The AI regulation was amended before it had even fully applied. The European Parliament endorsed the Digital Omnibus on AI on 16 June 2026 and the Council approved it on 29 June: the package pushes back the heaviest obligations, those on high-risk systems. The headline that came out of it — "the AI Act is delayed" — is nonetheless misleading.
What actually applies from 2 August 2026
The Article 50 transparency obligations were not deferred. From this month, anyone providing a system that interacts with people must make clear that there is an artificial intelligence on the other side, unless it is obvious from the context; synthetic content — audio, images, video, text — must be marked in machine-readable form; anyone using AI to produce a deepfake must disclose it; and anyone deploying emotion recognition or biometric categorisation must inform the people exposed to it.
One point almost always missed: the duty to label deepfakes applies even without intent to deceive. If the content resembles a real person it must be labelled, whatever the purpose — an advertising campaign, an internal training video, anything.
What moved, and by how much
Standalone high-risk systems under Annex III — recruitment, education, critical infrastructure, credit scoring, law enforcement — move to 2 December 2027. AI embedded in products regulated under Annex I, such as machinery, medical devices and vehicles, moves to 2 August 2028. There is then a single transitional window on transparency: generative systems placed on the market before 2 August 2026 have until 2 December 2026 to comply with the marking duty under Article 50(2).
What this means for a data protection officer
The penalties are not all the same, and picking the wrong tier is an expensive mistake: transparency breaches sit in the EUR 15 million or 3% of worldwide turnover tier, the prohibited practices of Article 5 in the EUR 35 million or 7% tier — a ceiling higher than the GDPR's.
This week's practical step is not to study high risk: it is to ask every client which user-facing systems contain AI. The chatbot on the website, the assistant in the portal, the images generated for social media, the synthetic voice on the switchboard. Those are the ones falling due now, and almost nobody has inventoried them, because they looked too trivial to belong in a register.
And a note on the deferral: two more years on high risk is not a pause. It is the time to build the conformity documentation, which is the slow part. Treating 2027 as far off will reproduce exactly the situation that made the Omnibus necessary.
Looking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free