Zum Hauptinhalt springen
← Zurück zum Blog

EU AI Act: 14 Days to August 2 — The Omnibus Is Signed, and Three Deadlines Close This Week

Teilen auf LinkedIn

9 Min. Lesezeit

Five weeks ago we wrote that August 2, 2026 was still standing despite the Digital Omnibus delay, with two pieces still to fall into place: formal adoption of the Omnibus, and the Commission's Code of Practice on labelling AI-generated content.

Both are now done. The Omnibus was signed on July 8, 2026. The Code of Practice was published on June 10, 2026 — and it turns out to cover deployers, not just AI vendors.

There are now 14 days until August 2. More urgently: three deadlines close within the next eight days, and one of them is a door that shuts for good.

Three deadlines close in the next eight days

Date What closes Who it affects
July 23, 2026 Consultation on the draft high-risk classification guidelines Anyone who thinks their AI may be Annex III high-risk
July 27, 2026, 18:00 CEST Deadline to join the initial signatories of the Article 50 Code of Practice Providers and deployers of generative AI
August 2, 2026 GPAI enforcement powers and Article 50 transparency become applicable Effectively everyone using customer-facing AI

The July 27 one is the easiest to miss and the only one that cannot be done late. The Code of Practice stays open for signature afterwards, but the initial signatories list — the one published before the Act's general application date — closes at 18:00 CEST that day.

The Omnibus is signed — and that changes less than you think

The legislative sequence finished quickly after our last article:

  • June 16, 2026 — the European Parliament formally adopted the Digital Omnibus on AI.
  • June 29, 2026 — the Council of the EU gave its final green light.
  • July 8, 2026 — the final act was signed.

The confirmed high-risk timeline is now settled: stand-alone Annex III systems move to December 2, 2027, and product-embedded Annex I systems to August 2, 2028.

But note the step that has not happened yet. As of today the act is still awaiting publication in the Official Journal, and it enters into force on the third day after that publication. Until then, the postponed dates are agreed and signed but not yet legally in force — the original timeline remains the technical baseline.

For most SMEs this is a footnote rather than a crisis: publication is expected imminently, and no regulator is going to enforce a high-risk deadline that the co-legislators have publicly and unanimously moved. But it is a good reason not to treat "the delay" as something you can lean on in writing. If you are documenting a compliance decision this month, cite the obligation you are meeting — not the one you expect to be excused from.

And in either case, none of it touches August 2. The Omnibus never proposed to.

The Code of Practice you probably have not heard of

This is the substantive development since our last article, and it is the one most likely to catch SMEs off guard.

On June 10, 2026, the AI Office published the final Code of Practice on Transparency of AI-Generated Content — the practical framework for demonstrating compliance with Article 50. It is built in two sections, and the second one is the reason this matters to you:

  • Section 1 — providers. Outputs of generative AI systems (audio, image, video, text) must be marked in a machine-readable format and detectable as artificially generated or manipulated.
  • Section 2 — deployers. Disclosure of deepfakes, and of AI-generated or AI-manipulated text published to inform the public on matters of public interest — with an exception where the content has undergone human editorial review.

Most Article 50 coverage has framed transparency as a vendor problem. It is not. If you publish AI-assisted content, run a customer-facing chatbot, or generate images or video, Section 2 speaks directly to you.

Should you sign? Adherence is voluntary. What signing buys is legal certainty: following a positive assessment by the Commission and the AI Board, signatories can demonstrate compliance with their Article 50 obligations across the EU, regardless of which national authority supervises them. For a small company operating in several member states, that is a meaningful simplification — one framework instead of an open question in each market.

What signing does not do is create the obligation. Article 50 binds you on August 2 whether you sign or not. The Code is the paved road, not the toll booth.

One more date buried in the Code: December 2, 2026 is the transitional compliance deadline under the grandfathering provision. If you have existing generative AI content pipelines, that is your runway — not August 2 — for retrofitting machine-readable marking.

What actually goes live on August 2

Two things, both unchanged by the Omnibus.

1. GPAI enforcement powers. General-purpose AI obligations have applied to new models since August 2, 2025, but the enforcement machinery was deliberately held back for a year so that providers and the AI Office could operationalise. That grace period ends. From August 2, 2026 the Commission and the AI Office can:

  • request technical documentation from a model provider (Article 91),
  • demand model access to run their own evaluations (Article 92),
  • require risk-mitigation measures (Article 93),
  • restrict or withdraw a model from the EU market,
  • and issue fines of up to 3% of global annual turnover or €15 million, whichever is higher (Article 101).

