Future Proof The Authority Stack
Independent European Publication AI Act Operator Desk · Regulation 2024/1689 Saturday, 25 April 2026
Agent Liability AI Act Operator Desk
The Authority Stack Briefing Weekly: EU AI Act enforcement, AI insurance market shifts, named carriers. Every Tuesday.
Read past issues →
Live Reference · Verified 17 August 2026

The EU AI Act has been rewritten. We track every deployer obligation, before and after the Digital Omnibus.

The Digital Omnibus entered into force on 27 July 2026 and moved Annex III high-risk obligations from 2 August 2026 to 2 December 2027, and Annex I to 2 August 2028. We publish this desk to track what moved and what did not. Four obligation clusters were never in scope and are in application now: the Article 5 prohibitions, in force since 2 February 2025; the Article 50 transparency duties; the GPAI obligations under Chapter V; and the Product Liability Directive 2024/2853, whose transposition deadline of 9 December 2026 sits entirely outside the AI Act. Our editorial firewall: every claim is anchored to a specific article, recital, or official institution text. No speculation is presented as settled law.

Calendar

Five dates that define the next eighteen months.

The Digital Omnibus proposal bifurcates the timeline. Some obligations remain fixed regardless of its adoption. Others shift by sixteen months if it passes. This section maps both scenarios, with each entry marked by status.

Next binding date Already in application Moved by the Omnibus
  1. 2 December 2026
    The next binding date
    Next

    Article 50(2) transitional period ends. New prohibition applies to existing systems.

    Two things land on this date. Providers of synthetic content systems already on the market before 2 August 2026 must meet the Article 50(2) machine-readable marking requirement. And the prohibition the Omnibus added, on AI systems that generate child sexual abuse material or that depict an identifiable person's intimate parts without consent, applies to systems already on the market. Verified against the European Commission's AI Act implementation timeline on 17 August 2026.

  2. 2 August 2026
    In application, passed

    Article 50 transparency obligations active. Enforcement commenced for prohibitions, GPAI and AI literacy.

    These were outside the deferral and are in application now. Article 50 transparency requirements for chatbot disclosure, synthetic content marking, emotion recognition disclosure and deepfake labelling apply to systems first placed on the market after 2 August 2026. Supervision and enforcement commenced on this date for the Article 5 prohibitions (in force since 2 February 2025), the GPAI obligations (since 2 August 2025) and Article 4 AI literacy. The Article 99 penalty regime also applies from this date, to the obligations that are themselves in application.

  3. 9 December 2026
    Confirmed regardless of Omnibus

    Product Liability Directive 2024/2853 transposition deadline

    Directive 2024/2853 is not part of the AI Act and is not affected by the Digital Omnibus. All 27 Member States must transpose it into national law by 9 December 2026. Once transposed, AI software becomes a product subject to strict liability, the rebuttable presumption of defect under Article 10 applies, and claimants gain the right to access evidence under Article 9. Cross-border deployers face this deadline in every jurisdiction where they operate.

  4. 30 June 2026
    Confirmed (US state law)

    Colorado AI Act enters force

    SB 24-205, signed May 2024, applies to any developer or deployer of high-risk AI systems that interact with Colorado residents, regardless of where the entity is incorporated. The definition of high-risk substantially overlaps with EU AI Act Annex III categories. European companies with US users or US subsidiaries face a parallel obligation architecture from this date. No Omnibus equivalent exists; this deadline is fixed.

  5. 2 December 2027
    Moved by the Omnibus

    Annex III high-risk obligations apply

    The Digital Omnibus entered into force on 27 July 2026. Annex III high-risk deployer obligations, including the Article 26 duties, the Article 27 FRIA and the Article 9 risk management system, apply from 2 December 2027 instead of 2 August 2026. High-risk AI embedded in products under Annex I moves to 2 August 2028. The Parliament had sought to decouple the FRIA from the wider deferral; it did not survive, and the FRIA falls due with the rest.

Editorial note: Every date on this timeline was read against the European Commission's own AI Act implementation timeline on 17 August 2026. This desk carried the pre-Omnibus position for three weeks longer than it should have. That is corrected here and logged in the corrections page.
Live tracker · Verified 17 August 2026

The Omnibus is in force. Where does each deadline stand now?

