On 2 August 2026, the EU AI Act shifted into its next major application phase.
This was significantly reshaped by the AI Omnibus, which took effect from 27 July 2026, having introduced important amendments and postponed key provisions in the AI Act. Jade Kowalski, Partner at DAC Beachcroft comments: "The headline act of the AI Omnibus was the postponement of the deadline introducing strict obligations for high-risk AI systems. Despite the pause on those compliance deadlines, deployers and providers should still be continuing their preparations, including evaluating the draft guidance published by the Commission on classifying high-risk AI systems." The consolidated text of the AI Act following the AI Omnibus can be found here.
The 2 August 2026 milestone was not without consequence though as the Article 50 transparency requirements took effect. This article examines the AI Omnibus amendments, the provisions now in force, and the European Commission’s guidance on high-risk AI systems and transparency obligations.
Transparency obligations: Are we clear?
Taking effect from 2 August 2026, Article 50 of the AI Act sets out four key requirements for both providers and deployers.
Providers must ensure that:
- AI systems intended to interact directly with individuals are designed and developed in such a way that the user is informed when they are directly interacting with an AI system (unless it would be reasonably obvious)
- Synthetic images, video, audio, or text content generated by an AI system is subject to content marking in a machine-readable format and detectable as artificially generated or manipulated, although note that the AI Omnibus introduced a postponement to 2 December 2026 of the content marking obligation for providers of general-purpose AI systems placed on the market before 2 August 2026
Deployers must ensure that users are informed:
- When an AI system utilising emotion recognition or biometric categorisation is operating
- Of the use of an AI system that produces deepfakes or AI-generated text on matters of public interest where there is no human review or editorial control.
To support providers and deployers, the European Commission published its finalised Guidelines to assist providers, deployers, and national authorities in interpreting and applying Article 50 in late July.
The key takeaways are as follows:
Providers:
- An 'interaction' with an AI system must be with a natural person, and not another AI system. The interaction can cover a single exchange (one prompt, one reply) or a series of exchanges.
- The obligation excludes instances such as customer service representatives using AI assistance or if the AI response is disseminated by another person
- Examples of in-scope interaction with an AI system include AI-enabled voice assistances, chatbots, AI hotlines or incidents for other reporting, and AI companions
- Out-of-scope examples include AI-enabled text auto-completion techniques, automated transcription, and translation tools
- The disclosure of the interaction with an AI system must be provided no later than the first interaction with the natural person. The format of that disclosure is not specified, and any appropriate technique may be used provided it is clear and distinguishable, complies with the aforementioned timing requirement and is compliant with accessibility requirements.
- The marking obligation is limited to implementing marks in a machine-readable format, and single technique or combination can be used by providers
- The means of detecting output as AI-generated or manipulated must be accessible to those persons exposed to it
- Explicit exceptions to the obligations are set out within Article 50(2), and examples of those exceptions are set out within the guidelines
Deployers:
- There is no specific means prescribed for advising users that a biometric or emotion recognition system is in operation, but any such information must be clear and distinguishable, and subject to accessibility criteria. The examples provided within the guidance include visible notices at each possible entrance to an exhibition room noting that facial images will be captured to assign them a specific age group. Again, this information must be provided at latest at the time of the first interaction, unless the exception for law enforcement purposes applies.
- Deepfakes carry four cumulative criteria: (i) resemblance of (ii) existing (iii) persons objects, places, entities, or events (iv) that would falsely appear to a person to be authentic or truthful. Applying these criteria, examples of deepfakes include an AI-generated video of individual resembling a politician giving a speech in front of an audience. By contrast, an AI-generated image of a sphinx flying over the Eiffel Tower would not.
- Examples of text informing the public on matters of public interest that must be labelled include AI-manipulated corporate reports published on a listed company’s website containing investor information. However, AI-generated fantasy novels or a news summary generated by a chatbot only available to the user who generated it are examples of text that would fall outside those requirements.
The publication of guidelines followed the European Commission's publication of the Code of Practice on Transparency of AI-generated Content in June 2026. The code can be signed by providers and deployers on a voluntary basis to help demonstrate compliance with the transparency obligations.
