Skip to content

analysisEU AI Act

EU AI Act update — September 2026: the Digital Omnibus is law and Article 50 applies

EU AI Act, July to August 2026: Regulation (EU) 2026/1744 in force, high-risk duties deferred to 2027 and 2028, Article 50 and GPAI enforcement live.

Edited and verified by Cognesio LLP

Researched with AI assistance · sources verified by Cognesio LLP · How this was made ↓

In the European Union, July and August 2026 rewrote the AI Act’s timetable and switched on its first Commission-enforced duties. This update covers both months, as no August issue was published, and describes what changed for law firms and legal technology vendors as deployers and providers.

What changed in July and August 2026

Regulation (EU) 2026/1744, the Digital Omnibus on AI, was signed on 8 July, published in the Official Journal on 24 July and entered into force on 27 July 2026. It defers the Annex III high-risk obligations to 2 December 2027 and the Annex I obligations to 2 August 2028. Article 50 transparency duties and Commission enforcement against general-purpose AI providers applied from 2 August 2026, unchanged.

What did the Digital Omnibus change?

The amending regulation replaces point (c) of the third paragraph of Article 113. Chapter III, Sections 1 to 3 now apply from 2 December 2027 for systems classified as high-risk under Article 6(2) and Annex III, and from 2 August 2028 for those under Article 6(1) and Annex I. The original dates were 2 August 2026 and 2 August 2027.

Two new prohibitions carry their own date. Article 5(1) gains points (ba) and (bb): AI systems that generate or manipulate sexually explicit material of an identifiable person without consent, and child sexual abuse material. Amended Article 113 applies them from 2 December 2026.

Article 4 on AI literacy is replaced. Providers and deployers “shall take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf”. The new text adds: “This obligation does not require providers or deployers to guarantee any specific level of AI literacy of any individual.” The obligation has applied since 2 February 2025; the wording, not the date, changed.

Article 111 gains a fourth paragraph: providers of generative AI systems on the market before 2 August 2026 have until 2 December 2026 to meet the Article 50(2) marking duty. Amended Article 111(2) brings high-risk systems already on the market under Chapter III only if their design changes significantly after the new dates; systems intended for public authorities must comply by 2 August 2030.

The Commission gets two deadlines of its own: delegated acts under a new Article 2(13), which lets Annex I requirements be limited where sectoral product law gives equivalent protection, by 2 August 2027, and post-market monitoring guidance under amended Article 72(3) by 2 September 2027. The Omnibus is on the Regulation Tracker.

What did the Commission publish?

Three documents landed in the window, all on the Article 50 duties that applied from 2 August.

On 8 July 2026 the Commission adopted its opinion that the Code of Practice on Transparency of AI-generated Content “adequately covers the obligations provided for in Articles 50(2), (4) and (5) AI Act”. The AI Board adopted its adequacy assessment on 9 July. About 190 organisations had signed by the end of July, according to the Commission’s 31 July news item, which also announces two signatory task forces for September 2026. The code’s tracker entry records the versions.

On 20 July 2026 the Commission approved its Guidelines on the transparency obligations under Article 50, document C(2026) 5054 final, replacing the May draft. The guidelines’ tracker page links the PDF; the practice section below quotes it.

On 31 July the Commission announced that from 2 August its AI Office, “together with national authorities”, would begin enforcing the Act. Its 2 August note puts fines for transparency breaches at “up to €15 million, or 3% of global annual turnover”. The enforcement page, last updated 24 August 2026, lists three bands: €35 million or 7% for prohibited practices, €15 million or 3% for other breaches including GPAI obligations, and €7.5 million or 1% for incorrect information supplied to authorities.

Two national implementation items fell inside the period. Ireland’s Regulation of Artificial Intelligence Act 2026 was signed into law on 21 July, and on 30 July the Department of Enterprise announced the AI Office of Ireland, chief executive Paul Byrne, as the single point of contact for the Act, expected to be operational by 2 August. Greece published Law 5321/2026, its AI Act implementation statute, on 20 July; the Special Secretariat for AI says it sets the national governance system and names competent authorities.

Which deadlines moved, and which did not?

