The confusion running through the market
Over the summer of 2026 you could read in a lot of places that "the AI Act has been delayed". That is only partly true, and the part that is not true is precisely the part that affects most companies.
Regulation (EU) 2026/1744, known as the Digital Omnibus and in force since 27 July 2026, postponed the obligations for high-risk AI systems: Annex III ones to 2 December 2027 and Annex I ones to 2 August 2028. Annex III covers uses with a direct impact on people — CV screening, creditworthiness assessment, biometrics, education, critical infrastructure, law enforcement.
What was postponed, then, is exactly what almost no small or mid-sized company was doing. What remains fully in force is what that same company does every Tuesday: drafting with AI, summarising reports, analysing documents, handling customers with an assistant.
The two obligations that do apply to you today
Article 4 · AI literacy
In force since 2 February 2025.
It requires providers and deployers to take measures to ensure their staff — and anyone operating AI systems on their behalf — have a sufficient level of AI literacy for the systems they use, taking into account their prior knowledge, the context of use, and the people the systems are used on.
Three points that are routinely missed:
- You are the "deployer". You do not have to build AI to have the obligation: using it professionally is enough. This is the part that surprises most companies.
- It is not a generic course. The level has to suit the context: somebody handling customer data needs different training from somebody writing marketing copy.
- You have to be able to demonstrate it. The regulation talks about taking measures. A measure that leaves no documentary trace is indistinguishable from one never taken, and the trace is what gets audited.
The Omnibus softened the wording — take measures that support literacy, rather than guarantee a specific level — but it neither removed nor postponed the article.
Article 50 · Transparency
In force since 2 August 2026.
It imposes disclosure duties by system type:
- Conversational systems. If a system is designed to interact directly with people, the user has to know they are talking to an AI, and know it at the first interaction, unless it is obvious from the context.
- Synthetic content. Text, images, audio and video generated or manipulated by AI must be marked in a machine-readable format and be detectable as artificially generated. It is a technical obligation, not a visual notice.
- Deepfakes and informational content. Deepfakes must be labelled as generated or manipulated, and content published to inform the public requires disclosure where it was generated or altered with AI.
- Emotion recognition and biometric categorisation. People exposed to these systems have to be told.
The practical consequence is uncomfortable: to know where Article 50 applies to you, you need to know which AI tools are genuinely in use across your organisation and for what. A company without that inventory cannot claim it complies, nor that the article does not apply.
And if those prompts carry data about people, the obligation overlaps with the GDPR, which requires a legal basis and a processor agreement for that same disclosure.
The full timeline, updated
| Date | What happens | Status |
|---|---|---|
| 1 August 2024 | Regulation (EU) 2024/1689 enters into force | Done |
| 2 February 2025 | Prohibited practices and AI literacy (Art. 4) | In force |
| 2 August 2025 | General-purpose models, governance and the penalty regime | In force |
| 2 August 2026 | Transparency (Art. 50) and market surveillance | In force |
| 2 December 2027 | Annex III high-risk systems | Postponed by the Digital Omnibus |
| 2 August 2028 | Annex I high-risk systems | Postponed by the Digital Omnibus |
Organising all of this with a management system, rather than with a folder of loose documents, is exactly what ISO 42001 proposes.