The Digital Omnibus rewrote the EU AI Act's compliance calendar in June, pushing the highest-stakes deadlines out by more than a year. But some obligations already took effect August 2, 2026, and that's the deadline most companies are missing.
Cecilia Ziniti, a three-time general counsel (Anki, Bloomtech, and Replit), built GC AI around the compliance workload she carried in-house at each of them. As of August 2026, 2,000+ legal teams across 53 countries use it, including 200+ public companies such as Hitachi, Zscaler, Eventbrite, and Columbia Sportswear.
Ariana Goodell arrived at a hardware company with AI built into the product at the exact moment the EU AI Act came online. On CZ and Friends, GC AI's podcast for in-house legal leaders, she named the skill that decides whether that goes well:
"If you want to do lawyering, there's a baseline AI literacy you're going to have to have."
That sentence is now regulatory text. Article 4 of the EU AI Act asks companies to support AI literacy across their workforce, and the rest of the regulation hands in-house counsel a longer list: transparency disclosures, high-risk system requirements now landing December 2027, human oversight design, and a vendor diligence tail that runs through 2028. The EU AI Act compliance checklist near the bottom turns that list into a quarter-long project.
One thing changed in late June, and it reset the whole compliance calendar. On June 29, 2026, the Council gave final approval to the Digital Omnibus package, which moves the high-risk compliance deadlines out by 16 to 24 months and adjusts several obligations. A compliance plan built on the original dates is now a year off. The corrected timeline is below.
GC AI, the enterprise legal AI platform built for in-house teams, runs the workflows this checklist assigns. Three GC AI features matter here:
Files for the AI system inventory, the Act, and the omnibus text in one reference library
Playbooks for AI vendor contract review
Automations for standing regulatory monitoring
What Is the EU AI Act?
The EU AI Act, Regulation (EU) 2024/1689, is the first comprehensive AI law from a major regulator. It entered into force on August 1, 2024 and applies obligations in phases based on risk: a short list of prohibited practices, a heavily regulated high-risk tier, transparency duties for AI that interacts with people or generates content, and a separate stack of obligations for general-purpose AI models. Penalties scale with the violation tier, up to a percentage of worldwide annual turnover for the most serious practices, covered in the enforcement section below.
The Act reaches far beyond companies headquartered in the EU. It applies to providers placing AI systems on the EU market wherever they are established, to deployers located in the EU, and to providers and deployers outside the EU when the system's output is used in the EU. A US SaaS company with EU customers, an EU subsidiary, or an EU-facing chatbot is in scope, which is why the EU AI Act lands on in-house counsel desks in San Mateo as often as in Stockholm.
Two roles carry most of the load: provider and deployer.
A provider develops an AI system or model and places it on the market.
A deployer uses an AI system under its own authority in a professional context. Most law departments are managing deployer obligations across dozens of vendor tools, plus provider obligations for anything the company ships with AI inside.
The EU AI Act Timeline After the June 2026 Digital Omnibus
The Digital Omnibus, agreed by Parliament and Council in May 2026 and given final approval on June 29, 2026, rewrote the compliance calendar. As of August 2026, the operative dates are:
Since February 2, 2025: Article 5 prohibitions apply (social scoring, workplace emotion recognition, and other banned practices), along with the Article 4 AI literacy obligation.
Since August 2, 2025: obligations for general-purpose AI (GPAI) model providers apply, along with the governance structure and most penalty provisions.
August 2, 2026: Article 50 transparency obligations apply on their original schedule: telling people they are interacting with AI, and labeling AI-generated content and deepfakes. Systems placed on the market before this date get a grace period until December 2, 2026 for the machine-readable watermarking piece.
December 2, 2026: end of the transition period for the two newly added prohibitions, which target AI systems that can generate non-consensual intimate imagery and child sexual abuse material without adequate safeguards.
December 2, 2027: the new deadline for standalone high-risk AI systems under Annex III, moved from August 2, 2026.
August 2, 2028: the new deadline for high-risk AI embedded in regulated products under Annex I, such as medical devices and machinery.
