AI

EU AI Act, August 2026: What Actually Applies Now (and What the Digital Omnibus Deferred)

TuniCyberLabs Team
6 min read

GPAI duties and Article 50 transparency are live in August 2026, but the Digital Omnibus may defer high-risk obligations to 2027 or 2028. Here is what applies now, what is provisional, and how to engineer for a moving timeline.

What actually applies under the EU AI Act in August 2026?

As of August 2026, four blocks of the EU AI Act (Regulation (EU) 2024/1689) are in force: the Article 5 prohibited practices and Article 4 AI-literacy duty (since February 2025), the Chapter V general-purpose AI (GPAI) obligations (since August 2025), and the Article 50 transparency duties (from 2 August 2026). High-risk timing is the contested part.

  • The Act applies in phases from its 1 August 2024 entry into force.
  • Since 2 February 2025: banned practices (social scoring, untargeted facial scraping, certain biometric categorisation, manipulative systems) and the duty to ensure staff AI literacy.
  • Since 2 August 2025: GPAI model-provider obligations, the governance and penalties framework, and the AI Office's supervisory role.
  • From 2 August 2026: the Article 50 transparency obligations and, as originally legislated, the Annex III high-risk obligations, the latter now clouded by the Digital Omnibus proposal.
  • Always verify against the primary EUR-Lex text; this timeline is being actively amended.

What did the Digital Omnibus propose to defer, and is it law yet?

The Digital Omnibus is a European Commission simplification package proposed in November 2025 that, among other things, would delay the AI Act's high-risk obligations, potentially into 2027 or 2028, tied to harmonised standards being ready. As of writing it is a proposal, not enacted law. Treat any deferral as provisional.

  • The package reportedly proposes to make high-risk application contingent on supporting standards and tools being available rather than on a fixed calendar date, and to ease documentation and registration burdens, especially for SMEs.
  • It must pass the ordinary legislative procedure, European Parliament and Council, so its content and timing can change or stall.
  • Do not architect on the assumption that high-risk duties have vanished; assume they are delayed, not deleted.
  • Confirm the current status via the Commission's AI Act pages and EUR-Lex before making compliance decisions.

For a broader view of what is shippable today, see EU AI Act in 2026: The Obligations That Actually Apply Now, and How to Ship Compliant AI Features.

Which GPAI model obligations are enforceable now?

Since 2 August 2025, providers of general-purpose AI models must maintain technical documentation, pass information downstream to system builders, publish a summary of training content, and hold a copyright policy respecting EU text-and-data-mining opt-outs. Models with systemic risk carry added evaluation, incident-reporting, and cybersecurity duties.

  • All GPAI providers: keep up-to-date technical documentation, provide integration information to downstream deployers, publish a public summary of training content using the AI Office template, and adopt a copyright policy honoring Article 4(3) of the DSM Directive (Directive (EU) 2019/790) reservations.
  • GPAI with systemic risk (indicatively models trained above 10^25 FLOP, or so designated): perform model evaluation and adversarial testing, assess and mitigate systemic risks, report serious incidents to the AI Office, and ensure adequate cybersecurity.
  • The voluntary GPAI Code of Practice (published July 2025) is the main route to demonstrate compliance, with Transparency, Copyright, and Safety-and-Security chapters.
  • Models placed on the market before 2 August 2025 have until 2 August 2027 to conform.

Documentation and provenance sit at the core here; see Securing the AI Supply Chain: AIBOM, Provenance, and Model Governance and Model Governance Engineers Will Actually Follow.

What does Article 50 transparency require you to build?

Article 50 requires disclosure, not approval. From 2 August 2026 you must tell people when they are interacting with an AI system, mark AI-generated or manipulated audio, image, video, and text in a machine-readable way, and disclose deepfakes. These are engineering tasks: labelling, watermarking, and provenance metadata.

  • Chatbots and AI interfaces: inform users they are dealing with an AI, unless it is obvious from context.
  • Synthetic media: providers must mark outputs as artificially generated or manipulated in a machine-readable format, think C2PA Content Credentials-style provenance and watermarks, where technically feasible.
  • Deepfakes and public-interest text: deployers must disclose artificially generated or manipulated content, with a human-editorial-review exception for some published text.
  • Emotion recognition and biometric categorisation: deployers must inform the exposed persons.
  • Build these once, centrally: a shared labelling and provenance layer beats retrofitting each feature.

Output handling and hostile-input assumptions overlap with Prompt Injection Defense in Depth: Assume the Text Is Hostile.

Are high-risk AI obligations in force, or on hold?

As originally legislated, Annex III high-risk obligations applied from 2 August 2026, with product-embedded high-risk systems under Annex I following on 2 August 2027. The Digital Omnibus proposes to push the Annex III date later. Until that proposal is adopted, treat the obligations as legally scheduled and keep preparing.

