Digital Omnibus defers high-risk AI but Article 50 is live
The EU AI Act's enforcement landscape has changed materially. If your firm uses AI tools — and at this point, most do — the revised timeline is not an excuse to delay. It is a restructured set of deadlines, some of which have already passed. Understanding exactly where you stand is now a board-level
EU AI Act Compliance Timeline Shifts: What Professional Services Firms Need to Know Now
The EU AI Act's enforcement landscape has changed materially. If your firm uses AI tools — and at this point, most do — the revised timeline is not an excuse to delay. It is a restructured set of deadlines, some of which have already passed. Understanding exactly where you stand is now a board-level concern, not just an IT question.
Here is what has changed, what is already in force, and what your firm needs to do about it.
What the Digital Omnibus Actually Changed
On 27 July 2026, the European Union formally adopted the Digital Omnibus on AI (Regulation (EU) 2026/1744), which amended several key provisions of the EU AI Act. The headline takeaway is that certain high-risk AI obligations have been deferred. The detail, however, matters enormously.
Stand-alone high-risk AI systems listed under Annex III — which includes systems used in employment decisions, access to essential services, and education — now face a compliance deadline of 2 December 2027, a 16-month extension from the original 2 August 2026 deadline. High-risk AI systems embedded within regulated products covered by Annex I, such as medical devices or industrial machinery, have a later deadline still: 2 August 2028.
The rationale is straightforward. Harmonised technical standards are not yet finalised, and the European Commission recognised that expecting full compliance against a moving technical target was counterproductive. For firms that had been scrambling to meet August 2026 deadlines on Annex III systems, this extension provides breathing room — but it should not be misread as a signal to pause governance work altogether.
What Is Already in Force — Right Now
The deferral of high-risk obligations does not apply universally, and this is where many firms are at immediate risk of non-compliance.
Article 50 transparency obligations came into full effect on 2 August 2026. These requirements apply to providers and deployers of AI systems across the board, not just those in high-risk categories. In practical terms, this means:
- If your firm uses AI-powered chatbots — whether client-facing or internally — users must be clearly informed they are interacting with an AI system.
- If your AI systems generate synthetic audio, images, video, or text, that content must carry machine-readable markings to make it identifiable as AI-generated.
For generative AI systems that were already on the market before 2 August 2026, a short grace period applies for watermarking obligations specifically, running until 2 December 2026. Beyond that date, no such accommodation exists.
For professional services firms — accountants using AI-assisted client communications, law firms deploying document drafting tools, HR consultancies using automated candidate screening, and marketing agencies generating AI content at scale — these transparency requirements are not abstract. They apply to tools many of your teams are likely already using.
New Prohibitions Coming in December 2026
The Digital Omnibus also introduced two new categories of prohibited AI practices, both taking effect from 2 December 2026. These prohibit AI systems that generate non-consensual intimate imagery (NCII) and child sexual abuse material (CSAM). While these prohibitions are unlikely to concern most professional services firms directly, they are relevant to any business operating AI platforms or marketplaces, and they signal the direction of travel: the scope of prohibited practices is expanding, not contracting.
One further change worth noting: the obligation around AI literacy has been modestly softened. Firms are now required to "support the development" of AI literacy among staff, rather than "ensure a sufficient level." This is a meaningful distinction in regulatory language, though it does not diminish the practical importance of training your people to work with AI responsibly.
Enforcement Is Active — and GDPR Compounds the Risk
The EU AI Office, alongside national competent authorities, began active enforcement of the Article 50 transparency requirements from 2 August 2026. The AI Office has published a voluntary Code of Practice on Transparency of AI-Generated Content, and reporting mechanisms are now available for individuals and businesses to flag suspected non-compliance. The regulatory infrastructure is operational.
Alongside AI Act enforcement, GDPR exposure continues to grow in parallel — and the two frameworks increasingly overlap. Cumulative GDPR fines have exceeded €7.1 billion since 2018, with €1.2 billion issued in 2025 alone. In 2025 and 2026 combined, the Irish Data Protection Commission issued €91 million in penalties, while France's CNIL levied over €20 million specifically for failures to conduct Data Protection Impact Assessments (DPIAs).
This DPIA point is particularly significant. The EU AI Act explicitly designates certain high-risk AI systems as triggers for GDPR Article 35 DPIA obligations. If your firm is deploying AI systems that process personal data — which is true of most HR, legal, and financial tools — you may face simultaneous obligations under both frameworks. The European Data Protection Board has also announced a coordinated enforcement action for 2026 focusing on transparency and information obligations under GDPR Articles 12 to 14, which aligns directly with the AI Act's Article 50 requirements.
The practical message: AI compliance and data protection compliance are no longer separate conversations. They need to be managed together.
The Global Dimension: Beyond EU Borders
While these regulations originate in the EU, their reach extends well beyond European firms. Any professional services business that serves EU clients, processes EU residents' data, or deploys AI tools from EU-regulated providers operates within this framework's scope. This includes UK firms post-Brexit, US and Canadian consultancies with EU-facing practices, and APAC and Middle East firms with European operations or client bases.
The UK's own AI regulatory approach remains principles-based and sector-specific for now, but the practical reality is that firms operating across jurisdictions cannot maintain separate compliance postures for each territory indefinitely. Aligning with the EU AI Act's requirements — particularly on transparency and documentation — provides a defensible baseline that tends to satisfy regulators in multiple markets.
A Case to Watch
The case of Like Company v. Google, currently before the Court of Justice of the European Union, is generating close attention. An Advocate General's opinion is expected by 3 September 2026. The outcome could have material implications for how AI-generated content and copyright obligations are interpreted across the EU — relevant to any firm creating, publishing, or monetising AI-assisted content.
What Your Firm Should Do Now
The compliance window is narrower than many firms realise. The immediate priorities are:
- Audit your AI tool inventory — catalogue every AI system in use across client-facing and internal functions, and identify which categories apply under the AI Act.
- Implement Article 50 transparency measures — if you have not already disclosed AI interactions to users and applied content markings, you are operating outside current law.
- Conduct or update DPIAs — for any AI system processing personal data, assess whether a DPIA is required under GDPR, particularly given the EDPB's current enforcement focus.
- Document your governance framework — even with the Annex III deadline extended to December 2027, regulators will expect to see evidence of preparedness, not a last-minute scramble.
The EU AI Act is not a future concern. Parts of it are in force now, enforcement is active, and the overlap with GDPR creates compounding liability for firms that are slow to act.
Ops Intel works with professional services firms across the UK, EU, US, Canada, the Middle East, and Asia-Pacific to navigate AI compliance obligations clearly and practically. If you need a structured assessment of where your firm stands — or a roadmap to get compliant — contact Ops Intel today to speak with one of our specialists.
Work with Ops Intel
Need help navigating AI compliance?
We build AI compliance frameworks and automation systems for professional services firms worldwide. Book a free 30-minute call or email us directly.