SecurityTechInsider AI security & governance
EN/ NL
Governance

The AI Act after the Digital Omnibus: postponement for high-risk, firm obligations from August 2026

The Digital Omnibus shifts high-risk deadlines to 2027-2028, but transparency obligations under article 50 already apply from 2 August 2026 for organisations.

27 August 2026 5 min
Illustration for this article: The AI Act after the Digital Omnibus. Layers of translucent film lifted apart, light scattering between the sheets.
Organisations must operationalise article 50 transparency controls by 2 August 2026, whilst preparing for high-risk classification deadlines in 2027 and 2028. Image: SecurityTechInsider — original editorial illustration

You must now identify every generative, interactive and classifying AI system in your organisation, determine whether you are its provider or deployer under the AI Act, and ensure that transparency obligations under article 50 are operationally live by 2 August 2026. This is not a future requirement. It is already in force.

The prompt is an analysis of 27 August 2026 of the transparency obligations now binding under the AI Act, which argues that the Digital Omnibus has postponed high-risk deadlines to 2027–2028 but left article 50 transparency duties intact and already active. The European Commission adopted final guidelines on 20 July 2026 with a start date of 2 August 2026, requiring providers to mark generative and interactive AI outputs as machine-readable and deployers to label deepfakes and certain AI-generated text. In our assessment, this means the AI Act is not postponed wholesale; it is precisely rescheduled. The transparency layer applies now. The high-risk classification layer applies later. You must treat them as two separate inventory and governance tasks running in parallel.

Which AI systems in your workflow fall under article 50 now?

Article 50 transparency obligations apply from 2 August 2026 to generative AI systems, interactive AI systems, and certain classifying systems used for emotion recognition, biometric categorisation and deepfakes. The scope is broad: if you deploy a generative model to produce text, code or images; if you operate an interactive chatbot or assistant; or if you use AI to infer emotional state or generate synthetic media, you are already subject to these rules. The obligation is not conditional on high-risk classification. It applies to the system type itself.

Your first task is to map which systems in your organisation fall into these categories. This is not a legal interpretation exercise. It is a technical inventory: which workflows use generative models, which use interactive interfaces, and which use classifying systems for the specified purposes. For each one, you must know the model, its purpose, and whether your organisation acts as the provider (the entity that makes the system available) or the deployer (the entity under whose authority it is used).

What transparency obligations must you operationalise?

  • User notification — users must be explicitly informed when they interact with a generative or interactive AI system.
  • Machine-readable marking — outputs from generative AI must carry markings that can be read by automated tools, not only by humans.
  • Deepfake labelling — deployers must label synthetic media created by AI, including deepfakes and certain AI-generated text.
  • Emotion recognition disclosure — systems that infer emotional or psychological states must inform users of this capability.
  • Biometric categorisation disclosure — systems that categorise individuals by biometric data must inform users.
  • Logging and auditability — you must be able to demonstrate which systems are in use, which transparency measures are active, and how they are enforced.

What concrete controls must you be able to demonstrate?

  1. Identify your role per system — document for each generative, interactive or classifying AI workflow whether your organisation is the provider or the deployer under the AI Act definition.
  2. Record the system and its purpose — maintain a register of which AI models are in use, what they are used for, and which article 50 category each one falls into.
  3. Implement user-facing transparency — ensure that users receive explicit notification before interacting with generative or interactive AI, and that outputs carry machine-readable markings where required.
  4. Establish labelling for synthetic media — where your organisation deploys systems that generate deepfakes or certain AI text, implement labelling that is visible to end users or downstream processors.
  5. Create an audit trail — log which systems are active, which transparency measures are in place, and how they are enforced, so that you can demonstrate compliance on request.
  6. Review model outputs for errors — establish a process to check AI outputs for factual accuracy, bias and harm before they are used in decision-making or released to users.

How do the postponed high-risk deadlines affect your planning now?

The Digital Omnibus has moved the application of article 6 (high-risk classification) to 2 December 2027 for use cases listed in Annex III and 2 August 2028 for product-based categories in Annex I. This is a genuine postponement, not a cancellation. The Commission is expected to publish final guidelines on high-risk systems by the end of 2026, well before those deadlines take effect. This gives you a window to classify your AI inventory along the Annex categories, assess the impact on fundamental rights, and plan which workflows will require high-risk controls such as human oversight, impact assessment and logging.

The two layers operate in parallel. Article 50 transparency obligations are live now. High-risk obligations will come into force later. A system may satisfy article 50 transparency requirements today and later be reclassified as high-risk, triggering additional controls. Your governance structure should anticipate this: record per workflow which article 50 obligations already apply, and flag which workflows are candidates for high-risk classification when the guidelines arrive.

What tooling can help, and what remains your responsibility?

Verification layers and privacy-preserving architectures can make your AI workflows more inspectable and auditable. A verification layer can route tasks through selected models while logging the differences between their outputs and the sources they cite, giving you visibility into what happens inside a workflow. A privacy-preserving architecture can anonymise sensitive documents before sending them to external models, with a fail-closed design that blocks processing if the privacy check fails. Neither of these removes your obligation to review model outputs for errors, nor do they guarantee legal compliance. They are tools that support your own professional judgement, not replacements for it.

The final determination of which classification is correct, which transparency measures suffice, and which workflows require escalation to high-risk governance remains with you. Tooling can make that judgement more informed and more defensible, but it cannot make it for you.

Sources: This article draws on reporting and guidance from OP, European Commission and Twobirds.

Marit Halversen

Written by

Marit Halversen

Covers AI governance and regulatory design, with a focus on how compliance obligations land on architecture rather than on paperwork.