AI Act and the Digital Omnibus: what changed in August 2026
The Digital Omnibus postponed high-risk system obligations to 2 December 2027. Only Article 50 on transparency took effect on 2 August 2026. What an Italian software house actually has to do.
Updated 15 August 2026. The previous version of this article was written before the Digital Omnibus and assumed that full high-risk obligations would apply from 2 August 2026. That is not what happened: Regulation (EU) 2026/1744, in force since 27 July 2026, moved that deadline to 2 December 2027. The sections on the timeline, the Italian authorities and the roadmap have been rewritten. If you read the November 2025 version and built a plan on it, the part to revise is the dates, not the obligations.
2 August 2026 was supposed to be the day the AI Act stopped being theory. For almost everyone, it was not. Five days earlier, on 27 July, Regulation (EU) 2026/1744 entered into force, the simplification package the press calls the Digital Omnibus, and it rewrote the timetable of the regulation’s most demanding chapter.
The result is that one thing took effect in August 2026, and it is the one that got the least coverage: Article 50, the transparency obligations. It covers chatbots, conversational agents and AI-generated content. Which is, far more prosaically, almost everything an Italian software house has shipped to production over the past two years.
TL;DR
- The Digital Omnibus (Reg. EU 2026/1744, in force since 27 July 2026) postponed the obligations for high-risk systems under Annex III from 2 August 2026 to 2 December 2027, and those under Annex I (AI embedded in already-regulated products: medical devices, machinery, toys) to 2 August 2028.
- Since 2 August 2026, Article 50 applies: anyone deploying a chatbot, a conversational agent or a system generating synthetic content must disclose it. For systems already on the market before that date, technical content marking must be compliant by 2 December 2026.
- The postponement is not an amnesty. The Article 5 prohibitions have applied since 2 February 2025, GPAI obligations since 2 August 2025, and the Omnibus added two new prohibitions effective 2 December 2026.
- In Italy the picture closed on 4 August 2026, when the Council of Ministers gave final approval to the two implementing decrees of Law 132/2025: AgID as notifying authority with inspection powers, ACN with market surveillance and sanctioning powers.
- The penalties under Article 99 have applied since August 2025, not since August 2026. What took effect on 2 August 2026 is Article 101, the fines the Commission can impose on GPAI model providers. Several Italian sources get this wrong.
- The operational consequence for an Italian software house: 16 extra months for high-risk, zero extra months for transparency. And transparency is what touches the largest number of products already in production.
What the Digital Omnibus actually did
The Digital Omnibus started as a simplification package: the Commission proposed it in November 2025 with the stated goal of reducing compliance burden at a point when the harmonised technical standards needed to demonstrate conformity of high-risk systems were not ready. That is the technical argument behind the postponement: the EN standards CEN-CENELEC has to produce for the AI Act are late, and without them the conformity assessment of high-risk systems would have had to be done without a shared reference.
The AI part of the package was adopted and has been in force since 27 July 2026. It did three things:
It moved high-risk. Annex III (standalone systems: employment, credit, education, essential services, law enforcement, critical infrastructure) from 2 August 2026 to 2 December 2027. Annex I (AI embedded in products that already have their own safety legislation) to 2 August 2028.
It confirmed transparency. Article 50 was left untouched: it applies from 2 August 2026, with a window until 2 December 2026 for systems already on the market to comply with technical marking of generated content.
It added two prohibitions. From 2 December 2026, systems generating non-consensual intimate imagery and systems producing child sexual abuse material are prohibited. These are new: they were not in the 2024 text.
One caveat worth putting in writing: as of 15 August 2026 the “data” part of the Digital Omnibus is still in trilogue. The simplifications you read about on GDPR, cookies and documentation duties are not law yet, and several Italian outlets are already reporting them as settled. What is in force is the AI part, and only that.
What took effect on 2 August 2026: Article 50
This is the part the original article dismissed as “light obligations”. Light they are, in terms of engineering work. But they are also the only ones that apply right now, and they apply across a far larger set of products than high-risk systems do.
