The Digital Omnibus is now in force. What actually changed for AI deployers.
The Digital Omnibus on AI entered into force 27 July 2026. Annex III moves to December 2027. Here is exactly what changed for deployers and what did not.
The Digital Omnibus entered into force on 27 July 2026 and moved Annex III high-risk obligations from 2 August 2026 to 2 December 2027, and Annex I to 2 August 2028. We publish this desk to track what moved and what did not. Four obligation clusters were never in scope and are in application now: the Article 5 prohibitions, in force since 2 February 2025; the Article 50 transparency duties; the GPAI obligations under Chapter V; and the Product Liability Directive 2024/2853, whose transposition deadline of 9 December 2026 sits entirely outside the AI Act. Our editorial firewall: every claim is anchored to a specific article, recital, or official institution text. No speculation is presented as settled law.
The Digital Omnibus proposal bifurcates the timeline. Some obligations remain fixed regardless of its adoption. Others shift by sixteen months if it passes. This section maps both scenarios, with each entry marked by status.
Two things land on this date. Providers of synthetic content systems already on the market before 2 August 2026 must meet the Article 50(2) machine-readable marking requirement. And the prohibition the Omnibus added, on AI systems that generate child sexual abuse material or that depict an identifiable person's intimate parts without consent, applies to systems already on the market. Verified against the European Commission's AI Act implementation timeline on 17 August 2026.
These were outside the deferral and are in application now. Article 50 transparency requirements for chatbot disclosure, synthetic content marking, emotion recognition disclosure and deepfake labelling apply to systems first placed on the market after 2 August 2026. Supervision and enforcement commenced on this date for the Article 5 prohibitions (in force since 2 February 2025), the GPAI obligations (since 2 August 2025) and Article 4 AI literacy. The Article 99 penalty regime also applies from this date, to the obligations that are themselves in application.
Directive 2024/2853 is not part of the AI Act and is not affected by the Digital Omnibus. All 27 Member States must transpose it into national law by 9 December 2026. Once transposed, AI software becomes a product subject to strict liability, the rebuttable presumption of defect under Article 10 applies, and claimants gain the right to access evidence under Article 9. Cross-border deployers face this deadline in every jurisdiction where they operate.
SB 24-205, signed May 2024, applies to any developer or deployer of high-risk AI systems that interact with Colorado residents, regardless of where the entity is incorporated. The definition of high-risk substantially overlaps with EU AI Act Annex III categories. European companies with US users or US subsidiaries face a parallel obligation architecture from this date. No Omnibus equivalent exists; this deadline is fixed.
The Digital Omnibus entered into force on 27 July 2026. Annex III high-risk deployer obligations, including the Article 26 duties, the Article 27 FRIA and the Article 9 risk management system, apply from 2 December 2027 instead of 2 August 2026. High-risk AI embedded in products under Annex I moves to 2 August 2028. The Parliament had sought to decouple the FRIA from the wider deferral; it did not survive, and the FRIA falls due with the rest.
The Omnibus moved Annex III high-risk obligations to 2 December 2027 and Annex I to 2 August 2028. It also added a prohibition and cut the Article 50(2) marking transition short. Our provision-by-provision tracker shows which of your obligations moved and which are enforceable today.
Open the Omnibus Tracker →Long form pieces on Article 26, the Revised Product Liability Directive, and the documentation operators need to hold on file when the provisions enter application.
The Digital Omnibus on AI entered into force 27 July 2026. Annex III moves to December 2027. Here is exactly what changed for deployers and what did not.
South Korea's AI Basic Act took effect 22 January 2026. This guide explains high-impact AI obligations, MSIT enforcement, penalty levels, and the comparison to the EU AI Act.
India AI regulation 2026 for operators: the DPDPA, IT Rules, MeitY advisories, the IndiaAI Mission, RBI FREE-AI work, and how India compares to the EU AI Act.
Switzerland AI regulation 2026: no horizontal AI Act, revFADP Article 21, FINMA guidance, Council of Europe accession, and the comparison to the EU AI Act.
