EU AI Act

Created: 2026-05-17 Updated: 2026-09-08 Source count: 20

Updated 2026-09-08 (catch-up scan for the 29 Aug–7 Sep 2026 outage) based on S-2026-08-31-ec-dsa-chatgpt-vlose-designation and S-2026-08-13-ec-ai-office-page-omnibus-in-force — (1) On 31 August 2026 the Commission designated ChatGPT a Very Large Online Search Engine (VLOSE) under the Digital Services Act (Reddit and Roblox as VLOPs), on the basis of ≥45 million average monthly EU users; the services have four months (by January 2027) to meet the additional DSA obligations “such as assessing and mitigating the systemic risks stemming from their service and algorithmic systems” [S-2026-08-31-ec-dsa-chatgpt-vlose-designation]. This is a DSA action, not an AI Act measure, but it places a GPAI-based service under a second EU governance layer alongside the AI Office’s GPAI regime — see the new Detail subsection. (2) The Commission’s own AI Office page (last updated 13 Aug 2026) states the AI Omnibus amendments “entered into force on 27 July” 2026, linking OJ L 2026/1744 — ✅ this confirms on primary footing the vendor-relayed 27 July date flagged ⚠️ in the banner below; the “two new prohibitions from 2 December 2026” claim remains unverified (the AI Office page does not mention it) [S-2026-08-13-ec-ai-office-page-omnibus-in-force]. Added as a Detail subsection, Key Points, a partially-resolved Open Question and two Sources.

Updated 2026-09-08 based on S-2026-08-25-credo-eu-omnibus-playbook (daily AI-governance vendor-intelligence scan; vendor-authored playbook, low authority) — Credo AI states the Digital Omnibus on AI “entered into force on 27 July 2026” and that “two new prohibitions follow on 2 December” 2026 (penalties up to €35M / 7%). ⚠️ This page’s last primary-sourced record (24 Jul) had the act signed 8 July 2026 and awaiting Official Journal publication; the 27 July date and the two-prohibitions claim are vendor-relayed and unverified here — recorded as a cross-check item for the daily regulatory-intelligence scan (Official Journal reference needed), not adopted as fact. The playbook’s 2 Dec 2027 / 2 Aug 2028 high-risk deadlines and 2 Aug 2026 transparency/enforcement start are consistent with this page.

Updated 2026-08-15 from Open Brain sync — Tensions addendum only: recorded the recurrence (in 10–11 Aug 2026 Open Brain vendor captures — Earnix, Daon, BigID) of the contested claim that Annex III high-risk obligations took effect 2 August 2026, against Open Brain’s own 3–5 Aug scan record and this page’s primary-source position (2 Dec 2027 / 2 Aug 2028). No change to the page’s substantive position; see the “secondary claims” Tension. No new Source page — the conflicting statements live in Open Brain captures, not vault sources.

Updated 2026-08-03 based on S-2026-07-31-ec-ai-act-enforcement-begins — the Commission’s press release (31 July 2026) confirms that AI Act enforcement (the AI Office together with national authorities) and the Article 50 transparency obligations commenced on 2 August 2026 — the date is now past as of this run. Interactive AI (chatbots) must tell users they are AI, deep fakes must be labelled, and AI-generated/altered content must carry machine-readable marks; the AI Office holds GPAI enforcement powers (technical-documentation requests, model evaluations, corrective measures, fines), and a first list of 180+ organisations has signed the voluntary Code of Practice on transparency of AI-generated content [S-2026-07-31-ec-ai-act-enforcement-begins]. This supersedes the page’s “scheduled / enforcement signalled” framing for the 2 Aug 2026 GPAI/transparency track (prior framing retained under Earlier view per no-delete). Reinforcing on substance — no change to the high-risk timeline (2 Dec 2027 stand-alone / 2 Aug 2028 product-embedded) or the Digital-Omnibus 2 Dec 2026 transparency-solution deadline. Added as an update banner, a Key Point, a Detail note, and a Source.