High-risk AI systems: An extended deadline and draft guidelines
The obligations relating to high-risk AI systems were due to apply from 2 August 2026, but those deadlines have now been postponed until:
- 2 December 2027 for those systems covered by Article 6(2) and Annex III
- 2 August 2028 for those systems covered by Article 6(1) and Annex I
The postponement is beneficial to both providers and deployers of high-risk AI systems. However, many organisations will need to continue their preparations at pace to ensure that they are properly able to meet with revised deadlines.
By way of reminder, Article 6 of the AI Act establishes two groups of AI systems identified as high-risk:
- Product safety AI systems: AI systems intended to be used as a 'safety component' within a product (or the AI system itself is a product), covered by the EU harmonisation legislation listed in Annex I of the AI Act, which are required to undergo a third-party conformity assessment with a view to placing on the market or putting into service of that product
- Standalone use cases: AI systems that fall into one of the use cases listed in Annex III of the AI Act: biometrics; critical infrastructure; education and vocational training, employment and workers; access to and enjoyment of essential services; law enforcement; migration, asylum and border control; and administration of justice and democratic processes (Article 6(2))
Earlier this year, the European Commission published draft Guidelines on the Classification of High-Risk AI Systems. These guidelines are intended to assist deployers and providers assess whether their AI systems met the definition of high-risk. The draft guidelines were open to consultation which closed in late July. The final guidelines are expected by the end of this year.
Even in draft form, the guidelines offer useful insight into how AI systems may be assessed as high-risk.
Guidelines for classification of high-risk AI systems under Annex I
The draft guidelines relating to Annex I emphasise that it is not possible to list all AI systems that may be classified as high-risk under Article 6(1). The guidelines are therefore limited to the main elements of the assessment procedure and a methodology for classification, applicable to all sectors set out in Annex I. Sector specific guidance may be developed over time.
The guidelines provide clarification on the core requirements of Article 6(1):
- Only AI systems that present significant risks to health, safety, or fundamental rights are classified as high-risk, but not all AI systems that are components of regulated products (or themselves regulated products) are high-risk. They must fulfil the criteria of Article 6(1).
- In order to be considered a 'safety component', there are two alternative scenarios that fulfil that definition: (1) the AI system either fulfils a 'safety function'; or (2) where 'the failure or malfunction of the AI system endangers the health and safety of persons or property'
- The term 'safety function' is further defined as an AI system that fulfils an intended purpose to prevent or mitigate risks to health and safety of persons or property. A real-world example is an AI system to detect whether safety-related parts are worn down and may need maintenance or replacement.
- The 'failure or malfunction' test is consequence‑based, covering incorrect outputs, loss of function or instability that could endanger health, safety, or property. Examples provided in the guidance include an AI system designed to "optimise combustion efficiency in household gas appliances". Although its intended aim of energy efficiency is not a safety function, failure, or malfunction could lead to carbon monoxide, fire, or explosion. By contrast, a similar system optimising heating schedules would not fulfil the criteria as only discomfort or higher energy bills were the possible outcomes.
Guidelines for classification of high-risk AI systems under Annex III
Annex III sets out use cases for AI systems across eight broad areas considered to be high-risk being biometrics; critical infrastructure; education and vocational training, employment, and workers; access to and enjoyment of essential services; law enforcement; migration, asylum, and border control; and administration of justice and democratic processes
The draft guidelines set out the following:
- The only relevant factor to determine whether an AI system qualifies as high-risk under Article 6(2) is whether the intended purpose forms one of the use cases listed in Annex III. The presence of human involvement does not affect the purpose and therefore has no effect on the classification as high-risk. Human oversight is instead a prerequisite for compliance with the high-risk AI system requirements.
- Where several AI systems form part of an AI system, so that their combined intended purposes or joint outputs influence an individual decision, the combined configuration is treated as a single AI system for the purpose of the high-risk classification
- Article 6(3) provides derogations or a 'filter mechanism' stating that an Annex III AI system shall not be considered high-risk where it does not pose "a significant risk of harm to the health, safety or fundamental rights of natural persons, including by not materially influencing the outcome of decision making" in the event that one of the specific, listed conditions is fulfilled which apply where the AI system is intended to: (a) perform a narrow procedural task; (b) improve the result of a previously completed human activity; (c) detect decision making patterns or deviations from prior decision making patterns and is not meant to replace or influence the previously completed human assessment, without proper human review; or (d) perform a preparatory task to an assessment relevant for the purposes of the use cases listed in Annex III
- The availability of the filter mechanism ensures case-specific proportionality in the classification of high-risk AI systems. The conditions are exhaustive, but alternative, and the application of the filter mechanisms is based on a self-assessment by the provider.
