{"id":74890,"date":"2026-08-31T11:14:12","date_gmt":"2026-08-31T09:14:12","guid":{"rendered":"https:\/\/fedil.lu\/?post_type=publication&#038;p=74890"},"modified":"2026-08-31T14:26:14","modified_gmt":"2026-08-31T12:26:14","slug":"ai-act-update-enforcement-begins-as-the-digital-omnibus-reshapes-the-timeline","status":"publish","type":"publication","link":"https:\/\/fedil.lu\/fr\/publications\/ai-act-update-enforcement-begins-as-the-digital-omnibus-reshapes-the-timeline\/","title":{"rendered":"AI Act update: Enforcement begins as the Digital Omnibus reshapes the timeline"},"content":{"rendered":"<div class=\"text-block js-section\">\n    <h2 class=\"text-block__title\" data-page-navigation=\"\">\n        \n    <\/h2>\n    <div class=\"text-block__text format-text\">\n        <p>The regulatory landscape of the AI Act (Regulation (EU) 2024\/1689) has undergone a major shift with the adoption of the Digital Omnibus on AI, which entered into force on 27 July 2026.<\/p>\n<p>While this text substantially postpones certain compliance deadlines such as for high-risk AI systems, it should in no way be read as a general slowdown in enforcement &#8211; quite the opposite.<\/p>\n<p>Several key obligations became fully applicable and enforceable as of 2 August 2026: key transparency obligations and the AI Office&rsquo;s full enforcement and investigation powers alongside an active sanctions framework.<\/p>\n<p>FEDIL has summarized below what changes for its members, including which obligations are now in force, which deadlines have shifted, and what additional simplifications the AI Omnibus introduces for SMEs and Small-Mid Caps.<\/p>\n<p>An updated timeline is also provided for greater clarity and visibility on the overall implementation schedule.<\/p>\n<p>Even though the compliance timeline for \u00ab\u00a0high-risk\u00a0\u00bb systems has been relaxed, transparency obligations already apply to many member companies as of now. FEDIL encourages its members to check without delay whether their AI systems fall within the scope of Article 50.<\/p>\n<p>For further guidance, members can also consult the\u00a0European Commission&rsquo;s AI Act Single Information Platform, which provides online interactive tools, including the AI Act Explorer and Compliance Checker, to help stakeholders determine whether they are subject to legal obligations and understand the steps needed to comply, available at\u00a0<a href=\"https:\/\/ai-act-service-desk.ec.europa.eu\/en\">https:\/\/ai-act-service-desk.ec.europa.eu\/en<\/a>.<\/p>\n\n    <\/div>\n<\/div>\n\n<div class=\"text-block js-section\">\n    <h2 class=\"text-block__title\" data-page-navigation=\"Obligations &amp; powers that entered into force on 2 August 2026\">\n        Obligations &amp; powers that entered into force on 2 August 2026\n    <\/h2>\n    <div class=\"text-block__text format-text\">\n        <ol>\n<li style=\"list-style-type: none;\">\n<ol type=\"a\">\n<li><strong>Article 50 : transparency requirements<\/strong>\n<ul>\n<li><strong>AI interaction disclosure:<\/strong> Providers and deployers of certain AI systems must comply with the transparency obligations set out in Article 50, covering four scenarios split between provider and deployer duties. In practice: people must be informed they are interacting with an AI system (e.g. customer service chatbots) unless this is obvious.<\/li>\n<li><strong>Watermarking &amp; synthetic content marking:<\/strong> Synthetic text, image, video, and audio outputs must be marked with machine-readable formats so they can be detected as AI-generated or manipulated.\n<ul>\n<li><em>Grace Period:<\/em> Systems already on the market before 2 August 2026 have until<strong> 2 December 2026<\/strong> to integrate machine-readable marking.