Updated 2026-07-30 based on S-2026-07-20-eu-ai-office-transparency-guidelines — the Commission published final Guidelines on the Article 50 transparency obligations for providers and deployers of AI systems on 20 July 2026, 13 days before the obligations start to apply on 2 August 2026. The Guidelines clarify the scope of Article 50: providers must design systems to tell users when they are directly interacting with an AI and add machine-readable marks to AI-generated/manipulated content; deployers must disclose deep fakes, AI-generated public-interest content published without human review or editorial control, and emotion-recognition / biometric-categorisation systems [S-2026-07-20-eu-ai-office-transparency-guidelines]. This advances and largely supersedes the page’s previously-recorded draft Article 50 guidelines / consultation from 8 May 2026 S-2026-05-08-eu-ai-office-article-50-transparency (moved forward, not deleted) and complements the 10 June 2026 voluntary content-marking Code. Reinforcing on the 2 Aug 2026 transparency track — no change to the high-risk timeline (2 Dec 2027 / 2 Aug 2028); note the distinct Digital-Omnibus 2 Dec 2026 deadline for providers’ AI-content transparency solutions. Added as a Key Point, an Earlier-view supersession note, and a Source.

Updated 2026-07-24 based on S-2026-06-29-council-ai-omnibus-final-adoption — the Council of the EU gave final adoption to the Digital Omnibus on AI (“Omnibus VII”) on 29 June 2026 (after European Parliament endorsement reported 16 June; act reported signed 8 July, awaiting Official Journal publication and entering into force on the third day after). This resolves the page’s standing “political agreement ≠ enacted law” open question — the high-risk delay (2 Dec 2027 stand-alone / 2 Aug 2028 product-embedded) is now enacted, not merely agreed. It also carries three new, FS-relevant changes: (i) national AI regulatory sandboxes deadline postponed from 2 Aug 2026 to 2 Aug 2027 — ⚠️ this supersedes the 2 Aug 2026 sandbox date previously recorded on this page from S-2025-11-19-eu-digital-omnibus (old date moved to Earlier view); (ii) the grace period for transparency solutions for artificially generated content cut from 6 to 3 months, new deadline 2 December 2026; and (iii) a clarification of AI Office competence over same-provider GPAI-based systems that lists financial institutions among the exceptions where national authorities remain competent. The CSAM/deepfake-nudification ban is confirmed as applying from December 2026. Added as Key Points, a Detail subsection, an Earlier-view supersession entry, and a resolved Open Question. [S-2026-06-29-council-ai-omnibus-final-adoption]

Updated 2026-07-09 based on S-2026-07-07-ec-ai-cybersecurity-action-plan — the Commission’s EU Action Plan on Cybersecurity and AI (7 July 2026) operationalises the Act’s requirement that advanced AI models be evaluated for risk before EU market placement: it announces an EU third-party evaluation capacity supporting the AI Office and a secure ENISA/JRC testing platform (Q4 2026), and references GPAI/Code-of-Practice enforcement from 2 Aug 2026. Added as a Key Point and cross-reference; reinforcing, not contradicting — no change to the timeline substance.

Updated 2026-07-07 based on S-2026-06-28-tanium-agentic-default-tiers (daily AI-governance vendor scan) — a secondary vendor analysis (Tanium via AIGI) claims the Digital Omnibus postponement makes August 2026 “the operative planning deadline” for high-risk AI compliance. ⚠️ This contradicts the primary-source timeline on this page (high-risk Annex III → 2 Dec 2027; product-embedded → 2 Aug 2028; the 2 Aug 2026 date applies to the GPAI/transparency track). Recorded as a new Tensions entry; page substance unchanged — the primary-source timeline stands.

