Control over AI
Blog
GDPR and workplace AI 8 min read

The AI Act timeline after the Digital Omnibus: what moved and what did not

Days before 2 August 2026, Brussels pushed the high-risk deadlines back to 2027 and 2028. The transparency rules and the fines carry on as planned. Here is the full timeline.

Legal advisor reviewing the new AI Act timeline for an organisation
Quick answer

The Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026) only moves the high-risk obligations of the AI Act: to 2 December 2027 for Annex III systems and to 2 August 2028 for AI in regulated products. The rest of the AI Act took effect on 2 August 2026 as planned, including the Article 50 transparency obligations. AI literacy has been softened from an obligation of result to an obligation of effort, but it has not disappeared. The GDPR is untouched: the omnibus that would change the GDPR is a separate proposal still under negotiation.

01

High-risk obligations (Annex III) move from 2 August 2026 to 2 December 2027

02

High-risk AI in regulated products (Annex I) follows on 2 August 2028

03

The Article 50 transparency obligations apply since 2 August 2026 as planned

04

AI literacy is now an obligation of effort, but it has not disappeared

05

The GDPR is unchanged: the omnibus touching the GDPR is still only a proposal

For many organisations, 2 August 2026 had been in the calendar for two years. On that day, most of the AI Act was due to apply, including the heavy obligations for high-risk AI systems. A week before the deadline, the calendar changed after all. On 27 July 2026, Regulation (EU) 2026/1744 entered into force, better known as the Digital Omnibus on AI. It moves the high-risk deadlines to late 2027 and 2028. The rest of the law took effect on 2 August as planned.

Where the Digital Omnibus came from

The European Commission presented the proposal on 19 November 2025, as part of a wider package to simplify digital regulation. The reason was practical: many of the technical standards and guidance documents that providers need to meet the high-risk requirements were not ready. Keeping the original date would have forced companies to comply with requirements whose details had not been settled.

The package split into two tracks. The AI track is now law: the European Parliament voted in favour on 16 June 2026, the Council followed on 29 June 2026, and the regulation has been in force since 27 July 2026. The second track, with proposals touching the GDPR and the cookie rules among other things, is still with Parliament and Council. More on that below.

The timeline as it stands

The AI Act entered into force on 1 August 2024 and phases in step by step. This is the schedule after the omnibus:

  1. The AI Act enters into force

    The starting gun. From here, the obligations phase in step by step.

  2. Prohibited practices and AI literacy

    The bans on AI with unacceptable risk apply, as does the duty to support AI literacy among staff.

  3. Rules for GPAI models

    Providers of general-purpose AI models must meet requirements on technical documentation, copyright, and transparency towards the chain.

  4. General application and transparency

    The Article 50 transparency obligations apply: chatbots identify themselves, AI content carries a machine-readable marking, deepfakes are recognisable. Supervisors can enforce.

  5. You are here
  6. New

    Two new prohibitions, end of transition

    AI systems for intimate images without consent and for material depicting child sexual abuse are prohibited. The transition period for the machine-readable marking ends.

  7. New

    AI sandboxes operational

    Every member state has at least one test environment where organisations can develop and test AI systems under supervision.

  8. Moved was 2 August 2026

    High-risk AI (Annex III)

    The obligations for high-risk uses such as hiring, assessment, and access to services. The deployer duties apply then too: human oversight, logging, and the FRIA.

  9. Moved was 2 August 2027

    High-risk AI in products (Annex I)

    The obligations for high-risk AI embedded as a safety component in regulated products, such as machinery and medical devices.

Moved and new dates follow from the Digital Omnibus on AI (Regulation (EU) 2026/1744), in force since 27 July 2026.

What moved

The biggest shift concerns high-risk AI. The obligations for Annex III systems, think of AI used for hiring and selection, employee assessment, or access to services, now apply from 2 December 2027 instead of 2 August 2026. The duties for deployers of those systems move with them: human oversight, informing workers in advance, logging, and the fundamental rights impact assessment (FRIA).

For high-risk AI embedded as a safety component in regulated products, such as machinery or medical devices (Annex I), the new date is 2 August 2028. The obligation for member states to have a national AI sandbox moves to 2 August 2027.

The omnibus also brings relief for smaller companies: simplified technical documentation, requirements that scale with the size of the organisation, and lower fine caps for SMEs.

What did not move

This is where much of the reporting went wrong over the past months. Only the high-risk part was deferred. All of this applies as planned:

  • The prohibited practices, such as social scoring, since 2 February 2025.
  • The rules for GPAI models, since 2 August 2025.
  • The Article 50 transparency obligations, since 2 August 2026. Chatbots must make clear you are talking to AI. AI-generated audio, images, video, and text must carry a machine-readable marking. Deepfakes must be recognisable as artificial. Anyone deploying emotion recognition or biometric categorisation must inform the people involved. There is one transition: generative systems already on the market have until 2 December 2026 for the machine-readable marking.
  • The fines. The ceilings stand: up to 35 million euros or 7 percent of global annual turnover for prohibited practices, up to 15 million euros or 3 percent for breaches of the transparency duties, among others.

And the GDPR was always separate from this. Personal data in an AI tool needs the same lawful basis, purpose limitation, and data minimisation today as it did last year.

AI literacy: softened, not scrapped

The omnibus also rewrites Article 4. It used to say: organisations must ensure a sufficient level of AI literacy among people working with AI systems on their behalf. It now says: organisations must take measures that support the development of AI literacy. Lawyers call that a shift from an obligation of result to an obligation of effort.

