The EU AI Act in 2026: What Actually Applies Right Now
What the EU AI Act requires on 6 October 2026 after the Digital Omnibus, what is coming and what to do now.
The EU AI Act did not slip as far as the headlines suggested. The Digital Omnibus on AI, Regulation (EU) 2026/1744, moved the high-risk deadlines, but it left the prohibitions, the general-purpose AI (GPAI) obligations, transparency duties and the fines exactly where they were. This post separates what is enforceable today from what is coming, and says what each role should do this quarter.
Last verified 2026-10-06. Every date below is checked against EUR-Lex or Commission pages; where only law-firm commentary was available, we say so.
What the Omnibus actually did
The Omnibus was adopted on 8 July 2026, published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. Its central change: fixed calendar dates replace the Commission's earlier conditional trigger for the high-risk rules. The Act itself is Regulation (EU) 2024/1689; the Commission's timeline page reflects the amended dates.
The dated table: today versus coming
| Date | What applies | Status on 6 Oct 2026 |
|---|---|---|
| 1 Aug 2024 | Act enters into force | In effect |
| 2 Feb 2025 | Definitions, AI literacy (Art 4), prohibited practices (Art 5) | In effect |
| 2 Aug 2025 | GPAI obligations (Chapter V), governance, penalty framework, national authorities due | In effect |
| 2 Aug 2026 | Most of the Act, including Art 50 transparency; Commission fining powers over GPAI providers (Art 101) | In effect |
| 2 Dec 2026 | New Art 5 prohibitions (non-consensual intimate imagery, CSAM generation); grace end for Art 50(2) machine-readable marking on generative systems already on the market before 2 Aug 2026 | Coming in under two months |
| 2 Aug 2027 | National AI regulatory sandboxes due (moved from 2 Aug 2026); legacy GPAI models placed on the market before 2 Aug 2025 must comply; Art 6 guidelines due | Coming |
| 2 Dec 2027 | Annex III high-risk obligations apply (was 2 Aug 2026) | Coming |
| 2 Aug 2028 | Annex I regulated-product high-risk obligations apply (was 2 Aug 2027) | Coming |
The full dated view lives on our AI Act timeline page.
What is already enforceable
Four things need no waiting.
Art 4, AI literacy. It has applied since 2 February 2025 to providers and deployers. The Omnibus softened the wording: organizations must take measures to support literacy, with no guarantee of a specific level, and the Commission, Member States and the Board are to support SMEs in particular. The duty still exists. See AI literacy under Article 4 for what a defensible program looks like.
Art 5, prohibited practices. In force since 2 February 2025. Article 5 covers manipulative techniques causing significant harm, exploiting vulnerabilities, social scoring, offence prediction solely from profiling, untargeted facial-image scraping, emotion inference in workplaces and education (medical and safety exceptions), certain biometric categorization, and real-time remote biometric identification for law enforcement (three narrow exceptions).
GPAI obligations. Chapter V has applied since 2 August 2025, and the Commission can now fine GPAI providers. Details are on our GPAI obligations page.
Art 50, transparency. From 2 August 2026, providers of systems that interact with people must make clear they are AI unless obvious. Providers of generative systems must mark synthetic audio, image, video and text outputs in a machine-readable way. Deployers must disclose deepfakes and disclose AI-generated text published to inform the public on matters of public interest, unless it was human-reviewed under editorial responsibility. The Commission published a voluntary Code of Practice on marking and labelling AI-generated content on 10 June 2026. Legacy generative systems have until 2 December 2026 for the marking duty only.
The fines are live
Penalties follow Article 99:
- Prohibited practices: up to EUR 35,000,000 or 7% of worldwide annual turnover, whichever is higher.
- Other operator obligations (providers, deployers, importers, distributors, Art 50 transparency): up to EUR 15,000,000 or 3%.
- Incorrect, incomplete or misleading information to authorities: up to EUR 7,500,000 or 1%.
- SMEs, including start-ups, pay whichever amount is lower. The Omnibus extends the lower-of rule to small mid-caps for the second and third tiers.
- GPAI providers are fined by the Commission under Art 101, up to 3% or EUR 15 million, whichever is higher.
Member States set national penalty rules for everything else. Art 99(7) lists mitigating factors, including technical and organizational measures in place and whether the operator self-reported. That is why evidence matters now. More on the penalties page.
What moved, and what did not
What moved
- Annex III high-risk obligations: 2 August 2026 to 2 December 2027.
- Annex I product-embedded high-risk obligations: 2 August 2027 to 2 August 2028.
- National sandboxes: 2 August 2026 to 2 August 2027.