Updated 2026-07-01 based on S-2026-07-01-ec-highrisk-consultation-extension-confirmeddirect retrieval of the primary Commission consultation page settles the long-standing 23 June vs 23 July 2026 deadline question: the page now states in terms that the consultation “was originally open… until 23 June” but “the deadline was extended to 23 July 2026”, with final guidelines to be adopted by end-2026 (Opening 19 May, Closing 23 July, last update 16 June 2026). ✅ Tension RESOLVED — the secondary reports of an extension (S-2026-06-16) are now confirmed on a primary page; the 23 June reading from S-2026-06-26 is explained as the originally-set date the page itself supersedes. The same page restates the Omnibus high-risk postponement (Dec 2027 stand-alone / Aug 2028 product-embedded) on primary footing. Key Points, Practical Applications, Open Questions and Tensions updated accordingly. Updated 2026-06-26 based on S-2026-06-26-ec-high-risk-guidelines-page — direct retrieval of the Commission’s high-risk classification guidelines policy page (the canonical page for the 19 May 2026 draft) provides primary-source evidence on the standing 23 June vs 23 July 2026 consultation-deadline question: the page states the targeted consultation is “open until 23 June 2026”. ⚠️ Contradiction narrowed, not resolved — the page’s own “Last update” is 19 May 2026, so it predates the 16 June secondary report of an extension to 23 July; the primary page therefore confirms 23 June as the originally set deadline but may not reflect a later extension. Both views preserved with attribution (see Tensions and Open Questions). The page also re-confirms the high-risk timeline (2 Dec 2027 areas / 2 Aug 2028 product-embedded). No change to substance. Updated 2026-06-24 based on S-2026-06-24-ec-ai-act-overview-page — direct retrieval of the European Commission’s canonical AI Act overview page provides primary-source corroboration of the post-Omnibus high-risk timeline previously assembled mainly from secondary captures: high-risk areas (biometrics, critical infrastructure, education, employment, migration/asylum/border) apply from 2 December 2027; high-risk systems embedded in products (e.g. lifts, toys) from 2 August 2028; full applicability remains 2 August 2026 with GPAI (since Aug 2025) and Article 50 transparency unaffected. Reinforcing, not contradicting — no change to substance, but the timeline’s evidential basis is upgraded from secondary to primary. The page does not state the high-risk classification guidelines consultation deadline, so the open 23 June vs 23 July 2026 question remains unresolved (a 24 June secondary source again indicated 23 June; ⚠️ still not confirmed on a primary Commission consultation page — not silently resolved). Updated 2026-06-16 based on S-2026-06-16-eu-ai-office-highrisk-consultation-status — secondary reporting indicates the targeted consultation on the 19 May 2026 draft high-risk classification guidelines has been extended to 23 July 2026 (from 23 June 2026), with final guidelines targeted for adoption by end-2026. ⚠️ Medium-confidence (secondary sources; not confirmed on a directly-retrieved Commission consultation page). Key Point and Open Question annotated; no change to the substance of the draft classification examples. Updated 2026-06-12 based on S-2026-06-10-eu-ai-office-content-marking-code-final — the Commission published the final voluntary Article 50 Code of Practice on marking and labelling of AI-generated content on 10 June 2026 (press release IP/26/1328). This confirms and supersedes the previous run’s ⚠️ unverified “~10 June” flag: the Code is now published, voluntary, and positioned as a practical compliance route for providers and deployers ahead of the 2 August 2026 Article 50 applicability date. Key Point, Detail, Practical Applications and Open Questions updated to reflect actual publication. Updated 2026-06-11 based on S-2026-06-11-eu-ai-office-content-marking-code — the voluntary Article 50 Code of Practice on marking and labelling of AI-generated content reached its closing-plenary / final-publication window (May–June 2026 per the official policy page, last updated 22 May 2026). Refines the existing “Code expected June 2026” wording with the working-group structure (providers: machine-readable marking; deployers: deepfake / public-interest-text disclosure) and flags an unconfirmed secondary claim that the final code was published ~10 June 2026 (not asserted). No change to the 2 Aug 2026 Article 50 applicability date. Updated 2026-06-08 based on S-2026-05-22-eu-ai-office-prohibitions-highrisk-review — Commission’s first Article 112(1) annual review report on the Article 5 prohibitions and Annex III high-risk list (22 May 2026) added; it concludes substantive review is early-stage (prohibitions only applied since 2 Feb 2025, enforcement not yet in force, evaluation needs ≥1 year of practice and the high-risk classification guidelines), flags a CSAM / non-consensual-intimate-content gap addressed via the 7 May AI Omnibus, and positions sandboxes as the evidence-collection mechanism. Added as a Key Point, a Detail subsection and an Open Question. Updated 2026-06-01 based on S-2026-05-07-eu-ai-omnibus-agreement — EU co-legislators reached political agreement on the AI omnibus on 7 May 2026, confirming the high-risk timeline (2 Dec 2027 for high-risk areas; 2 Aug 2028 for product-embedded high-risk). This partially supersedes the prior “delay is proposed but not yet law” framing for the high-risk track; formal adoption is still pending and GPAI / Article 50 remain on the 2 Aug 2026 track. Prior framing preserved under “Earlier view”. Updated 2026-05-29 based on S-2026-05-08-eu-ai-office-article-50-transparency — Commission’s draft Article 50 transparency guidelines consultation added; voluntary Code of Practice on marking/labelling expected June 2026. Updated 2026-05-28 based on S-2026-05-19-eu-ai-office-high-risk-draft — Commission’s overdue Article 6 high-risk classification draft guidelines issued.