The omnibus also extended the Act's simplified compliance framework from SMEs to mid-cap companies with up to 750 employees and 150 million euros in annual revenue, which pulls a large share of in-house teams into lighter documentation and reduced fines. Covington's Inside Privacy analysis is a great deep read on the full change list.
Only one deadline survived the omnibus this year: transparency, which took effect August 2, 2026. High-risk moved to late 2027, turning what used to be a fire drill into a program you can build properly.
EU AI Act Transparency Requirements (Article 50)
Article 50 transparency requirements apply from August 2, 2026 and cover four situations:
AI systems that interact directly with people must disclose that fact.
Providers of systems generating synthetic audio, image, video, or text must mark outputs as artificially generated in a machine-readable way.
Deployers of emotion recognition or biometric categorization systems must inform the people exposed to them.
Deployers publishing deepfakes must disclose the content was artificially generated or manipulated.
For most in-house teams the practical work sits in three places:
Customer-facing chatbots and voice agents: each one needs a "you are interacting with AI" disclosure unless it is obvious from context. Inventory them now, including the ones marketing launched without telling you.
AI-generated content in the wild: marketing videos, product imagery, synthetic voiceovers, and AI-drafted text published on matters of public interest each trigger marking or disclosure duties, split between your company as deployer and your vendors as providers.
Vendor paper: the watermarking obligation belongs to providers, so your vendor contracts should warrant Article 50 compliance and back the warranty with an indemnification that survives.
The four-month watermarking grace period for systems already on the market before August 2, 2026 runs until December 2, 2026. The disclosure duties themselves took effect August 2, and any gap there is already overdue.
Some companies got there without being told to. Clay built an internal AI writing policy that makes every employee own every line they publish, arriving at the same accountability standard Article 50 now requires by law.
EU AI Act Requirements for High-Risk AI Systems
High-risk AI systems face the heaviest EU AI Act requirements: a risk management system, data governance, technical documentation, automatic event logging, transparency to deployers, human oversight, and standards for accuracy, robustness, and cybersecurity, plus conformity assessment before the system goes to market. These obligations now apply from December 2, 2027 for Annex III systems and August 2, 2028 for Annex I product-embedded systems.
Employment is the Annex III category most likely to touch your company. AI systems used for recruitment screening, candidate ranking, promotion decisions, task allocation, and termination decisions are high-risk.
If HR runs an AI resume screener, your company is a high-risk deployer with duties of its own: use the system per the provider's instructions, assign trained human oversight, monitor operation, keep logs, and inform affected workers. Banks, insurers, and providers of essential public services also owe a fundamental rights impact assessment under Article 27 before first use.
The deferral to December 2027 is the single biggest planning change from the omnibus. Eighteen months is enough time to run vendor diligence properly, and the conformity documentation you demand from providers in 2026 contracts becomes your compliance file in 2027.
Human Oversight Requirements (Article 14)
Article 14 requires high-risk AI systems to be designed so natural persons can effectively oversee them: understand the system's capacities and limitations, monitor for anomalies, remain aware of automation bias, interpret outputs correctly, decide to override or disregard the output, and stop the system entirely. The provider builds the oversight tools; the deployer assigns competent people and gives them authority and training.
"Human in the loop" is a design requirement and a staffing requirement. A rubber-stamp reviewer satisfies neither. When you paper an AI vendor deal, ask which Article 14 measures ship in the product, and document who on your side holds the override.
Security, Accuracy, and Robustness Requirements (Article 15)
Article 15 requires high-risk systems to achieve appropriate accuracy, robustness, and cybersecurity across their lifecycle, including resilience against attacks that manipulate training data (data poisoning) or inputs (adversarial examples), and controls for feedback loops in systems that keep learning. Providers must declare accuracy levels and metrics in the instructions for use.
Pull those declared accuracy metrics into the agreement as representations and warranties, so the declared accuracy binds the vendor the way pricing does. Align the limitation of liability so an accuracy failure that triggers regulatory exposure sits outside the standard cap.
Explainability and the Right to an Explanation
Two provisions carry the explainability load. Article 13 requires high-risk systems to be transparent enough that deployers can interpret and use the output, with instructions that disclose characteristics, limitations, and performance. Article 86 gives any person affected by a decision based on a high-risk system's output the right to a clear and meaningful explanation of the AI's role in the decision, when the decision produces legal or similarly significant effects.
