Menu di accessibilità (premi Invio per aprire)

July 16, 2026

Digital Omnibus and AI Act: obligations to meet by 2 August 2026

Updated as of 20 July 2026: the new deadlines for high-risk systems, the transparency obligations under Art. 50, and what changes with the adoption of the Digital Omnibus

Updated as of 20 July 2026

2 August 2026 remains the next key deadline of Regulation (EU) 2024/1689, the AI Act, but not everything takes effect on that date. The Digital Omnibus, the simplification package that amends the AI Act, has completed its legislative process and has pushed forward the most burdensome obligations for high-risk systems. By contrast, the transparency obligations under Article 50 and the start of the sanctioning regime remain confirmed, with no postponement.


AI Act 2026: what is postponed and what is not, in summary

  • What’s postponed: the application of the rules on high-risk AI systems, from 2 August 2026 to 2 December 2027 (Annex III) and 2 August 2028 (Annex I).

  • What isn’t postponed: the transparency obligations under Article 50, the start of enforcement and the sanctions regime, and most of the Regulation’s other rules, all confirmed for 2 August 2026.

  • What’s only partly postponed: the technical marking of synthetic content (Article 50(2)) for systems already on the market before 2 August 2026 has a transitional deadline until 2 December 2026.

  • The Digital Omnibus was definitively adopted by the Council of the EU on 29 June 2026; only publication in the Official Journal remains, expected by the end of July 2026, ahead of the 2 August deadline.


Digital Omnibus AI Act: where the legislative process stands

The Digital Omnibus has completed the legislative path between the European Parliament and the Council. Here are the milestones, reconstructed precisely because the dates changed several times during the procedure:

DateStep
19 November 2025The European Commission presents the Digital Omnibus proposal (COM/2025/836)
7 May 2026Provisional political agreement in trilogue between Parliament, Council and Commission
16 June 2026The European Parliament approves the text in its final form (423 votes in favour, 57 against, 174 abstentions)
29 June 2026The Council of the European Union formally adopts the regulation
Expected by end of July 2026Publication in the Official Journal of the EU
3rd day after publicationEntry into force of the regulation

Important point for those planning compliance: until publication in the Official Journal, the original 2024 AI Act timeline formally continues to apply from a strictly legal standpoint. The new deadlines are now politically and technically defined, but not yet legally effective. Publication is nevertheless expected before 2 August 2026, therefore in good time.

Table showing the milestones of the Digital Omnibus legislative process, from the European Commission's proposal on 19 November 2025 to the regulation's entry into force

Digital Omnibus: the effect on AI Act deadlines

What is postponed: high-risk AI systems (2027–2028)

The core of the reform concerns high-risk systems (credit scoring, recruitment, biometrics, critical infrastructure, education, work, migration, justice): the application of the relevant rules is postponed from 2 August 2026 to:

  • 2 December 2027 for standalone high-risk systems (Annex III);

  • 2 August 2028 for high-risk systems integrated into products already regulated by EU safety legislation (Annex I).

This postponement is the most significant change introduced by the Digital Omnibus compared to the original 2024 timeline. For a complete overview of the additional procedural changes, which concern more technical aspects (registration, documentation, relationships with other sectoral legislation), it is recommended to refer to the text of the regulation as soon as it is published in the Official Journal of the EU.

What is not postponed: obligations confirmed for 2 August 2026

The Digital Omnibus does not affect this deadline for the following aspects, which remain fully confirmed and must be prepared by 2 August 2026:

  • The transparency obligations under Article 50 (detailed in the next section), which apply regardless of the entry into force of the Digital Omnibus.

  • The start of the application of sanctions at national and Union level: the supervisory authorities designated by Member States become fully operational. Sanctions can reach up to 35 million euro or 7% of global annual turnover for the most serious infringements.

  • The entry into force of the majority of the provisions of the Regulation not amended by the Omnibus.


Article 50 AI Act: transparency obligations to prepare before August

Article 50 imposes four distinct transparency obligations, addressed to providers (those who develop and place an AI system on the market under their own name or trademark) and deployers (those who use the system in the context of their professional activity). The same organisation may play both roles for different systems.

1. Interaction with AI systems (Art. 50(1))

Providers of systems intended to interact directly with natural persons must ensure that those persons know they are interacting with an AI, unless this is already evident from the context for a reasonably well-informed and attentive person, or in the case of systems authorised for the investigation of criminal offences.

2. Marking synthetic content (Art. 50(2) — the only obligation that is partially postponed)

Providers of systems that generate synthetic content (audio, images, video, text, including GPAI models) must ensure outputs are marked in a machine-readable format and recognisable as artificial (watermarks, metadata, digital fingerprints). Operational note confirmed: for systems already on the market before 2 August 2026, the effective deadline to comply with this specific obligation is 2 December 2026, thanks to the amendment of Art. 111(4) introduced by the Digital Omnibus. It is the only exception within Art. 50: all other obligations remain set for 2 August 2026.