TL;DR

The EU AI Act is the EU’s risk-based regulation of AI systems and General-Purpose AI (GPAI) models. The headline near-term date is 2 August 2026, when core obligations for high-risk AI systems (Annex III, Articles 8–15), Article 50 transparency, and full enforcement of GPAI provider obligations (including fines) all become applicable. The Commission’s simplification proposal — the Digital Omnibus (“AI omnibus”) — reached political agreement on 7 May 2026, setting the high-risk timeline at 2 December 2027 for systems used in high-risk areas (biometrics, critical infrastructure, education, employment, migration/asylum/border) and 2 August 2028 for high-risk systems embedded in products [S-2026-05-07-eu-ai-omnibus-agreement]. This is a political agreement pending formal adoption, not yet enacted law; GPAI and Article 50 transparency obligations remain on the 2 August 2026 track. Practitioner posture: the high-risk relief now looks firm enough to sequence around, but do not stand down 2 August 2026 GPAI / transparency readiness.

Key Points

  • The Act distinguishes prohibited, high-risk, and limited-risk / transparency AI systems, with separate rules for GPAI models and a transparency regime under Article 50 [S-2025-11-19-eu-digital-omnibus][S-2026-04-29-eu-ai-office-gpai].
  • GPAI provider obligations have applied since 2 August 2025; full Commission enforcement, including fines up to 6% of global annual turnover, begins 2 August 2026 [S-2026-04-29-eu-ai-office-gpai].
  • Pre-2 August 2025 GPAI models on the market have until 2 August 2027 to comply [S-2026-04-29-eu-ai-office-gpai].
  • High-risk obligations (Annex III, Articles 8–15) — including risk management systems, data governance, human oversight, technical documentation, and incident reporting — apply from 2 August 2026 unless delayed by the Digital Omnibus [S-2025-11-19-eu-digital-omnibus].
  • Article 50 transparency obligations apply from 2 August 2026, and on 20 July 2026 the Commission published final Guidelines clarifying their scope: providers must (a) tell users when they are directly interacting with an AI and (b) add machine-readable marks to AI-generated/manipulated content; deployers must disclose deep fakes, unreviewed AI-generated public-interest content, and emotion-recognition / biometric-categorisation systems [S-2026-07-20-eu-ai-office-transparency-guidelines]. A separate Digital-Omnibus milestone sets 2 December 2026 as the deadline for providers’ transparency solutions for AI-generated content (grace period cut from 6 to 3 months) [S-2026-06-29-council-ai-omnibus-final-adoption].
  • Enforcement and Article 50 transparency obligations commenced on 2 August 2026 (confirmed by the Commission’s 31 July 2026 press release; the date is now past as of 2026-08-03): the AI Office, together with national authorities, began enforcing the Act, and interactive AI must disclose it is AI, deep fakes must be labelled, and AI-generated/altered content must carry machine-readable marks [S-2026-07-31-ec-ai-act-enforcement-begins]. The AI Office holds enforcement powers over GPAI models — it can request technical documentation, evaluate models, require corrective measures and issue fines — and the Commission published a first list of more than 180 organisations that have signed the voluntary Code of Practice on transparency of AI-generated content [S-2026-07-31-ec-ai-act-enforcement-begins].
  • The Commission missed its statutory 2 February 2026 deadline to publish Article 6 high-risk classification guidelines [S-2026-04-29-eu-ai-office-gpai]; draft guidelines with worked examples were subsequently issued 19 May 2026 with a targeted consultation — non-binding but stated to “guide enforcement” [S-2026-05-19-eu-ai-office-high-risk-draft]. The consultation was originally open until 23 June 2026 and has been extended to 23 July 2026 (a 4-week extension requested by stakeholder associations), with final guidelines to be adopted by end-2026 — now confirmed directly on the primary Commission consultation page (Opening 19 May, Closing 23 July, last update 16 June 2026) [S-2026-07-01-ec-highrisk-consultation-extension-confirmed]. ✅ This resolves the earlier 23 June vs 23 July uncertainty: the 23 June date seen on the policy page [S-2026-06-26-ec-high-risk-guidelines-page] was the originally-set deadline, since superseded. The draft is hosted on the AI Act Single Information Platform [S-2026-05-19-eu-ai-office-high-risk-draft].
  • Article 50 transparency / labelling guidelines are in preparation for Q2 2026 publication; a November 2026 watermarking requirement is referenced for AI-generated audio, image, video, and text [S-2026-04-29-eu-ai-office-gpai].
  • The Commission opened a targeted stakeholder consultation on draft guidelines for AI transparency obligations under Article 50 on 8 May 2026, with feedback by 3 June 2026; Article 50 obligations become applicable 2 August 2026 [S-2026-05-08-eu-ai-office-article-50-transparency].
  • Providers must inform users when they are interacting with an AI system and add machine-readable marks to enable detection of AI-generated or manipulated content; deployers must inform people of exposure to deep fakes, AI-generated public-interest publications, and emotion-recognition or biometric-categorisation systems [S-2026-05-08-eu-ai-office-article-50-transparency].