If your company uses AI in lending, hiring, insurance, or benefits decisions, Article 86 requests will arrive through the same channels as GDPR data subject requests, and the response requires knowing what the system contributed to the decision. Build that answer before the first request, with the same playbook discipline you use for DPA review.
General-Purpose AI (GPAI) Obligations
GPAI model providers have owed their obligations since August 2, 2025: technical documentation, information for downstream providers, a copyright policy, and a public summary of training content, with an added layer of systemic-risk obligations for the most capable models. This tier binds OpenAI, Anthropic, Google, and Meta long before it binds you, and it is the reason your model vendors can now hand you documentation they could shrug about in 2024.
Collect what the law already forces upstream: ask model vendors for their GPAI documentation and pass-through terms, and store them with the contract. When a regulator or enterprise customer asks how your AI feature complies, the answer starts with the paper trail your vendor owes the AI Office anyway.
Penalties and Enforcement
The fine ceilings run in three bands: 35 million euros or 7% of worldwide annual turnover for prohibited practices, 15 million euros or 3% for most other violations including high-risk obligations, and 7.5 million euros or 1% for supplying incorrect information to authorities.
Enforcement splits between the European AI Office, which supervises GPAI models directly, and national market surveillance authorities in each member state, which handle high-risk and transparency enforcement. The omnibus package softened the exposure for smaller companies by extending reduced fines and simplified documentation to mid-caps.
Plan for indirect enforcement. Enterprise customers, procurement teams, and insurers are already writing EU AI Act compliance into their diligence questionnaires, so the Act's requirements arrive in your inbox as contract asks years before a regulator calls.
The EU AI Act Compliance Checklist for In-House Counsel
Run this checklist as a quarter-long project, and the December 2027 deadline turns into routine paperwork instead of a scramble. The sequencing follows the deadline order, so the top items retire the earliest exposure first.
Inventory every AI system: every tool the company builds, buys, or embeds, including the tools individual teams adopted without procurement. You cannot classify what you have not found.
Map your role for each system: provider, deployer, or both. Provider obligations attach to what you ship; deployer obligations attach to what you use.
Screen against Article 5 prohibitions: this includes the two added by the omnibus (non-consensual intimate imagery and CSAM generation capability), which carry a transition period ending December 2, 2026.
Close the Article 50 gaps: disclosure lines on every customer-facing chatbot, labeling for AI-generated media, and deepfake disclosures were due August 2, 2026, so any gap here is already overdue. The watermarking grace period still applies to pre-existing systems.
Stand up the AI literacy program: Article 4 has required it since February 2025, and the omnibus softened the wording toward supporting staff development. If you or your team are new to AI, GC AI's legal AI classes, including 101 Intro to AI Prompting, teach lawyers how to write prompts for contract review, research, and drafting.
Classify candidate high-risk systems against Annex III: start with anything HR uses for recruitment, promotion, or termination.
Rewrite the AI vendor contract playbook: Article 50 compliance warranties, Article 15 accuracy metrics as representations and warranties, Article 14 oversight features documented, indemnification for regulatory exposure, a data protection addendum aligned with GDPR Article 28, and audit support through the termination tail.
Collect GPAI documentation from model vendors: they have owed it to downstream users since August 2025.
Scope the fundamental rights impact assessment: required if the company is a bank, insurer, or provider of essential public services deploying high-risk systems.
Assign human oversight owners: name one for each high-risk candidate system, with training and documented override authority per Article 14.
Calendar the moved deadlines: December 2, 2027 for Annex III, August 2, 2028 for Annex I. Brief the board on what moved and what stayed, because coverage written before the omnibus still says August 2026.
Monitor implementation quarterly: harmonized standards, AI Office guidance, and member-state enforcement all shift the practical bar between now and 2028. GC AI's Regulatory Monitoring Skill Creator turns this item into a standing automation.
How GC AI Helps You Meet the Duties in the EU AI Act
The legal department still own these duties. A legal AI platform makes them cheaper to carry.
