All news
Regulation August 19, 2026 5 min

2 August did not vanish: it narrowed

The Digital Omnibus deferred the high-risk obligations to 2027 and 2028, but the Article 50 transparency duties have applied since this month

The AI regulation was amended before it had even fully applied. The European Parliament endorsed the Digital Omnibus on AI on 16 June 2026 and the Council approved it on 29 June: the package pushes back the heaviest obligations, those on high-risk systems. The headline that came out of it — "the AI Act is delayed" — is nonetheless misleading.

What actually applies from 2 August 2026

The Article 50 transparency obligations were not deferred. From this month, anyone providing a system that interacts with people must make clear that there is an artificial intelligence on the other side, unless it is obvious from the context; synthetic content — audio, images, video, text — must be marked in machine-readable form; anyone using AI to produce a deepfake must disclose it; and anyone deploying emotion recognition or biometric categorisation must inform the people exposed to it.

One point almost always missed: the duty to label deepfakes applies even without intent to deceive. If the content resembles a real person it must be labelled, whatever the purpose — an advertising campaign, an internal training video, anything.

What moved, and by how much

Standalone high-risk systems under Annex III — recruitment, education, critical infrastructure, credit scoring, law enforcement — move to 2 December 2027. AI embedded in products regulated under Annex I, such as machinery, medical devices and vehicles, moves to 2 August 2028. There is then a single transitional window on transparency: generative systems placed on the market before 2 August 2026 have until 2 December 2026 to comply with the marking duty under Article 50(2).

What this means for a data protection officer

The penalties are not all the same, and picking the wrong tier is an expensive mistake: transparency breaches sit in the EUR 15 million or 3% of worldwide turnover tier, the prohibited practices of Article 5 in the EUR 35 million or 7% tier — a ceiling higher than the GDPR's.

This week's practical step is not to study high risk: it is to ask every client which user-facing systems contain AI. The chatbot on the website, the assistant in the portal, the images generated for social media, the synthetic voice on the switchboard. Those are the ones falling due now, and almost nobody has inventoried them, because they looked too trivial to belong in a register.

And a note on the deferral: two more years on high risk is not a pause. It is the time to build the conformity documentation, which is the slow part. Treating 2027 as far off will reproduce exactly the situation that made the Omnibus necessary.

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free

Related articles

Regulation
26the article nobody signs before broadcasting

Who answers for the live stream of the under-14 match? Sweden answers the question nobody asks

On 25 August the Swedish authority published guidance on streaming youth sport. Many clubs stream children's matches online, and the guidance sets out the factors that decide what is allowed. But the part worth reading is the other one: responsibility when the municipality owns the venue and the club wants to install cameras.

Aug 25, 2026New 5 min
Regulation
24months after which a past incident should not be used

The score they refuse your credit with can be requested, and it has to be explained

On 19 August the CNIL translated for the public its May 2026 recommendation on assessing creditworthiness. Inside are three numbers and one principle that concern anyone doing scoring: twenty-four months for past incidents, six months for the data of a refused application, and a right of access to the score that cannot be dismissed by invoking trade secrecy.

Aug 19, 2026New 6 min
Regulation
2EDPB criteria and the DPIA becomes mandatory

In schools, advertising trackers are prohibited — and consent has nothing to do with it

On 24 August the CNIL published its rules for the digital workspaces used in schools. The decisive point is not the protection of minors but a principle of administrative law: the neutrality of the public education service includes commercial neutrality, so trackers used for advertising or profiling are prohibited in principle. If the tool has them, the controller must switch them off.

Aug 24, 2026New 6 min