  • A voluntary Code of Practice on marking and labelling of AI-generated content, drafted by independent experts, is expected to be finalised in June 2026 and will complement the guidelines as a compliance-evidence tool [S-2026-05-08-eu-ai-office-article-50-transparency]. The drafting exercise reached its Closing Plenary / final-code publication window (May–June 2026), organised around a Providers working group (machine-readable marking of audio/image/video/text) and a Deployers working group (deepfake and AI-generated public-interest-text disclosure); the code, once Commission-approved, is the voluntary tool to demonstrate compliance with Article 50(2)/(4) [S-2026-06-11-eu-ai-office-content-marking-code]. The final Code was published on 10 June 2026 (press release IP/26/1328) — voluntary, with signatories committing to visually disclose AI-generated content using a standard set of EU AI Office icons, plus a how-to-sign process, Q&A and an info session; this resolves the prior run’s unverified-publication flag. The 2 August 2026 Article 50 applicability date is unchanged [S-2026-06-10-eu-ai-office-content-marking-code-final].
  • Member States must have AI regulatory sandboxes in place by 2 August 2026superseded (2026-07-24): the adopted Digital Omnibus postpones the national AI-sandbox establishment deadline to 2 August 2027 [S-2026-06-29-council-ai-omnibus-final-adoption]. The original 2 Aug 2026 date [S-2025-11-19-eu-digital-omnibus] is retained under Earlier view.
  • The AI Act simplification package is now enacted, not just agreed. The Council gave final adoption on 29 June 2026 to the Digital Omnibus on AI (“Omnibus VII”), following European Parliament endorsement (reported 16 June 2026); the act is reported signed 8 July 2026 and “will be published in the EU’s official journal shortly and will enter into force on the third day after this publication” [S-2026-06-29-council-ai-omnibus-final-adoption]. The enacted high-risk application dates are 2 December 2027 (stand-alone) and 2 August 2028 (product-embedded).
  • The grace period for providers to implement transparency solutions for artificially generated content is reduced from 6 months to 3 months, with a new deadline of 2 December 2026 [S-2026-06-29-council-ai-omnibus-final-adoption].
  • The enacted regulation clarifies AI Office competence for AI systems built on GPAI models where the model and system share a provider, and lists exceptions where national authorities remain competent — including financial institutions (alongside law enforcement, border management and judicial authorities) [S-2026-06-29-council-ai-omnibus-final-adoption]. For banks this means national competent authorities (not the AI Office) retain supervisory competence over such same-provider GPAI-based systems.
  • The CSAM / non-consensual-intimate-content (“nudification”) ban added to the AI Act is confirmed to apply from December 2026 [S-2026-06-29-council-ai-omnibus-final-adoption].
  • The Commission’s EU Action Plan on Cybersecurity and AI (7 July 2026) builds on the AI Act (alongside the Cyber Resilience Act, NIS2 and Cyber Solidarity Act) and cites the Act’s requirement that advanced AI models be evaluated and their risks assessed before EU market placement; it announces an EU third-party evaluation capacity supporting the EU AI Office, an ENISA structured-access blueprint, and an ENISA/JRC secure testing platform (Q4 2026) for critical sectors including finance (reached via NIS2/DORA) [S-2026-07-07-ec-ai-cybersecurity-action-plan].
  • Deployers / embedders of third-party GPAI models in regulated workflows must evidence upstream-provider compliance — copyright policy and training-data summary — within their own AI governance and third-party risk frameworks [S-2026-04-29-eu-ai-office-gpai].
  • The Digital Omnibus on AI entered into force on 27 July 2026 — stated on the Commission’s own European AI Office page (last updated 13 Aug 2026), which links the Official Journal reference OJ L 2026/1744; the same page records that the AI Office is recruiting ~40 additional contractual agents for its enforcement team (applications closing 8 Sep 2026) [S-2026-08-13-ec-ai-office-page-omnibus-in-force].
  • ChatGPT was designated a Very Large Online Search Engine (VLOSE) under the Digital Services Act on 31 August 2026 (Reddit and Roblox as VLOPs), on the basis of self-declared ≥45 million average monthly EU users; the services have four months, by January 2027, to comply with the additional DSA obligations, “such as assessing and mitigating the systemic risks stemming from their service and algorithmic systems” (illegal content, minors, users’ well-being, fundamental rights, electoral processes, public security) [S-2026-08-31-ec-dsa-chatgpt-vlose-designation]. The designation is a DSA measure and says nothing about the AI Act or financial services; its relevance here is that a GPAI-based service is now under two distinct EU governance regimes with different supervisors and timelines [inference].
  • The Commission adopted its first Article 112(1) annual review report on the prohibitions (Article 5) and high-risk list (Annex III) on 22 May 2026, concluding that substantive evaluation is still early-stage — the prohibitions only applied from 2 February 2025, enforcement rules are not yet applicable, and meaningful review needs at least a year of practice plus the published high-risk classification guidelines; it flags a regulatory gap on AI-generated CSAM / non-consensual intimate content (being closed by the 7 May 2026 AI Omnibus ban) and positions regulatory sandboxes as the evidence-collection mechanism for future reviews [S-2026-05-22-eu-ai-office-prohibitions-highrisk-review].

