Digital Omnibus on AI

You still register the AI system you decided isn’t high-risk

Under Article 6(4) of the EU AI Act (Regulation (EU) 2024/1689), a provider who concludes under Article 6(3) that its Annex III system is not, in fact, high-risk still has to register that system in the EU database — with a short summary of the grounds on which it reached that conclusion. That entry sits in the public section. The Commission’s Digital Omnibus proposal of 19 November 2025 tried to delete this obligation outright. Both the Council, in its negotiating mandate of 13 March 2026, and the European Parliament’s IMCO and LIBE committees, in a joint report adopted five days later on a 101-9-8 vote, independently rejected the deletion. The final text reinstates registration, with streamlined content requirements. If your compliance plan was drafted off the November proposal, it’s currently wrong.

The rule in one paragraph

Exemption doesn’t mean invisibility. Concluding that your Annex III system clears the Article 6(3) bar doesn’t end your paperwork — it starts a different kind. You keep the internal assessment that got you to that conclusion, you file a summary of it in the EU database, and that summary sits where the public can read it.

The three database categories

The EU database sorts entries into three categories, and who files depends on which one applies:

  • Category 1 — genuinely high-risk systems under Article 6(2) and Annex III. Filed under Annex VIII Section A. The provider files.
  • Category 2 — systems a provider has assessed as not-high-risk under Article 6(3). Filed under Annex VIII Section B. The provider files.
  • Category 3 — high-risk systems used by public authority deployers. Filed under Annex VIII Section C, including a summary of the data protection impact assessment carried out under Article 35 GDPR. The deployer files, not the provider.

Category 2 is the one that catches people off guard, precisely because “not high-risk” sounds like an off-ramp from the database entirely. It isn’t.

What your competitors get to read

Category 2 entries go into the public section of the database, the same section genuinely high-risk registrations sit in. The public section is free to access, navigable, and machine-readable. That’s not a side effect — it’s the design.

The practical consequence is straightforward and easy to underestimate: the legal argument you’re relying on to stay out of the high-risk regime is a document a competitor, a journalist, or an NGO can read, and can challenge. If your reasoning under Article 6(3) is thin, it’s thin in public.

The Article 80 backstop

Article 80 gives market surveillance authorities a specific procedure for exactly this situation, and it’s worth reading in full rather than taking on faith. Where an authority has sufficient reason to believe a system a provider classified as not-high-risk is actually high-risk, it tests that classification against the Article 6(3) conditions and the Commission’s guidelines. If the test confirms the system is high-risk, the authority orders the provider to bring it into compliance within a deadline the authority sets. Miss that deadline, and fines follow under Article 99 — that’s the backstop the brief refers to, and it’s a real, specific consequence, not a vague risk of reputational harm.

There’s a second, sharper consequence sitting one paragraph later. If the authority’s review finds the provider classified the system as not-high-risk specifically to circumvent the Chapter III Section 2 requirements — not a good-faith misjudgment, but an evasive one — that draws its own, separately finable violation under Article 99.

And Article 80 names its own evidence source. In exercising their oversight, market surveillance authorities may carry out checks that take into account, in particular, information stored in the EU database. That’s not a general observation about transparency — it’s the Act telling authorities where to look first. Your Category 2 summary isn’t a filing that disappears into an archive; it’s a named input into exactly the kind of review Article 80 describes.

What the Omnibus changed

The sequence is worth having straight, because it moved more than once. The Commission’s Digital Omnibus package, published 19 November 2025, proposed deleting the Article 6(4) registration obligation for self-assessed not-high-risk systems entirely. The Council’s negotiating mandate of 13 March 2026 rejected that specific deletion while broadly aligning with the Commission elsewhere, reinstating a simplified registration obligation. Five days later, on 18 March 2026, the Parliament’s IMCO and LIBE committees adopted a joint report doing the same, by a 101-9-8 vote. A provisional political agreement reached on 7 May 2026 confirmed the reinstatement, with streamlined Annex VIII Section B content — fewer data points required in the filing, without removing the filing itself. Parliament adopted the final text on 16 June 2026, and the Council gave its final green light on 29 June 2026.

