Prices & updates · AI Policy & Security
EU AI Act: what applies and when, after the 2026 Omnibus
Short answer
The AI Act applies in stages: prohibited practices and AI literacy since February 2, 2025; general-purpose model rules since August 2, 2025; most other rules, including chatbot, deepfake and AI-content transparency, since August 2, 2026. The 2026 Digital Omnibus (Regulation (EU) 2026/1744) moved high-risk obligations to December 2, 2027 (Annex III) and August 2, 2028 (Annex I) and adds two prohibitions from December 2, 2026.

Prices, limits and features change often. We date every figure and link to its source: check the vendor's page before you buy or build. How we make money.
The EU Artificial Intelligence Act (Regulation (EU) 2024/1689) entered into force on August 1, 2024, but its rules apply in stages. In July 2026 the EU changed several of those dates with the "Digital Omnibus on AI", Regulation (EU) 2026/1744, which entered into force on July 27, 2026. This guide sets out what applies now and what comes next, with the article for each rule, from the texts published in the Official Journal and checked on October 1, 2026.
It is general information, not legal advice. If your company builds or sells AI systems that could be high-risk, talk to a lawyer who knows the regulation.
Timeline: what applies and when
| Date | What applies | Where |
|---|---|---|
| Aug 1, 2024 | The regulation enters into force | Art. 113 |
| Feb 2, 2025 | Definitions, AI literacy and the original list of prohibited practices | Chapters I and II, Arts. 4 and 5 |
| Aug 2, 2025 | Rules for general-purpose AI models, governance and penalties | Chapters V, VII and XII |
| Jul 27, 2026 | The Digital Omnibus on AI enters into force | Regulation (EU) 2026/1744 |
| Aug 2, 2026 | Most of the regulation, including the transparency rules for chatbots, deepfakes and AI-generated content | Art. 113, Art. 50 |
| Dec 2, 2026 | Two new prohibitions (below), and the deadline for generative AI systems already on the market before Aug 2, 2026 to mark their output | Art. 5(1)(ba) and (bb), Art. 50(2) |
| Aug 2, 2027 | Each member state must have at least one AI regulatory sandbox running | Art. 57, as amended |
| Dec 2, 2027 | Obligations for high-risk systems listed in Annex III (stand-alone uses such as hiring or credit scoring) | Chapter III, Sections 1 to 3 |
| Aug 2, 2028 | Obligations for high-risk AI in regulated products listed in Annex I | Chapter III, Sections 1 to 3 |
The two high-risk dates are the main change made by the Omnibus. They were originally August 2, 2026 for Annex III systems and August 2, 2027 for Annex I. The regulation's own recitals say that keeping the original date risked "a significant increase in implementation costs" because the supporting standards and tools were not ready.
Who has obligations
The regulation assigns duties by role:
- Providers develop an AI system or model and place it on the market under their name. Most obligations fall on them.
- Deployers use an AI system under their own authority in a professional activity. A company using an AI assistant or a chatbot for its customers is a deployer.
- Importers and distributors have their own, lighter obligations.
What applies to most businesses using AI today
AI literacy (Art. 4). As amended by the Omnibus, providers and deployers must "take measures to support the development of AI literacy" of their staff and others who use AI systems on their behalf, considering their knowledge and the context of use. The amended text adds that this "does not require providers or deployers to guarantee any specific level of AI literacy of any individual". In practice: training and guidance proportionate to how your people use AI.
Transparency (Art. 50), from August 2, 2026:
- Chatbots and other systems that talk to people: providers must design them so people are told they are interacting with an AI system, unless that is obvious from the context.
- Generated content: providers of systems that generate synthetic audio, images, video or text must mark the output in a machine-readable format so it can be detected as AI-generated.
- Deepfakes: deployers that generate or manipulate image, audio or video "constituting a deep fake" must disclose it. For evidently artistic, satirical or fictional work, the duty is limited to disclosing it in a way that does not spoil the work.
- AI-written text about matters of public interest: deployers that publish AI-generated text "with the purpose of informing the public on matters of public interest" must disclose it, unless the text has gone through human review or editorial control and a person or company holds editorial responsibility for it.
- Emotion recognition and biometric categorisation: deployers must inform the people exposed to them.
The information must be given "in a clear and distinguishable manner", at the latest at the first interaction or exposure.