Detail

Structure of the Act

The AI Act creates a tiered framework. Annex I lists Union harmonisation legislation under which AI systems used as safety components may be deemed high-risk; Annex III lists high-risk use cases by application area (employment, credit scoring, biometric ID, etc.). Articles 8–15 set the substantive obligations for providers of high-risk systems: risk management, data governance, technical documentation, record-keeping, transparency, human oversight, accuracy / robustness / cybersecurity, and quality management.

Timeline pressure and the Digital Omnibus

The Commission’s Digital Omnibus proposal, adopted 19 November 2025, would link the application of high-risk rules to the availability of harmonised standards. The Council adopted its position on 13 March 2026; the Parliament on 26 March 2026; trilogue targeted a first agreement by 28 April 2026 [S-2025-11-19-eu-digital-omnibus]. If passed, long-stop dates would push to 2 December 2027 for Annex III and 2 August 2028 for Annex I systems. Crucially, the Omnibus does not delay GPAI obligations or Article 50 transparency — those remain on the 2 August 2026 track [S-2025-11-19-eu-digital-omnibus]. Update (7 May 2026): co-legislators reached political agreement on the AI omnibus; the Commission now states high-risk-area rules apply from 2 December 2027 and product-embedded high-risk rules from 2 August 2028, with GPAI and Article 50 unaffected — though formal adoption of the amended text is still pending [S-2026-05-07-eu-ai-omnibus-agreement]. These dates are corroborated directly on the Commission’s canonical AI Act overview page (retrieved 24 June 2026), upgrading the timeline from secondary to primary-source footing [S-2026-06-24-ec-ai-act-overview-page]. The agreement also reinforces the AI Office’s powers (centralising oversight of systems built on GPAI models), bans AI “nudification” / CSAM-generating apps, extends simplified requirements to SMEs and small mid-caps, and widens regulatory-sandbox access [S-2026-05-07-eu-ai-omnibus-agreement]. The harmonised standards underpinning the timeline are being developed by CEN-CENELEC JTC 21, with prEN 18286 flagged as a near-term marker [S-2026-04-29-eu-ai-office-gpai][S-2026-05-06-paul-ai-data-pathway].