What’s actually different in the streamlined Section B, line by line, isn’t something I can confirm precisely — commentary consistently describes it as a reduced set of required data points rather than a restructured form, but I haven’t seen the specific before-and-after list. What isn’t in question is the outcome: the obligation survived a deletion attempt from its own drafter, unanimously rejected by both co-legislators before trilogue even started.

One more date worth anchoring this to: Annex III high-risk obligations, under the same reform, now apply from 2 December 2027 rather than the original 2 August 2026. The registration duty for Category 2 systems tracks that same timeline.

The one Annex III category that escapes the EU database

There’s a genuine exception, and it’s narrow. High-risk AI systems falling under Annex III point 2 — critical infrastructure — register at national level instead of in the EU database. The Act doesn’t name a single EU-wide national register to check; the obligation is simply pushed down to whichever Member State mechanism applies, and that mechanism isn’t uniform across the Union. If your system is critical-infrastructure-adjacent, “check the EU database” isn’t the right instruction to give your compliance team.

Frequently asked questions

Do I register before or after placing the system on the market?

Before. Registration is structured as a precondition tied to placing the system on the market or putting it into service, not a filing you make afterward to tidy up the paperwork. Treat the Article 6(3) assessment and the database entry as part of your go-live checklist, not a follow-up task.

What if my system triggers the profiling override?

Then Article 6(3) isn’t available to you at all. Any Annex III system also used to profile natural persons is high-risk regardless of how narrow, preparatory, or human-reviewed its role looks otherwise — there’s no exemption to claim. You’re in Category 1, filing under Annex VIII Section A, not Category 2.

Can I redact the grounds I file?

Not for a standard Category 2 entry — the summary of your grounds is what goes in the public section, and that’s the point of the filing. Restricted, non-public treatment is reserved for specific categories named in the Act, chiefly biometrics, law enforcement, migration and border control, and similar sensitive uses. A conventional HR, credit, or education system claiming the Article 6(3) exemption doesn’t get that treatment.

Who registers if we’re the importer, not the original developer?

Ordinarily, the original provider — including one established outside the EU, acting through its EU authorised representative. You become the provider yourself, with the provider’s registration duty, only if you put your own name or trademark on the system, make a substantial modification to it, or modify a non-high-risk system’s intended purpose in a way that makes it high-risk. A straightforward import without any of that doesn’t shift the filing obligation onto you.

Does this apply to a system already on the market?

This is genuinely less settled than the rest of this piece. The Act’s general grandfathering rule protects high-risk systems already on the market from the new obligations unless they undergo significant changes, and the same logic would plausibly extend to a system you’d assessed, before the relevant date, as not needing Article 6(3) registration at all. But I haven’t found a source that addresses this specific edge case directly, so treat it as a reasonable inference rather than a confirmed answer, and check it against the Commission’s guidance before relying on it.

Posted by admin in Digital Operational Compliance & EU AI Act Knowledge Base

“Safety component” after the Omnibus: a narrower test

The Digital Omnibus narrows the definition that decides whether AI embedded in a regulated product counts as high-risk under the EU AI Act (Regulation (EU) 2024/1689). AI used solely for user assistance, performance optimisation, service efficiency or automation, or convenience or quality control no longer makes a component a “safety component” — and doesn’t trigger high-risk classification by virtue of sitting inside a regulated product — unless its failure or malfunction would actually endanger health or safety. Separately, the Machinery Regulation moved out of Annex I Section A into Section B entirely, so AI-enabled machinery now complies with sectoral safety rules instead of both regimes at once. Every guide written before May 2026 is describing a test that no longer applies.

The old test and why it swept too wide

Article 6(1) classifies an AI system as high-risk when two conditions are both met: it’s intended for use as a safety component of a product, or is itself a product, covered by the Annex I Union harmonisation legislation; and that product requires third-party conformity assessment under that legislation before it can be placed on the market. Whether an AI function counts as a “safety component” in the first place decides whether this whole test even applies.

