Skip to content

EU AI Act timeline 2026: what the Digital Omnibus changed

EU AI Act dates after the Digital Omnibus: chatbot transparency applies from 2 August 2026; Annex III high-risk moves to 2 Dec 2027, Annex I to 2 Aug 2028.

AFKzona Group · 6 min read

The short answer

  • The Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force on 27 July 2026 and moved the high-risk deadlines, not the transparency ones.
  • Article 50 transparency duties, including telling people they are talking to an AI, apply from 2 August 2026.
  • Generative systems already on the market before 2 August 2026 have until 2 December 2026 for machine-readable marking of their output.
  • High-risk rules for Annex III systems apply from 2 December 2027, and for Annex I products from 2 August 2028.
  • In Lithuania the Communications Regulatory Authority (RRT) is the AI market surveillance authority and single point of contact.

The EU AI Act applies in stages, and the Digital Omnibus on AI, Regulation (EU) 2026/1744, changed some of those stages in July 2026. What applies now: prohibited practices and AI literacy (since February 2025), rules for general-purpose AI models (since August 2025) and transparency duties such as telling people they are talking to a chatbot (since 2 August 2026). What moved: high-risk obligations, now due on 2 December 2027 for Annex III systems and 2 August 2028 for Annex I products.

Much of what was written about the AI Act in 2024 and 2025 still quotes the old high-risk date of 2 August 2026. This article sets out the dates as they stand in September 2026, what the Omnibus did and did not change, and what a Lithuanian business using or building AI should do this year.

What is the Digital Omnibus on AI?

The Digital Omnibus on AI is Regulation (EU) 2026/1744, which amends the AI Act to simplify it and postpone some obligations. It was adopted on 8 July 2026, published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. Its biggest effect is on high-risk AI deadlines.

The AI Act is Regulation (EU) 2024/1689, the EU's law on artificial intelligence. It entered into force on 1 August 2024 and sorts AI systems by risk: some practices are banned, some systems are high-risk and heavily regulated, some carry transparency duties, and the rest are largely left alone.

The Omnibus does four things that matter to most businesses:

  1. It postpones high-risk obligations to 2 December 2027 (Annex III) and 2 August 2028 (Annex I).
  2. It softens AI literacy in Article 4 from ensuring "a sufficient level" of literacy to taking measures to support it.
  3. It gives generative AI systems already on the market a grace period to 2 December 2026 for machine-readable marking of their output.
  4. It adds two prohibitions, from 2 December 2026, on AI generation of non-consensual intimate imagery and child sexual abuse material.

It also adds simplifications for small and medium-sized enterprises, including simplified technical documentation and proportionate quality management systems.

Which AI Act rules already apply in 2026?

Three sets of rules already apply: the list of prohibited practices and the AI literacy duty since 2 February 2025, the obligations for providers of general-purpose AI models since 2 August 2025, and the Article 50 transparency duties since 2 August 2026. The Omnibus did not defer the transparency duties.

DateWhat appliesChanged by the Omnibus?
2 February 2025Prohibited practices (Article 5); AI literacy (Article 4)Article 4 softened to "support"
2 August 2025General-purpose AI model obligations; governance; penaltiesNo
2 August 2026Article 50 transparency duties; most remaining provisionsNo
2 December 2026Machine-readable marking for generative systems already on the market; two new prohibitionsNew date
2 December 2027High-risk obligations for Annex III systemsMoved from 2 August 2026
2 August 2028High-risk obligations for Annex I productsMoved from 2 August 2027

Article 50 is the AI Act's transparency article. It requires that people are told when they interact with an AI system, that synthetic audio, images, video and text are marked as AI-generated in a machine-readable way, and that deepfakes and emotion recognition are disclosed.

What changed for high-risk AI?

High-risk obligations were postponed. Stand-alone high-risk systems listed in Annex III, such as AI used in recruitment, education, credit scoring and critical infrastructure, now have to comply from 2 December 2027. High-risk AI that is a safety component of products covered by Annex I legislation, such as medical devices, has until 2 August 2028.

A high-risk AI system is one the AI Act lists as posing significant risk to health, safety or fundamental rights. Such systems need risk management, data governance, technical documentation, logging, human oversight, accuracy and robustness measures, and in many cases a conformity assessment before they are placed on the market.

The postponement is a deferral, not a cancellation. If you build a system that screens job applicants, scores creditworthiness or allocates public services, the requirements are the same; you have more time to meet them. Logging, documentation and human oversight are far cheaper to design in from the start than to add to a finished system.

What applies to chatbots from 2 August 2026?

