedule. Whether you read the change as sensible sequencing or as industry successfully softening a law that was about to bite depends on where you're standing, but the mechanics of what changed are specific and limited rather than sweeping.

When do high-risk AI system obligations now apply after the Omnibus delay?

The Digital Omnibus staggers the high-risk timeline into two dates rather than one. Standalone high-risk AI systems — the category originally on track to face obligations around August 2026 — now have until December 2027. High-risk AI systems embedded in already-regulated products, which were generally following a schedule roughly a year behind the standalone category to begin with, now have until August 2028, preserving a similar gap between the two sub-categories rather than closing it. Neither date affects anything outside the high-risk classification: general-purpose AI model obligations and Article 50 transparency and disclosure duties remain on the original, already-binding schedule that took effect 2 August 2026. Businesses building toward the delayed dates should treat them as a firm ceiling for a compliance program to be complete, not as a reason to defer starting the underlying risk-assessment and documentation work.

Which AI Act obligations were NOT delayed by the Digital Omnibus?

Three categories of obligation were untouched by the Digital Omnibus and remain on their original binding schedule. The ban on prohibited AI practices remains in full force — there was never a delay proposal for this category, since it's a flat prohibition rather than a compliance regime with a buildup period. General-purpose AI model provider obligations, including transparency and documentation duties toward downstream users, also continued on schedule. And Article 50's transparency and disclosure requirements — chatbot notices, synthetic-media labeling — became binding on 2 August 2026 exactly as planned. The delay was specific to high-risk AI system obligations, the category involving conformity assessments, technical documentation, and human oversight design for systems used in things like hiring, credit, and medical devices. A business that assumed the Digital Omnibus meant blanket relief across the whole Act would be working from an inaccurate picture of what actually happened.

What is the maximum fine under the EU AI Act, and does it differ for prohibited practices vs other breaches?

For the enforcement powers that took effect on 2 August 2026, reporting has centered on fines reaching the higher of EUR 15 million or 3% of a company's global annual turnover — a formula regulators favor because it scales with company size rather than becoming a rounding error for the largest AI developers. The Act's broader penalty framework is understood to be tiered by severity, with the most serious category of violations — prohibited practices specifically — treated as the most severe tier and other compliance failures assessed at a comparatively lower level, consistent with how the EU has structured penalties in other major digital regulations. The exact figures that apply to each specific violation type are worth confirming against current guidance for the specific obligation in question, since this is an area where implementing detail continues to get clarified as enforcement actions actually happen.

Does the EU AI Act apply to a US or Asian company with no EU office?

Yes, and this is one of the most consistently misunderstood parts of the Act's reach. Like the GDPR before it, the AI Act applies based on where an AI system's output is used or where it's placed on the market, not based on where the company developing it is headquartered or incorporated. A US or Asian company with zero physical presence in the EU is still squarely within the Act's scope if its AI product is placed on the EU market or if the system's output is used within the EU. Companies that have spent years treating GDPR's extraterritorial reach as settled, unavoidable reality for anything touching EU users should apply exactly the same assumption here — "we don't have an EU office" has never been a meaningful compliance defense under either regulation, and building on that assumption is a genuinely risky bet.

What is a 'general-purpose AI model' under the AI Act and who counts as its provider?

A general-purpose AI model, in the Act's framing, is one trained on broad data at scale and capable of competently performing a wide range of distinct tasks, rather than being narrowly built for one specific function — the kind of foundation model that ends up embedded, often invisibly, inside thousands of other companies' products. The provider is the entity that develops the model, or has it developed, and places it on the market or puts it into service under its own name — the party responsible for the model's technical documentation and transparency obligations toward everyone downstream who builds on it. A company that merely licenses and uses someone else's GPAI model inside its own product is generally a deployer of that model rather than its provider, even though it might simultaneously be the provider of its own downstream product built on top of it — the same company can hold both roles for different systems at once.

Do customer-facing chatbots need to disclose they are AI under Article 50?

