The EU's AI Act Omnibus agreement, finalised in May 2026, extended some deadlines, simplified certain requirements for smaller businesses, and added a few new obligations. It's the most substantive amendment package to the Act since it entered into force, and it shifts the full compliance deadline for high-risk AI systems to 2 December 2027.
That sounds like good news, and in some ways it is. But it doesn't mean you can wait.
The full compliance timeline
EU AI Act entered into force
The Act became law. The clock started for all businesses operating in or selling to the EU.
Prohibited AI practices banned + AI literacy requirements
Social scoring, subliminal manipulation, and certain biometric surveillance banned. AI literacy (Article 4) now legally required — businesses must document that staff using AI tools have sufficient understanding to do so appropriately.
General-Purpose AI (GPAI) obligations
Providers of models like GPT-4, Claude, and Gemini must comply with transparency and data governance requirements. As a deployer, this reinforces why using enterprise-grade, paid versions of these tools matters.
Transparency obligations (Article 50)
Chatbot disclosure required — customers must be told they're interacting with an AI. AI-generated content must be labelled. Emotion recognition and deepfake obligations apply. Not deferred by the Omnibus — this deadline stands. Fines up to €15m or 3% of worldwide turnover.
New prohibitions + deferred synthetic-content marking
Two new prohibited practices take effect: AI systems that generate or manipulate non-consensual intimate imagery or CSAM are banned. Separately, for AI systems generating synthetic content that were placed on the EU market before 2 August 2026, the provider's obligation to mark outputs in a machine-readable format — deferred four months by the Omnibus — now applies.
High-risk AI system compliance (Annex III)
Extended 16 months from the original 2 August 2026 date. Covers AI used in recruitment, credit scoring, education, healthcare, and critical infrastructure. Documentation, monitoring, and human oversight must be in place. Compliance programmes should be substantially advanced now.
Regulated-product safety components (Annex I)
High-risk AI embedded in regulated products (medical devices, vehicles, lifts) — deferred one year from the original 2 August 2027 date. Documentation requirements apply throughout.
The August 2026 transparency deadline has now passed
If you have any customer-facing AI interactions and you haven't addressed transparency obligations yet, that's the immediate priority. By Q1 2026, EU member states had already issued 50 fines totalling €250 million — enforcement isn't theoretical.
What about UK businesses specifically?
The EU AI Act applies to you if you have EU customers, EU staff, or your AI systems affect people in the EU. Prohibitions have been enforceable since February 2025. The full weight of high-risk AI obligations applies from 2 December 2027.
For businesses operating purely within the UK, there is currently no single binding UK AI law with hard compliance dates. UK regulators — the ICO, FCA, CMA — are each developing AI guidance within their sectors, and a government-backed UK AI bill is expected but not yet confirmed.
Aligning with the EU framework now is the sensible approach for any UK business, regardless of whether you currently trade in Europe. When UK legislation does arrive, it will almost certainly follow a similar risk-based architecture.
One genuinely useful update from the Omnibus
The SME simplification now extends to companies with up to 750 employees and €150 million revenue. Previously, simplified requirements — reduced technical documentation, streamlined conformity assessments, sandbox access — only applied to micro and small businesses. That threshold change is significant, and it means more UK mid-market businesses qualify for a lighter compliance pathway than they would have under the original Act.
Where you need to act
- Audit any customer-facing AI interactions — chatbots, automated responses, AI-generated content
- Implement chatbot disclosure notices before 2 August 2026
- Label any AI-generated content published externally
- Implement AI literacy training and document it — this was required from February 2025
- Build an AI system register listing every tool in use, its risk level, and data handling status
- Complete risk classification for all AI systems — especially anything touching HR, recruitment, or credit
- Document your impact assessment process for new AI deployments
- Establish board-level accountability for AI governance
The honest summary
Treat 2026 as the preparation year, not the compliance year. The businesses that are scrambling to get compliant by the deadlines are the ones that left it too late.
The ones building their framework now — AI system register, impact assessment process, governance structure, staff training records — will find each subsequent deadline straightforward rather than stressful.
The August 2026 transparency deadline is the most urgent for most SMEs. Start there.
Need help understanding where your business stands against the AI Act deadlines?

