In brief

  • The AI Act sets out a phased set of obligations, with some rules already in force and new deadlines from 2026.
  • From August 2, 2026, transparency requirements, internal governance measures, and full enforcement of penalties come into effect.
  • The Digital Omnibus postpones some deadlines for high-risk AI systems, but the framework still needs to be monitored closely.
  • Companies should start with an inventory, system classification, training, and a clear assignment of responsibilities.
  • AI compliance and GDPR need to be managed together, especially where personal data is involved.

Regulation (EU) 2024/1689 — the AI Act — sets out a phased implementation timeline. Understanding what is already in force, what will apply from August 2, 2026, and which deadlines have been redefined by the Digital Omnibus is the first step toward building an orderly, sustainable AI governance path that fits with a company’s existing processes.

Which AI Act obligations are already in force

Since February 2, 2025, the Regulation’s general provisions have applied, along with the requirement to ensure an adequate level of AI literacy for staff involved in using or managing AI systems, and the bans on practices considered unacceptable.

Under the conditions set out in Article 5 of the Regulation, prohibited practices include:

  • the use of manipulative or deceptive techniques capable of distorting a person’s behavior;
  • the exploitation of vulnerabilities linked, for example, to age, disability, or specific social or economic circumstances;
  • social scoring systems that lead to harmful or unfavorable treatment;
  • emotion recognition in the workplace and in education, with limited exceptions;
  • other uses expressly listed in Article 5.

Since August 2025, obligations have applied to providers of general-purpose AI models — the so-called GPAI models — including transparency and technical documentation requirements.

August 2, 2026: transparency obligations and the start of enforcement

The August 2, 2026 deadline widens the scope of applicable rules and makes internal oversight of the AI tools used within a company a more pressing need.

The first area concerns the transparency obligations set out in Article 50 of the Regulation, which apply to systems that interact directly with people — such as chatbots and automated assistants — and to those that generate synthetic content: text, images, or audio produced with AI support.

On this point, the Digital Omnibus introduces an important operational clarification: for systems already placed on the market before August 2, 2026, the transition period granted to providers to comply with watermarking obligations is reduced from six to three months. As a result, the effective compliance deadline is not August 2, 2026, but December 2, 2026.

A second area concerns the full operability of the penalty system: from August 2026, national supervisory authorities are fully active and the penalties set out in the Regulation can be applied. In Italy, oversight of GPAI models is entrusted to the National Cybersecurity Agency, under Law 132/2025.

Digital Omnibus and the AI Act: new deadlines for high-risk systems

On June 29, 2026, the Council of the European Union approved the Digital Omnibus, the package of amendments to the AI Act that redraws the deadlines for systems classified as high-risk. The text is awaiting publication in the EU Official Journal, after which it will enter into force three days later. The new dates set for high-risk systems are:

  • December 2, 2027 for standalone systems (Annex III);
  • August 2, 2028 for systems integrated into products already regulated by sector-specific legislation (Annex I).

The package also affects two other areas.

  • The deadline for national authorities to set up regulatory sandboxes — testing environments for trialing AI systems before they reach the market — is pushed back to August 2, 2027.
  • In addition, AI systems embedded in machinery will no longer fall under the direct application of the AI Act; instead, they will be governed by the Machinery Regulation (EU) 2023/1230. However, the Commission will need to update that regulation with AI-specific safety requirements equivalent to those of the AI Act, to avoid protection gaps during the transition.

In any case, until the Digital Omnibus is published in the Official Journal, the original deadlines formally remain in force. Publication is expected before August 2026, with the stated aim of avoiding a situation where the original deadline takes effect before the legislative process is complete. This is a reasonable expectation, but not yet a legal certainty: anyone managing compliance within an organization should factor this in when planning, continuing to prepare as though the original deadline applies and treating the postponement as extra margin.

How to get AI governance started in your company

The postponements introduced by the Digital Omnibus spread the governance work out over time, without reducing its scope. The work of mapping, classification, and internal organization should start as soon as possible, since the quality of the process also depends on the consistency with which it is built.

This process can be broken down into a few steps, detailed below.

Inventory

The starting point is having a clear picture of what is actually running within the organization. Many companies use AI tools without a structured inventory:

  • writing assistants,
  • document classification systems,
  • predictive analytics tools,
  • AI components embedded in third-party software.

The Regulation distinguishes between providers, deployers, importers, and distributors, and the same organization can hold different roles depending on the system in question. Identifying the systems in use and clarifying the organization’s role with respect to each one is the prerequisite for any serious compliance effort.

Classification

The second step concerns risk-level classification, based on the potential impact on people, rights, safety, and essential services: a spam filter and an algorithm used in a personnel selection process don’t carry the same regulatory profile, and therefore don’t require the same level of oversight.

A technical-organizational classification exercise — without necessarily launching a formal legal assessment right away — makes it possible to set priorities and scope the work rationally.

Training

On the training side, the obligation to ensure an adequate level of AI literacy for people working with these tools is already in force. The required training must ensure that anyone using an AI system understands the tool, knows its limitations, and knows when human oversight is needed. For many organizations, this is also the quickest step to get moving, and it delivers positive effects on the day-to-day use of these tools, regardless of regulatory deadlines.

Compliance and GDPR

Finally, anyone processing personal data within their AI systems needs to treat AI compliance and GDPR as a single track. Assessing the legal basis, data minimization, purpose limitation, and, where necessary, a data protection impact assessment are all part of the same organizational design. Addressing them separately creates redundancies and, very often, gaps.

AI Act compliance: why it pays to start building the path now

Organizations that move their compliance work forward only in response to urgent deadlines rarely manage to build a sustainable AI governance structure over time. Starting the process as early as possible, on the other hand, means being able to build an accurate inventory, define roles and responsibilities with proper care, and face future deadlines with a system that’s already up and running.

The regulatory complexity of the AI Act is real, but it can be managed with the right method. Knowing which tools are actually being used within the company and moving forward with full awareness is the path to building a solid, reliable setup.

*This article is for informational purposes only and does not replace specific legal or compliance advice. The regulatory framework is evolving: for formal compliance requirements, consulting a qualified advisor is recommended.*