AI GOVERNANCE AND REGULATION / INTERMEDIATE

The EU AI Act After The Digital Omnibus: Risk Tiers And The Real Timeline

The EU AI Act sorts AI by risk. A July 2026 amendment moved the high-risk deadlines to December 2027 and August 2028 and added new bans. Here is what applies and when.

Checked against primary sources and independently reviewed on . Sources are listed at the end.

The EU Artificial Intelligence Act, Regulation (EU) 2024/1689, is binding law in all 27 Member States. It entered into force on 1 August 2024 and applies in stages.1 In July 2026 the EU amended it through the Digital Omnibus on AI, Regulation (EU) 2026/1744, which pushed back the most demanding obligations and added two new bans.2

Many explainers written before mid 2026 still show 2 August 2026 as the date when high-risk rules start. That is no longer correct. This article sets out the risk tiers, the dates that apply as of October 2026, and a simple way to judge whether a system might be high-risk. General-purpose models such as large language models have their own regime, covered in General-Purpose AI Models Under The EU AI Act.

Who The Act Applies To

The Act reaches well beyond companies based in the EU. It applies to providers that place AI systems or general-purpose AI models on the EU market wherever they are established, to deployers located in the EU, and to providers and deployers in other countries when the output of their AI system is used in the EU.1 A UAE company selling an AI hiring tool to a European employer, for example, can be in scope.

The two roles matter throughout. A provider develops an AI system and puts it on the market under its own name. A deployer uses an AI system in its own work. Most obligations fall on providers, but deployers have duties too.

Four Tiers Of Risk

The Act does not regulate AI as a single category. It places systems in tiers according to the harm their use could cause, with duties that grow as the risk rises.

  1. Unacceptable Risk: ProhibitedPractices banned outright under Article 5, such as social scoring, manipulative techniques that cause significant harm, untargeted scraping of facial images and emotion recognition at work or school, with narrow exceptions.
  2. High Risk: Strict RequirementsAI used as a safety component of regulated products that need third-party conformity assessment (Annex I), or in sensitive areas listed in Annex III, such as hiring, credit, education, essential services, law enforcement and migration.
  3. Transparency Risk: Disclosure DutiesUnder Article 50, people must be told when they talk to an AI system or are exposed to emotion recognition or biometric categorisation, synthetic content must be machine-readably marked, and deepfakes must be disclosed. These duties can apply on top of the high-risk rules.
  4. Minimal Risk: No New DutiesMost AI, such as spam filters or stock forecasting, carries no specific obligations under the Act, though the AI literacy duty still applies.
The EU AI Act risk tiers, from the most restricted at the top. General-purpose AI models sit alongside this pyramid under a separate chapter.

Breaking the prohibitions carries the heaviest fines in the Act: up to EUR 35 million or 7 percent of worldwide annual turnover, whichever is higher. Most other breaches, including of high-risk and transparency duties, can reach EUR 15 million or 3 percent. For small and medium-sized enterprises the lower of the two figures applies, and the Digital Omnibus extended that treatment to small mid-cap companies for most fines.3

High-risk providers must run a risk management system, apply data governance to training data, keep technical documentation and logs, give deployers clear instructions, design for human oversight, and meet standards for accuracy and cybersecurity (Articles 9 to 15). Deployers must use the system as instructed, assign competent human oversight and monitor its operation. Public bodies and some private deployers, such as those assessing creditworthiness, must also carry out a fundamental rights impact assessment before use (Article 27).4

What The Digital Omnibus Changed

The Omnibus was adopted on 8 July 2026 and published in the Official Journal on 24 July 2026. It entered into force on the third day after publication, which is 27 July 2026, the date the Commission also gives on its AI Act page.2 5

The main changes, as of October 2026:

  • High-risk deadlines moved. Requirements for Annex III systems now apply from 2 December 2027, and for AI in Annex I products from 2 August 2028. The original dates were 2 August 2026 and 2 August 2027. A high-risk system whose type and model was already placed on the market or put into service before the new dates is caught only if its design changes significantly afterwards, and this covers later identical units of that model too. Systems meant for public authorities must comply by 2 August 2030 in any case.6
  • Two new prohibitions. From 2 December 2026, the Act bans AI systems that create realistic intimate imagery of identifiable people without their consent, and systems that generate child sexual abuse material as defined in the EU directive on that subject.7 For providers, the ban covers systems built for this purpose, and systems whose design makes such output a reasonably foreseeable result that can be reproduced without significant technical modification, where no adequate safeguards are in place to prevent it. For deployers, it covers using a system in order to produce such material.8
  • More time for content marking. Generative systems already on the market before 2 August 2026 have until 2 December 2026 to mark their output in a machine-readable way under Article 50(2).6
  • AI literacy softened. Article 4 used to make providers and deployers responsible, as far as they could, for their staff reaching an adequate level of AI literacy. Under the new wording they must take steps that help staff build that literacy, and nobody has to guarantee that any particular person reaches a set level.9
  • Other adjustments. These include a legal basis to process sensitive personal data for bias detection, a narrower definition of “safety component”, lighter treatment for small mid-cap companies, and exclusive AI Office supervision of certain AI systems built on a provider’s own general-purpose model. Machinery was also moved from Section A to Section B of Annex I. For Section B products, only a few AI Act provisions apply directly, and the high-risk requirements for AI in machinery are instead to be written into the Machinery Regulation through delegated acts that must apply by 2 August 2028.10

The Omnibus did not change the core obligations for general-purpose AI models, the prohibitions already in force, or the 2 August 2030 deadline for high-risk systems used by public authorities.6

The Timeline As Of October 2026

  1. In effect

    European Union · European Parliament and Council Binding

    Prohibited AI practices in Article 5 apply, together with the AI literacy duty in Article 4.