The workflows above map to GC AI directly:
Research runs the regulatory tracking with citations to primary sources.
Files holds the Act, the omnibus text, and your AI inventory as a permanent reference library.
Playbooks turns your AI vendor terms, the checklist item with the longest tail, into a repeatable review that flags a missing Article 50 warranty the way it flags a missing liability cap today.
Regulatory Monitoring Skill Creator builds a custom agent scoped to the EU AI Act. Name the jurisdiction, the risk area, and a materiality threshold, and it tracks AI Office guidance and member-state enforcement, verifies each change against primary sources, and assigns a priority tier.
For the broader shortlist conversation, start with the best legal AI tools for in-house counsel guide.
This is the pattern of regulatory change Joys Choi, Senior Director of Legal at Tipalti, described:
"GC AI has become a daily partner for our lean legal team. It gives us fast, reliable analysis across multiple jurisdictions and keeps us ahead of regulatory change. It's transformed how we operate."
That's the EU AI Act problem in miniature: one regulation, 27 member states implementing it, and a Digital Omnibus that rewrote the calendar mid-stream.
The checklist above works with or without GC AI. GC AI adds an AI inventory built in Files, a vendor playbook rewrite done once and reused across every contract, and regulatory monitoring that catches the next omnibus before your compliance calendar goes stale again. August 2, 2026 already passed. Start with the vendor contracts you haven't updated yet.
Frequently Asked Questions
Did the EU AI Act Get Delayed?
Yes, in part. The Digital Omnibus package, given final approval by the Council on June 29, 2026, moved the high-risk compliance deadlines to December 2, 2027 for Annex III systems and August 2, 2028 for AI embedded in regulated products. The Article 50 transparency obligations kept their original August 2, 2026 date, and the prohibitions and GPAI obligations already in force stay in force.
Does the EU AI Act Apply to US Companies?
Yes, when the AI touches the EU. The Act applies to providers placing AI systems on the EU market regardless of where they are established, and to companies outside the EU when their system's output is used in the EU. A US company with EU customers, EU employees using AI tools, or an EU-facing product is typically in scope for at least deployer obligations.
Is Using ChatGPT or Another AI Chatbot Covered by the EU AI Act?
Ordinary business use of a general-purpose chatbot is minimal-risk and carries no direct obligations for the user, though the model provider owes GPAI obligations upstream. Duties arrive when you deploy the tool in a regulated way: wiring it into recruitment decisions creates a high-risk deployment, and putting it in front of customers triggers the Article 50 disclosure duty. The privacy questions are a separate analysis, covered in Is ChatGPT private?
Who Enforces the EU AI Act?
The European AI Office enforces the rules for general-purpose AI models directly, while national market surveillance authorities in each member state enforce the high-risk, transparency, and prohibition rules against providers and deployers. Fines reach 35 million euros or 7% of worldwide turnover for prohibited practices, with lower bands for other violations.
What Risk Categories Does the EU AI Act Establish?
The Act sorts AI systems into four tiers: a short list of prohibited practices banned outright, a high-risk tier carrying the heaviest obligations, transparency duties for AI that interacts with people or generates content, and a separate obligation stack for general-purpose AI models. After the June 2026 Digital Omnibus, high-risk deadlines moved to December 2, 2027 for standalone Annex III systems and August 2, 2028 for product-embedded Annex I systems, while transparency duties and GPAI obligations kept their earlier dates.
What Is the Difference Between a Provider and a Deployer Under the EU AI Act?
A provider develops an AI system or model and places it on the market. A deployer uses an AI system under its own authority in a professional context. Most legal departments are managing deployer obligations across dozens of vendor tools, plus provider obligations for anything the company ships with AI inside.
What Are the Penalties for Non-Compliance with the EU AI Act?
Fines run in three bands: 35 million euros or 7% of worldwide annual turnover for prohibited practices, 15 million euros or 3% for most other violations including high-risk obligations, and 7.5 million euros or 1% for supplying incorrect information to authorities. The June 2026 Digital Omnibus softened exposure for smaller companies by extending reduced fines and simplified documentation to mid-caps.
This content is for informational purposes only and does not constitute legal advice.






