Table of Contents
- First, work out what you are
- The five-step survival plan
- What getting it wrong costs
- What else the Omnibus changed
- The tools worth using
- Where to start
For most of 2026 the EU AI Act sat on compliance roadmaps as a hard deadline: 2 August 2026, the date the bulk of its obligations were due to become applicable. That deadline moved. On 27 July 2026 the Digital Omnibus on AI (Regulation (EU) 2026/1744, the “AI Omnibus”) entered into force, published in the Official Journal on 24 July 2026, and amended the AI Act days before the original enforcement date could bite. It pushed the main high-risk deadlines out by more than a year, eased a handful of requirements, and added new prohibited practices.
The regulation itself entered into force back on 1 August 2024, and parts of it are already live. The prohibitions have applied since February 2025, and the core transparency obligations have applied since 2 August 2026. What the Omnibus bought most businesses is time on the heaviest category, high-risk systems, not a way out of scope. If your company builds AI, procures AI, or runs systems whose outputs reach people inside the EU, you are already covered, and the penalties still sit well above the GDPR ceiling.
This guide walks through what it takes to stay compliant under the amended timeline: how to classify your own role, the steps to work through, what non-compliance costs, and the official tools that let you audit your position without hiring a consultant.
First, work out what you are
Before you touch a single obligation, pin down two things: your role and your reach.
Deployer or provider. If your company uses third-party AI systems under its own authority, you are a deployer. If you develop an AI system or a general-purpose model and place it on the market under your own name, you are a provider. Most of your legal duties change depending on which side of that line you sit, so this is the first call to make.
Geographic scope. The Act travels. Even if your business is headquartered entirely outside the EU, in Switzerland or the US for example, it applies to you the moment the outputs your AI generates are used inside the Union. The location of your head office will not keep you out of scope.
The five-step survival plan
Getting compliant is less about panic and more about method. These five steps take you from “we have no idea what we’re running” to a defensible position.
1. Build a model inventory
Start with a status-quo audit of your exposure. Identify every AI system currently in use, in development, or lined up for procurement, and catalogue them in a single centralised repository. You cannot classify or govern what you have not yet listed, so this is the foundation for everything that follows. The Omnibus adds a specific reason to keep this list current: it introduced new prohibited practices, so an inventory built before mid-2026 may now contain systems that need reassessing.
2. Classify each system by risk
The Act sorts AI into four tiers. Where a system lands decides how much work you owe.

Unacceptable risk (banned).
Systems that threaten safety, livelihoods, or fundamental rights are prohibited outright. The original bans have applied since 2 February 2025 and cover social scoring, emotion recognition in workplaces and schools, and untargeted scraping of facial images to build databases.
The AI Omnibus extended the list. It is now also prohibited to use AI systems to generate or manipulate child sexual abuse material, or to generate non-consensual intimate or sexually explicit content depicting identifiable individuals, the so-called “nudifier” applications. That prohibition covers image, video, and audio content. Any provider or deployer of generative AI capable of producing such material should treat its technical safeguards, content-moderation policies, and terms of use as a priority review.
High risk (strictly regulated).
Systems that determine access to employment such as CV-screening tools, along with credit scoring, insurance risk pricing, and safety components in critical infrastructure.
This is where the Omnibus made its biggest change. The bulk of the high-risk obligations under Chapter III of the AI Act now apply from 2 December 2027 for stand-alone high-risk systems, meaning those listed in Annex III across areas such as biometrics, critical infrastructure, employment, education, access to essential services, law enforcement, migration, and the administration of justice.
For high-risk AI used as a safety component of a regulated product under Annex I, such as systems embedded in medical devices, machinery, or aviation equipment, the deadline is 2 August 2028. These extensions apply to Chapter III obligations only. They do not defer the transparency requirements set out below, which remain in force from 2 August 2026.
The Omnibus also clarified what counts as a “safety component.” AI systems that only assist users or optimise performance are not automatically treated as safety components where their failure or malfunction does not create a health or safety risk. If you run AI in operational or productivity contexts, that clarification may keep some systems out of the high-risk category, so it is worth reassessing borderline cases.
Limited (transparency) risk.
Conversational AI such as chatbots and generative models. These systems have to tell users they are dealing with a machine and clearly mark deepfakes and AI-generated text. The core transparency rules took effect on 2 August 2026.
The Omnibus added a short grace period for the marking of synthetic content: systems that generate synthetic audio, image, video, or text and that were placed on the market before 2 August 2026 have until 2 December 2026 to meet the watermarking obligation. Systems placed on the market on or after 2 August 2026 must comply from that date. If you deploy generative AI, check when each system went to market and plan the marking work accordingly.
Minimal or no risk. Spam filters, AI in video games, and similar systems carry no additional obligations.
3. Meet your deployer obligations for high-risk systems
If you deploy high-risk AI, the law expects you to:
- Operate the system strictly in line with its instructions of use.
- Monitor operation and report any identified risks or serious incidents without delay.
- Assign human oversight to trained personnel inside your organisation.
- Ensure the input data you feed the system is relevant and sufficiently representative.
- Carry out a Fundamental Rights Impact Assessment (FRIA) before deployment. This applies to public service providers, public bodies, and organisations running credit or insurance risk evaluations.
