✨ New — try Standpoint free for 14 days: full access to all 15 frameworks. A card is required, but you won’t be charged. Start your free trial →
Standpointby AI Service Pro
Security Intelligence / EU AI Act
Guide

EU AI Act Compliance Checklist: What's Actually Due in 2026 (Post-Omnibus)

M
Mohammad
Founder, AI Service Pro · 9 min read

Quick answer: If your company offers or uses AI that touches EU users, two things are due on August 2, 2026: Article 50 transparency obligations (telling people they're interacting with AI, labeling AI-generated content) and the activation of GPAI enforcement and penalty powers. The heavier high-risk system obligations (Annex III) were postponed by the Digital Omnibus to December 2, 2027. This checklist walks through what to do now, what to prepare for 2027, and how to check where you stand — without a €30K consulting engagement.

What is the EU AI Act in simple terms?

Definition: The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive AI law. It classifies AI systems by risk — prohibited, high-risk, limited-risk (transparency), and minimal-risk — and assigns obligations to providers and deployers of each class, with fines of up to €35 million or 7% of global annual turnover for the most serious violations.

It entered into force on August 1, 2024 and applies in stages. The prohibitions (social scoring, manipulative techniques, most real-time biometric identification in public spaces) have applied since February 2, 2025. The next stage — and the one most companies are actually facing — arrives August 2, 2026.

Is the EU AI Act delayed? What did the Digital Omnibus change?

Partly — and this is where most advice online is now wrong.

In May 2026, EU institutions reached agreement on the Digital Omnibus on AI, which rewrote the enforcement timeline (DLA Piper tracker):

ObligationOld dateNew date
Article 50 transparency (chatbot disclosure, content labeling)Aug 2, 2026Aug 2, 2026 — unchanged
GPAI penalty powers + market surveillanceAug 2, 2026Aug 2, 2026 — unchanged
High-risk AI systems (Annex III: hiring, credit, education, essential services…)Aug 2, 2026Dec 2, 2027 (16-month deferral)
High-risk embedded in regulated products (Annex I)Aug 2, 2027Aug 2, 2028

The Omnibus also extended the SME simplified regime to companies with up to 750 employees or €150M revenue — meaning most startups reading this qualify for lighter documentation requirements.

So: "the AI Act got delayed" is half true. If you were dreading high-risk conformity assessments, you got 16 months of breathing room. If you run a chatbot, generate content with AI, or ship any AI feature to EU users — your deadline didn't move.

Does the EU AI Act apply to my company?

Probably, if any of these are true — and note it applies to non-EU companies too:

  • You provide an AI system (build/sell it under your brand) that's placed on the EU market or whose output is used in the EU.
  • You deploy AI (use it operationally) in the EU — including third-party tools like ChatGPT, Claude, or an AI feature inside your SaaS product.
  • Your users include EU residents, even if you're incorporated in the US or Canada.

The fastest way to find out which obligations hit you: run the free EU AI Act applicability check — 10 minutes, ungated, no sales call.

What's still due on August 2, 2026? (Do these now)

1. Inventory every AI touchpoint (Week 1)

You can't comply with rules you haven't mapped. List every place AI interacts with users or generates content: chatbots, support agents, recommendation features, AI-written email or marketing content, voice agents, image generation. Shadow AI counts — IBM's 2025 Cost of a Data Breach research found that breaches involving unsanctioned "shadow AI" cost organizations roughly $670,000 more than average incidents, so the inventory pays for itself even outside compliance.

2. Chatbot and AI-interaction disclosure (Article 50(1))

Any AI system intended to interact directly with people must be designed so that people know they're talking to an AI, unless it's obvious from context. Practical fix: a persistent "AI assistant" label in the UI plus a line in your first message. Not a buried terms-of-service clause.

3. Label AI-generated and manipulated content (Article 50(2) and 50(4))

Providers of systems generating synthetic audio, image, video, or text must ensure outputs are marked machine-readable as AI-generated. Deployers publishing deepfakes or AI-generated text on matters of public interest must disclose it. If you publish AI-assisted content at scale, decide your labeling standard now (C2PA/provenance metadata where feasible, visible labels where not).