Formal adoption of the Digital Omnibus (29 June 2026)

The 7 May 2026 political agreement was converted into an adopted act when the Council gave its final green light on 29 June 2026 (Omnibus VII), following the European Parliament’s endorsement (reported 16 June 2026); the act is reported signed 8 July 2026 and awaits Official Journal publication, entering into force on the third day after [S-2026-06-29-council-ai-omnibus-final-adoption]. Beyond confirming the high-risk dates (2 Dec 2027 / 2 Aug 2028), the enacted text makes several changes not previously on this page: it postpones the national AI regulatory-sandbox deadline to 2 August 2027 (from 2 August 2026); shortens the transparency-solution grace period for AI-generated content from 6 to 3 months, setting a new 2 December 2026 deadline; confirms the CSAM/deepfake-nudification ban from December 2026; and clarifies AI Office competence over same-provider GPAI-based systems by listing exceptions where national authorities remain competent — including financial institutions. It also adds a mechanism (implementing acts) to resolve overlaps where sectoral law (medical devices, toys, lifts, watercraft) has AI-specific requirements similar to the AI Act, exempts Machinery-Regulation products from direct AI Act applicability, and obliges the Commission to issue guidance that minimises compliance burden for high-risk operators covered by sectoral harmonisation legislation [S-2026-06-29-council-ai-omnibus-final-adoption]. Practitioner read (not in source): for banks the financial-institutions competence carve-out and the 2 December 2026 transparency deadline are the two most operationally material items — the former shapes who supervises same-provider GPAI-based systems, the latter pulls forward the effective date by which customer-facing AI-content labelling must be implemented [inference].

Enforcement commenced (2 August 2026)

The Commission confirmed on 31 July 2026 that AI Act enforcement began on 2 August 2026: the AI Office, together with national authorities, is responsible for implementing, supervising and enforcing the Act, and on the same date the Article 50 transparency obligations started to apply [S-2026-07-31-ec-ai-act-enforcement-begins]. Operationally the now-live transparency duties are that chatbots and other interactive AI must tell users they are dealing with AI, deep fakes (AI-edited or -generated images, video, audio) must be labelled, and AI-generated or altered content must carry machine-readable marks so it can be detected. The Commission frames these as reducing deception and manipulation while giving businesses “a practical way to show compliance”, and reports a first list of more than 180 organisations that have signed the voluntary Code of Practice on transparency of AI-generated content that operationalises the rules [S-2026-07-31-ec-ai-act-enforcement-begins]. This confirms the milestone the wiki had recorded as scheduled/signalled from earlier sources; it does not change the high-risk timeline (2 Dec 2027 / 2 Aug 2028) or the Digital-Omnibus 2 December 2026 transparency-solution deadline. Practitioner read (not in source): with the transparency regime now in force and enforcement live, the near-term assurance task for FS deployers shifts from “prepare for 2 August” to “evidence that customer-/public-facing AI (chatbots, document generation, deepfake-prone workflows) meets Article 50 and that machine-readable marking is in place”, ahead of the 2 December 2026 transparency-solution deadline [inference].

