Governance & Operations

EU AI Act: What Applies When

The Digital Omnibus on AI — Regulation (EU) 2026/1744 — entered into force on 27 July 2026 and moved the high-risk deadlines. It left Article 50 transparency where it was. Select any milestone to see what it means for an agent system.

In force now
Grace period running
Deferred by the Omnibus
2 Feb 2025 Prohibited practices & AI literacy In force
click to expand

Unacceptable-risk practices are banned outright, and organisations must ensure staff working with AI systems have sufficient AI literacy.

For agent builders: the literacy duty is easy to overlook. It covers the people operating and overseeing your agents, not only those building them — which matters directly for anyone staffing a human review queue.

2 Aug 2025 General-purpose AI model obligations In force
click to expand

Transparency, documentation, and copyright obligations for providers of general-purpose AI models. The Omnibus significantly expanded the AI Office's supervisory powers here.

For agent builders: these bind the model provider, not you — unless substantial modification makes you a provider. Your compliance posture is now partly downstream of a supervisory relationship you are not party to.

2 Aug 2026 Article 50 transparency — most requirements In force
click to expand

People interacting directly with an AI system must be informed they are doing so, unless it would be obvious to a reasonably well-informed person. Disclosure must be clear and distinguishable at the first interaction.

For agent builders: this is the obligation that applies today and the one most likely to require changing something already shipped. Disclosure must be a property of the system, holding across every channel the agent is reachable through — including the ones your team did not build.

The "obvious in the circumstances" carve-out narrows as agents improve. An agent indistinguishable from a human is precisely the case where it does not apply.

2 Dec 2026 Machine-readable marking of AI-generated content Grace period
click to expand

Providers of systems generating synthetic audio, image, video, or text must mark outputs as artificially generated in a machine-readable format. The Omnibus extended the grace period to this date.

For agent builders: "machine-readable" makes this a data-lineage problem rather than a disclaimer. Decide where marking happens — mark at generation and downstream transforms may strip it; mark at egress and you must know which content was model-generated by the time it reaches the boundary.

2 Dec 2026 New prohibitions: CSAM and non-consensual content Grace period
click to expand

Introduced by the Omnibus. Both placing on the market and use are prohibited, with required safeguards including refusal training, output controls, and content filtering.

2 Aug 2027 Regulatory sandboxes established Deferred
click to expand

Member states must have AI regulatory sandboxes operational. Moved by the Omnibus from the original date.

2 Dec 2027 High-risk obligations — stand-alone Annex III systems Deferred
was 2 August 2026
click to expand

Risk management, data governance, technical documentation, logging, human oversight, accuracy and robustness, and conformity assessment.

For agent builders: this is a build schedule, not a reprieve. Conformity work constrains architecture and takes longer than sixteen months in a large organisation — starting in 2027 means rebuilding rather than building.

The Omnibus also reinstated the duty to register systems self-assessed as non-high-risk in the EU database, with a lighter administrative footprint. An undocumented self-assessment is now a gap.

2 Aug 2028 High-risk obligations — Annex I embedded in regulated products Deferred
was 2 August 2026
click to expand

AI embedded in products already covered by EU safety frameworks — medical devices, machinery, toys, and similar.

The date most teams were watching is not the date that binds them

Enterprise attention concentrated on 2 August 2026 for high-risk obligations, which moved to December 2027. Article 50 transparency stayed — so the provision that applies most directly to conversational agents is the one already in force.

Where enterprise agents land in Annex III

Employment

Recruitment and selection, task allocation, monitoring and evaluation of performance. Where agent enthusiasm concentrates, and squarely high-risk.

Essential services

Creditworthiness evaluation, insurance pricing and risk assessment, access to essential public and private services.

Education

Admissions decisions, assessment of learning outcomes, monitoring during testing.

Article 6(3) derogation

Available for narrow procedural tasks, improving prior human activity, pattern detection without replacing human assessment, or preparatory work — but never for a system profiling natural persons.