- SME relief (simplified technical documentation under Art 11, proportionate quality management under Art 17, priority sandbox access) extended to small mid-caps.
- A new Art 4a gives a legal basis to process special-category data for bias detection and correction where strictly necessary.
What did not move
- Art 5 prohibitions and Art 4 literacy: still 2 February 2025.
- GPAI obligations: still 2 August 2025, with legacy models by 2 August 2027.
- Art 50 transparency: still 2 August 2026.
- The fine ceilings.
- Registration under Art 6(4) and 49(2) for Annex III systems a provider has self-assessed as not high-risk. According to law-firm commentary, the Commission proposed dropping it and negotiators rejected that.
What is still not settled
Three things to treat with caution.
- Harmonised standards are not yet cited. The Commission's standardisation FAQ expects the first standards in 2026, then a review before citation in the Official Journal. Until then there is no presumption of conformity from harmonised standards. Trackers report that the quality-management standard EN 18286 was approved in July 2026 with citation pending, while standards for risk management, cybersecurity and logging remain at earlier stages. The same FAQ says a generic AI management-system standard does not match the Act's QMS requirement, so the Commission requested a dedicated one.
- The Art 6 guidelines are still draft. The Commission published consultation drafts on 19 May 2026. According to Bird & Bird's reading, the Art 6(3) exemption conditions are read narrowly.
- The GDPR half of the Omnibus is not law. The separate GDPR and ePrivacy "data omnibus", proposed on 19 November 2025, is still moving. According to recent trackers, there was no Council mandate and no committee vote as of early October 2026, and the proposals on legitimate interest for AI training are contested. GDPR applies unchanged. See GDPR for AI.
National enforcement is also uneven. Member States were due to designate authorities by 2 August 2025; according to a June 2026 tracker, only nine had designated both. The Commission keeps an official list.
What to do this quarter, by role
If you are a provider of AI systems
- Classify every system against Annex III and the Art 6(3) exemption, and write down the reasoning. Our classification flowchart walks through it.
- Check Art 50 now: does the system disclose that it is AI, and does a generative system mark its outputs? Legacy systems have until 2 December 2026 for marking.
- Screen against the Art 5 list, including the two new entries from 2 December 2026.
- Start high-risk groundwork despite the 2027 date: risk management, data governance, documentation, logging, oversight. The high-risk checklist maps these.
If you are a deployer
- Run your literacy program and keep records of who was trained on what.
- Inventory every AI system in use, including shadow AI, and screen each against Art 5.
- Satisfy Art 50 duties for deepfakes and published AI-generated text.
- Watch Art 25: putting your name on a high-risk system, modifying it substantially or changing its intended purpose can make you the provider.
- Prepare for Art 26 duties: human oversight by trained people, log retention under your control for at least six months, informing workers before workplace use, and feeding the provider's instructions into your GDPR DPIA.
If you are a GPAI provider
- Maintain technical documentation, downstream information, a copyright policy and the public training-content summary.
- If a model may exceed the 10^25 FLOP systemic-risk presumption, plan evaluation, adversarial testing, incident reporting and cybersecurity under Art 55.
- Models placed on the market before 2 August 2025 have until 2 August 2027. Commission fining powers have applied since 2 August 2026.
- Decide whether to sign the voluntary GPAI Code of Practice.
- Downstream modifiers: per non-binding Commission guidelines, you become a provider only if your modification compute exceeds a third of the original training compute (secondary summary).
Why the delay is not a pause
The extra 16 months for Annex III are time to build evidence, not time to wait. Classification decisions, literacy records, system inventories and logs are cheap to start now and expensive to reconstruct later. For the wider picture, see enterprise AI governance and risk, state-level AI compliance and the EU AI Act hub.
How Swfte supports this
Swfte is a Sovereign Intelligence Platform built for Europe: six layers, from sovereign infrastructure to governed agents and workflows, with a Trust and Governance Fabric of 13 facets (including Human oversight, Auditability, Traceability and Evidence) running through all of them. It is designed to let you attach a Trust Profile to each AI system, recording owner, risk level, approved models, data residency, allowed and restricted actions, and the human approval rule, which gives you an inventory and an evidence trail to start AI Act readiness from. Swfte provides the technical controls, governance mechanisms and evidence to support deployment within applicable requirements; the exact posture depends on use case, jurisdiction, deployment and configuration. See /eu, /platform/governance, /platform/sovereignty, /platform/trust-profile and /trust for what is in place today and what is still in progress.
This is not legal advice. Check the current text of the regulation and your national rules, and talk to counsel about your own situation.