The EU AI Act after the Omnibus: what applies now, and what moved
The high-risk rules moved to December 2027 and August 2028. The transparency rules did not move at all — they have applied since 2 August. A plain map of where the EU AI Act stands after the Digital Omnibus, and what a Portuguese company shipping AI should do with the extra time.
- Published
- Reading
- 4 minutes
- Topics
- EU AI Act
Regulation
AI
Compliance - Written by
- Pedro Thomaz
- Discipline
- AI Systems
- Share
If you followed the EU AI Act this year, you probably heard two things that sound contradictory: that the big deadline was 2 August 2026, and that it was postponed. Both are true, for different parts of the law. Here is where things stand now that the dust has settled.
The change came through the Digital Omnibus on AI, a package meant to simplify the rules before the heaviest obligations kicked in. Parliament and Council agreed it in May, it was published in the Official Journal on 24 July 2026 and it entered into force on 27 July — a few days before the original deadline it was moving.
What moved
- High-risk systems in the Annex III areas — AI used for things like recruitment, credit, education, access to essential services, biometrics, critical infrastructure — now have until 2 December 2027, instead of 2 August 2026.
- High-risk AI inside products already regulated by EU safety law (Annex I: machinery, toys, medical devices and so on) now has until 2 August 2028.
- The AI literacy duty was softened: providers and deployers must now support the development of AI literacy among their staff, rather than ensure a given level of it.
What did not move
- Transparency (Article 50) has applied since 2 August 2026. If people interact with an AI system, they have to be told, unless it is obvious. Content generated or manipulated by AI — images, audio, video, and in some cases text — has to be disclosed or marked. Systems that were already on the market get until 2 December 2026 for the machine-readable marking of their output.
- The prohibited practices have applied since February 2025, and the Omnibus added one: AI systems that generate non-consensual intimate imagery or child sexual abuse material, with a transition period until 2 December 2026.
- The rules for general-purpose model providers have applied since August 2025.
The fines did not change either: up to €35 million or 7% of worldwide turnover for prohibited practices, and up to €15 million or 3% for most other obligations.
The mistake to avoid
The tempting reading of all this is "nothing to do until 2028". For most companies in Portugal that is wrong in two ways.
First, the part that is live today is exactly the part most small companies touch: a chatbot on the website, an AI-written product description, a generated image in a campaign. None of that is high-risk, and all of it is Article 50 territory. The obligation is light — tell people, label content — but it is in force.
Second, a deadline that moved is a deadline that exists. Fourteen months sounds like a lot until you remember what high-risk compliance actually involves: risk management, data governance, technical documentation, logging, human oversight, a quality system. That is not a form you fill in the month before. It is the way the product has to be built.
Our own case: AI inside a medical device
We sit on the interesting side of this. RVer, our clinical VR system, is registered with Infarmed as a Class I medical device, and it includes RVer AI, an assistant that orders the content library for a given clinical goal. So we had to read Annex I carefully.
Under Article 6(1), AI connected to a regulated product is high-risk when two things are true: it is the product or a safety component of it, and the product has to go through a third-party conformity assessment. A Class I device like ours is self-certified under the medical device rules, without a notified body — so, in our reading, RVer AI does not fall into the high-risk category through that route. It also does not diagnose, prescribe or decide anything: it ranks content towards a goal the clinician chose, and it shows the evidence behind each suggestion. That is our reading, not legal advice, and the answer would change if the device class did.
We build it as if the stricter rules applied anyway — logging, documentation, a human who decides — because in healthcare the AI Act is the second regulator in the room, not the first. We wrote more about that in what it takes to ship a Class I medical VR app.
What to do with the extra time
- Make an inventory. Every place your company uses AI, including the tools inside other tools. Most people are surprised by the length of the list.
- Sort it into three buckets: transparency only (most of it), possibly high-risk, and prohibited (hopefully empty).
- Fix the transparency items now. Label the chatbot. Mark generated media. It is cheap and it has been required since August.
- For anything possibly high-risk, start the documentation habit today. Decisions written down as they are made cost a fraction of reconstructing them in 2027.
If you want the general orientation first, our builder's guide to the EU AI Act covers how the risk categories work. The Omnibus changed the calendar. It did not change the direction.