The EU’s Digital Omnibus on AI entered into force on 27 July 2026, finalising the targeted amendments to the AI ActThe EU Artificial Intelligence Act was approved by the EU Council on 21 March 2024. A world-first comprehensive AI law, intended to harmonise rules for the development, deployment, and use of artificial intelligence systems across the EU.. The changes give organisations more time to comply with the requirements for high-risk AI systems.
However, it does not delay the main transparency obligations under Article 50, which apply from 2 August 2026.
The revised deadlines for high-risk AI systems are now:
New measures have also been introduced to simplify certain administrative requirements, widen access to regulatory sandboxes, and provide more support for SMEs.
Article 50 transparency obligations require organisations to help people recognise when they are interacting with AI or encountering AI-generated or manipulated content.
Depending on whether your organisation provides or uses an AI system, you may need to:
A limited extension until 2 December 2026 applies to the machine-readable marking requirement for generative-AI systems placed on the market before 2 August 2026. The other Article 50 obligations are not subject to this extension.
Start by reviewing where AI is already being used across your organisation. Confirm your role for each AI system, identify which transparency requirements apply and record how they are being met.
UK and other non-EU organisations may also be affected where they provide AI systems into the EU, or their systems’ outputs are used there.
Michael McCagh, DPO and AI specialist at The DPO Centre advises:
‘Organisations should bear in mind that transparency is NOT solely the supplier’s responsibility. Further, vendor assurances are not enough on their own to demonstrate compliance. Rather, transparency checks need to be built into existing approval processes before an AI tool is introduced or content reaches the public.’
‘The extended deadlines for high-risk AI give organisations slightly more time, but don’t wait to implement governance measures. Putting controls in place takes time. Start identifying any gaps in governance and put measures in place before the requirements take effect.’
We have updated our Compliance with the AI Act blog series to reflect the Digital Omnibus and the latest European CommissionOne of the core institutions of the European Union, responsible for lawmaking, policymaking and monitoring compliance with EU law. guidance.
The series covers:
For more news and insights about data protection and AI governanceThe framework of policies, processes, and roles that ensure Artificial Intelligence (AI) is developed and used responsibly, ethically, and in compliance with applicable laws, societal expectations, and corporate values. follow The DPO Centre on LinkedIn