    Regulation (EU) 2024/1689 (AI Act), Article 113(a). Applies to providers and deployers of AI systems in or affecting the EU. Source · Explainer · Verified 7 Oct 2026

  2. In effect

    European Union · European Parliament and Council Binding

    Obligations for providers of general-purpose AI models (Chapter V) apply.

    Regulation (EU) 2024/1689 (AI Act), Article 113(b). Applies to providers of general-purpose AI models placed on the EU market. Source · Explainer · Verified 7 Oct 2026

  3. In effect

    European Union · European Parliament and Council Binding

    General application date, including the Article 50 transparency duties for chatbots, deepfakes and emotion recognition.

    Regulation (EU) 2024/1689 (AI Act), Article 113. Applies to providers and deployers of the AI systems covered by Article 50. Source · Explainer · Verified 7 Oct 2026

  4. Upcoming

    European Union · European Parliament and Council Binding

    New prohibitions on AI systems that generate non-consensual intimate imagery or child sexual abuse material apply.

    Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI), Article 113(a). Applies to providers and deployers of AI systems in or affecting the EU. Source · Explainer · Verified 7 Oct 2026

  5. Upcoming

    European Union · European Parliament and Council Binding

    Machine-readable marking of synthetic content under Article 50(2) for generative systems already on the market before 2 August 2026.

    Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744, Article 111(4). Applies to providers of generative AI systems placed on the market before 2 August 2026. Source · Explainer · Verified 7 Oct 2026

  6. Upcoming

    European Union · European Parliament and Council Binding

    General-purpose AI models placed on the market before 2 August 2025 must comply with the Chapter V obligations.

    Regulation (EU) 2024/1689 (AI Act), Article 111(3). Applies to providers of general-purpose AI models already on the market before 2 August 2025. Source · Explainer · Verified 7 Oct 2026

  7. Upcoming

    European Union · European Parliament and Council Binding

    High-risk requirements apply to the Annex III use cases, such as hiring, credit scoring, education and biometrics. Where the type and model was already placed on the market or put into service before this date, units are covered only after a significant design change, except systems intended for public authorities, which must comply by 2 August 2030 (Article 111(2)).

    Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744, Article 113(c)(i). Applies to providers and deployers of high-risk AI systems listed in Annex III. Source · Explainer · Verified 7 Oct 2026

  8. Upcoming

    European Union · European Parliament and Council Binding

    High-risk requirements apply to AI in products covered by the EU product laws in Section A of Annex I. For Section B laws, such as machinery, vehicles and aviation, the requirements come mainly through those sector rules. Where the type and model was already placed on the market or put into service before this date, units are covered only after a significant design change, except systems intended for public authorities (2 August 2030).

    Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744, Article 113(c)(ii). Applies to providers of AI that is, or is a safety component of, an Annex I product that must undergo third-party conformity assessment. Source · Explainer · Verified 7 Oct 2026

  9. Upcoming

    European Union · European Parliament and Council Binding

    High-risk AI systems intended for use by public authorities that were placed on the market or put into service before the high-risk rules applied must comply, whether or not their design has changed.

    Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744, Article 111(2). Applies to providers and deployers of high-risk AI systems used by public authorities. Source · Explainer · Verified 7 Oct 2026

Countdowns run to the end of each deadline date (UTC) and are calculated in your browser. "Binding" means legally or contractually required; other labels describe supervisory expectations, guidance, drafts or announcements. Always check the source for the current text.

In short: the original prohibitions, AI literacy and general-purpose model rules are already live. Transparency duties for chatbots and deepfakes have applied since 2 August 2026, apart from the marking extension for older generative systems. High-risk requirements are the main obligations still ahead.

Is My System High-Risk?

The flowchart below follows the structure of Article 6. It is a simplification for orientation only and is not legal advice. Borderline cases depend on detailed legal tests and on Commission guidance, so confirm any conclusion with qualified counsel.

Does the system carry out a practice listed in Article 5, such as social scoring or emotion recognition in the workplace?

  • Yes:

    Prohibited. The practice cannot be offered or used in the EU, subject only to the narrow exceptions in Article 5. The original bans have applied since 2 February 2025; the two added by the Omnibus apply from 2 December 2026.

  • No:

    Is it a safety component of, or itself, a product covered by the EU laws in Annex I that needs third-party conformity assessment?