Twenty-three days remain before August 2, 2026. The concrete deployer checklist for the final three weeks, built to work whether or not the delay passes.
A living comparison of maximum AI regulatory penalties across the EU, US, UK, China, Korea, Japan, Brazil, Canada, and Singapore, updated as rules change.
Australia AI regulation 2026 for operators: the Voluntary AI Safety Standard, proposed mandatory guardrails, Privacy Act reform, ASIC and APRA guidance for AI.
EU AI Act Article 3 definitions explained: provider, deployer, operator, GPAI model, systemic risk. Which category you fall into determines every obligation you carry.
Most professional indemnity, E&O, and cyber policies do not clearly cover AI mistakes, and exclusions are being added at 2026 renewals. What to check in your policy, plus the affirmative AI coverage trend (Counterpart, Coalition).
Article 25 of Regulation (EU) 2024/1689 explains when a deployer or distributor becomes a provider. Covers substantial modification, rebranding, contractual duties, and liability allocation across the AI value chain.
Article 4 of Regulation (EU) 2024/1689 requires deployers to ensure AI literacy for all staff using AI. Already in force since February 2025. A complete guide to what the obligation requires.
Article 99 of Regulation (EU) 2024/1689 explained for deployers: three fine tiers, how amounts are set, SME proportionality under Art 99(6), and the link to Art 101 GPAI fines.
The complete operator guide to EU AI Act deployer obligations. Art 4 literacy, Art 5 prohibitions, Art 6 classification, Art 9-15 high-risk requirements, Art 26 duties, Art 27 FRIA, Art 50 transparency, enforcement and penalties.
When an AI agent makes a mistake, liability falls on the business that deployed it, not the model provider. The EU liability chain under the AI Act and the revised Product Liability Directive, real cases, and the evidence that reduces exposure.
Two free browser-based tools for deployers working toward the 2 August 2026 deadline. No account required. No data transmitted.
Enter your AI deployment details across seven form sections and generate a structured draft Fundamental Rights Impact Assessment covering all mandatory elements of Article 27(1)(a)-(g). Print or save as PDF in under 15 minutes.
Twenty-five questions across five operator obligation categories. Each question scored 0, 1, or 2 points. Receive an instant readiness percentage and per-category breakdown showing where your gaps are largest before 2 August 2026.
A free three-question widget that tells your readers whether their AI system is likely high-risk under EU AI Act Annex III. One iframe snippet. No account, no API key, no cookies. CC-BY 4.0. Every embed carries an attribution link back to agentliability.eu.
The deployer of a high risk AI system shall take appropriate technical and organisational measures to ensure that they use such systems in accordance with the instructions for use.Article 26(1), Regulation (EU) 2024/1689 · The AI Act
The AI Act is often discussed in the language of prohibition and risk classification. Operator liability sits in a quieter register. It is procedural, continuous, and cumulative. It applies from the moment a system is put into service inside the Union, and it does not distinguish between in house deployments and third party agents operating under contract.
Three interpretations have hardened over the past six months. First, the deployer's duty to monitor outputs cannot be delegated to the provider through a terms of service. Second, human oversight under Article 14 is a design requirement, not a run time option. Third, fundamental rights impact assessments under Article 27 are expected for any public body and for any private deployer operating in the sectors listed in Annex III.
This publication tracks those interpretations as they cross from academic commentary into supervisory practice. Each piece is dated, footnoted to the text, and maintained as the Commission and national authorities issue guidance.
When an AI agent causes harm, three parties carry different standards of obligation. The Act binds the deployer to procedural duties; the revised Product Liability Directive binds the provider of a defective product; the affected party receives a rebuttable presumption in their favour.
Designs the AI system and places it on the Union market.
Puts the system into service in the course of a professional activity.
Natural or legal person who experiences harm traceable to the system.
Agent Liability EU sits inside a network of five sister publications covering the regulatory, certification, and insurance dimensions of autonomous AI agent deployment.
A published framework from Future Proof Intelligence for assessing autonomous AI agent deployments. Seven dimensions. Independent. Continuously maintained.
Read the framework