Yes, in general — Article 50 requires that a person interacting with an AI system be informed they're doing so, unless it's already obvious from the circumstances that they're talking to a machine rather than a human. This obligation became binding on 2 August 2026 alongside the AI Office's new enforcement powers, which makes it one of the more immediate, practical compliance items for almost any consumer-facing business rather than something limited to companies that think of themselves as "AI companies." A support widget, a sales chatbot, or a voice assistant that doesn't clearly disclose its AI nature is a live compliance gap right now, not a future one. This is exactly the kind of disclosure and scoping question worth resolving at the design stage of any AI agent or automation build, rather than adding a notice after the fact once a system is already live.

What is the deadline for watermarking AI-generated content under Article 50(2)?

The watermarking and labeling obligation under Article 50 — requiring that AI-generated or manipulated audio, video, image, or text content that could pass as authentic be marked as artificial — became legally binding on 2 August 2026, the same date the AI Office's enforcement powers activated and the same date the rest of Article 50's transparency requirements took effect. This obligation was not touched by the Digital Omnibus's delay, which applied specifically to high-risk AI system obligations rather than to transparency and labeling duties. Any business generating synthetic media at scale — marketing content, product imagery, voice or video content — that could reasonably be mistaken for authentic, human-made content should treat this as a currently binding requirement rather than an upcoming one, since it's already part of what the AI Office can investigate and enforce against today.

By how long did the Digital Omnibus push back the deadline for standalone high-risk AI systems?

Standalone high-risk AI systems were on track to face compliance obligations around 2 August 2026 — the same date the Act's other enforcement mechanisms activated — before the Digital Omnibus pushed that specific deadline out to December 2027. That's a delay of roughly sixteen months, giving providers and deployers of standalone high-risk systems substantially more runway to complete conformity assessments, technical documentation, and human oversight design than the original timeline allowed. It's worth treating that extra time as an opportunity to build a genuinely durable compliance program rather than as permission to defer the underlying work, since conformity assessment for a real high-risk system — one used in hiring, lending, or similarly consequential decisions — tends to take considerable calendar time to do properly, and starting that process late against even a pushed-back deadline is still a foreseeable, avoidable risk.

By how long did the Digital Omnibus push back the deadline for high-risk AI embedded in products?

High-risk AI systems embedded in already-regulated products — AI components inside medical devices or industrial machinery, for example, rather than standalone high-risk systems — were generally tracking a schedule roughly a year behind the standalone high-risk category to begin with, reflecting how these systems are typically assessed alongside the broader product's existing safety certification process. The Digital Omnibus pushed this category's deadline out to August 2028, preserving roughly that same year-long gap relative to the standalone category's new December 2027 date rather than closing it. In practical terms, this gives manufacturers of AI-embedded regulated products meaningfully more time to integrate AI Act conformity assessment into their existing product certification workflows, which tend to already be complex, multi-year processes for products like medical devices — an added AI-specific compliance layer is easier to build into that process from the start than to retrofit close to a hard deadline.

How many new staff did the EU AI Office add in 2026 and why?

Reporting on the buildout behind this enforcement phase has put the figure at roughly 38 new staff added to the EU AI Office in 2026, specifically to grow its investigation and enforcement capacity ahead of the powers that activated on 2 August 2026. That kind of staffing investment is itself a meaningful signal: regulators don't typically build out a dedicated enforcement function unless they intend to actually use it, which is a reasonable basis for treating this enforcement phase as substantively different from the Act's earlier, more paperwork-oriented milestones. It also suggests where early enforcement attention is likely to concentrate first — general-purpose AI model providers, given that the AI Office holds direct EU-level oversight of that category, compared with high-risk systems, which lean more heavily on national market surveillance authorities like Germany's BNetzA for day-to-day enforcement.

Can EU AI Office investigators get direct access to a company's AI model for evaluation?

The AI Office's enforcement powers include the ability to request technical documentation, testing results, and evaluation information from general-purpose AI model providers as part of its oversight role, and to investigate suspected non-compliance more broadly. Whether a specific investigation extends to something closer to direct technical access to a model — rather than documentation and evaluation data about it — depends on the specifics of the inquiry and the cooperation of the provider involved; the publicly described mechanics center on information and documentation requests rather than a generalized right to operate a company's model directly. For high-risk systems specifically, national market surveillance authorities carry a parallel role and can request documentation and access needed to verify a system's compliance with its stated technical specifications as part of their own oversight function.