The original definition of safety component covers a component that fulfils a safety function for a product or AI system, or whose failure or malfunction endangers the health and safety of persons or property. That second limb is where the trouble sits. Read expansively, almost any function embedded in a regulated product can be argued into it — an optimisation model inside a lift or a boiler doesn’t itself perform a safety function, but a sufficiently loose reading of “failure… endangers health and safety” could sweep it in anyway, on the theory that anything going wrong inside safety-regulated machinery carries some attenuated safety implication.

What the new test asks

The narrowed definition collapses this to one question: could the component’s failure or malfunction actually endanger health or safety? If the answer is no, and the function is assistance, optimisation, efficiency, automation, convenience, or quality control, it isn’t a safety component — regardless of what product it happens to sit inside.

Two examples on either side of the line. A predictive-maintenance model that flags when industrial machinery needs servicing is squarely an optimisation function: if it fails, the direct consequence is a missed maintenance window, not an immediate safety event, so it’s a strong candidate for falling outside the safety-component definition under the new test. A torque-limiting or collision-avoidance function built into the same machinery is a different case entirely — its failure directly creates a safety risk, which is exactly what the carve-out was never meant to exempt. The label attached to a function matters far less than what actually happens when it fails.

Annex I Section A vs Section B

This distinction decides how much of the Act applies at all. Section A covers New Legislative Framework legislation — medical devices, toys, personal protective equipment, gas appliances, and, until this reform, machinery. Section B covers other Union harmonisation legislation, including aviation security, agricultural and forestry vehicles, motor vehicle type-approval, marine equipment, and rail interoperability. For systems in Section B, only Article 6(1) itself, Articles 102 to 109, and Article 112 apply — essentially none of the Act’s substantive high-risk apparatus, the conformity assessment procedures, or the registration duties reach them at all.

The Omnibus moved only the Machinery Regulation from Section A to Section B. That’s a narrower outcome than what was actually on the table during trilogue: the deadlock that briefly collapsed negotiations centred on a Parliament proposal to exclude far more broadly — medical devices, toys, connected cars, and industrial machinery all together. The final compromise pulled back to Machinery alone. It isn’t a deregulation of industrial AI, either — the Commission is empowered to adopt delegated acts under the Machinery Regulation itself, not the AI Act, adding AI-specific health and safety requirements for systems that would otherwise have been high-risk. Oversight doesn’t disappear; it moves into the sectoral regime.

The other overlap relief, and its condition

Products that stayed in Section A — medical devices and toys among them — get a different, conditional form of relief instead of a full carve-out. Where the sectoral legislation already contains AI-specific requirements equivalent to or higher than the AI Act’s own, the Commission may, by implementing act, limit how far Articles 9 to 15 and 17 to 25 actually apply to those systems. That’s a genuinely different legal instrument from the Machinery-specific delegated acts, and it comes with its own timing: implementing acts addressing this general sectoral overlap are expected by 2 August 2027, while the Machinery-specific delegated acts are expected by 2 August 2028, tied to when Annex I obligations actually start binding. Both dates are worth putting on a calendar. Neither is a rule you can rely on today — nothing is actually limited until the Commission acts.

When any of this binds

Annex I high-risk obligations now apply from 2 August 2028 rather than 2 August 2027, under the same Digital Omnibus reform that deferred Annex III obligations to 2 December 2027. As with every date in this reform, it binds only once the amending regulation is published in the Official Journal and enters into force — as of this writing, formal adoption and publication were still pending, with the original 2 August 2026/2027 calendar remaining the legally operative one until that happens.

Frequently asked questions

Is a predictive maintenance model a safety component?

Generally not, under the narrowed test — unless the specific machine’s failure mode makes a missed service interval itself a direct safety event rather than an efficiency loss. That’s genuinely fact-specific: the same category of model can land on either side depending on what actually happens when the maintenance flag is missed.

Does the Medical Devices Regulation change?

