On 27 July 2026 the Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force and amended the AI Act, Regulation (EU) 2024/1689. Many headlines summed it up in one word: delay. That is only half true. The obligations for high-risk systems have moved, but several others did not, and some started applying on 2 August 2026, exactly as planned.
For a company using AI, this is the moment to get the picture right. The extra time is real, and it is best used to build the governance that lets AI grow inside the business, not to put adoption on hold.
What applies, and since when
| Date | What applies |
|---|---|
| 2 February 2025 | Prohibited practices (Article 5) and AI literacy (Article 4). |
| 2 August 2025 | Obligations for providers of general-purpose AI models (Articles 53 and 55). |
| 2 August 2026 | Transparency obligations (Article 50). The Commission can enforce the rules on general-purpose AI models, and the penalty regime is fully in place. |
| 2 December 2026 | Machine-readable marking of AI-generated content for systems already on the market before 2 August 2026. New prohibitions added by the Omnibus, on AI that generates non-consensual intimate imagery or child sexual abuse material. |
| 2 December 2027 | High-risk systems listed in Annex III (for example in employment, education, credit and access to essential services). Previously 2 August 2026. |
| 2 August 2028 | High-risk AI embedded in products covered by EU harmonisation legislation (Annex I). Previously 2 August 2027. |
What is already live for companies that use AI
Most companies are not AI providers. They are deployers: they use systems built by others in their own processes. For them, three things matter today.
- AI literacy (Article 4). In force since February 2025. The Omnibus revised the wording and gave the Commission and Member States a role in supporting it, especially for SMEs, but the expectation remains that people who use AI at work understand what it does and where it can go wrong.
- Transparency towards people (Article 50). Since 2 August 2026, deployers must tell people when they are exposed to emotion recognition or biometric categorisation, must disclose deepfakes, and must disclose AI-generated text published to inform the public on matters of public interest, unless it went through human review and someone holds editorial responsibility. Providers must make chatbots identify themselves and mark synthetic content in a machine-readable way.
- Prohibited practices (Article 5). Already in force, with the highest fines.
The penalties are not symbolic. Under Article 99, prohibited practices can cost up to €35 million or 7% of worldwide turnover, and most other obligations up to €15 million or 3%. For SMEs the lower of the two amounts applies.
What to prepare by December 2027
If any of your uses could fall under Annex III (screening candidates, evaluating employees, assessing creditworthiness, pricing insurance), Article 26 will apply to you as a deployer. In practice it asks you to:
- use the system according to the provider's instructions;
- assign human oversight to people with the competence and authority to exercise it;
- make sure the input data you control is relevant and representative for the purpose;
- monitor the system, report risks and serious incidents, and suspend use when needed;
- keep the logs the system generates for at least six months;
- inform workers' representatives before using it at work, and inform people when a high-risk system makes or assists decisions about them.
Public bodies and some private deployers, such as those assessing creditworthiness or pricing life and health insurance, must also carry out a fundamental rights impact assessment (Article 27). Harmonised standards that will give a presumption of conformity are still being finalised by CEN and CENELEC, so the organisations that start now will set their processes before the standards arrive, not after.
In Italy, Law 132/2025 designates AgID as the notifying authority and ACN as the market surveillance authority and single point of contact, while the Bank of Italy, CONSOB and IVASS keep their role in the financial sector.
Mapping your AI uses against the new dates? We can show you how the controls described below work on a real workload. Talk to the TrustTwin OS team.
Growth and compliance pull in the same direction
Most of what the AI Act asks of deployers is good engineering anyway: know what the system can see, keep a human in the loop where it matters, keep records, keep data where it is allowed to be. The difficulty is that most AI tools were not designed around these ideas. Assistants connected to a flat file share see everything their user sees. Prompts leave the building by default. Nobody can say afterwards where a job ran.
TrustTwin OS is designed around principles that can make compliant deployment practical. It does not make anyone compliant by itself, and we do not claim it does. What it does is give you controls that map to what the regulation asks.
| What the AI Act asks | How TrustTwin OS supports it |
|---|---|
| Relevant, controlled input data (Art. 26(4)); data minimisation under the GDPR | Every item is scoped at creation to a context, group and role. Agents inherit the same boundaries and know only what that context allows. |
| Human oversight (Art. 26(2)) | Agents work on behalf of a person, with scoped and revocable tokens, and ask for confirmation before acting in a shared space. |
| Logs and traceability (Art. 26(5) and 26(6)) | Agent actions are audited, and the evidence layer keeps a record of where each workload ran and which decisions were made. |
| Data protection and residency (with the GDPR) | Local, private, EU-only or country-specific processing applied as hard limits. If a residency rule cannot be guaranteed, the workload does not run. |
| Control over where inference happens | With Agents Node, models run on the user's own machine and prompts do not leave it during inference. |

These controls are already running in production in SweetHive, for small and mid-size businesses, and in AerariumChain, where cultural institutions process data about irreplaceable objects under strict rules on where that data may go.
Four steps for the next quarter
- Inventory. List every AI system in use, who provides it, what data it sees and what decisions it touches.
- Classify. Mark which uses could fall under Annex III, which trigger Article 50 transparency, and which are low risk.
- Scope the data. Make sure each assistant or agent can reach only the information its task requires.
- Keep records. Decide where logs live, for how long, and who reviews them.
Final obligations always depend on the models you deploy, the use case, the risk classification and your role as provider or deployer. This article is general information, not legal advice. What it can show is that compliance is easier to reach on an architecture built for control than on one where control is added afterwards.
Sources
- Regulation (EU) 2024/1689 (AI Act), consolidated text on EUR-Lex: eur-lex.europa.eu/eli/reg/2024/1689
- Regulation (EU) 2026/1744 (Digital Omnibus on AI): eur-lex.europa.eu/eli/reg/2026/1744
- Hunton Andrews Kurth, EU Digital Omnibus on AI enters into force, 28 July 2026: hunton.com
- Gibson Dunn, EU AI Act Omnibus agreement, 27 May 2026: gibsondunn.com
- Jones Walker, Yes, August 2 still matters, 16 July 2026: joneswalker.com
- European Commission, Code of Practice on marking and labelling of AI-generated content: digital-strategy.ec.europa.eu
- Italian Department for Digital Transformation, Law on artificial intelligence: innovazione.gov.it