HomeBlog › EU AI Act
EU AI Act

EU AI Act Compliance: The Complete 2026 Guide

Last updated 2 August 2026 — reflects the Digital Omnibus on AI.

Everything a product, legal, or engineering team needs to understand EU AI Act compliance in 2026 — the updated timeline after the Digital Omnibus, who is in scope, what applies today, and what the fines are.

If your company builds, sells, or deploys AI and touches the European market, the EU AI Act (Regulation (EU) 2024/1689) is now your baseline. It is the world's first comprehensive AI law, and after the Digital Omnibus on AI reshaped several deadlines in mid-2026, a lot of the advice published in 2024 and 2025 is out of date. This guide is the current, plain-English picture as of August 2026 — what applies today, what was pushed back, who is in scope, and what the fines are.

In one line: transparency obligations (Article 50) apply from 2 August 2026, while most high-risk obligations were deferred to December 2027 and August 2028 by the Digital Omnibus. Prohibited practices and general-purpose AI (GPAI) rules are already in force.

What is the EU AI Act?

The EU AI Act is a risk-based regulation. Instead of writing rules for specific technologies, it sorts AI systems into risk tiers and attaches obligations to each tier. The higher the risk to health, safety, or fundamental rights, the heavier the requirements.

EU AI Act timeline: what applies when (2024–2028)

This is the part that changed. The original Act front-loaded high-risk obligations onto 2 August 2026. The Digital Omnibus on AI — politically agreed on 8 July 2026 and awaiting publication in the Official Journal — pushed those back. Here is the current schedule:

DateWhat appliesStatus
1 Aug 2024Act enters into forceDone
2 Feb 2025Prohibited practices (Art 5) + AI literacy duty (Art 4)In force
2 Aug 2025GPAI model obligations (Art 53–55); governance bodiesIn force
2 Aug 2026Transparency obligations (Art 50)Now live
2 Dec 2026Grace period ends for watermarking of existing systems; new prohibition on AI-generated non-consensual intimate imagery / CSAMUpcoming
2 Dec 2027High-risk stand-alone systems (Annex III) — deferred from Aug 2026Deferred
2 Aug 2028High-risk embedded in regulated products (Annex I) — deferred from Aug 2027Deferred

What the Digital Omnibus on AI changed

The Digital Omnibus is a simplification package. For the AI Act specifically, the headline changes are:

Two cautions. First, the Omnibus was still awaiting formal publication in the Official Journal at the time of writing; treat the deferred dates as the firm political agreement rather than a settled statutory text. Second, a longer runway is not a reason to stop — high-risk documentation takes months to build, and the transparency rules that are live already touch most companies.

Does the EU AI Act apply to my company?

Almost certainly, if you have European users. Like GDPR, the Act has extraterritorial reach. You are in scope if you are:

So a US or UK startup with EU customers, or an agency deploying an AI tool for an EU client, is squarely in scope. A company with no EU users and no EU output is generally not.

EU AI Act penalties and fines

The fines are tiered and, at the top end, larger than GDPR:

ViolationMaximum fine
Prohibited practices (Art 5)€35 million or 7% of global annual turnover
Other obligations — including Article 50 transparency and high-risk duties€15 million or 3% of global turnover
Supplying incorrect information to authorities€7.5 million or 1.5% of turnover

Whichever figure is higher applies. SMEs and startups face proportionally reduced caps, but are not exempt.

What to do now: a practical checklist

  1. Inventory your AI. List every AI system and model you build or use, including third-party APIs embedded in your product.
  2. Classify each system by risk tier. Most SaaS products land in "limited risk," which means Article 50 transparency — the obligation that is live today.
  3. Ship the transparency basics now: disclose AI chatbots, mark AI-generated content in a machine-readable way, and label deepfakes. See our Article 50 guide.
  4. Stand up governance. An ISO 42001 AI management system gives you a defensible, auditable framework that maps cleanly onto the Act.
  5. Meet the AI literacy duty (Art 4) — already in force — by training staff who build or operate AI.
  6. Use the deferral wisely. If any of your systems are high-risk, start Annex IV technical documentation now; the December 2027 deadline arrives faster than it reads.

Need help getting AI Act–ready?

GenAI Labs helps teams classify their AI systems, produce the documentation the Act requires, and ship compliant products. Book a working session with our team.

Talk to GenAI Labs →

Frequently asked questions

When does the EU AI Act apply?

The Act entered into force on 1 August 2024 and applies in stages. Prohibited practices and the AI literacy duty applied from 2 February 2025, GPAI model obligations from 2 August 2025, and transparency obligations (Article 50) from 2 August 2026. Following the Digital Omnibus on AI, high-risk obligations were deferred to 2 December 2027 (Annex III stand-alone systems) and 2 August 2028 (Annex I product-embedded systems).

What is the difference between the original AI Act deadlines and the Digital Omnibus dates?

The original AI Act required most high-risk obligations from 2 August 2026 (Annex III) and 2 August 2027 (Annex I). The Digital Omnibus on AI, agreed on 8 July 2026, deferred these to 2 December 2027 and 2 August 2028 respectively. Transparency obligations under Article 50 were not deferred and apply from 2 August 2026.

Does the EU AI Act apply to companies outside the EU?

Yes. Like the GDPR, the AI Act has extraterritorial reach. It applies to any provider placing an AI system on the EU market, any deployer located in the EU, and any provider or deployer whose AI system output is used in the EU, regardless of where the company is based.

What are the fines for breaching the EU AI Act?

Up to €35 million or 7% of global annual turnover for prohibited practices; up to €15 million or 3% for breaching other obligations, including transparency and high-risk duties; and up to €7.5 million or 1.5% for supplying incorrect information. The higher of the fixed sum or turnover percentage applies. SMEs face reduced caps.

Is the EU AI Act in force now in 2026?

Yes. Multiple parts are already in force: prohibited practices (since February 2025), GPAI obligations (since August 2025), and transparency obligations under Article 50 (since 2 August 2026). Only the high-risk obligations remain in the future, deferred to December 2027 and August 2028.

← More articles from GenAI Labs