Insights ·

The EU AI Act after the Omnibus: what applies now, what moved, and how to grow with AI inside the rules

High-risk obligations moved to December 2027, but transparency duties have applied since 2 August 2026. What companies that use AI must do today, what to prepare, and how TrustTwin OS supports it.

WEREALeggi in italianoLire en françaisAuf Deutsch lesenLeer en español

On 27 July 2026 the Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force and amended the AI Act, Regulation (EU) 2024/1689. Many headlines summed it up in one word: delay. That is only half true. The obligations for high-risk systems have moved, but several others did not, and some started applying on 2 August 2026, exactly as planned.

For a company using AI, this is the moment to get the picture right. The extra time is real, and it is best used to build the governance that lets AI grow inside the business, not to put adoption on hold.

What applies, and since when

DateWhat applies
2 February 2025Prohibited practices (Article 5) and AI literacy (Article 4).
2 August 2025Obligations for providers of general-purpose AI models (Articles 53 and 55).
2 August 2026Transparency obligations (Article 50). The Commission can enforce the rules on general-purpose AI models, and the penalty regime is fully in place.
2 December 2026Machine-readable marking of AI-generated content for systems already on the market before 2 August 2026. New prohibitions added by the Omnibus, on AI that generates non-consensual intimate imagery or child sexual abuse material.
2 December 2027High-risk systems listed in Annex III (for example in employment, education, credit and access to essential services). Previously 2 August 2026.
2 August 2028High-risk AI embedded in products covered by EU harmonisation legislation (Annex I). Previously 2 August 2027.

What is already live for companies that use AI

Most companies are not AI providers. They are deployers: they use systems built by others in their own processes. For them, three things matter today.

  • AI literacy (Article 4). In force since February 2025. The Omnibus revised the wording and gave the Commission and Member States a role in supporting it, especially for SMEs, but the expectation remains that people who use AI at work understand what it does and where it can go wrong.
  • Transparency towards people (Article 50). Since 2 August 2026, deployers must tell people when they are exposed to emotion recognition or biometric categorisation, must disclose deepfakes, and must disclose AI-generated text published to inform the public on matters of public interest, unless it went through human review and someone holds editorial responsibility. Providers must make chatbots identify themselves and mark synthetic content in a machine-readable way.
  • Prohibited practices (Article 5). Already in force, with the highest fines.

The penalties are not symbolic. Under Article 99, prohibited practices can cost up to €35 million or 7% of worldwide turnover, and most other obligations up to €15 million or 3%. For SMEs the lower of the two amounts applies.

What to prepare by December 2027

If any of your uses could fall under Annex III (screening candidates, evaluating employees, assessing creditworthiness, pricing insurance), Article 26 will apply to you as a deployer. In practice it asks you to:

  • use the system according to the provider's instructions;
  • assign human oversight to people with the competence and authority to exercise it;
  • make sure the input data you control is relevant and representative for the purpose;
  • monitor the system, report risks and serious incidents, and suspend use when needed;
  • keep the logs the system generates for at least six months;
  • inform workers' representatives before using it at work, and inform people when a high-risk system makes or assists decisions about them.

Public bodies and some private deployers, such as those assessing creditworthiness or pricing life and health insurance, must also carry out a fundamental rights impact assessment (Article 27). Harmonised standards that will give a presumption of conformity are still being finalised by CEN and CENELEC, so the organisations that start now will set their processes before the standards arrive, not after.

In Italy, Law 132/2025 designates AgID as the notifying authority and ACN as the market surveillance authority and single point of contact, while the Bank of Italy, CONSOB and IVASS keep their role in the financial sector.

Mapping your AI uses against the new dates? We can show you how the controls described below work on a real workload. Talk to the TrustTwin OS team.

Growth and compliance pull in the same direction

Most of what the AI Act asks of deployers is good engineering anyway: know what the system can see, keep a human in the loop where it matters, keep records, keep data where it is allowed to be. The difficulty is that most AI tools were not designed around these ideas. Assistants connected to a flat file share see everything their user sees. Prompts leave the building by default. Nobody can say afterwards where a job ran.

TrustTwin OS is designed around principles that can make compliant deployment practical. It does not make anyone compliant by itself, and we do not claim it does. What it does is give you controls that map to what the regulation asks.

What the AI Act asksHow TrustTwin OS supports it
Relevant, controlled input data (Art. 26(4)); data minimisation under the GDPREvery item is scoped at creation to a context, group and role. Agents inherit the same boundaries and know only what that context allows.
Human oversight (Art. 26(2))Agents work on behalf of a person, with scoped and revocable tokens, and ask for confirmation before acting in a shared space.
Logs and traceability (Art. 26(5) and 26(6))Agent actions are audited, and the evidence layer keeps a record of where each workload ran and which decisions were made.
Data protection and residency (with the GDPR)Local, private, EU-only or country-specific processing applied as hard limits. If a residency rule cannot be guaranteed, the workload does not run.
Control over where inference happensWith Agents Node, models run on the user's own machine and prompts do not leave it during inference.
SweetHive dashboard showing a hive with its contexts, connectors and scoped messages
SweetHive, built on TrustTwin OS: work is organised in hives and contexts, and agents and apps inherit the same boundaries.

These controls are already running in production in SweetHive, for small and mid-size businesses, and in AerariumChain, where cultural institutions process data about irreplaceable objects under strict rules on where that data may go.

Four steps for the next quarter

  1. Inventory. List every AI system in use, who provides it, what data it sees and what decisions it touches.
  2. Classify. Mark which uses could fall under Annex III, which trigger Article 50 transparency, and which are low risk.
  3. Scope the data. Make sure each assistant or agent can reach only the information its task requires.
  4. Keep records. Decide where logs live, for how long, and who reviews them.

Final obligations always depend on the models you deploy, the use case, the risk classification and your role as provider or deployer. This article is general information, not legal advice. What it can show is that compliance is easier to reach on an architecture built for control than on one where control is added afterwards.


Sources