Not in the same way. Medical devices remain in Annex I Section A — they didn’t get the Machinery-style move to Section B. What they get instead is the conditional relief described above: if the Commission determines, by implementing act, that the sectoral legislation already imposes equivalent AI-specific requirements, application of the relevant AI Act articles can be limited. Until that happens, the full parallel regime still applies.

What about toys and lifts?

Both stay in Section A, on the same footing as medical devices — eligible for the conditional implementing-act relief if the Commission acts, but not moved to Section B the way Machinery was. Lifts in particular sit under their own directive, separate from the Machinery Regulation, and nothing in this reform touched that separately.

Does “quality control” cover visual inspection?

Often, but not automatically. A visual-inspection model that flags defective units for human review before they’re used is a strong fit for the quality-control carve-out — its failure means a defect goes unflagged, not an immediate safety event. But if that inspection is the only safeguard standing between a genuinely dangerous defective unit and its use, the “failure would endanger health or safety” test can still catch it. The function’s name doesn’t decide the answer; the actual consequence of it failing does.

Who decides — us or the notified body?

The provider makes the initial classification call, consistent with how Article 6 works generally — nobody else does it for you upfront. Where third-party conformity assessment still applies, a notified body’s scope determination matters downstream, but a market surveillance authority retains the ordinary power to review a provider’s classification later and require correction if it disagrees, the same oversight mechanism that applies to Article 6(3) classification calls elsewhere in the Act.

Posted by admin in RegTech Glossary & Standards

Targeted job ads are high-risk AI under Annex III

Annex III point 4(a) of the EU AI Act (Regulation (EU) 2024/1689) covers AI intended to be used for recruiting or selecting natural persons, “in particular for placing targeted job advertisements, analysing and filtering applications, and evaluating candidates.” Targeted job advertising is named first, ahead of application filtering and candidate evaluation, in the operative text itself. Most HR compliance programmes classify the applicant tracking system and the interview-scoring tool without ever looking at the ad-targeting stack behind a recruitment campaign — because that stack usually sits with marketing, not HR, and nobody told marketing this Annex applies to them too.

What Annex III point 4 actually lists

Point 4(a) covers recruiting or selecting natural persons, with three named examples: placing targeted job advertisements, analysing and filtering applications, and evaluating candidates. Point 4(b) covers a separate category — decisions affecting the terms of a work-related relationship, promotion or termination of a work-related contract, allocating tasks based on an individual’s behaviour or personal traits, and monitoring or evaluating the performance and behaviour of people already in that relationship.

Why the ad stack is the blind spot

Follow where ownership actually sits inside a typical organisation. The applicant tracking system has an HR owner, and by now usually has an AI Act classification attached to it. The audience-targeting model deciding who sees a given job advertisement — built into or bolted onto a recruitment marketing campaign — has a marketing owner, and in most organisations no classification has ever been attempted. Both sit inside the same legal category. Annex III point 4(a) doesn’t distinguish between the system that decides who to interview and the system that decides who gets shown the ad in the first place; it names the second one first.

Can you exempt out under Article 6(3)?

Article 6(3) lets a provider treat an Annex III system as not high-risk where it poses no significant risk of harm and meets one of four conditions: it performs a narrow procedural task; it improves the result of a previously completed human activity; it detects decision-making patterns or deviations from them without replacing or influencing a previously completed human assessment without proper human review; or it performs a preparatory task for an assessment relevant to an Annex III use case.

Test an ad-targeting model against these honestly rather than reaching for whichever sounds closest. Deciding which individuals see a job advertisement, based on inferred interests, behaviour, or demographic proxies, is not a narrow procedural task — it’s a substantive targeting decision, arguably the central function of the model. It’s a weak fit for “improving a previously completed human activity” unless a human already decided the exact audience and the model only optimises delivery mechanics within that fixed audience. It doesn’t detect patterns or deviations from prior decisions in the way the third ground contemplates. And it’s a stretch to call the core targeting decision merely “preparatory” to some later assessment, when the targeting decision is often the entire point of the system.

