Guide · Regulation
The Digital Omnibus changed the timeline in July 2026. Here is what already applies, what arrives on 2 December 2027, the obligations for a business that uses AI, and a six-step action plan.
The date that moved
High-risk deadline: moved from 2 August 2026 to 2 December 2027.
In short
For most SMEs, the AI Act currently comes down to three tasks: train the teams that use AI, label agents and chatbots as AI, and check that no use falls into a high-risk category. Everything else depends on what your systems do.
Timeline
| Date | What applies | Reference |
|---|---|---|
| 1 August 2024 | Regulation enters into force | Art. 113 |
| 2 February 2025 | Prohibited practices and AI literacy | Art. 5 and 4 |
| 2 August 2025 | General-purpose AI models, penalty regime, national authorities | Chap. V, Art. 70 and 99 |
| 2 August 2026 | Transparency obligations (chatbots, generated content) | Art. 50 |
| 2 December 2026 | Content marking for systems already on the market; two new bans | Art. 50(2) and 5 |
| 2 August 2027 | National regulatory sandboxes; general-purpose models placed on the market before 2 August 2025 | Art. 57 and 111 |
| 2 December 2027 | High-risk systems under Annex III | Art. 6(2) |
| 2 August 2028 | High-risk systems built into products (Annex I) | Art. 6(1) |

What changed
The Commission proposed the Digital Omnibus on AI on 19 November 2025. The European Parliament voted for it on 16 June 2026 and the Council gave final approval on 29 June. It was published in the Official Journal on 24 July 2026 as Regulation (EU) 2026/1744 and entered into force on 27 July 2026. It is now binding law.
What it means for a business:
The postponement leaves the rules already in force untouched. It gives sixteen more months to prepare high-risk uses, including recruitment: our comparison of AI agencies for HR explains what this means for tools that screen job applications.
Today
Prohibited practices (Article 5), since 2 February 2025. These include social scoring, manipulation that exploits vulnerabilities, and emotion recognition in the workplace or in education, except for medical or safety reasons. An HR tool that analyses candidates' emotions during video interviews falls under this ban.
AI literacy (Article 4), since 2 February 2025. Businesses that use AI systems must take measures so that their staff, and the people who use these systems on their behalf, understand the tools. In its FAQ, the Commission states that no certification is required, that there is no one-size-fits-all approach, and that keeping an internal record of training is useful. It suggests four steps: a general understanding of AI, the role of the business, the risks of the systems in use, and then training suited to each person's level.
Transparency (Article 50), since 2 August 2026. People must be told they are dealing with an AI, at the latest during the first interaction, unless it is obvious. Deepfakes must be labelled. Our guide to the transparency obligation for AI agents explains who must do what between the tool vendor and the business that deploys it.
Classification
A system is classified by its purpose, and its sector alone settles nothing. Under Article 6(2), a system is high-risk when it is used for one of the purposes listed in Annex III.
| Level | Examples | Regime |
|---|---|---|
| Unacceptable | Social scoring, emotion recognition at work | Banned since 2 February 2025 |
| High-risk | Screening job applications, credit scoring, life and health insurance pricing | Obligations from 2 December 2027 |
| Transparency | Chatbots, conversational agents, generated content | People must be informed since 2 August 2026 |
| Minimal | Internal automation, spam filters, writing assistance | No specific obligation beyond Article 4 |
Article 6(3) sets out an exception. A system listed in Annex III does not count as high-risk if it only performs a narrow procedural task, improves the result of a human activity already completed, detects patterns without replacing human assessment, or performs a preparatory task. This exception never applies to a system that profiles natural persons. A provider relying on it must document its assessment.
The Commission is preparing guidelines on this classification; the final version is expected by the end of 2026.
By sector
| Sector | High-risk (Annex III or I) | Usually outside high-risk |
|---|---|---|
| Human resources | Targeted job ads, sorting and filtering applications, evaluating candidates, promotion or termination decisions, performance monitoring (4a, 4b) | Writing job ads, scheduling interviews, answering candidate questions |
| Real estate | Creditworthiness assessment for a mortgage (5b). Tenant scoring is a grey area | Lead qualification, writing listings, booking viewings |
| Legal | Systems used by a judicial authority or in alternative dispute resolution (8a) | Legal research and case pre-qualification in a law firm |
| Healthcare | Emergency patient triage (5d); AI built into a medical device subject to third-party conformity assessment (Annex I, 2 August 2028) | Appointment booking, administrative document sorting |
For concrete use cases by profession, see our guides on human resources, real estate, legal and healthcare.
Your role
The AI Act separates the provider, who develops an AI system or has it developed and places it on the market under its own name, from the deployer, who uses a system under its authority in a professional context. An SME using an AI tool it has bought is a deployer. It can become a provider if it sells a system under its own brand, substantially modifies it, or changes its purpose to the point of making it high-risk.
For a high-risk system, Article 26 requires the deployer, from 2 December 2027, to:
Article 27 adds a fundamental rights impact assessment for some deployers: public bodies, private entities providing public services, and businesses that use AI to assess people's creditworthiness or price life or health insurance.
When you commission a custom agent, the split of roles should be written into the contract. Our design principles are set out in our guide to AI agent security.
Financial risk
| Breach | Maximum fine |
|---|---|
| Prohibited practice (Article 5) | €35M or 7% of worldwide annual turnover |
| Other obligations, including deployer and transparency obligations | €15M or 3% |
| Incorrect or misleading information supplied to authorities | €7.5M or 1% |
For SMEs and start-ups, Article 99(6) uses the lower of the two amounts. These figures are caps: the national authority sets the fine based on the seriousness and duration of the breach and the size of the business.
France
As of 13 September 2026, France has not yet passed the law designating its competent authorities. The provisions sit in a bill adapting French law to EU law, approved by the Senate on 18 February 2026 and still under discussion at the Assemblée nationale.
The bill gives coordination and the single point of contact role to the DGCCRF (French consumer protection authority), and a central role to the CNIL (French data protection authority) for high-risk systems, in particular those related to employment and biometrics. The ACPR would oversee credit and insurance, the ANSM medical devices, and Arcom synthetic content. These roles still need to be confirmed by the final vote.
In its Q&A page updated on 17 August 2026, the CNIL points out that it remains fully competent to apply the GDPR, and that the AI Act adds to the GDPR without replacing it.
Taking action
This work is part of our AI consulting and of every project we deliver in a regulated sector. If your use relies on an AI API, data hosting is also a question: see our guide to Claude API pricing and hosting.
FAQ
Related guides
Article 50 in detail: who must inform whom, and how.
Human oversight, logging and least privilege in practice.
The sector most directly affected by the high-risk rules.
Links verified at publication. Regulatory texts change — always defer to the official source.
A question, a project, an idea? We respond within 24h. Free audit, no commitment.