In practice, little changes about what is sensible. You still want to show that you are doing something: explaining what AI may and may not be used for, and which data does not belong in a prompt. Our guide on what you can and cannot share with AI is a usable part of that.

Two new prohibitions from 2 December 2026

The omnibus also adds to the list of prohibited practices. From 2 December 2026, AI systems intended for creating or spreading intimate images without the consent of the person depicted are prohibited, as are systems intended for creating material depicting child sexual abuse.

The GDPR omnibus is not here yet

The second track of the package, which would move the cookie rules into the GDPR, raise the threshold for reporting data breaches, and add a legal basis for training AI models, is still a proposal. Supervisory authorities are critical and parts of the text have already been dropped in negotiations. Do not count on it. Until Parliament and Council agree, the GDPR applies as you know it.

What this means for your planning

Deferral is not cancellation. For most organisations, the list is the same as before the omnibus:

  1. AI register. Track which AI tools are in use and for what. The AI Tools module does that work continuously.
  2. Short AI policy. A few pages with the rules for staff is often enough.
  3. AI literacy. Even as an obligation of effort, you want to be able to show what you do.
  4. Data processing agreement and GDPR basics. These were always separate from the AI Act.
  5. Using high-risk AI? Then you have until December 2027 for human oversight, logging, and the FRIA. Use that time, because the requirements themselves barely change.

An AI register kept by hand goes stale the moment a tool shows up that nobody logged. BeeSensible's catalog covers that step: over 700 AI tools, each scored for risk, with new arrivals added and assessed as they appear.

Search tool, vendor or categoryโ€ฆ
700+ tools
ChatGPT๐Ÿ‡บ๐Ÿ‡ธ
HighAllowed
Claude๐Ÿ‡บ๐Ÿ‡ธ
MediumAllowed
DeepSeek๐Ÿ‡จ๐Ÿ‡ณnew
CriticalNot allowed
Perplexity๐Ÿ‡บ๐Ÿ‡ธnew
MediumNo decision yet
Mistral๐Ÿ‡ซ๐Ÿ‡ท
LowNo decision yet
Midjourney๐Ÿ‡บ๐Ÿ‡ธ
MediumNo decision yet

Every tool, scored for risk

700+ AI tools, each scored Low to Critical, with nothing pre-approved or pre-blocked until someone decides.

More about AI Tools

What to set up in the meantime

The timeline moved, the risk on the work floor did not. An employee pasting customer data into a prompt today is not waiting for December 2027. What the AI Act and the GDPR both ask for is the same thing: not just policy on paper, but measures that demonstrably work. BeeSensible connects three things that usually sit apart:

See

Which AI tools are actually in use, how often, and at what risk. Every tool scored against a catalog of more than 700.

See the AI Tools module
Decide

Every tool's status is the organisation's own call: allowed, limited, not allowed. The risk score is advice, never a verdict.

Help

That decision shows up while someone works: a notice on the tool, a highlight while you type. Never a block.

See Realtime Privacy
Substantiate

The same observations become substantiation: aggregated figures per framework and per measure. Never the text, never one person.

Dashboard ยท Accountability GDPRNIS2AI Act
  • Register of AI services

    Vendor, hosting, and a decision per tool

    Substantiated
  • AI literacy

    Highlights at the moment of typing and figures on how they were handled

    Substantiated
  • Appropriate security

    Critical data highlighted and handled before sending

    Substantiated
  • Data breach procedure

    BeeSensible provides the early signal; reporting and follow-up remain your own process

    Not substantiated
One set of observations, usable as substantiation in every framework. BeeSensible supports compliance; it does not make you compliant by itself.

The highlight appears while you type in browser-based AI tools, so sensitive data can be removed, replaced, or masked before the prompt is sent. That supports data minimisation under the GDPR and makes AI literacy concrete at the moment it counts. The accountability view in the dashboard turns those same observations into substantiation per framework and per measure. BeeSensible runs on ISO 27001 certified EU infrastructure.

Further reading: what the AI Act means for your business alongside the GDPR and GDPR and workplace AI.

FAQ

Common questions

Has the AI Act been postponed?

No. Only the obligations for high-risk AI systems move: to 2 December 2027 for Annex III and to 2 August 2028 for AI in regulated products. The prohibited practices, the rules for GPAI models, and the Article 50 transparency obligations apply as planned.

What is the Digital Omnibus on AI?

An amending regulation (Regulation (EU) 2026/1744) that adjusts and simplifies parts of the AI Act. The European Commission proposed it on 19 November 2025, the European Parliament voted in favour on 16 June 2026, the Council followed on 29 June 2026, and it has been in force since 27 July 2026.

Which obligations apply since 2 August 2026?

The Article 50 transparency obligations: chatbots must make clear you are talking to AI, AI-generated content must carry a machine-readable marking, deepfakes must be recognisable as artificial, and anyone deploying emotion recognition must inform the people involved. The Commission can also enforce the GPAI rules since that date.

When do the high-risk obligations apply?

From 2 December 2027 for systems listed in Annex III, such as AI used for hiring, assessment, or access to services. For high-risk AI embedded as a safety component in regulated products (Annex I), the date is 2 August 2028.

Is AI literacy still required?

Yes, but in a softer form. The omnibus turns Article 4 from an obligation of result (ensure a sufficient level of AI literacy) into an obligation of effort (take measures that support its development). In practice the same things remain sensible: set out what staff may do with AI and make sure they know which data does not belong in a prompt.

Does the GDPR change too?

No. The part of the omnibus package that touches the GDPR and the cookie rules is a separate proposal, still with the European Parliament and the Council. Until something comes out of that, the GDPR applies in full.