Prohibited practices
Since February 2, 2025, Article 5 bans AI systems that:
- use subliminal, manipulative or deceptive techniques that materially distort behaviour and cause significant harm;
- exploit vulnerabilities due to age, disability or a specific social or economic situation;
- score people on their social behaviour or personal traits, leading to unjustified or unrelated detrimental treatment;
- predict the risk of a person committing a crime based solely on profiling or personality traits;
- build facial recognition databases through untargeted scraping of facial images from the internet or CCTV;
- infer emotions in the workplace or in education, except for medical or safety reasons;
- categorise people by biometric data to infer race, political opinions, trade union membership, religious beliefs, sex life or sexual orientation;
- use real-time remote biometric identification in public spaces for law enforcement, except in narrowly defined cases.
From December 2, 2026, the Omnibus adds two more: AI systems that generate or manipulate realistic intimate images, video or audio of an identifiable person without their explicit consent, and AI systems that generate child sexual abuse material. For providers, the ban covers systems whose intended purpose is that output, or whose design makes it "a reasonably foreseeable and reproducible outcome".
Penalties
Member states set the penalties within the regulation's limits. Breaching the prohibitions can cost up to €35 million or 7% of worldwide annual turnover, whichever is higher. Breaching most other obligations, including the transparency rules of Article 50 and deployers' obligations, can cost up to €15 million or 3%. The regulation requires penalties to take into account the interests and economic viability of small and medium-sized enterprises.
A short checklist
- List where you use AI, and for each use whether you are a provider or a deployer.
- Check Article 5 against anything that scores, profiles, monitors emotions or uses biometric data.
- Put AI literacy measures in place: guidance and training matched to how each team uses AI.
- Label chatbots and AI-generated media from August 2, 2026, and keep records of how you do it.
- Check whether any use is high-risk under Annex III (for example, recruitment, education, credit or essential services). If so, plan for December 2, 2027.
For how AI agents fit into this, including the security side, see AI agents for business.
What we checked
- Article 113: application from August 2, 2026; Chapters I and II from February 2, 2025; Chapters V, VII, XII and Chapter III Section 4 from August 2, 2025; Article 6(1) originally from August 2, 2027. (EUR-Lex (Publications Office of the EU), )
- Article 5(1)(a) to (h) prohibited practices; Article 50(1) to (5) transparency obligations, including deepfakes and AI-generated text on matters of public interest; Article 99(3) and (4) fines of up to EUR 35 million or 7% and EUR 15 million or 3%. (EUR-Lex (Publications Office of the EU), )
- Regulation (EU) 2026/1744 of July 8, 2026, published July 24, 2026 and in force on the third day after publication, moves Chapter III Sections 1 to 3 to December 2, 2027 (Annex III) and August 2, 2028 (Annex I). (EUR-Lex (Publications Office of the EU), )
- The Omnibus replaces Article 4 (AI literacy), adds prohibitions in Article 5(1)(ba) and (bb) from December 2, 2026, gives pre-existing generative systems until December 2, 2026 to comply with Article 50(2), and requires a national AI regulatory sandbox by August 2, 2027. (EUR-Lex (Publications Office of the EU), )
What may change
- The Commission is due to publish guidelines, codes of practice and delegated acts on several articles in 2026 and 2027.
- National penalty rules and supervisory authorities differ by member state.
- Harmonised standards for high-risk systems are still being developed.
Frequently asked questions
When does the EU AI Act apply?
In stages: Chapters I and II (including AI literacy and prohibited practices) since February 2, 2025; general-purpose AI model rules since August 2, 2025; most of the regulation since August 2, 2026; high-risk obligations from December 2, 2027 (Annex III) and August 2, 2028 (Annex I).
Did the Digital Omnibus delay the AI Act?
Only parts of it. Regulation (EU) 2026/1744, in force since July 27, 2026, moved the high-risk obligations to December 2, 2027 and August 2, 2028. The transparency rules of Article 50 still apply from August 2, 2026.
Do I have to tell customers they are talking to a chatbot?
Article 50(1) requires providers to design chatbots so people are informed they are interacting with an AI system, unless that is obvious from the context. The information must be clear and given at the latest at the first interaction.
What are the fines under the AI Act?
Up to €35 million or 7% of worldwide annual turnover, whichever is higher, for prohibited practices, and up to €15 million or 3% for most other obligations. Member states set the penalties within those limits.
Sources
- Regulation (EU) 2024/1689 (Artificial Intelligence Act), Official Journal text, EUR-Lex (Publications Office of the EU). Accessed October 1, 2026.
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), amending Regulation (EU) 2024/1689, EUR-Lex (Publications Office of the EU). Accessed October 1, 2026.
Spotted an error or an outdated price? Tell us and we will fix it.
Change history
- : First published, including the changes made by the Digital Omnibus on AI (Regulation (EU) 2026/1744).
Next review: .