The EU AI Act: what applies now, and what moved
By Eoghan Kenny · 15 September 2026
The EU AI Act's transparency obligations have applied since 2 August 2026. The high-risk obligations that were due on the same date were deferred to 2 December 2027 for standalone systems and 2 August 2028 for AI embedded in regulated products.
Those two sentences describe a situation many organisations have half-understood. The deferral was widely reported. The fact that a substantial set of obligations landed anyway, on the original date, was reported far less.
If your organisation runs a chatbot, publishes generated content, or has any AI-assisted workflow that produces text or images, you are already in scope of a live obligation.
What changed, and why
The Digital Omnibus on AI was approved by the European Parliament on 16 June 2026, given final Council approval on 29 June, and entered into force on 27 July 2026 as Regulation (EU) 2026/1744.
The reason was standards rather than substance. The Act says that if you follow certain agreed technical standards, you are presumed to have met the requirement. Those standards were not written in time. The European standards bodies missed their deadline, and the Commission's own guidance on how to classify a system was also late. Organisations facing obligations from August 2026 would have had requirements with no defined way of proving they had met them.
The requirements themselves were not softened. What you will need to demonstrate in December 2027 is what you would have needed to demonstrate in August 2026. Only the date moved.
What applies today
Since 2 February 2025. The banned uses. These include social scoring, scraping faces from the internet or CCTV to build recognition databases, and inferring emotions in workplaces and schools. Also the duty on AI literacy. The Omnibus softened the wording of this from a duty to ensure staff have a sufficient level of understanding to a duty to take measures that support it. It still binds every provider and deployer, and national supervision of it began on 3 August 2026.
Since 2 August 2025. The rules for general-purpose AI models, meaning the large models other products are built on. Providers of those models have to keep technical documentation, give information to the companies building on them, have a copyright policy, and publish a summary of what the model was trained on.
Since 2 August 2026. The Act became generally applicable, along with the transparency duties: telling people when they are dealing with AI, and marking content that AI generated. This is the date most organisations should be looking at, and it has passed.
What the transparency obligations require
The transparency duties, set out in Article 50, reach much wider than the high-risk rules. They attach to the interaction itself, so it does not matter how your system is classified.
Anyone interacting with an AI system has to be told they are, unless it is obvious. Audio, images, video and text produced by AI have to be marked in a way that software can detect. Systems that read emotions or sort people by biometric characteristics have to tell the people exposed to them. Deep fakes have to be disclosed.
There is no exemption for systems that already existed, with one exception. If your system was generating content on the EU market before 2 August 2026, you have until 2 December 2026 to add the machine-readable marking.
Penalties for breaching the transparency duties reach EUR 15 million or 3 per cent of global turnover.
What was deferred, and to when
Standalone high-risk systems: 2 December 2027. These are classified by what they are used for, and the list is in Annex III of the Act. It includes recruitment and managing workers, credit scoring, insurance pricing, access to education and assessment, critical infrastructure, law enforcement, migration and borders, and the courts.
AI built into regulated products: 2 August 2028. This covers AI that acts as a safety component inside a product already regulated by EU law, including medical devices, diagnostics, machinery, vehicles and marine equipment. The longer runway exists because these products already go through their own approval process, and the AI requirements have to be folded into it rather than run alongside.
Neither date depends on any further decision by the Commission. An earlier draft would have tied the dates to standards being confirmed. That was dropped from the final text.
It is worth being precise about what moved, because a lot of commentary treats the deferral as though it covered everything. It did not. It moved the requirements that apply to high-risk systems, and nothing else. The prohibitions that have applied since February 2025, the rules for general-purpose AI models, and the general application date of 2 August 2026 were all left exactly where they were.
The Omnibus also added two new prohibitions to Article 5, covering AI-generated non-consensual intimate imagery and child sexual abuse material. These apply from 2 December 2026.
Does the deferral mean you can wait?
No, for three reasons, and this is the part that matters most.