The Omnibus moved Annex III high-risk obligations to 2 December 2027 and Annex I to 2 August 2028. It also added a prohibition and cut the Article 50(2) marking transition short. Our provision-by-provision tracker shows which of your obligations moved and which are enforceable today.

Open the Omnibus Tracker →
Current stage
In force
Next binding date
2 Dec 2026
Binding deadline
2 Aug 2026
Proposed new date
2 Dec 2027
Latest Analysis

Recent briefings from the desk.

Long form pieces on Article 26, the Revised Product Liability Directive, and the documentation operators need to hold on file when the provisions enter application.

14 June 2026 · Liability

Who is liable when an AI agent makes a mistake?

When an AI agent makes a mistake, liability falls on the business that deployed it, not the model provider. The EU liability chain under the AI Act and the revised Product Liability Directive, real cases, and the evidence that reduces exposure.

Tools

Interactive compliance tools for operators.

Two free browser-based tools for deployers working toward the 2 August 2026 deadline. No account required. No data transmitted.

Article 27 · Compliance

FRIA Generator

Enter your AI deployment details across seven form sections and generate a structured draft Fundamental Rights Impact Assessment covering all mandatory elements of Article 27(1)(a)-(g). Print or save as PDF in under 15 minutes.

Articles 9, 13, 14, 26 · Readiness

AI Act Readiness Scorecard

Twenty-five questions across five operator obligation categories. Each question scored 0, 1, or 2 points. Receive an instant readiness percentage and per-category breakdown showing where your gaps are largest before 2 August 2026.

For Publishers

Embed the High-Risk Classifier on your site.

A free three-question widget that tells your readers whether their AI system is likely high-risk under EU AI Act Annex III. One iframe snippet. No account, no API key, no cookies. CC-BY 4.0. Every embed carries an attribution link back to agentliability.eu.

Get the embed code Preview the widget →
Widget at a glance
Questions3
Based onAnnex III
File size<25 KB
External dependenciesNone
LicenceCC BY 4.0
The deployer of a high risk AI system shall take appropriate technical and organisational measures to ensure that they use such systems in accordance with the instructions for use.
Article 26(1), Regulation (EU) 2024/1689 · The AI Act
Editorial Position

How we read the text.

The AI Act is often discussed in the language of prohibition and risk classification. Operator liability sits in a quieter register. It is procedural, continuous, and cumulative. It applies from the moment a system is put into service inside the Union, and it does not distinguish between in house deployments and third party agents operating under contract.

Three interpretations have hardened over the past six months. First, the deployer's duty to monitor outputs cannot be delegated to the provider through a terms of service. Second, human oversight under Article 14 is a design requirement, not a run time option. Third, fundamental rights impact assessments under Article 27 are expected for any public body and for any private deployer operating in the sectors listed in Annex III.

This publication tracks those interpretations as they cross from academic commentary into supervisory practice. Each piece is dated, footnoted to the text, and maintained as the Commission and national authorities issue guidance.

Figure 01

How liability moves across the chain.

When an AI agent causes harm, three parties carry different standards of obligation. The Act binds the deployer to procedural duties; the revised Product Liability Directive binds the provider of a defective product; the affected party receives a rebuttable presumption in their favour.

01
Provider

Designs the AI system and places it on the Union market.

AI Act · PLD 2024 Arts. 16 · 25 · Dir. 2024/2853 Conformity assessment, technical documentation, strict liability for defective product.
02
Deployer

Puts the system into service in the course of a professional activity.

AI Act · PLD 2024 Art. 26 · Art. 10 PLD Use per instructions, human oversight, logs, rebuttable presumption of defect.
03
Affected party

Natural or legal person who experiences harm traceable to the system.

Figure 01. Allocation of obligations, standards of proof, and presumptions across the AI value chain under EU law, as of April 2026. Not legal advice.
The Network

Five properties, one framework.

Agent Liability EU sits inside a network of five sister publications covering the regulatory, certification, and insurance dimensions of autonomous AI agent deployment.

The Published Framework
AC Methodology
v 1.0 · 2026

The Agent Certified Methodology

A published framework from Future Proof Intelligence for assessing autonomous AI agent deployments. Seven dimensions. Independent. Continuously maintained.

Read the framework
01Trust & Safety 02Context Integrity 03Distribution Control 04Product Maturity 05Governance 06AI Integration 07Autonomy Envelope