EU AI Act 2026: What Moved, What Didn’t, What to Build
The Deadline Moved. Not Much Else Did.
On June 29, 2026, the Council of the European Union gave final approval to the Digital Omnibus, the first amendment to the EU AI Act since it was adopted in 2024. The headline change: the compliance deadline for high-risk AI systems under Annex III moved from August 2, 2026 to December 2, 2027, a 16-month deferral. AI embedded in regulated products such as medical devices and machinery got a separate 12-month extension, to August 2, 2028.
One procedural detail matters for anyone planning against these dates. The amendment was signed on July 8, 2026 and takes effect three days after publication in the Official Journal, which has to happen before August 2, 2026 for the new calendar to replace the old one in time. Until that publication lands, the original AI Act timeline stays the legal baseline.
That deferral covers the heaviest compliance work: risk management, data governance, human oversight, conformity assessment. It does not touch three things still on the original schedule. Article 50 transparency obligations, covering chatbot disclosure and AI-content labeling, take effect August 2, 2026 regardless of risk tier. Watermarking duties follow on December 2, 2026 for systems already on the market, and apply from August 2, 2026 for anything launched after that date. And the Act’s extraterritorial reach was never in question: if a product’s output reaches a user in the EU, the company is in scope, wherever it is headquartered.
Fines run up to €35 million or 7% of global annual turnover under Article 99, whichever is higher, live and enforceable since August 2, 2025.
The Full Timeline, Updated
The Digital Omnibus did not touch the Act’s underlying architecture. Four risk tiers, the conformity assessment regime, the General-Purpose AI (GPAI) track, and the AI Office’s oversight role all remain exactly as adopted in the consolidated text of Regulation (EU) 2024/1689. What changed is the calendar. The chart below lays out every obligation already in force, what’s still due in 2026, and what’s now pushed to 2027 and 2028.
Four Tiers, One Question: Which One Is Your Product?
Every AI system placed on the EU market, or whose output reaches an EU user, falls into one of four tiers. Unacceptable-risk practices, including social scoring and certain biometric categorization, have been banned since February 2, 2025. High-risk systems, covering domains like recruitment, credit scoring, and law enforcement, carry the heaviest documentation and testing burden, now due December 2, 2027 for stand-alone systems. Limited-risk systems face the Article 50 transparency duties. Minimal-risk systems carry no obligations at all. Most B2B SaaS products land in limited or high risk depending on what the AI actually decides, not what model it’s built on.
Provider or Deployer? The Line That Changes Your Budget
If a product calls a foundation model’s API and uses its output largely as-is, that makes it a deployer under the Act. Deployer obligations are real but comparatively light: use the system as intended, monitor for known risks, keep basic usage records.
Substantially modify a foundation model, through extensive fine-tuning or by changing its intended purpose, and the classification can shift to provider. Provider obligations include the full Articles 9-15 stack: risk management, technical documentation, conformity assessment. The AI Office’s guidelines define the boundary, and it remains a gray area worth tracking rather than assuming away.
A retrieval-augmented generation (RAG) pipeline built on top of an off-the-shelf model usually stays deployer territory. A model retrained on proprietary data to change its core behavior usually does not. Map every AI feature on the roadmap against this line before scoping compliance work, not after.
What to Architect for High-Risk Systems (Articles 9-15)
A documented process that identifies, evaluates, and mitigates risks across the system’s entire lifecycle, not a one-time assessment before launch.
Training, validation, and testing data need documented quality, representativeness, and bias checks, with the documentation itself treated as a deliverable.
Automatically generated logs, version-controlled documentation, and a clear audit trail from any decision back to the data and model version that produced it.
A defined mode of human involvement, whether human-in-the-loop, on-the-loop, or over-the-loop, with named people trained for the role and a real ability to intervene, not a rubber-stamp UI.
The system needs to perform consistently under adverse conditions, resist adversarial manipulation, and degrade safely rather than fail silently. See our DevSecOps practices for the security half of this requirement.
Providers need an organization-level QMS wrapping all of the above, not just per-project documentation.
Article 50 Still Lands August 2, 2026
Article 50 applies regardless of risk tier, which is what makes it easy to underestimate. Any system that interacts with a person needs to disclose that it’s AI, unless that’s obvious from context. Any system that generates or manipulates image, audio, or video content needs to label that output as AI-generated, in a machine-readable format. Watermarking specifically follows on December 2, 2026, shortened from the original six-month grace period to three. Neither date moved during the Omnibus negotiations. A product team that built its 2026 roadmap around the Annex III deferral and skipped Article 50 will find the wrong obligation was on the calendar.
What a Violation Actually Costs (Article 99)
Three fine tiers under Article 99 of the AI Act, live and enforceable since August 2, 2025.
For SMEs and startups, the lower of the two figures applies, not the higher. A startup with €3 million in annual turnover facing a prohibited-practice violation is capped at roughly €210,000, not €35 million, though the practice itself still has to stop immediately.
Headquartered in the US Doesn't Mean Out of Scope
That reach is exactly why the provider/deployer distinction above matters as much for a Texas-incorporated startup as for a Berlin one.
Build the Compliance Layer Once
Retrofitting audit trails, human-oversight hooks, and documented data lineage into a system that’s already shipping costs more than designing them in from the first sprint. It costs more again if a fine-tuning decision quietly reclassifies a team from deployer to provider mid-project. Teams that map their AI features against the risk tiers and the provider/deployer line before scoping a build tend to ship the compliance layer once. Teams that treat the 2027 deferral as a reason to wait tend to build it twice: once informally now, and once properly under deadline pressure later.
Ready to map your product roadmap against these obligations? Contact our team to scope an AI Act readiness review.
Common Mistakes We See
Teams tracking just the high-risk deadline can miss Article 50 disclosure and December 2026 watermarking, both unaffected by the deferral.
Calling an API doesn’t guarantee deployer status if fine-tuning or repurposing crosses into provider territory.
Articles 9-15 describe engineering work, logging, versioning, human-oversight UI, not paperwork produced after the system is built.
Article 2’s reach depends on where the output lands, not where the company is incorporated.
FAQ
Yes, for stand-alone high-risk systems under Annex III. The Council of the European Union gave final approval to the Digital Omnibus on June 29, 2026, deferring that deadline from August 2, 2026 to December 2, 2027.
Article 50 transparency obligations, covering AI disclosure and content labeling, take effect August 2, 2026 as originally scheduled. Watermarking for AI-generated content follows on December 2, 2026.
Yes. Article 2 applies to any provider or deployer whose AI system is placed on the EU market or whose output is used by a person in the EU, regardless of where the company is headquartered.
A deployer uses an AI system as intended. A provider places it on the market or has substantially modified it, for example through significant fine-tuning. Providers carry the full Articles 9-15 obligations; deployers carry lighter ones.
Up to €35 million or 7% of global annual turnover for prohibited practices, €15 million or 3% for most high-risk and transparency violations, and €7.5 million or 1% for providing incorrect information to regulators, under Article 99.
Yes. For SMEs and startups, regulators apply the lower of the fixed euro amount or the percentage of turnover, not the higher, which caps exposure well below the headline €35 million figure.