<\/li>\n<\/ul>\n<\/li>\n<li><strong>Deepfake &amp; public-interest text labeling:<\/strong> Deepfakes (altered or generated realistic audio, video, or images) and AI-generated texts published on matters of public interest must be clearly labeled.<\/li>\n<\/ul>\n<\/li>\n<li>GPAI enforcement &amp; investigation powers\n<ul>\n<li>While substantive obligations for General-Purpose AI (GPAI) model providers came into force on 2 August 2025, the European Commission and the European AI Office gained full operational enforcement powers on 2 August 2026.<\/li>\n<li>The AI Office can now issue binding information requests, conduct model evaluations, require risk mitigation measures and accept binding commitments.<\/li>\n<\/ul>\n<\/li>\n<li><strong>Guidance to support compliance with the transparency rules<\/strong>\n<ul>\n<li>The <a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/policies\/code-practice-ai-generated-content\">Code of Practice on Marking and Labelling of AI-generated Content<\/a> is a voluntary tool to guide providers and deployers of generative AI systems to comply with transparency obligations. These include a <a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/policies\/eu-icons-labelling-ai-generated-content\">set of icons<\/a> that creators, publishers and other deployers of generative AI systems may use to disclose the artificial nature of certain images, audio &#8211; including deepfakes &#8211; and text.<\/li>\n<li>The <a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/policies\/guidelines-ai-transparency-obligations\">Guidelines on transparency obligations for providers and deployers of certain AI systems<\/a> clarify the scope of application, relevant legal definitions, the transparency obligations and the exceptions.<\/li>\n<\/ul>\n<\/li>\n<li><strong>Sanctions and penalty framework<\/strong>\n<ul>\n<li>The general sanctioning framework is now active. Infringements of Article 50 transparency requirements or GPAI obligations carry fines up to <strong>\u20ac15 million or 3% of total worldwide annual turnover<\/strong> (whichever is higher). These obligations apply immediately to all in-scope systems regardless of when they were placed on the market, though content generated and published before that date doesn&rsquo;t need retroactive labeling.<\/li>\n<\/ul>\n<\/li>\n<li><strong>New prohibitions<\/strong>\n<ul>\n<li>The Omnibus introduced an explicit prohibition on AI systems designed to generate non-consensual intimate imagery or child sexual abuse material, with a transitional grace period ending <strong>2 December 2026<\/strong>.<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n\n    <\/div>\n<\/div>\n\n<div class=\"text-block js-section\">\n    <h2 class=\"text-block__title\" data-page-navigation=\"Deadline obligations postponed by the Digital Omnibus on AI\">\n        Deadline obligations postponed by the Digital Omnibus on AI\n    <\/h2>\n    <div class=\"text-block__text format-text\">\n        <p>The Digital Omnibus on AI pushed back the deadlines for <strong>high-risk AI<\/strong> systems to ensure that technical standards, harmonized guidelines, and national competent authorities are fully established before enforcement begins.<\/p>\n<p>It has been published and entered into force on 27 July 2026. Full text <a href=\"https:\/\/eur-lex.europa.eu\/eli\/reg\/2026\/1744\/oj\/eng\">HERE<\/a>.<\/p>\n<table border=\"1\">\n<tbody>\n<tr>\n<td><strong>Category<\/strong><\/td>\n<td><strong>Original deadline<\/strong><\/td>\n<td><strong>New deadline<\/strong><\/td>\n<td><strong>Key obligations affected<\/strong><\/td>\n<\/tr>\n<tr>\n<td><strong>Standalone High-Risk AI Systems (Annex III) <\/strong><em>(e.g., employment screening, credit scoring, biometrics, education, critical infrastructure)<\/em><\/td>\n<td>2 August 2026<\/td>\n<td><strong>2 December 2027<\/strong><\/td>\n<td>Mandatory Risk Management Systems (RMS), Quality Management Systems (QMS), technical documentation, automatic logging, human oversight, accuracy, and conformity assessments.