ObligationBefore 27 July 2026AfterSource
Annex III high-risk (incl. administration of justice, point 8(a))2 August 20262 December 2027Reg. 2026/1744, amended Art. 113(c)(i)
Annex I product-embedded high-risk2 August 20272 August 2028Amended Art. 113(c)(ii)
Article 50 transparency (chatbots, marking, deepfakes, public-interest text)2 August 20262 August 2026Art. 113, unchanged
Article 50(2) marking, generative systems already on the market2 August 20262 December 2026New Art. 111(4)
New prohibitions, Art. 5(1)(ba) and (bb)none2 December 2026Amended Art. 113(a)
Commission enforcement powers over GPAI providers2 August 20262 August 2026Chapter V, unchanged
Article 4 AI literacy2 February 20252 February 2025 (text rewritten)Reg. 2026/1744, point (5)

What did not change is as long a list. The Article 50 date held. Chapter V on general-purpose AI models kept its 2 August 2025 obligations and its 2 August 2026 enforcement date. Annex III point 8(a), “AI systems intended to be used by a judicial authority or on their behalf to assist a judicial authority in researching and interpreting facts and the law”, keeps its wording; only its date moved.

Two anticipated events did not happen. No harmonised standard has been cited in the Official Journal; the Commission’s standardisation page, last updated 3 August 2026, records prEN 18286 entering public enquiry in October 2025 and nothing since. The high-risk classification guidelines remain the draft of 19 May 2026, with no final version on the draft’s page.

A law firm using an AI system in its work is a deployer. Article 3(4) defines the term as “a natural or legal person, public authority, agency or other body using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity”. For a firm outside the EU, Article 2(1)(c) applies the Act to deployers “located in a third country, where the output produced by the AI system is used in the Union”; the UK explainer sets out that test.

For deployers, the deferral touches little. Point 8(a) is written for systems used by or on behalf of a judicial authority; a firm’s research or drafting tool is outside that wording. What moved is the date from which a vendor supplying such a system to a court faces Chapter III: 2 December 2027, not 2 August 2026.

What applies now is Article 50(4). Its second subparagraph obliges deployers of an AI system that generates text “published with the purpose of informing the public on matters of public interest” to disclose that the text was AI-generated, unless it “has undergone a process of human review or editorial control” and a person “holds editorial responsibility”. Paragraph 131 of the 20 July guidelines counts “the administration of justice and law enforcement” among public-interest matters, gives “AI-manipulated text by a consultant for a client advice regarding measures to be taken for regulatory compliance with applicable legislation” as an example outside scope, and says text is not published where it is “private, interpersonal correspondence (for professional purposes)”.

The line the guidelines draw runs between client advice and public commentary. A firm’s AI-assisted note on a new judgment, posted on its website, is published text on the administration of justice. It escapes the label only under the human-review exception, which paragraph 134 defines as “the deliberate examination of the substance of the content by one or more natural persons possessing relevant knowledge and professional judgement”, with fact-checking “a minimum requirement”. Paragraph 135 rules out “spell-checking or grammatical correction” and “cursory editorial approval”. Paragraph 136 adds that AI edits made after sign-off void the exception.

The rewritten Article 4 lowers the bar on training: a deployer takes measures to support AI literacy and need not guarantee any level of it. The regulation page records the duty, in application since 2 February 2025.

What was checked and not found

SafeLegalAI swept EUR-Lex, the Commission’s AI Act, enforcement, standardisation and news pages, the EDPB and EDPS sites, CEN-CENELEC JTC 21, official national AI pages found in the Regulation Tracker, and the artificialintelligenceact.eu trackers for 1 July to 3 September 2026. No EDPB or EDPS opinion on the Act appeared; the last is Joint Opinion 1/2026 on the Omnibus proposal, from February. No EU delegated or implementing act was published. Official pages confirmed the Ireland and Greece items above; the community tracker’s count of nine states with clear designations is dated 17 June 2026.

The next dated events are the Article 50 task forces in September, then the 2 December 2026 marking deadline for existing generative systems and the new prohibitions on the same day. The open question is which case the AI Office chooses to enforce first. The timeline article carries the summer’s rows.

Sources