What's the difference between a 'provider' and a 'deployer' under the AI Act?

A provider develops an AI system, or has one developed, and places it on the market or puts it into service under its own name — the party that carries the heaviest obligations, including conformity assessment, technical documentation, and registration for high-risk systems. A deployer uses an AI system under its own authority in a professional context without having developed it — generally facing lighter obligations, such as ensuring appropriate human oversight, using the system according to the provider's instructions, and in some cases informing people affected by its use. The distinction matters because obligations attach to the role, not to the company as a whole: a business can be a provider for one AI system it built and sells, and simultaneously a deployer for a different, third-party AI tool it merely licenses and uses internally, with each system's obligations assessed separately.

Do GPAI models placed on the market before August 2025 get extra compliance time?

Yes — the Act built in a grace period for general-purpose AI models that were already on the market before their provider obligations first applied, generally understood to extend to around August 2027, giving providers of pre-existing models a longer runway to complete documentation and compliance work rather than facing an immediate compliance scramble the moment the obligations took effect. This grandfathering reflects a reasonable practical concern: a model already embedded across thousands of downstream products can't realistically be brought into full compliance overnight without disrupting everything built on top of it. New GPAI models placed on the market after that initial cutoff don't get the same extended runway — they're expected to meet provider obligations from the point they're placed on the market, which is a meaningful planning distinction for any company currently developing a new foundation model for EU release.

Is signing the EU's GPAI Code of Practice mandatory or voluntary?

Voluntary — no GPAI provider is legally required to sign it. In practice, though, it functions as something closer to a practical safe harbor: providers that sign the Code of Practice and follow it get a presumption of conformity with several of the Act's GPAI obligations, which is a meaningfully easier path to demonstrating compliance than assembling equivalent evidence from scratch through direct documentation. For most GPAI providers, the realistic choice isn't "comply or don't comply" — the underlying transparency and documentation obligations apply regardless — it's whether to get there through the Code of Practice's more defined path or through a bespoke compliance process that has to independently satisfy the same underlying requirements without the benefit of the presumption the Code provides.

Which German regulator enforces the AI Act - BNetzA or a newly created agency?

BNetzA — the Bundesnetzagentur, Germany's existing federal network agency that already regulates telecoms, energy, and postal markets. Germany's AI Market Surveillance and Innovation Promotion Act (KI-MIG), passed by the Bundestag on 11 June 2026 and effective 29 July 2026, designated BNetzA as the national market surveillance authority for the AI Act rather than standing up a brand-new dedicated agency from scratch. That choice reflects a fairly common regulatory pattern of extending an existing, experienced regulator's remit rather than building new institutional capacity from zero, and it gives businesses operating in Germany a concrete, named point of contact for AI Act market surveillance questions well ahead of when many other member states had settled the equivalent question domestically.

Does Germany's KI-MIG create new substantive AI obligations, or only enforcement infrastructure?

Primarily enforcement infrastructure rather than new substantive rules. KI-MIG's core function is naming and empowering the domestic authorities responsible for enforcing the EU AI Act inside Germany — designating BNetzA as the market surveillance authority and DAkkS as the conformity assessment notifying body — rather than inventing new categories of prohibited AI use or new disclosure obligations layered on top of what the EU regulation already requires. Since the AI Act is an EU regulation, its substantive obligations are already uniform across every member state; what varies nationally is the enforcement machinery that puts those obligations into practice. For a business already tracking AI Act compliance at the EU level, KI-MIG mainly changes who specifically you'd hear from in Germany, rather than adding to the underlying list of things you're required to do.

What role does France's INESIA play in AI Act implementation?

INESIA — France's National Institute for the Evaluation and Security of AI, established in February 2025 — functions as the coordinating body across the various French national agencies and sector regulators that touch AI oversight, rather than as a single new enforcement authority in the way Germany's KI-MIG names BNetzA. Its role has run alongside a longer sequence of implementing decrees tied to France's 2024 SREN Law, with that decree process continuing through 2025 and into 2026 to fill in operational detail as it's finalized. The practical effect for a business operating in France is less about one clean deadline and more about an incremental, ongoing buildout of the regulatory apparatus — INESIA providing the coordinating structure while the SREN Law's decrees supply the specifics over time, a genuinely different institutional path than Germany's toward broadly the same destination.