    • Yes:

      Is the product covered by one of the sector laws in Section B of Annex I, such as motor vehicles, civil aviation, marine equipment, rail or machinery?

      • Yes:

        High-Risk, Handled Mainly Through Sector Law. Only a few AI Act provisions apply directly: the classification rule, the rules on real-world testing for these products, and the amending, transitional and review provisions. The AI requirements are to be built into the sector laws themselves.

      • No:

        High-Risk Under Article 6(1). Requirements apply from 2 August 2028 to new types and models of system. Where the first unit of a type and model was placed on the market or put into service before that date, later identical units are caught only after a significant design change, except systems meant for public authorities, which must comply by 2 August 2030.

    • No:

      Is it intended for a use listed in Annex III, such as recruitment, credit scoring, exam scoring, access to public benefits or biometrics?

      • Yes:

        Does it profile individuals?

        • Yes:

          High-Risk. Annex III systems that profile people are always high-risk. Requirements apply from 2 December 2027 to new types and models of system. Where the first unit of a type and model was placed on the market or put into service before that date, later identical units are caught only after a significant design change, except systems meant for public authorities, which must comply by 2 August 2030.

        • No:

          Does it only perform a narrow procedural or preparatory task, improve the result of a completed human activity, or spot patterns or deviations in past decisions without replacing human review, so that it does not materially influence the outcome?

          • Yes:

            Possibly Not High-Risk. Document your reasoning before release and keep it ready for regulators.

          • No:

            High-Risk. Requirements apply from 2 December 2027 to new types and models of system. Where the first unit of a type and model was placed on the market or put into service before that date, later identical units are caught only after a significant design change, except systems meant for public authorities, which must comply by 2 August 2030.

      • No:

        Not High-Risk Under Article 6. Use the transparency check below, and remember the AI literacy duty and other laws such as data protection.

A simplified high-risk check based on Article 6 of the EU AI Act. Not legal advice.

Whatever the result above, check transparency separately. The Article 50 duties sit alongside the high-risk rules rather than replacing them, so a high-risk system can carry both.12 The one exception in this simplified view is a Section B product, where the AI Act applies only in part.

Does the system interact with people, generate synthetic audio, images, video or text, create deepfakes, or recognise emotions or categorise people by biometric data?

  • Yes:

    Transparency Duties Apply. These sit alongside any result from the first check. Article 50 duties have applied since 2 August 2026. Generative systems already on the market before then have until 2 December 2026 to add machine-readable marking.

  • No:

    No Article 50 Duties. This answer covers Article 50 only. Any prohibition or high-risk result from the first check still stands; if neither applied, only the AI literacy duty applies under the Act, though other laws such as data protection still apply.

A simplified check of the Article 50 transparency duties. Not legal advice.

Footnotes

  1. European Parliament and Council, “Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)”, Official Journal, 12 July 2024. eur-lex.europa.eu ↩ ↩2

  2. European Parliament and Council, “Regulation (EU) 2026/1744 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 (Digital Omnibus on AI)”, 8 July 2026, Official Journal, 24 July 2026. eur-lex.europa.eu ↩ ↩2

  3. Regulation (EU) 2024/1689, Article 99(3), (4) and (6) eur-lex.europa.eu, with Article 99(6a) inserted by Regulation (EU) 2026/1744, Article 1, point (38). eur-lex.europa.eu ↩

  4. Regulation (EU) 2024/1689, Articles 6, 9 to 15, 26 and 27 and Annex III. eur-lex.europa.eu ↩

  5. European Commission, “AI Act”, page updated 3 August 2026. digital-strategy.ec.europa.eu ↩

  6. Regulation (EU) 2026/1744, Article 1, points (39) and (40), amending Articles 111 and 113 of the AI Act, and recitals 38 to 40. eur-lex.europa.eu ↩ ↩2 ↩3

  7. European Parliament and Council, “Directive 2011/93/EU on combating the sexual abuse and sexual exploitation of children and child pornography”, 13 December 2011, Article 2. eur-lex.europa.eu ↩

  8. Regulation (EU) 2026/1744, Article 1, point (7), inserting Article 5(1), points (ba) and (bb), and Article 5(1a) and (1b) of the AI Act. eur-lex.europa.eu ↩

  9. Regulation (EU) 2026/1744, Article 1, point (5), replacing Article 4 of the AI Act, and recital 8. eur-lex.europa.eu ↩

  10. Regulation (EU) 2026/1744, Article 1, points (2) and (41), Article 3 and recital 42 eur-lex.europa.eu; European Parliament and Council, “Regulation (EU) 2023/1230 on machinery”, 14 June 2023. eur-lex.europa.eu ↩

  11. Regulation (EU) 2026/1744, recital 2. eur-lex.europa.eu ↩

  12. Regulation (EU) 2024/1689, Article 50, in particular paragraph 6 eur-lex.europa.eu; Article 2(2) as replaced by Regulation (EU) 2026/1744, Article 1, point (2). eur-lex.europa.eu ↩

Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.