Guide · 2026-09-21T00:00:00.000Z · reviewed 2026-09-21T00:00:00.000Z

What the EU AI Act requires from a company that uses AI, after the Omnibus

The four duties that apply now, the two that were deferred, and what to do this quarter. Written for companies that use AI tools rather than build models.

Who this is for

You use AI: a support chatbot, copilots for drafting and code, image generators for marketing, maybe a screening tool in recruitment. You do not train models. Under the EU AI Act you are mostly a deployer, and sometimes a provider if you substantially modify a system or put your name on it.

What the Omnibus changed

The Digital Omnibus on AI (Regulation (EU) 2026/1744) was published on 24 July 2026 and entered into force on 27 July. It moved the high-risk obligations, softened the AI-literacy duty, added a marking duty for generative output, and left Article 50 untouched. Many companies heard “the AI Act was delayed”. For deployers, most of what applies to them was not.

The four duties that apply now

1. AI literacy (Article 4), since 2 February 2025. You must take measures, to your best extent, so that staff and others operating AI on your behalf have sufficient AI literacy. The Omnibus clarified that you do not have to guarantee any specific level. In practice the evidence expected is a training register, a programme, some validation of learning, and written usage rules. The Commission is to publish practical examples.

2. Transparency (Article 50), since 2 August 2026. If your chatbot talks to people, it must say it is AI unless that is obvious. Generated audio, image, video and text must be marked as artificial in a machine-readable way (the provider’s job, but you must not strip the marks). Deepfakes must be disclosed. AI-generated text published on matters of public interest must be disclosed unless a person reviewed it and holds editorial responsibility. People exposed to emotion recognition or biometric categorisation must be informed. Disclosure must be clear, distinguishable and accessible, at the latest at the first interaction.

3. Machine-readable marking of generative output, from 2 December 2026. A new duty introduced by the Omnibus. Check with each generative tool you use what mark it applies and whether the mark survives your export path.

4. National enforcement. Poland’s implementing act has applied since 11 August 2026, and its supervisor KRiBSI can inspect and fine from 28 October 2026, with seven days’ notice and remote inspections by default. Polish law-firm guidance lists what an inspector expects to see: an AI system register, assigned roles, documented training, verified vendor commitments, an AI usage policy staff have acknowledged, updated contracts, an incident procedure and an inspection protocol. Other Member States have their own supervisors; the list is a good proxy anywhere.

What was deferred

Deferred is not cancelled. If you use AI in hiring or credit, the impact assessment and vendor documentation take months to assemble. Start now, without the deadline pressure.

Fines

Three tiers: up to €35M or 7% of global turnover for prohibited practices, €15M or 3% for most other duties including Article 50, and €7.5M or 1% for incorrect information to authorities. For SMEs the lower of the fixed amount and the percentage applies. Use the fine calculator to see your cap.

What to do this quarter

  1. Build the AI system inventory. Everything else hangs off it.
  2. Roll out an acceptable-use policy and collect acknowledgments.
  3. Put disclosures where people first meet your AI. The disclosure generator gives you the texts.
  4. Train staff and keep the register.
  5. Send your vendors a questionnaire covering transparency support, documentation and incident notice.
  6. Write a one-page incident procedure and name an owner.

All six are documents in the Compliance Kit.

Sources