Is the UK bound by the EU AI Act after Brexit?

Not directly — the UK isn't an EU member and has no domestic obligation to apply the AI Act as its own law. But the Act reaches UK companies anyway wherever their AI systems affect EU markets: a UK-based provider selling an AI product into the EU, or whose system's output is used by people in the EU, doesn't get to opt out simply because the UK itself hasn't legislated an equivalent statute. Absent its own comprehensive AI law, the UK is instead relying on existing frameworks — UK GDPR, the Data (Use and Access) Act 2025, and sector regulators including the ICO, Ofcom, the FCA, and the MHRA — to address AI-related risk within their existing remits. A UK business with genuine EU exposure needs to track AI Act compliance on its own terms regardless of the UK's domestic regulatory choices.

What happens if a company misses the 2 August 2026 transparency deadline?

Missing an already-binding obligation like Article 50 disclosure or GPAI transparency duties exposes a company to the AI Office's investigation and enforcement powers, which can include information requests, formal investigation, and fines reaching the higher of EUR 15 million or 3% of global annual turnover where non-compliance is found. In practice, enforcement bandwidth is finite, and the AI Office will inevitably prioritize the most visible or highest-impact cases first rather than pursuing every gap simultaneously — but that's a reason for humility about timing, not a reason to treat the obligation as low-risk. A company that's missed the deadline is better served by closing the gap immediately and documenting the remediation than by waiting to see whether enforcement attention arrives, since a demonstrated good-faith effort to comply tends to matter in how a regulator responds if an investigation does eventually happen.

How does the EU AI Act's approach compare to the US National AI Policy Framework?

They're close to opposites in structure and philosophy. The EU AI Act is a binding, risk-tiered statute with a dedicated enforcement body that now has real investigative and fining power, built on the premise that AI risk should be regulated proactively and comprehensively across sectors. The US National Policy Framework, introduced in March 2026, is a nonbinding set of legislative recommendations favoring "minimally burdensome" AI standards and explicit federal preemption of state laws seen as undue burdens — a framework, not a law, reflecting a philosophy that lighter-touch, market-driven governance should prevail over binding, prescriptive rules. Law firms including Morgan Lewis and Baker Botts have been explicit that this positions the US framework directly against the EU's model. For a multinational business, the practical result is having to satisfy the stricter of the two wherever it operates in both markets, regardless of which philosophy either government ultimately settles on domestically.

Are SMEs and startups exempt from any EU AI Act obligations?

Not from the Act's core substantive obligations — a small company placing a genuinely high-risk AI system on the market is still subject to high-risk obligations, and a startup's AI product is banned just as thoroughly as a large company's if it falls into a prohibited-practice category. What the Act does provide is proportionality and support measures aimed at making compliance more achievable for smaller organizations — provisions like documentation support, prioritized or reduced-cost access to regulatory sandboxes, and simplified conformity-assessment pathways in some contexts — rather than a blanket carve-out from the rules themselves. Treating "we're a small company" as grounds to skip classification and compliance work entirely is a common but risky misreading of how the Act actually treats company size: it affects how much support and flexibility you get in meeting obligations, not whether the obligations apply at all.

What is DAkkS's role in EU AI Act conformity assessment in Germany?

DAkkS — Germany's national accreditation body — was designated under KI-MIG as the notifying body responsible for conformity assessment procedures under the AI Act within Germany. In practical terms, that means DAkkS is the body that accredits and oversees the conformity assessment bodies that businesses in Germany would work with to certify high-risk AI systems against the Act's requirements, playing a role analogous to the accreditation function it already performs for other EU product-safety and standards regimes. Pairing DAkkS's existing accreditation expertise with BNetzA's market surveillance role gave Germany a relatively clear, complete domestic enforcement structure well ahead of the EU-wide enforcement phase — a useful reference point for businesses trying to understand what "who do I actually deal with" looks like once other member states finish standing up their own equivalent structures.

Want results like this?

Keep reading