- Notify employees and workers’ representatives before deploying a high-risk system in the workplace.
- Honour the right to an explanation for any person subjected to AI-assisted decision-making.
These obligations survive the Omnibus unchanged. What changed is the clock: for stand-alone Annex III systems they apply from 2 December 2027, and for Annex I embedded systems from 2 August 2028. The extra time is meant to let businesses absorb the technical standards, guidelines, and conformity-assessment procedures that are still being finalised. It does not reduce the amount of work, so the sensible approach is to keep building against the obligations now.
4. Close the AI literacy gap
Article 4, effective since 2 February 2025, requires attention to AI literacy, and the Omnibus softened how the duty is framed. Providers and deployers are now required to take measures to support the development of a sufficient level of AI literacy among staff and others operating AI systems on their behalf, rather than to guarantee that level outright.
The Commission and Member States are obliged to help, including through published examples of compliance. The underlying expectation has not disappeared, but the legal exposure where an individual falls short is lower. Foundational training on the risks, the opportunities, and responsible oversight remains one of the cheapest steps on this list to get right, and existing programmes can be reviewed against the materials the Commission and Member States release over time.
5. Put governance at board level
Boards can no longer hand AI to the IT team and look away. Directors are expected to oversee due diligence on every AI vendor. If a third-party hiring tool you rely on turns out to be biased or non-compliant, your business is the one standing in front of the regulator and the reputational fallout.
What getting it wrong costs
The Act’s penalties are deliberately steep, and they exceed the GDPR thresholds:
- Up to €35 million or 7% of total worldwide annual turnover, whichever is higher, for prohibited practices or data non-compliance.
- Up to €15 million or 3% of turnover for other breaches.
- Up to €7.5 million or 1% for supplying incorrect or misleading information to regulators.
For SMEs, the lower of the two figures applies. For larger enterprises, the higher one does. The Omnibus extended existing relief for small and medium-sized enterprises (SMEs) and small mid-cap enterprises (SMCs), including simplified technical documentation, proportionate quality-management obligations, mitigated penalties, and maintained priority access to regulatory sandboxes. The relief eases the route to demonstrating compliance rather than lowering the substantive requirements that eventually apply.
What else the Omnibus changed
A few further amendments matter mainly for providers and businesses in regulated sectors:
- Reduced overlap with sectoral law. Where sector-specific legislation already imposes AI-specific requirements equivalent to the AI Act, the Commission can limit the Act’s application through delegated acts, cutting duplicate compliance for sectors such as medical devices, lifts, and toys. Machinery was removed from the products where safety components must meet the full high-risk rules, pending a separate legislative project.
- Simplified conformity assessment. A conformity-assessment body can now file a single application and undergo a single procedure to be designated under both the AI Act and relevant EU harmonisation law. Certain Notified Bodies already designated under sector law may run high-risk AI assessments during a transitional period while awaiting formal designation.
- Stronger AI Office supervision. The AI Office, the Commission body overseeing general-purpose AI model providers, gained wider powers, including reach over certain AI systems from GPAI model providers and over AI integrated into very large online platforms and search engines regulated under the Digital Services Act.
The tools worth using
You do not have to interpret the regulation on your own. The European Commission has published a set of free, official tools that let you assess and audit your position.
Official interactive tools (European Commission)
The AI Act Single Information Platform and Service Desk is the central hub. From there you can reach:
- EU AI Act Compliance Checker. An interactive tool that helps you evaluate whether your AI systems and general-purpose models meet the requirements, and points you to the steps needed to comply.
- AI Act Explorer. A navigation portal for browsing the chapters, annexes, and recitals of the Act, with article-level summaries.
- High-risk AI systems guidance. Available through the Service Desk to help you determine whether your systems fall into the high-risk categories under the Commission’s classification methodology.
- Service Desk submission portal. An online route to put questions directly to the expert teams working alongside the EU AI Office, reachable from the Service Desk.
Official guidelines and codes of practice
- Guidelines on Prohibited AI Practices and AI System Definitions. Commission frameworks with legal explanations and concrete examples that clarify the scope of the Act.
- General-Purpose AI (GPAI) Code of Practice. A voluntary tool that helps providers align their transparency, copyright, and safety-and-security policies.
- GPAI Training Content Template. The standard public-summary template for detailing the data sources used to train a model.
- Code of Practice on marking AI-Generated Content. Guidance and a standardised EU icon set for visibly disclosing artificially generated content such as deepfakes.
- Regulatory sandboxes and secure testing platforms. Controlled, real-world environments approved by market surveillance authorities, where you can validate innovative AI solutions before commercial deployment.
Where to start
If your inventory is still a blank page, the quickest first move is to run your systems through the official Compliance Checker and build your list from what it flags. From there, the deployer obligations above become a working audit checklist rather than a wall of legal text. The extended high-risk deadlines give you room to do this properly, so the calm approach is to use the time rather than bank it.
At Neodata, we build AI systems for enterprise, so these are the same questions we work through internally. If the Act has just moved up your priority list, treating it as an inventory-and-classification exercise, rather than a legal emergency, is the calmest way in.