The Guidelines for Annex III provide multiple examples of appropriate use cases within the eight broad areas, those use cases that are out of scope, and also appropriate application of the 'filter mechanism' under Article 6(3).
AI Omnibus: other changes you need to know
The AI Omnibus also introduced other less eye-catching but highly relevant changes for providers and deployers:
- Simplification and clarification of the registration requirements for AI systems treated as not being high-risk under Article 6(3) of the AI Act. Although these systems must still be registered in the EU database, the AI Omnibus significantly streamlined the required content.
- Targeted but significant changes to prohibited AI practices, specifically inserting explicit prohibitions on AI systems generating or manipulating non-consensual intimate material and synthetic child sexual abuse material
- Simplifying the regulation applicable to SMEs (small and medium enterprises) and extending this to defined SMCs (small mid-cap enterprises) too. SMCs are identified as having a higher rate of growth and level of innovation but still face similar administrative burdens to SMEs. Definitions for SMEs and SMCs have been introduced, allowing both categories access to simplified technical documentation requirements and special consideration in the application of penalties.
- The EU AI Office will be involved in the extension of AI regulatory sandboxes and real-world testing. An EU-level sandbox for AI models based on GPAI, where the model and system are deployed by the same provider, will be facilitated by the AI Office to facilitate cross-border collaboration. The scope of real-world testing that is permitted outside regulatory sandboxes will be extended to providers/prospective providers of high-risk AI systems covered in Annex I.
- An expansion to the legal basis for processing special categories of personal data for bias detection and correction. Providers and deployers of all AI models and systems (not just limited to high-risk systems) are now permitted to process special categories of personal data for the purposes of bias detection and correction. This processing would be subject to strict safeguards including pseudonymisation, deletion after use, and records of the processing activity as set out in Article 10(5).
- Greater flexibility has been introduced by the removal of a prescription for harmonised post-market monitoring plans. This allows providers of high-risk AI systems to put in place a system for post-market monitoring that is tailored to their organisation.
- The AI Office has been given greater power through centralised oversight of AI systems built on general-purpose AI models (excluding those covered in Annex I) or embedded in very large online platforms and very large search engines (as defined in the Digital Markets Act). The Commission has also been empowered to define the enforcement powers and procedures of the AI Office including the ability to impose fines and other sanctions.
- Targeted changes have been made clarifying the interplay between the AI Act and other EU legislation such as the GDPR, Cyber Resilience Act, and Machine Regulations. For example, the Omnibus added a new provision in Article 42(2a) that explicitly states any high-risk AI system subject to both the AI Act and the Cyber Resilience Act will be deemed compliant with Article 15 of the AI Act if the essential cybersecurity requirements in the Cyber Resilience Act (or a similar horizontal cybersecurity regulation) are fulfilled.
Digital Omnibus covering data, cybersecurity, and privacy rules
The AI Omnibus is part of the wider 'Digital Omnibus', which would be completed by a second (draft) regulation making changes to the EU's digital legislative framework, specifically data, cybersecurity, and privacy rules, such as the GDPR and the ePrivacy Directive.
The draft regulation was published in November 2025, alongside the first version of the AI Omnibus, and can be found here. In December 2025, our colleagues considered its content and how it would simplify the EU's digital legislative framework.
At the time of writing, the draft regulation is still being considered by the European Parliament, with a committee decision awaited. Proposed amendments to the Commission's draft were published in late July, suggesting that there will be further interinstitutional negotiations before a final version is approved.
Based on the Commission's initial draft, if the proposals (or any agreed variations) are passed, then the large majority would take effect immediately (three days after publication in the Official Journal). Proposed amendments to the ePrivacy Directive would take effect after a 6-month transitional period, and there would be a minimum 18-month implementation period for the creation of the single-entry point for incident reporting. We will continue to monitor developments.