Contents

Artificial Intelligence
EU AI Act consulting: system classification, policies, AI governance, training.
Discover →
Cybersecurity
CISO-as-a-service consulting: posture, remediation roadmap, ongoing support.
Discover →From 2 August 2026 the AI Act is generally applicable and supervisory authorities have full powers. The Digital Omnibus pushed the high-risk part forward, so the list of what is due today is shorter than the one written in 2024.
The tables apply to whoever provides AI systems and to whoever uses them, companies and public bodies alike, with no size thresholds.
The checklist of obligations in force
| Obligation | Who it applies to | In force since | What you need to have |
|---|---|---|---|
| Disclosing that the other side is an AI (Art. 50.1) | providers of systems interacting with people | 2 Aug 2026 | a notice at the start of the conversation, in the product and in the documentation |
| Emotion recognition and biometric categorisation (Art. 50.3) | whoever deploys the system | 2 Aug 2026 | prior notice to the people captured, aligned with the GDPR one |
| Disclosing deepfakes and public-interest text (Art. 50.4) | whoever deploys the system and circulates the content | 2 Aug 2026 | a visible label on the content, unless there is human review or editorial responsibility |
| Technical marking of synthetic content (Art. 50.2) | providers of generative systems | 2 Aug 2026 for systems placed on the market from today, 2 Dec 2026 for those already on it | machine-readable marking that is effective, reliable and interoperable, making the content detectable as generated or manipulated |
| AI literacy (Art. 4) | providers and deployers | 2 Feb 2025 | training measures proportionate to the role, tracked |
| Staying out of prohibited practices, for the most part (Art. 5) | everyone | 2 Feb 2025 | a documented check on use cases, reread against the prohibitions the Omnibus added on non-consensual intimate images and synthetic CSAM |
| Rules for GPAI models (Arts. 53-55) | providers of models placed on the market from 2 Aug 2025 | 2 Aug 2025 | technical documentation, copyright policy, summary of training data |
What is not mandatory today
| Obligation | When it starts |
|---|---|
| Stand-alone high-risk systems, Annex III | 2 December 2027 |
| High-risk systems tied to products, Annex I | 2 August 2028 |
| Marking of synthetic content (Art. 50.2), only for generative systems already on the market before 2 August 2026 | 2 December 2026 |
| Providers of GPAI models placed on the market before 2 August 2025 | 2 August 2027 |
| National regulatory sandboxes | 2 August 2027 |
The three things to do anyway
An inventory of the AI systems used or supplied, with risk classification against the consolidated text and an internal point of contact. Without it there is no answering a request for information, and it is the same inventory needed for the Cyber Resilience Act and for NIS2, so it makes sense to build only one.
The Article 50 work wherever systems are already exposed. A chatbot on the website, an assistant inside the product or a service that generates content need interface and documentation work measured in days. It is today’s deadline, not a future one.
Using the sixteen months gained on high risk. The postponement to December 2027 moves the date rather than the work: conformity assessment, risk management, data quality and human oversight still have to be built, and they are the same items that come back in the obligations where GDPR and the AI Act overlap.
Why the dates changed
Regulation (EU) 2026/1744 of 8 July 2026, amending Regulation (EU) 2024/1689 along with Regulations (EU) 2018/1139 and (EU) 2023/1230, was published in the Official Journal of the European Union on 24 July 2026 and entered into force on 27 July. It closes a process that began with the provisional political agreement of 7 May, passed through the European Parliament vote of 16 June and the Council’s adoption on 29 June.
Until 27 July the applicable date was still 2 August 2026, because a political agreement produces no legal effect and negotiated dates become binding only on publication. The postponement therefore took effect with six days of margin over the deadline it moves, and until that moment anyone who had suspended their compliance programme on the strength of the Omnibus was uncovered.
The Omnibus also touches the perimeter: it clarifies the notion of safety component and the high-risk classification criteria, excludes products already governed by the Machinery Regulation from direct application, and introduces support measures for SMEs and small mid-caps.
The obligations in detail
Transparency, Article 50. Anyone providing systems that interact with people has to make their artificial nature recognisable. Anyone deploying emotion recognition or biometric categorisation has to inform the people exposed, and anyone circulating deepfakes has to disclose them. It is the obligation touching the largest number of organisations, because it covers any conversational assistant exposed to customers or citizens. The article also covers generated or manipulated text meant to inform the public, unless there is human review or editorial responsibility. Technical marking of synthetic content, which sits in paragraph 2 of the same article and consists in making it machine-detectable rather than carrying a visible disclosure, applies from today to generative systems placed on the market from 2 August 2026: the transition until 2 December 2026 covers only those who already had their system on the market before that date.
AI literacy. The Article 4 training obligation has been in force since 2 February 2025, but from today someone can check compliance with it. The Omnibus softened its scope compared with the original text, so a programme designed last year should be checked against the consolidated version before being treated as settled. On top of the European layer sits the Italian one: law 132/2025 and its implementing decrees impose cross-cutting training and assign competences to ACN and AgID.
General-purpose models. The Article 53-55 rules apply from 2 August 2025 to models placed on the market from that date, while providers of models placed before it must comply by 2 August 2027. Article 54 concerns authorised representatives of providers established outside the Union and Article 55 covers models with systemic risk. From today the Commission can fully enforce them, penalties included.
Who supervises and the penalties
National authorities had to be designated and given powers by 2 August 2025, and the penalty regime has been applicable since then. What changes today is the object: the Article 50 transparency obligations become verifiable and punishable too, and the Commission gains the power to fully enforce the general-purpose model obligations.
In Italy coordination sits with the National Cybersecurity Agency, with AgID as the second authority designated by law 132/2025 and sector competences for the Data Protection Authority, Banca d’Italia, Consob and IVASS. For practices prohibited under Article 5 the ceiling is EUR 35 million or 7% of total worldwide annual turnover, whichever is higher. For general-purpose model providers the Commission can go up to EUR 15 million or 3%.
Sources
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), text in the Official Journal
- Regulation (EU) 2024/1689 (AI Act), text in the Official Journal
- key4biz: the Digital Omnibus amendments published in the EU Official Journal
- Il Sole 24 ORE: from 2 August supervision and transparency duties begin
- ADVANT Nctm: the Council adopts the AI Act simplification regulation
- Studio Legale Stefanelli: the EU Council adopts the regulation, high-risk deadlines slip