Models placed on the market before August 2, 2025 have until August 2, 2027 to be brought into compliance — a detail worth knowing if your vendor is running an older model family.

2. Article 50 transparency becomes binding. Users must be told when they are interacting with AI. AI-generated content must be labelled. Deepfakes must be marked. Emotion-recognition and biometric-categorisation uses must inform the affected person.

Behind the transparency obligations sit real penalties: information and transparency violations carry fines up to €7.5M or 1% of global turnover.

Still a deployer, still a smaller job

Worth repeating because the fine figures cause more panic than they should: the heavy GPAI obligations land on the providers of the models — OpenAI, Anthropic, Google, Mistral and their peers. If you use those models through an API or a subscription, you are a deployer, and you do not inherit them.

We broke the split down in detail in what SME deployers need to know about GPAI enforcement. If you are not certain which side of the line you are on, our provider or deployer checker settles it in four questions — and it is worth two minutes before you spend two weeks preparing for the wrong obligation.

What this means for SMEs

A realistic 14-day checklist. None of these require a consultant.

  1. Inventory and triage, today. List every AI system you use or ship. For each: what it does, whether it faces customers, whether it generates content. This is the input to everything below, and most SMEs can finish it in an afternoon.

  2. Get Article 50 labels live before August 2. Disclose AI interaction in your chatbot. Label AI-generated content. Mark deepfakes. This is the single most common gap and the cheapest to close — usually a line of copy, not an engineering project.

  3. Decide on the Code of Practice by July 27, 18:00 CEST. Read Section 2 against your own content pipeline. If you publish AI-assisted material on matters of public interest, signing gives you an EU-wide compliance framework instead of a per-country question. This is the only item on the list with a hard, unrecoverable cutoff.

  4. Run vendor due diligence on your GPAI tools. Confirm your model provider is meeting its obligations, note whether it is a GPAI Code of Practice signatory, and file the record. Your job as a deployer is to choose compliant vendors — not to replicate their documentation.

  5. Confirm AI literacy training is in place. Article 4 has been in force since February 2, 2025, with no delay and no grace period. See our Article 4 AI literacy guide, or work straight through the AI literacy checklist.

  6. Diarise December 2, 2026. Two things land that day: the Code of Practice transitional compliance deadline, and the new Article 5 prohibition on AI generating CSAM and non-consensual intimate imagery. If you ship any image or video generation feature, confirm now that it cannot be misused.

The bottom line

The Omnibus is signed. High-risk obligations really have moved to December 2027 and August 2028, and if your AI sits in Annex III you genuinely have more room than you did in the spring.

But the two obligations arriving on August 2, 2026 were never part of that negotiation, and they are the ones that apply to ordinary businesses running ordinary AI. Transparency is not a high-risk problem. It is a chatbot-on-your-website problem.

Fourteen days is enough. Labelling is a copy change, vendor due diligence is an email, and the AI literacy work was due eighteen months ago anyway. The companies that struggle in August will not be the ones that ran out of time — they will be the ones that read "delayed" in June and stopped reading.


Not sure which August 2 obligations apply to you? Take the free ClearAct risk assessment quiz — two minutes, and you will know exactly which tier and which deadlines you face. You can also confirm whether you are a provider or deployer, or close the Article 4 gap that is already in force with the AI literacy checklist.

Verwandte Artikel

Digital Omnibus Trilogue Fails: Why August 2 Deadline Is Suddenly Back in Play

On April 28, 2026, after 12 hours of talks, Parliament and Council failed to reach agreement on the Digital Omnibus reforms. With trilogue resumed May 13, the August 2 deadline is no longer guaranteed to be delayed. Here is what stalled and what SMEs should do this month.

Artikel lesen →

EU AI Act: 7 Weeks to August 2 — What the Omnibus Delayed and What Still Applies

The Digital Omnibus deal was confirmed on May 13, 2026, pushing high-risk obligations to 2027 and 2028. But August 2, 2026 still binds GPAI enforcement and Article 50 transparency. With roughly seven weeks left, here is exactly what survived the delay and what SMEs must do now.

Artikel lesen →

Machen Sie unsere kostenlose Risikobewertung

Finden Sie in 2 Minuten heraus, wo Ihr Unternehmen unter der EU-KI-Verordnung steht.

Quiz starten