The override that ends the argument

Even where one of the four grounds might plausibly fit, Article 6(3) closes with an override that applies notwithstanding all of them: an Annex III system is always considered high-risk if it carries out profiling of natural persons. No exemption survives that. An audience model built on individual behavioural traits — inferred interests, browsing history, demographic signals used to decide who sees what — is profiling by any ordinary reading of the term. That ends the Article 6(3) argument regardless of how well the model might otherwise have fit one of the four narrow grounds.

The price of claiming the exemption anyway

If you conclude your ad-targeting model genuinely clears Article 6(3) despite this, the exemption doesn’t make the system invisible. You keep the underlying assessment, and you register the system in the EU database with a summary of the grounds you relied on — and that summary sits in the database’s public section, readable by anyone, including a competitor or an advocacy group. The mechanics of that registration duty, and what happens if a market surveillance authority later disagrees with your classification, are covered in full in a companion piece on Article 6(3) registration and Article 80 enforcement rather than repeated here.

When this bites

Annex III obligations now apply from 2 December 2027, following the Digital Omnibus deferral, once the amending regulation is actually published in the Official Journal. Recruitment and employment systems sit in the Annex III categories that go through internal-control self-assessment rather than a notified body, so unlike biometric AI, there’s no third-party capacity bottleneck standing between now and that date. The sixteen-odd months between now and then are for inventory and classification work specifically — finding every system that touches recruitment, including the ones marketing owns — and that work doesn’t depend on any external standard or authority being ready first. Nothing about the extended timeline changes what needs to be found; it only changes how much time there is to find it.

Frequently asked questions

Does using LinkedIn’s ad targeting make us a deployer?

Likely yes. The platform is ordinarily the provider of the underlying targeting system, and the business running a recruitment campaign through it is the deployer — deployer obligations attach to you regardless of who built the model underneath the campaign tool you’re using.

What if the vendor says their tool isn’t high-risk?

Verify it yourself rather than relying on that assurance. The classification decision, and the consequences if a market surveillance authority later disagrees with it, attach to whoever is actually making the call — a vendor’s own marketing claim about its product’s risk tier doesn’t relieve you of that.

Are we the provider or the deployer?

Ordinarily the deployer, using a system someone else built. You become a provider yourself only if you put your own name or branding on the system, substantially modify it, or change a non-high-risk system’s intended purpose in a way that makes it high-risk — the same test that applies to importers and rebranders elsewhere in the Act.

Does a job board’s own matching algorithm count?

To the extent a job board’s algorithm recruits, selects, or filters candidates on an employer’s behalf, that function sits inside Annex III 4(a) in its own right — with the job board as a plausible provider of that specific functionality and the posting employer as its deployer.

Does an internal mobility tool count?

That sits closer to Annex III 4(b) than 4(a) — assessing existing employees for promotion or transfer eligibility is a decision affecting the terms of an employment relationship, not external recruitment. The same profiling override applies equally regardless of which limb of point 4 the tool falls under.

Posted by admin in Workforce, Labour & HR Compliance Reporting

EU AI Act Article 50 deadline: what didn’t get delayed

Article 50 of the EU AI Act (Regulation (EU) 2024/1689) applies from 2 August 2026. The Digital Omnibus on AI deferred the high-risk rules — stand-alone Annex III systems to 2 December 2027, systems embedded in regulated products under Annex I to 2 August 2028 — and left the transparency obligations exactly where they were. One piece moved: the Article 50(2) machine-readable marking duty for systems already on the market, which gets until 2 December 2026.

So the headline everyone read — the EU delayed the AI Act — describes a deferral that skipped the obligation closest to landing. If you ship a chatbot, a generative feature, or anything that produces synthetic images, audio, video or text into the EU, your deadline did not move.

What actually applies on 2 August 2026?