Since 2 August 2026, anyone interacting with an AI system must be told so, unless it is obvious to a reasonably well-informed, observant and circumspect person. The information must be clear and distinguishable and given at the latest at the time of the first interaction. This applies to website chatbots, AI phone agents and AI e-mail assistants alike.

The duty sits with the provider, the company that develops the AI system or has it developed and puts it on the market under its own name. A business that uses a chatbot on its own site is a deployer. Deployers carry their own Article 50 duties for deepfakes, published AI-generated text on matters of public interest, and emotion recognition. In practice, a deployer should still check that the chatbot on its site shows the disclosure, because the visitor sees one website, not two roles.

We cover the practical side in a separate Article 50 chatbot disclosure checklist.

Breaches of Article 50 fall under the AI Act's "other obligations" tier of fines: up to €15 million or 3% of worldwide annual turnover, whichever is higher. For SMEs, including start-ups, the cap is whichever of the two is lower.

Who enforces the AI Act in Lithuania?

In Lithuania, the Communications Regulatory Authority (Ryšių reguliavimo tarnyba, RRT) is the market surveillance authority and the single point of contact under the AI Act, since 1 April 2025. The Innovation Agency is the notifying authority for bodies that assess high-risk AI systems, since 2 August 2025.

Both were designated through amendments to Lithuanian law approved by the Seimas on 14 January 2025, according to the Ministry of the Economy and Innovation. For a business, RRT is the authority to watch for guidance and, eventually, for enforcement of transparency duties.

What should a Lithuanian business do this year?

Start with an inventory: list every AI system you build, sell or use, and put each one in a risk category. Then fix what already applies, which for most businesses means chatbot disclosure and AI literacy, and plan the high-risk work if any system falls under Annex III. Our view is that the postponement is the time to design, not to wait.

  1. List your AI systems. Include tools bought from vendors: a chatbot, a CV-screening tool, an AI writing assistant used for published content.
  2. Classify each one. Prohibited, high-risk, transparency duty, or minimal risk. Most business chatbots fall under transparency.
  3. Fix transparency now. Chatbots must disclose that they are AI from 2 August 2026. Generative systems already on the market need machine-readable marking by 2 December 2026.
  4. Support AI literacy. Brief the staff who use AI tools on what they do, where they fail and when a person must decide.
  5. Plan high-risk work early. If a system falls under Annex III, start the logging, documentation and human-oversight design before 2027, not in it.
  6. Put it in writing. A short register of systems, categories and owners is the first thing a regulator or a customer will ask for.

Regulatory dates change. We will re-check this article against the Official Journal each quarter and update the date at the top when anything moves.

Get help with AI Act readiness

We build AI systems with audit trails, human approval and documentation designed in; see AI governance and security and AI agents. For a review of an existing AI system against these dates, a code review and security audit starts at €1,500. To talk through your inventory, book a free 30-minute call.

Common questions

When does the EU AI Act apply?

In stages. Prohibited practices and AI literacy have applied since 2 February 2025, general-purpose AI model rules since 2 August 2025, and transparency duties such as chatbot disclosure since 2 August 2026. After the Digital Omnibus, high-risk rules apply from 2 December 2027 for Annex III systems and from 2 August 2028 for Annex I products.

Did the Digital Omnibus delay the AI Act?

Only in part. Regulation (EU) 2026/1744 postponed the high-risk obligations and softened the AI literacy duty, and it gave generative systems already on the market until 2 December 2026 for machine-readable marking. It did not postpone the Article 50 duty to tell people they are interacting with an AI system, which applies from 2 August 2026.

Does the AI Act apply to a small business using a chatbot?

Yes, if the chatbot talks to people. Article 50 requires that people are told they are interacting with an AI system unless it is obvious. The provider must design for this, and a business deploying the chatbot on its website should check that the disclosure is actually shown. Fines for SMEs are capped at the lower of the percentage and the fixed amount.

Who supervises the AI Act in Lithuania?

The Communications Regulatory Authority (Ryšių reguliavimo tarnyba, RRT) has been the market surveillance authority and single point of contact under the AI Act since 1 April 2025. The Innovation Agency is the notifying authority for bodies that assess high-risk AI systems, from 2 August 2025.

Sources

  1. Regulation (EU) 2024/1689 (Artificial Intelligence Act), EUR-Lex
  2. Regulation (EU) 2026/1744 (Digital Omnibus on AI), ELI
  3. NicFab — Digital Omnibus on AI: Regulation (EU) 2026/1744 published in the Official Journal
  4. AI Act Explorer — Digital Omnibus on AI
  5. AI Act Explorer — Article 99: Penalties
  6. Ministry of the Economy and Innovation of Lithuania — National competent authorities under the AI Act

Tell us what you need built.

A free 30-minute call with the engineer who would lead it. You leave with a scope outline and a price range.