The transparency obligations were untouched. They are live now, and they catch organisations that operate nothing high-risk at all.
The documentation describes decisions you are making today. The technical documentation the Act asks for, set out in Annex IV, records design choices, how data was handled, and how risks were assessed. Those decisions are being made now. Reconstructing that record in 2027, from a system already running, costs several times what writing it down as you go costs. A system put into service today still has to be compliant in December 2027, with the evidence behind it.
Human oversight has to be built in. The Act requires high-risk systems to be designed so that a person can meaningfully oversee them and step in. If your system does not currently allow that, adding it is a redesign, measured in release cycles rather than weeks.
What this means for organisations in Ireland and the UK
The Act applies extraterritorially. It reaches providers placing AI systems on the EU market regardless of where they are established, deployers located in the EU, and providers and deployers in third countries whose system output is used in the EU.
For an Irish organisation, the Act applies directly. For a UK organisation selling into the EU, or whose AI output is used there, it applies through that reach.
The Act also does not replace GDPR. Both apply to any AI system that processes personal data. You may need a data protection impact assessment under GDPR and a fundamental rights impact assessment under the AI Act, covering different questions about the same system.
What to do now
Two clocks are running at different speeds.
The near one is small and cannot be deferred. Identify every point where someone interacts with an AI system you provide or deploy, and every workflow that generates synthetic content. Disclose the first. Mark the second. Most organisations can complete this in days.
The far one is larger and benefits from being started now. Go through the lists in Annex III and Annex I and work out which of your systems appear. Set up a way of assessing risk that runs continuously rather than once. Write the documentation down as the decisions are made, not afterwards.
In my experience, the mistake happens the moment a deadline moves. People stop, treat the extra time as a reason to wait, and forget that the deadline moved because there was too much work left to do, not because the requirement got any lighter. The organisations that keep going tend to be ready comfortably before the new date. The ones that pause pick it up again a year later, realise how little progress they actually made, and spend the final months trying to compress a year of work into weeks. It runs the same as a crash diet: stop completely for months, then rush back in right before the deadline, and you end up worse off than if you had just kept a steady pace.
Eoghan Kenny, Co-Founder and CEO at 3Be
The dates in one place
| Date | What applies |
|---|---|
| 2 February 2025 | Prohibited practices, AI literacy obligation |
| 2 August 2025 | GPAI model obligations |
| 2 August 2026 | General application, Article 50 transparency duties |
| 2 December 2026 | Machine-readable marking for pre-existing synthetic content systems, and two new Article 5 prohibitions |
| 2 August 2027 | GPAI models placed before August 2025 |
| 2 December 2027 | Annex III high-risk systems |
| 2 August 2028 | Annex I product-embedded high-risk systems |
Common questions
Does the EU AI Act apply now?
Yes. The Act became generally applicable on 2 August 2026, including the duty to tell people when they are dealing with AI. The banned uses have applied since February 2025, and the rules for general-purpose AI models since August 2025.
What was deferred by the Digital Omnibus?
Only the requirements that apply to high-risk systems. Standalone high-risk systems moved from 2 August 2026 to 2 December 2027. AI built into regulated products moved from 2 August 2027 to 2 August 2028. Nothing else in the calendar changed.
Does the AI Act apply to UK organisations?
It can. The Act applies to anyone putting an AI system on the EU market, wherever they are based, and to organisations outside the EU whose system output is used inside it.
What are the penalties?
Prohibited practices reach EUR 35 million or 7 per cent of global turnover. High-risk non-compliance and transparency breaches reach EUR 15 million or 3 per cent. Supplying incorrect information to authorities reaches EUR 7.5 million or 1 per cent.
Does the AI Act replace GDPR?
No. Both apply at the same time to AI systems that process personal data. The AI Act does not give you a new legal basis for processing under GDPR.
Where do you stand?
The Compliance Health Check assesses your maturity across governance, risk management, evidence, ownership and operational maturity. Twenty questions, about five minutes, and you see your result before entering any details. Start the Health Check.