<\/td>\n<\/tr>\n<tr>\n<td><strong>High-Risk AI embedded in regulated products (Annex I)<\/strong><em>(e.g., medical devices, aviation, machinery, automotive safety components)<\/em><\/td>\n<td>2 August 2027<\/td>\n<td><strong>2 August 2028<\/strong><\/td>\n<td>Sectoral compliance alignment and combined conformity assessment procedures.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<ul>\n<li><strong>Additional omnibus adjustments &amp; simplifications<\/strong>\n<ul>\n<li><strong>SME \/ Small-Mid Cap (SMC) relief:<\/strong> Regulatory simplifications (such as streamlined technical documentation and adjusted fine caps) were expanded to include Small-Mid Caps.<\/li>\n<li><strong>AI Regulatory Sandboxes:<\/strong> The deadline for establishing national AI regulatory sandboxes was pushed to 2 August 2027.<\/li>\n<li><strong>Reduced registration burdens:<\/strong> Providers who determine that an Annex III system is not high-risk (because it performs purely narrow or administrative tasks) face reduced registration requirements.<\/li>\n<li><strong>Bias correction allowance:<\/strong> Providers and deployers are granted specific permissions to process special categories of personal data exclusively to detect and correct algorithmic bias.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n    <\/div>\n<\/div>\n\n<div class=\"text-block js-section\">\n    <h2 class=\"text-block__title\" data-page-navigation=\"Practical timeline of entry into force of the AI Act\">\n        Practical timeline of entry into force of the AI Act\n    <\/h2>\n    <div class=\"text-block__text format-text\">\n        <table border=\"1\">\n<tbody>\n<tr>\n<td><strong>Date<\/strong><\/td>\n<td><strong>AI Act status<\/strong><\/td>\n<\/tr>\n<tr>\n<td><strong>2 Feb. 2025\u00a0<\/strong><\/td>\n<td>Prohibited AI practices + definitions + AI literacy (Art. 4)<\/td>\n<\/tr>\n<tr>\n<td><strong>2 Aug. 2025<\/strong><\/td>\n<td>GPAI obligations + governance<\/td>\n<\/tr>\n<tr>\n<td><strong>2 July. 2026<\/strong><\/td>\n<td>AI Omnibus enters into force<\/td>\n<\/tr>\n<tr>\n<td><strong>2 Aug. 2026<\/strong><\/td>\n<td>Transparency obligations (Art. 50) + general AI Act provisions + penalties<\/td>\n<\/tr>\n<tr>\n<td><strong>2 Dec. 2026<\/strong><\/td>\n<td>Article 50 (2) grace period ends for pre-existing GenAI systems + certain new prohibited practices apply<\/td>\n<\/tr>\n<tr>\n<td><strong>2 Dec. 2027<\/strong><\/td>\n<td>High-risk AI &#8211; Annex III obligations apply<\/td>\n<\/tr>\n<tr>\n<td><strong>2 Aug. 2028<\/strong><\/td>\n<td>High-risk AI &#8211; Annex I \/ product-related obligations apply<\/td>\n<\/tr>\n<tr>\n<td><strong>2 Aug. 2030<\/strong><\/td>\n<td>Final deadline for certain high-risk AI used by public authorities<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n\n    <\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"","protected":false},"author":14,"featured_media":0,"template":"","class_list":["post-74890","publication","type-publication","status-publish","hentry"],"acf":[],"_links":{"self":[{"href":"https:\/\/fedil.lu\/fr\/wp-json\/wp\/v2\/publication\/74890","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fedil.lu\/fr\/wp-json\/wp\/v2\/publication"}],"about":[{"href":"https:\/\/fedil.lu\/fr\/wp-json\/wp\/v2\/types\/publication"}],"author":[{"embeddable":true,"href":"https:\/\/fedil.lu\/fr\/wp-json\/wp\/v2\/users\/14"}],"version-history":[{"count":9,"href":"https:\/\/fedil.lu\/fr\/wp-json\/wp\/v2\/publication\/74890\/revisions"}],"predecessor-version":[{"id":74907,"href":"https:\/\/fedil.lu\/fr\/wp-json\/wp\/v2\/publication\/74890\/revisions\/74907"}],"wp:attachment":[{"href":"https:\/\/fedil.lu\/fr\/wp-json\/wp\/v2\/media?parent=74890"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}