Anyone interacting with an AI system must know it. This covers chatbots, voice assistants, conversational agents. The obligation sits with the system provider. The exception (the case that is “obvious to a reasonably well-informed person”) is narrower than people assume: a WhatsApp agent that answers in natural Italian and signs off with the company name is obvious to nobody.
Synthetic content must be marked. Text, images, audio and video generated or manipulated by AI must be marked in a machine-readable format and detectable as artificial. Technical marking inside the file is required on top of the visible disclaimer, which means touching the generation pipeline, not the interface.
Deepfakes must be disclosed. Content depicting real people, places or events in a manipulated way must be labelled as such, with exceptions for artistic, satirical and fictional work, where the label must still be made available in a way that does not obstruct the work.
Emotion recognition and biometric categorisation: exposed individuals must be informed.
The date to mark is 2 December 2026 for systems already on the market before 2 August. If you have a product that generates content and it has been live since before this summer, that is your deadline, not 2027.
The postponement does not mean “do nothing”
Worth being explicit, because the wrong reading is the convenient one and it is circulating widely.
The prohibitions have been operational for 18 months. Article 5 has applied since 2 February 2025. Social scoring, emotion recognition in the workplace and in schools, biometric categorisation to infer protected characteristics, untargeted scraping of facial images: already prohibited, with fines up to 35 million euro or 7% of global turnover.
AI literacy has been an obligation since February 2025. Article 4 requires providers and deployers to ensure a sufficient level of AI literacy among staff operating the systems. It is the kind of obligation nobody checks until something goes wrong, at which point it is the first thing asked for.
GPAI obligations have applied since August 2025. They fall on model providers, not on those integrating them via API.
Two new prohibitions arrive on 2 December 2026, introduced by the Omnibus and described above.
And your customers are not waiting for 2027. This is the practical point. Contractual pressure along the AI supply chain works the way it does under NIS2: it arrives before inspections do. A customer who will have to demonstrate conformity of a high-risk system in 2027 starts asking suppliers for evidence 12 to 18 months earlier, because they need time to replace the ones who cannot produce it. The postponement to 2 December 2027 moves the legal deadline, not the date the questionnaire lands on your desk.
High-risk systems: what remains, with the new deadline
Annex III lists eight areas. For an Italian software house, four come up most often:
Employment: CV screening, decisions on promotion or termination, task allocation, performance monitoring.
Essential services: credit scoring, welfare eligibility assessment, emergency call prioritisation, medical triage.
Education: admissions, learning assessment, classroom behaviour monitoring.
Critical infrastructure: management of road traffic, water, gas, electricity, district heating.
The other four (biometrics, law enforcement, migration and border control, administration of justice) rarely touch a software SME, and when they do it is almost always as a subcontractor to the public sector.
The substantive obligations did not change with the Omnibus. There are still eleven, and it helps to read them as a list of artefacts to produce rather than principles to respect:
| Obligation | Concrete artefact | Who produces it |
|---|---|---|
| Risk management system | Living risk analysis document, updated each release | Product owner + tech lead |
| Data governance | Dataset description, sources, cleaning, bias assessment | Data engineer |
| Technical documentation | The 9 sections of Annex IV, retained for 10 years | Tech lead |
| Record keeping | Automatic logging of inputs, outputs, anomalies | Backend |
| Transparency to the deployer | User manual with limits, accuracy, failure modes | Product + tech writing |
| Human oversight | Technical mechanism for intervention and suspension | Design + backend |
| Accuracy, robustness, cybersecurity | Declared metrics and measurement method | QA + security |
| Conformity assessment | Structured self-assessment (or notified body for biometrics) | Compliance |
| CE marking + EU declaration | Signed formal document | Legal |
| EU database registration | Entry in the Commission’s public register | Compliance |
| Post-market monitoring | Feedback collection and incident reporting procedure | Support + product |
The right-hand column is the one usually missing from AI Act presentations, and it is the one that decides whether the project happens: nine of these eleven obligations are not legal work, they are product and engineering work.
New deadline: 2 December 2027 for Annex III, 2 August 2028 for Annex I.