4. Emotion recognition and biometric categorization disclosure (Article 50(3))

If you use emotion recognition or biometric categorization on people, you must inform them. Most SMBs can simply confirm they don't do this — document that confirmation.

5. Know your GPAI position

If you build on top of GPAI models (OpenAI, Anthropic, Google APIs), the GPAI model obligations sit mostly with the model provider — the GPAI Code of Practice had roughly 24 signatories as of June 2026, including Amazon, Anthropic, Google, IBM, Microsoft, and Mistral AI. Your job as a downstream provider: keep records of which models you use, their provider documentation, and how you've configured them. From August 2, 2026, penalty powers and market surveillance activate — regulators can start asking questions and fining.

6. Assign an owner and document as you go

One named person (founder, CTO, or ops lead — you don't need a compliance hire) owns the inventory, the disclosure decisions, and a simple decision log. The SME simplified regime reduces how much documentation you need; it doesn't remove the need to have any.

What should I prepare for December 2, 2027? (High-risk runway)

  1. Screen against Annex III. High-risk categories include AI used in hiring and worker management, credit scoring, education access, essential services, law enforcement, and critical infrastructure. If your product touches any of these, the 2027 obligations (risk management system, data governance, technical documentation, human oversight, conformity assessment) are substantial — 16 months is not too much runway.
  2. If you're high-risk: start the risk management system now. It's the longest-lead item and maps heavily onto ISO 42001 and NIST AI RMF work you may already be doing — see how the frameworks crosswalk.
  3. If you're not high-risk: document why. A one-page screening memo is cheap insurance when a customer or regulator asks.

Ongoing hygiene (any company, any size)

  1. Re-screen quarterly — new AI features change your classification.
  2. Watch provider updates — your obligations shift when your GPAI vendor changes models or terms.
  3. Fold this into one assessment cadence — EU AI Act, ISO 42001, and NIST AI RMF overlap enormously; assessing them together is dramatically cheaper than three separate exercises.

What are the penalties for non-compliance?

Three tiers, per Article 99: up to €35M or 7% of global turnover for prohibited practices; up to €15M or 3% for violations of most other obligations (including Article 50 transparency); up to €7.5M or 1% for supplying misleading information to authorities. SMEs pay the lower of the percentage or fixed amount. Enforcement bodies gain their full powers for the 2026-scope obligations on August 2, 2026.

How do I check where we stand?

Run a structured self-assessment against the actual obligations rather than guessing from blog posts. Standpoint's free Sightline scan shows your gaps against the EU AI Act alongside ISO 42001, NIST AI RMF, ISO 27001, and SOC 2 — it won't certify you or file anything for you, but it answers the first question every founder has: where do we actually stand today? Start the free scan.

FAQ

Is the EU AI Act delayed to 2027?

Only the high-risk (Annex III) obligations moved to December 2, 2027. Article 50 transparency obligations and GPAI enforcement still take effect August 2, 2026.

Does the EU AI Act apply to US or Canadian companies?

Yes, if your AI system is placed on the EU market or its output is used in the EU. Incorporation location doesn't exempt you.

Do I need to comply if I just use ChatGPT or Claude via API?

The heavy GPAI model obligations sit with the model provider, but as a deployer/downstream provider you still own user-facing transparency (disclosure, labeling) and documentation of what you use and how.

What is a high-risk AI system under the EU AI Act?

A system used in an Annex III domain — hiring, credit, education, essential public/private services, law enforcement, migration, justice — or safety components of regulated products (Annex I). These face the December 2027 obligations.

Are there simplified rules for startups?

Yes. The Digital Omnibus extended the SME simplified regime to companies up to 750 employees or €150M revenue — lighter documentation, same core obligations.

See where you stand — free
2-minute check · no card · runs in your browser
Run your free check →
Newsletter
Practical AI-governance & security tips, monthly

No fluff, no fear-selling. Unsubscribe anytime.

// Keep reading