← Insights / Compliance

Digital Omnibus pushes high-risk AI deadlines to 2027–2028, but Article 50 transparency rules are live now

The EU AI Act has reached a turning point. As of 2 August 2026, enforcement of key provisions is live. If your business deploys AI systems that interact with users — or if you work with clients who do — the question is no longer whether these rules apply to you. It is whether you are ready.

Compliance 26 August 2026 6 min read

The EU AI Act Is Now Enforcing: What the Digital Omnibus Means for Your Business

The EU AI Act has reached a turning point. As of 2 August 2026, enforcement of key provisions is live. If your business deploys AI systems that interact with users — or if you work with clients who do — the question is no longer whether these rules apply to you. It is whether you are ready.

The headline story is not the headline deadline. Much of the commentary around the AI Act has focused on high-risk AI requirements, and those timelines have indeed shifted. But the provisions that are active right now deserve immediate attention from professional services firms in every jurisdiction.

What the Digital Omnibus Actually Changes

Regulation (EU) 2026/1744, known as the Digital Omnibus on AI, entered into force on 27 July 2026 and has restructured the application timeline for high-risk AI systems. The rules governing standalone high-risk AI systems — those listed in Annex III of the AI Act, which include systems used in employment, credit scoring, and access to essential services — now apply from 2 December 2027. High-risk AI systems embedded in regulated products under Annex I, such as medical devices and machinery, face an even later deadline of 2 August 2028.

For many organisations, this is a meaningful reprieve. Preparing for high-risk AI obligations is a substantial undertaking, requiring conformity assessments, technical documentation, human oversight mechanisms, and registration in the EU database. The extended timeline gives businesses additional runway to build compliant systems rather than rush ill-prepared deployments.

However, the Digital Omnibus has not moved everything. The extended deadlines apply specifically to high-risk classifications. Businesses that interpret this as a general postponement of AI Act obligations do so at their own risk.

What Is Already Enforceable

The AI Act's transparency obligations under Article 50 are in force as of 2 August 2026. These are not procedural technicalities. They impose clear requirements on any business operating AI systems that engage with users.

Specifically, providers of AI-powered chatbots and similar conversational systems must ensure users are explicitly informed they are interacting with an AI, not a human. AI-generated content — including synthetic media and deepfakes — must be labelled as such. These obligations apply regardless of where the deploying organisation is headquartered. If you are serving EU-based users, you are within scope.

The AI Office has also gained full enforcement powers over providers of General-Purpose AI (GPAI) models as of this date. This is significant for the broader AI supply chain. Firms relying on third-party foundation models — whether for internal productivity tools or client-facing products — should be scrutinising their providers' compliance posture and reviewing their contractual arrangements accordingly.

Prohibited AI practices have been enforceable since February 2025. Social scoring systems and manipulative AI — systems designed to exploit vulnerabilities or subliminally influence behaviour — are already prohibited. New prohibitions on AI systems that generate non-consensual sexually explicit deepfakes or child sexual abuse material will take effect from 2 December 2026.

The Penalty Exposure Is Material

These are not symbolic fines. Non-compliance with prohibited AI practices carries penalties of up to €35 million or 7% of global annual turnover, whichever is higher. Breaches of high-risk AI requirements or GPAI obligations can result in fines of up to €15 million or 3% of global turnover. Providing false or misleading information to regulators may attract penalties of up to €7.5 million or 1% of global turnover.

For international businesses — whether based in New York, Dubai, Singapore, or Toronto — these figures reflect global turnover, not European revenue. The extraterritorial reach of EU regulation has been demonstrated clearly through GDPR enforcement, and the AI Act follows the same structural logic.

GDPR Enforcement Is Running in Parallel

Organisations cannot treat AI compliance and data protection compliance as separate workstreams. GDPR enforcement against AI systems is intensifying. By early 2026, cumulative GDPR fines had exceeded €7.1 billion, with €1.2 billion issued in 2025 alone. Data Protection Authorities are processing more than 443 breach notifications per day.

The Dutch DPA's €30.5 million fine against Clearview AI in 2024 for scraping facial images without consent illustrates the specific risk that AI systems processing biometric or sensitive personal data face when they lack a proper legal basis. Any AI tool that ingests personal data — which, in professional services, is almost every tool — must be assessed against GDPR obligations in addition to AI Act requirements.

The Court of Rome's annulment in March 2026 of the Italian Garante's €15 million fine against OpenAI introduced genuine legal complexity. That ruling was the only final GDPR enforcement action concerning generative AI, and its implications remain unclear pending the full reasoning of the Court and a possible appeal. The case highlights that the regulatory framework around generative AI is still being actively shaped by the courts — and that businesses should not mistake legal uncertainty for regulatory safety.

The International Dimension

For professional services firms operating across multiple jurisdictions, the compliance picture is complex but navigable. The EU AI Act's territorial scope mirrors GDPR: it applies to systems serving EU users, regardless of where the provider is established. A marketing agency in Toronto deploying an AI content tool for European clients, or a law firm in Dubai using AI-assisted document review for EU-facing transactions, cannot assume geographic distance equals regulatory distance.

At the same time, parallel frameworks are developing. The UK is pursuing its own approach through existing regulators rather than a single AI Act equivalent. The US continues to operate through a fragmented mix of federal guidance and state-level legislation. Canada's proposed AIDA framework remains in development. Businesses operating globally must map their AI use cases against each relevant jurisdiction's requirements, rather than assuming a single compliance approach will suffice.

Where to Focus Right Now

The practical priorities for professional services businesses are clear. First, audit every AI system that interacts with users — chatbots, virtual assistants, automated response tools — and confirm that transparency disclosures are in place. Second, review any AI-generated content produced for clients or published publicly: labelling obligations are live. Third, assess your GPAI dependencies and request documentation from providers. Fourth, begin the preliminary classification work to determine whether any of your AI systems fall into high-risk categories under Annex III, so that the 2027 deadline does not arrive without a compliance plan in place.

The extended timelines the Digital Omnibus provides are an opportunity, not an invitation to defer.


Ops Intel helps professional services businesses navigate AI compliance obligations across the EU AI Act, GDPR, and parallel international frameworks. Whether you are conducting an initial AI audit, reviewing your vendor contracts, or building a compliance programme from the ground up, our team works with firms in the UK, EU, North America, the Middle East, and Asia-Pacific.

Get in touch with Ops Intel to discuss your AI compliance obligations and how we can help you meet them.

Work with Ops Intel

Need help navigating AI compliance?

We build AI compliance frameworks and automation systems for professional services firms worldwide. Book a free 30-minute call or email us directly.

Call Now Claim Your Free Audit