GPAI obligations, and why they almost certainly do not apply to you
Since August 2025, providers of general-purpose models have had their own obligations: technical documentation of the model, information for downstream integrators, a policy on copyright compliance in training data, and a public summary of the content used for training. Models above the systemic-risk threshold (10^25 FLOP of training compute) additionally face model evaluation, red teaming, risk management, serious-incident reporting and protection of the model itself.
If you call an OpenAI, Anthropic or Google API, these obligations belong to your supplier. They become yours in two cases: if you train a model from scratch, or if you fine-tune so substantially that you change its capabilities. The second is less theoretical than it sounds, and the line is not sharp: if you are considering a heavy fine-tune on an open model, it is worth asking the question beforehand rather than afterwards.
Penalties: who gets the dates wrong
This is the point where we have seen the most confusion, including in otherwise reliable sources.
Article 99, which contains the penalties for operators, has applied since 2 August 2025. Not since August 2026. The three tiers are the familiar ones: up to 35 million euro or 7% of global turnover for breaching the prohibitions; up to 15 million or 3% for substantive obligations; up to 7.5 million or 1.5% for incorrect or incomplete information to authorities. For SMEs and start-ups the lower of the percentage and the fixed amount applies, not the higher.
What took effect on 2 August 2026 is Article 101, the fines the European Commission can impose directly on providers of GPAI models. That covers a handful of companies worldwide.
So saying “penalties under the AI Act kick in from 2 August 2026” is wrong in both directions: operator penalties had already been in force for a year, and the new ones apply to almost nobody reading this.
The Italian picture closed on 4 August 2026
Until this summer, national governance was the missing piece. Law 132/2025 set the principles and, in Article 24, delegated the Government to align national law with the AI Act. The two delegated legislative decrees passed preliminary examination on 10 June 2026 and were finally approved by the Council of Ministers on 4 August 2026, after the opinions of the parliamentary committees.
The split is as follows:
- AgID: notifying authority, with inspection powers. It accredits and supervises conformity assessment bodies.
- ACN: market surveillance and sanctioning power. This is the body that will bring an infringement against you.
- Banca d’Italia, CONSOB, IVASS for systems in their respective supervised sectors, and the Italian Data Protection Authority where the system processes personal data.
The decrees do not stop at governance: they introduce civil liability for AI-caused damage, restrict the use of biometric databases to narrow cases under judicial control, address deepfakes, and create a criminal offence for failure to adopt security measures.
Correction to the previous version of this article, which named AgID as the single notifying and supervisory authority on the basis of a March 2024 decree-law: the correct designation is the one in the August 2026 decrees, and it separates notification (AgID) from sanctioning supervision (ACN).
What to do now: the roadmap with the real dates
Planning changes substantially compared with a year ago, because the order of urgency changes.
By 2 December 2026: transparency
This is the only near deadline, and it touches the most products.
- Inventory of conversational and generative systems already in production. Every chatbot, agent, text or image generation feature, internal or delivered to customers.
- Interaction disclosure on every conversational system. That is a day of work per product, and it needs doing.
- Technical marking of generated content. This is the non-trivial part: it requires changing the generation pipeline so the machine-readable format ends up in the file, not in the interface. Budget one to three weeks per product depending on how deeply generation is integrated.
- Deepfake labelling, if you produce content depicting real people or events.
During 2027: high-risk, for those who have it
- Classification. For each system: prohibited, high-risk Annex III, high-risk Annex I, transparency, minimal risk, GPAI. This is the exercise you do once and then maintain, and most software houses discover they have nothing in Annex III.
- Gap analysis on the eleven obligations, only for systems that turn out to be high-risk. With a December 2027 deadline there is time to do it properly, and the first half of 2027 is the right window because the CEN-CENELEC harmonised standards should be available by then and they change how conformity is demonstrated.
- Implementation. This is the long piece: 4 to 12 months of product work, not consulting work.
Continuously
- Answering customer questionnaires. They are starting to arrive now. Having a classification already done and a documentation page ready turns a two-day request into a one-hour one.
- AI literacy, an obligation since February 2025, satisfied with documented training rather than a course bought and never attended.
Common mistakes we are seeing now
1. “The AI Act was postponed, we’ll deal with it in 2027.” What was postponed is the chapter that most likely does not apply to you. What almost certainly does apply, Article 50, has been in force since August and has a December 2026 deadline.
