AI Act Readiness for EU Companies: What to Fix Before August 2026
If your compliance plan was built before May 2026, parts of it are already wrong.
On May 7, 2026, the European Parliament and Council reached a provisional agreement on the Digital Omnibus on AI, delaying several high-risk AI deadlines that the industry had been counting down. Annex III high-risk obligations moved from August 2026 to December 2, 2027. Article 50(2) watermarking moved to December 2, 2026.
That led some teams to relax. That is a mistake.
August 2, 2026 still matters. Multiple obligations take effect or gain enforcement teeth on that date. Treating the Omnibus as "we got an extra year on everything" is how deployers end up unprepared.
This article is general information, not legal advice. Confirm obligations with qualified counsel for your specific systems and jurisdictions.
What still applies on August 2, 2026
According to post-Omnibus analyses from Axis Intelligence and the EU AI Act Checklist:
Article 50 transparency (most provisions)
Users interacting with AI must know they are interacting with AI. AI-generated content must be labeled appropriately. Emotional-recognition and certain synthetic media disclosures apply as enacted.
If your product presents AI output as human-written without disclosure, you have a UX compliance problem, not just a legal footnote.
GPAI enforcement authority
GPAI model obligations have applied since August 2, 2025. What activates August 2026 is the EU AI Office's power to impose fines on GPAI providers for noncompliance, up to €15 million or 3% of global annual turnover.
If you are a deployer using third-party models, you inherit supply-chain risk: vendor diligence matters.
Article 4 AI literacy
Providers and deployers must ensure personnel operating AI have sufficient AI literacy. Obligations have been in force since February 2025; enforcement infrastructure becomes operational across member states by August 2026.
"We'll train people later" is no longer a schedule you control.
Article 5 prohibited practices
Prohibitions (manipulation, social scoring, certain biometric uses, etc.) have been legally operative since February 2025. August 2026 brings fuller cross-border enforcement infrastructure, not new permissions to ignore existing bans.
What moved (do not ignore, but calendar correctly)
| Obligation | Original date | New date (Omnibus, provisional) |
|---|---|---|
| Annex III high-risk systems | Aug 2, 2026 | Dec 2, 2027 |
| Annex I embedded high-risk | Aug 2, 2027 | Aug 2, 2028 |
| Article 50(2) watermarking (existing models) | Aug 2, 2026 | Dec 2, 2026 |
The Omnibus remains provisional until formally adopted. Monitor final text in the Official Journal. If adoption fails, original dates may apply (Baker Botts analysis).
Deployer vs provider: know your role
Most enterprises are deployers: you use AI in products and internal tools, often via APIs from GPAI providers. You are not training frontier models, but you are responsible for:
- Transparency in user-facing AI features
- AI literacy for staff who operate systems
- Risk classification of your use cases (even if high-risk deadlines moved)
- Vendor diligence on subprocessors and data handling
- Documentation that supports conformity if your system is high-risk later
Using ChatGPT or Claude through a consumer account without governance is not a deployer strategy. It is shadow AI with regulatory exposure.
90-day action plan (starting now)
Weeks 1–2: Inventory
- List every AI system affecting EU users (customer-facing and internal)
- Tag each: vendor, data types processed, human oversight level, user-facing yes/no
- Identify which use Article 50 transparency triggers (chatbots, content generation, synthetic media)
Weeks 3–4: Classification
- Preliminary risk classification against Annex III categories (employment, credit, education, etc.)
- Even with deferred high-risk dates, classification drives resource allocation
- Document decisions; "we haven't classified" is not a defensible state
Weeks 5–8: Fix user-facing gaps
- Add AI disclosure to chat interfaces ("You are chatting with an AI assistant")
- Label AI-generated content in product outputs where required
- Update privacy notices and subprocessors lists for AI vendors
Weeks 9–12: Governance infrastructure
- AI literacy program for operators (not just data scientists: PMs, support, HR using AI tools)
- Approved vendor list; block or monitor shadow AI (see our shadow AI post)
- Technical controls: EU-region inference, zero retention architecture, audit metadata
How infrastructure choices help
Compliance is easier when architecture matches policy:
- EU regional deployment for data residency arguments
- Zero prompt retention so GDPR erasure and breach scope stay bounded
- Centralized API gateway with logging for token usage and model routing (metadata, not content)
- Human-in-the-loop workflows for high-impact decisions
Autark is designed for deployers who need EU-capable, zero-retention inference without building a full AI compliance team from scratch. See Trust Center and Company.
The bottom line
August 2026 is not the deadline for everything. It is also not a free pass.
Transparency, literacy, prohibited practices, and GPAI enforcement are live or activating. High-risk system work is deferred, not deleted.
Inventory now. Disclose in product. Train operators. Fix shadow AI. Document everything.
Your counsel will thank you. Your auditors will expect it.