  • High-risk categories include AI used in employment, education, essential services, critical infrastructure, biometrics, and law enforcement (Annex III).
  • Obligations cover a risk-management system, data governance, technical documentation, logging, human oversight, accuracy and robustness, plus conformity assessment and EU database registration.
  • The safe engineering position is to keep building the management system now: if the deferral passes you gain buffer, and if it does not you are ready.
  • Watch CEN-CENELEC JTC 21 harmonised standards, whose availability is the practical gating factor either way.

Who is a provider versus a deployer, and why does it change your duties?

Your obligations under the AI Act hinge on your role. A provider develops or places an AI system or GPAI model on the market under its own name; a deployer uses one under its authority in a professional context. Most SMEs are deployers, but fine-tuning or rebranding a model can quietly turn you into a provider.

  • Providers carry the heavier load: conformity assessment for high-risk systems, technical documentation, GPAI transparency, and post-market monitoring.
  • Deployers still have duties: human oversight, using systems per the provider's instructions, some Article 50 disclosures, and, for certain high-risk public-sector uses, a fundamental-rights impact assessment.
  • Role can flip: substantially modifying a high-risk system, or putting your own name or trademark on it, can make a deployer into a provider with the full obligation set.
  • Importer and distributor roles add further checks, so map every AI system to a named responsible party before you argue about which rules bite.

How do you engineer for a timeline that keeps moving?

Decouple compliance capabilities from statutory dates. Build the reusable pieces, an AI-system inventory, model and data documentation, a transparency and labelling layer, and an incident channel to the AI Office, so whatever date the Digital Omnibus fixes, you flip a switch rather than start a project. Track primary sources, not headlines.

  • Maintain an AI inventory classifying each system (prohibited / high-risk / limited / minimal) and its provider-versus-deployer role.
  • Documentation as a pipeline: generate model cards, data provenance, and evaluation results in CI, not as a one-off audit scramble.
  • Central transparency layer: one service for AI-interaction notices, content labelling, and provenance metadata.
  • Governance you will follow: lightweight, engineer-owned, and versioned, not a binder nobody reads.
  • Monitor primary sources: EUR-Lex, the Commission's AI Office, and the Digital Omnibus file, because the dates in this article may already have moved.

How TuniCyberLabs helps

We help EU and North African teams separate what the AI Act requires today from what the Digital Omnibus may defer: AI-system inventories, GPAI documentation and copyright-policy work, an Article 50 transparency and provenance layer, and a high-risk management system staged to whatever date lands. Because timelines remain in flux, we map every obligation to the current EUR-Lex text and the latest Commission guidance. Book an AI Act readiness review with our engineers.

TAGS
EU AI ActGPAIArticle 50Digital OmnibusAI ComplianceAI TransparencyAI GovernanceHigh-Risk AI

Frequently Asked Questions

What parts of the EU AI Act apply in 2026?

+

By August 2026, the prohibited practices and AI-literacy duty (in force since February 2025), the general-purpose AI model obligations (since August 2025), and the Article 50 transparency requirements (from 2 August 2026) all apply. The status of high-risk obligations is the moving part, subject to the Digital Omnibus proposal. Verify current dates against EUR-Lex.

Is the Digital Omnibus law?

+

As of writing, no. The Digital Omnibus is a European Commission proposal from November 2025 to simplify several digital rules, including deferring parts of the AI Act. It still has to pass the European Parliament and Council under the ordinary legislative procedure, so both its content and timing can change. Check the Commission's AI Act pages for the latest status.

When do high-risk AI obligations apply?

+

Under the AI Act as enacted, Annex III high-risk systems were scheduled from 2 August 2026 and product-embedded high-risk systems from 2 August 2027. The Digital Omnibus proposes to push the earlier date later, potentially into 2027 or 2028, tied to harmonised standards. Until it is adopted, treat 2 August 2026 as the legal baseline and confirm with primary sources.

What are the GPAI obligations under the AI Act?

+

Providers of general-purpose AI models must keep technical documentation, share integration information with downstream builders, publish a summary of training content, and maintain an EU copyright policy. Models posing systemic risk add model evaluation, adversarial testing, incident reporting to the AI Office, and cybersecurity measures. The voluntary GPAI Code of Practice is the main compliance route.

What does Article 50 of the AI Act require?

+

Article 50 sets transparency duties applying from 2 August 2026: telling users when they interact with AI, marking AI-generated or manipulated audio, image, video, and text in machine-readable form, and disclosing deepfakes. In practice this means building labelling, watermarking, and provenance metadata such as C2PA Content Credentials into your products, with narrow exceptions.

Do the AI Act penalties apply yet?

+

Yes. The penalty framework has applied since 2 August 2025. Breaching the prohibited-practice rules can cost up to 35 million euro or 7 percent of global annual turnover; most other obligation breaches up to 15 million euro or 3 percent; and supplying incorrect information up to 7.5 million euro or 1 percent. Enforcement mechanics are still maturing across Member States.

Need help with
this topic
?

Our team specializes in the technologies and strategies discussed in this article. Let’s talk about how we can help your business.

Get in Touch