Back to Blog
Compliance

AI Act Readiness for EU Companies: What to Fix Before August 2026

Autark Compliance

If your compliance plan was built before May 2026, parts of it are already wrong.

On May 7, 2026, the European Parliament and Council reached a provisional agreement on the Digital Omnibus on AI, delaying several high-risk AI deadlines that the industry had been counting down. Annex III high-risk obligations moved from August 2026 to December 2, 2027. Article 50(2) watermarking moved to December 2, 2026.

That led some teams to relax. That is a mistake.

August 2, 2026 still matters. Multiple obligations take effect or gain enforcement teeth on that date. Treating the Omnibus as "we got an extra year on everything" is how deployers end up unprepared.

This article is general information, not legal advice. Confirm obligations with qualified counsel for your specific systems and jurisdictions.

What still applies on August 2, 2026

According to post-Omnibus analyses from Axis Intelligence and the EU AI Act Checklist:

Article 50 transparency (most provisions)

Users interacting with AI must know they are interacting with AI. AI-generated content must be labeled appropriately. Emotional-recognition and certain synthetic media disclosures apply as enacted.

If your product presents AI output as human-written without disclosure, you have a UX compliance problem, not just a legal footnote.

GPAI enforcement authority

GPAI model obligations have applied since August 2, 2025. What activates August 2026 is the EU AI Office's power to impose fines on GPAI providers for noncompliance, up to €15 million or 3% of global annual turnover.

If you are a deployer using third-party models, you inherit supply-chain risk: vendor diligence matters.

Article 4 AI literacy

Providers and deployers must ensure personnel operating AI have sufficient AI literacy. Obligations have been in force since February 2025; enforcement infrastructure becomes operational across member states by August 2026.

"We'll train people later" is no longer a schedule you control.

Article 5 prohibited practices

Prohibitions (manipulation, social scoring, certain biometric uses, etc.) have been legally operative since February 2025. August 2026 brings fuller cross-border enforcement infrastructure, not new permissions to ignore existing bans.

What moved (do not ignore, but calendar correctly)

ObligationOriginal dateNew date (Omnibus, provisional)
Annex III high-risk systemsAug 2, 2026Dec 2, 2027
Annex I embedded high-riskAug 2, 2027Aug 2, 2028
Article 50(2) watermarking (existing models)Aug 2, 2026Dec 2, 2026

The Omnibus remains provisional until formally adopted. Monitor final text in the Official Journal. If adoption fails, original dates may apply (Baker Botts analysis).

Deployer vs provider: know your role

Most enterprises are deployers: you use AI in products and internal tools, often via APIs from GPAI providers. You are not training frontier models, but you are responsible for:

  • Transparency in user-facing AI features
  • AI literacy for staff who operate systems
  • Risk classification of your use cases (even if high-risk deadlines moved)
  • Vendor diligence on subprocessors and data handling
  • Documentation that supports conformity if your system is high-risk later

Using ChatGPT or Claude through a consumer account without governance is not a deployer strategy. It is shadow AI with regulatory exposure.

90-day action plan (starting now)

Weeks 1–2: Inventory

  • List every AI system affecting EU users (customer-facing and internal)
  • Tag each: vendor, data types processed, human oversight level, user-facing yes/no
  • Identify which use Article 50 transparency triggers (chatbots, content generation, synthetic media)

Weeks 3–4: Classification

  • Preliminary risk classification against Annex III categories (employment, credit, education, etc.)
  • Even with deferred high-risk dates, classification drives resource allocation
  • Document decisions; "we haven't classified" is not a defensible state

Weeks 5–8: Fix user-facing gaps

  • Add AI disclosure to chat interfaces ("You are chatting with an AI assistant")
  • Label AI-generated content in product outputs where required
  • Update privacy notices and subprocessors lists for AI vendors

Weeks 9–12: Governance infrastructure

  • AI literacy program for operators (not just data scientists: PMs, support, HR using AI tools)
  • Approved vendor list; block or monitor shadow AI (see our shadow AI post)
  • Technical controls: EU-region inference, zero retention architecture, audit metadata

How infrastructure choices help

Compliance is easier when architecture matches policy:

  • EU regional deployment for data residency arguments
  • Zero prompt retention so GDPR erasure and breach scope stay bounded
  • Centralized API gateway with logging for token usage and model routing (metadata, not content)
  • Human-in-the-loop workflows for high-impact decisions

Autark is designed for deployers who need EU-capable, zero-retention inference without building a full AI compliance team from scratch. See Trust Center and Company.

The bottom line

August 2026 is not the deadline for everything. It is also not a free pass.

Transparency, literacy, prohibited practices, and GPAI enforcement are live or activating. High-risk system work is deferred, not deleted.

Inventory now. Disclose in product. Train operators. Fix shadow AI. Document everything.

Your counsel will thank you. Your auditors will expect it.

Trust Center · Contact