Four transparency obligations apply in full and unchanged from 2 August 2026. They sit in Article 50 and they split across providers and deployers:

  • Article 50(1) — AI interaction disclosure. Providers must design systems that interact directly with people so those people are informed they are dealing with an AI system, unless it would be obvious to a reasonably well-informed, observant and circumspect individual.
  • Article 50(3) — emotion recognition and biometric categorisation notice. Deployers must inform the people exposed to the system and process their personal data in line with data protection law. Recital 18 confines “emotion” to states such as anger, satisfaction or shame — it excludes physical states like pain and fatigue.
  • Article 50(4) — deepfake and public-interest text labelling. Deployers must disclose artificially generated or manipulated image, audio and video content, and AI-generated text published to inform the public on matters of public interest.
  • Article 50(5) — how the notice is given. Clear and distinguishable, at the latest at the first interaction or exposure, conforming to accessibility requirements, and accounting for vulnerable people.

Article 50(6) makes these cumulative with the high-risk and general-purpose AI transparency duties rather than an alternative to them. And the exposure is real money: Article 99(4)(g) puts breaches of Article 50 in the tier of up to €15,000,000, or 3% of total worldwide annual turnover for the preceding financial year if the offender is an undertaking, whichever is higher. For SMEs and start-ups, Article 99(6) inverts that — the cap is the percentage or the fixed amount, whichever is lower.

The one thing that moved

Article 50(2) — the provider duty to mark synthetic output in a machine-readable format and make it detectable as artificially generated — now applies from 2 December 2026 for systems placed on the market before 2 August 2026. Systems placed on the market from 2 August 2026 comply on placing. There is no relief for new products.

Here the sources contradict each other, and the contradiction starts at the top. The Council’s press release of 29 June 2026 says the regulation “reduces the grace period for providers to implement transparency solutions for artificially generated content from 6 months to 3 months, with the new deadline set on 2 December 2026.” Both halves of that sentence cannot be right: 2 August to 2 December is four months. Law firm summaries have repeated the three-month figure because they were reading the press release. The date is the operative fact and the date is 2 December 2026 — write that in the plan, not the arithmetic.

There is a second wrinkle worth checking against the final text. The Commission’s FAQ on the Code of Practice on Transparency of AI-Generated Content describes the transitional period as covering AI systems in scope of Article 50(2) and (4) placed on the market before 2 August 2026. The Council press release describes it narrowly, as a grace period for providers implementing marking. The narrow reading is the safer one to plan against.

What the Omnibus did defer

The deferrals are real, they are substantial, and none of them touch Article 50(1), (3), (4) or (5). Taken from the Council’s own record of the adopted regulation:

Obligation Original date New date
Stand-alone high-risk AI systems (Article 6(2), Annex III) 2 August 2026 2 December 2027
High-risk AI embedded in regulated products (Article 6(1), Annex I) 2 August 2027 2 August 2028
National AI regulatory sandboxes established by competent authorities 2 August 2026 2 August 2027
Article 50(2) marking, systems on the market before 2 August 2026 2 August 2026 2 December 2026
New Article 5 prohibition on AI-generated NCII and CSAM December 2026

That last row is the tell. This package was not a retreat. It added a prohibition on generating non-consensual sexual imagery and child sexual abuse material — the “nudifier” ban — into Article 5, alongside the deferrals. Marilena Raouna, Cyprus’s Deputy Minister for European Affairs, framed the adoption this way: “by banning AI-generated or manipulated sexual deepfakes and AI-generated child sexual abuse material, we are sending a clear message that technological progress must always go hand in hand with the protection of our fundamental values.”

The regulation also clarifies the AI Office’s supervisory competence over AI systems built on general-purpose AI models by the same provider, while leaving national authorities competent in law enforcement, border management, judicial authorities and financial institutions. Products covered by the Machinery Regulation ((EU) 2023/1230) are exempted from the AI Act’s direct applicability, and a new mechanism lets the Commission limit AI Act requirements by implementing act where sectoral law — medical devices, toys, lifts, watercraft — already imposes similar ones.

Is the Omnibus actually law yet?