3. Emotion recognition and biometric categorisation (Art. 50(3))

Deployers must inform exposed persons and process personal data in compliance with the GDPR. These systems generally remain classified as high-risk.

4. Deepfakes and texts of public interest (Art. 50(4))

Deployers who generate or manipulate content that constitutes a deepfake must declare its artificial nature (with a mitigated obligation for artistic, satirical or fictional works). A similar obligation applies to AI-generated texts published to inform the public on matters of public interest, unless there is human editorial review.

Cross-cutting rule (Art. 50(5))

The information must be provided in a clear, distinguishable and accessible manner, at the latest at the time of the first interaction or exposure. References to terms and conditions or external documentation are not sufficient.


The reservations of EDPB and EDPS on the Digital Omnibus

The simplification process was not without tensions. The joint EDPB–EDPS Opinion 1/2026 of 20 January 2026 warned that easing the rules must not result in a rollback of safeguards, contesting in particular the removal of the registration obligation for systems self-excluded under Art. 6(3) and calling for the “strict necessity” standard to be maintained for the processing of sensitive data in bias detection.


AI Act in Italy: Law 132/2025

Alongside the European process, Law 132/2025 remains fully in force, having incorporated the AI Act into the Italian legal system, introducing the offence of deepfake (Art. 613-quater of the Criminal Code) and strengthening the link with the Model 231 framework. Italian companies must therefore take into account a dual compliance track, European and national, regardless of what is postponed at European level.

What must be done before August 2026: 5 operational steps

The compliance path in view of 2 August 2026 can be structured in five steps:

  • Inventory AI systems in use — Map every tool employed (chatbots, writing assistants, content generation tools, third-party AI components) and identify your role for each (provider, deployer, importer, distributor).

  • Classify the risk level — Distinguish low-impact tools from those requiring tighter oversight, to correctly size priorities, taking into account the new 2027–2028 deadlines for high-risk systems.

  • Verify the transparency obligations under Art. 50 — Check every automated touchpoint and prepare the required notices, avoiding insufficient solutions such as mentioning them only in terms and conditions. For providers of synthetic content already on the market, start immediately assessing technical marking solutions (watermarking, metadata, standards such as C2PA), in view of the 2 December 2026 deadline — implementation and validation times are not immediate.

  • Integrate AI governance with GDPR compliance — When AI systems process personal data, coordinate the assessment of the legal basis, data minimisation and any impact assessments with AI Act obligations, to avoid duplication.

  • Document the measures adopted — From 2 August 2026, supervisory authorities may request concrete evidence of internal procedures: keeping documentation on inventory, classification, notices and marking is an essential safeguard in case of inspection.


Frequently asked questions on what is postponed and what must be done before August 2026

What exactly is postponed with the Digital Omnibus? The application of the rules on high-risk AI systems, from 2 August 2026 to 2 December 2027 (Annex III) and 2 August 2028 (Annex I). Also postponed, but only for systems already on the market before 2 August 2026, is the deadline for technical marking of synthetic content (Art. 50(2)), until 2 December 2026.

What is not postponed and must be prepared by 2 August 2026? The transparency obligations under Article 50 (for all systems not already on the market before that date), the start of the application of sanctions at national and EU level, and most of the other provisions of the Regulation.

Is the Digital Omnibus already in force? It was definitively adopted by the Council of the EU on 29 June 2026, after the Parliament’s approval on 16 June. Only publication in the Official Journal of the EU is pending, expected by the end of July 2026, with entry into force on the third day thereafter. Until that moment, the original 2024 timeline formally remains in force.

Has the Digital Omnibus removed obligations on high-risk systems? No. It has postponed their application to 2 December 2027 (Annex III) and 2 August 2028 (Annex I), without removing their substantive content.

What happens if a company fails to comply by August 2026? From 2 August 2026, national supervisory authorities are fully operational and can sanction breaches of the obligations that were not postponed. For Article 50 specifically, the sanction tier set out in Article 99 of the Regulation is up to €15 million or 3% of global turnover, whichever is higher — the more severe tier (€35 million or 7%) remains reserved solely for prohibited practices under Article 5.


Fonti


This article is for information purposes only and does not replace a specific legal or compliance assessment. The regulatory framework is evolving — in particular, it should be noted that, at the date of publication of this article, the Digital Omnibus has been adopted but not yet published in the Official Journal of the EU. For formal requirements, it is recommended to consult a qualified advisor and verify the published text as soon as it becomes available.

Marta Magnini

Marta Magnini

Digital Marketing & Communication Assistant at Aidia, graduated in Communication Sciences and passionate about performing arts.

Aidia

At Aidia, we develop AI-based software solutions, NLP solutions, Big Data Analytics, and Data Science. Innovative solutions to optimize processes and streamline workflows. To learn more, contact us or send an email to info@aidia.it.