2. “We use the OpenAI API, OpenAI handles it.” OpenAI answers as the GPAI provider of its model. You answer for the AI system you build by integrating it. The allocation of responsibility along the supply chain is explicit in the regulation and cannot be contracted away.
3. “We don’t do high-risk.” Probably true, but it should be verified by reading Annex III, not by intuition. CV screening is high-risk. An assistant that makes suggestions to a physician is high-risk. A system that estimates creditworthiness is high-risk. A bot that books meeting rooms is not.
4. “We’ll wait for AgID guidance.” The Italian authorities were designated on 4 August 2026 and are building the machine now. Operational guidance will arrive gradually. The text of the regulation and the European AI Office guidelines are already enough to classify your own systems, which is the part you need immediately.
5. Treating documentation as a one-off PDF. AI Act technical documentation is a living artefact: it has to be updated at every significant release. In an inspection, a stale document makes your position worse rather than better.
FAQ
Did the Digital Omnibus cancel the AI Act?
No. It moved the application of high-risk obligations later, confirmed everything else and added two prohibitions. The Article 5 prohibitions, GPAI obligations, the AI literacy duty and the Article 99 penalties were already applicable before and still are.
I have had a chatbot in production for a year. What do I do, and by when?
Two things. Disclosure to the user that they are interacting with an AI system, due since 2 August 2026. And, if the chatbot generates synthetic content that is published or delivered, machine-readable technical marking, for which systems already on the market have until 2 December 2026.
Does an internal enterprise RAG system fall under the AI Act?
It depends on the use, not the technology. A RAG that answers employee questions about the holiday policy is not high-risk. The same RAG used to support personnel selection decisions falls under the “employment” area of Annex III, even if it only makes suggestions. The criterion is the area of deployment.
Do SMEs get exemptions?
They get relief on technical documentation and a lower penalty ceiling, but no exemption from the substantive obligations. If you build a high-risk system, all eleven obligations apply to an eight-person company too.
How do the AI Act and the GDPR fit together?
They are complementary. The GDPR governs the processing of personal data, the AI Act governs the system. An AI system processing personal data falls under both: you need a DPIA under Article 35 GDPR and AI Act risk management, which can be coordinated but are not the same document. In Italy the Data Protection Authority cooperates with AgID and ACN on overlapping cases.
Does a system already in production that becomes high-risk in 2027 have to be rebuilt?
Article 111 provides a transitional regime: high-risk systems already placed on the market before the application date fall under the full obligations when they undergo a substantial modification of their design. In practice, a frozen system has a window and an evolving system does not. And since almost no software stays frozen for two years, the window is narrower in practice than it sounds.
What will a public sector customer ask for?
The tenders we are seeing in 2026 ask for the risk classification of the proposed systems, evidence of technical documentation, and the name of a contact for AI conformity. The high-risk postponement is not slowing these requests down, because a contracting authority writes requirements against the life of the contract, not against the application date.
What is left to do by 2 December
The Digital Omnibus bought 16 months for those building high-risk systems, and zero months for everyone else. Since “everyone else” is the vast majority of Italian software houses, the practical effect of the postponement on this year’s workload is close to nil: Article 50 remains, the 2 December 2026 deadline remains, the prohibitions remain and AI literacy remains.
The most useful thing to do this quarter is smaller than a compliance programme: inventory your systems, classify them once and properly, and bring chatbots and content generation into line. The rest has a real deadline in December 2027, and by then the harmonised standards that are missing today should exist.
If you want an initial assessment of the AI systems you use or are building, with the classification done and the list of missing artefacts, let’s talk. The first conversation is free.
For more: the pillar page on security-aware custom software, the AI Act compliance implementation page for hands-on support, and the related article on NIS2 for Italian software houses, where the supply chain pressure mechanism works exactly the same way.
If what we write is useful to you, you can set us as a preferred source on your Google account. It only affects your own results, and you can undo it whenever you want.
If your case looks like the one in this article, tell us about it. A real conversation with the people who build the software: no automated quotes, no sales bots.