As at 16 July 2026, no. The European Parliament endorsed the text on 16 June 2026 and the Council gave its final green light on 29 June 2026, closing procedure 2025/0359(COD). But the Council’s own next-steps note says the act “will be published in the EU’s official journal shortly and will enter into force on the third day after this publication.” No publication has been confirmed at the time of writing.

Until entry into force, the original calendar in Article 113 is the law. That is not a technicality — it is the difference between a plan and a hypothesis. The arithmetic is tight: with entry into force three days after publication, the regulation has to reach the Official Journal by 30 July 2026 to be in force before the 2 August 2026 date it is meant to displace. The co-legislators know this, which is why the Council said it treated this part of the package with “utmost priority.”

You can check the position yourself against the adopted text (PE-30-2026-INIT) and the EU Law tracker entry for procedure 2025/359 rather than against a summary. If you are reading this after publication, the dates in the table above are binding; before it, they are a forecast with very good odds.

What this means for your roadmap

An Article 50 programme cannot be re-baselined to 2027. Marking, labelling and first-interaction notice are engineering and design work against a fixed date, and the Omnibus gives you nothing on any of them except the legacy marking window.

The concrete pieces to have in place:

  • Inventory by Article 50 paragraph, not by risk tier. Article 50 catches minimal-risk systems. A support chatbot that will never be high-risk is still in scope of 50(1).
  • Marking for generative output across every modality — audio, image, video, text — for anything placed on the market from 2 August 2026, and by 2 December 2026 for what is already out there.
  • A decision on the Code of Practice. The Code of Practice on Transparency of AI-Generated Content was published on 10 June 2026; the Commission concluded on 8 July 2026 that it adequately covers Articles 50(2), (4) and (5), and the AI Board adopted its adequacy assessment the following day. Signing is voluntary and severable — the provider section and the deployer section can be signed independently. It is also not conclusive evidence of compliance, in the Commission’s own words.
  • Watch for the Commission’s Article 50 guidelines, which the Commission has said will be published ahead of 2 August 2026 and which will settle scope questions the Code deliberately leaves alone — including how far the “obvious” exception in Article 50(1) actually reaches.

The reasonable read of the last twelve months: the EU deferred the obligations that depend on infrastructure it hasn’t built — harmonised standards, notified bodies, designated national authorities — and kept the ones that depend only on you.

Frequently asked questions

Did the EU delay the whole AI Act?

No. The Digital Omnibus on AI deferred the high-risk obligations under Article 6(2) and Annex III to 2 December 2027, and those under Article 6(1) and Annex I to 2 August 2028, plus the national sandbox deadline to 2 August 2027. The Article 5 prohibitions (in force since 2 February 2025), the general-purpose AI rules (2 August 2025) and the Article 50 transparency obligations (2 August 2026) were not deferred.

Do I need watermarking by August 2026?

If the system is placed on the EU market from 2 August 2026, yes — Article 50(2) machine-readable marking applies at the point of placing, with no transitional period. If the system was already on the market before that date, the marking duty applies from 2 December 2026.

What if my system shipped in 2025?

It gets the Article 50(2) marking extension to 2 December 2026. It does not get an extension on Article 50(1) interaction disclosure, Article 50(3) emotion recognition notice or Article 50(4) deepfake labelling — those apply from 2 August 2026 regardless of when the system shipped.

Are the prohibitions delayed?

The existing Article 5 prohibitions have applied since 2 February 2025 and were never in scope of the deferral. The Omnibus adds a new prohibition on AI-generated non-consensual intimate imagery and CSAM, which the Council says takes effect in December 2026.

When will the Omnibus be in the Official Journal?

Not confirmed as at 16 July 2026. The Council said on 29 June 2026 that publication would follow “shortly,” with entry into force on the third day after. Working back from 2 August 2026, publication needs to happen by 30 July 2026 for the new dates to displace the old ones in time.

What is the fine for breaching Article 50?

Article 99(4)(g) sets the ceiling at €15,000,000 or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher. For SMEs and start-ups, Article 99(6) reverses the test: the cap is whichever of the two is lower.

Posted by admin in Data, Identity & Compliance UX Knowledge Base