Regulatory layering: ChatGPT under the DSA as well as the AI Act (31 August 2026)

On 31 August 2026 the Commission designated ChatGPT a Very Large Online Search Engine (VLOSE) under the Digital Services Act, alongside Reddit and Roblox as VLOPs, because the services declared at least 45 million average monthly EU users; from notification they have four months — by January 2027 — to meet the additional VLOP/VLOSE obligations, which the Commission illustrates as “assessing and mitigating the systemic risks stemming from their service and algorithmic systems” across illegal content, minors, users’ physical and mental well-being, fundamental rights, electoral processes and public security [S-2026-08-31-ec-dsa-chatgpt-vlose-designation]. The notice does not mention the AI Act. Practitioner read (not in source): this is the first designation of a general-purpose-AI chat service under the DSA’s systemic-risk regime, so the same service now answers to the EU AI Office for its GPAI-model obligations (enforced since 2 Aug 2026 [S-2026-07-31-ec-ai-act-enforcement-begins]) and to the Commission’s DSA supervisors for service-level systemic-risk assessment and mitigation — two instruments, two supervisory tracks, two timelines. For FS firms that consume ChatGPT as a third party, the read-across is to due-diligence evidence rather than to any new obligation of their own: the provider’s DSA risk assessments and mitigations (and, if the fuller DSA package applies as it does to other VLOPs/VLOSEs, its independent audits) become potential inputs to Operational Resilience and Third Party Risk assessments [inference]. Whether enterprise/API deployments fall inside the designation’s scope is not stated in the notice and remains an open question.

Financial services interaction

Banks and payment-services firms must evidence AI compliance through existing prudential and conduct frameworks rather than parallel structures. The EBA position is that CRR/CRD are technology-neutral and can host AI controls within existing model risk, operational risk, ICT and outsourcing frameworks [S-2025-11-eba-ai-act-mapping]. See EBA Supervisory Direction on AI and Governance for the EBA mapping exercise. The FCA’s UK posture is similar — see FCA approach to AI.

Enforcement architecture

The EU AI Office sits within the European Commission and is responsible for GPAI oversight, Code of Practice work, and supplementary guidance. Member State competent authorities will supervise high-risk systems within their jurisdictions. Non-compliance risks fines up to 6% of global annual turnover (GPAI) or 3% (high-risk), with the AI Office signalling enforcement starts 2 August 2026 [S-2026-04-29-eu-ai-office-gpai].

Article 50 transparency obligations — draft guidelines and consultation

The Commission published draft guidelines on the Article 50 transparency obligations on 8 May 2026 and opened a targeted stakeholder consultation closing 3 June 2026, ahead of final adoption [S-2026-05-08-eu-ai-office-article-50-transparency]. The guidelines clarify the substantive obligations: providers must inform users when interacting with AI and apply machine-readable marks to AI-generated or manipulated content; deployers must disclose deepfakes, AI-generated public-interest publications, and emotion-recognition or biometric-categorisation systems. A complementary voluntary Code of Practice on marking and labelling of AI-generated content, drafted by independent experts, is expected in June 2026 [S-2026-05-08-eu-ai-office-article-50-transparency]. That Code reached its Closing Plenary / final-publication window in May–June 2026, structured around two working groups (providers: machine-readable marking of audio/image/video/text; deployers: deepfake and AI-generated public-interest-text disclosure), and once Commission-approved will be the voluntary tool to demonstrate compliance with Article 50(2)/(4) [S-2026-06-11-eu-ai-office-content-marking-code]. The final Code was published on 10 June 2026 (Commission press release IP/26/1328): a voluntary instrument with a signature process, an accompanying set of EU labelling icons, and supporting Q&A — confirming the publication that the 11 June capture had flagged as unverified [S-2026-06-10-eu-ai-office-content-marking-code-final]. Article 50 obligations become applicable from 2 August 2026 — and unlike the high-risk obligations track, Article 50 is not in scope of the Digital Omnibus delay proposal, so the 2 August 2026 enforcement cliff for transparency obligations remains firm [S-2025-11-19-eu-digital-omnibus][S-2026-05-08-eu-ai-office-article-50-transparency].

The Article 112(1) annual review (22 May 2026)

The Commission’s first annual monitoring report under Article 112(1) — assessing whether the Article 5 prohibitions and the Annex III high-risk list need amending — was adopted on 22 May 2026 [S-2026-05-22-eu-ai-office-prohibitions-highrisk-review]. Its substance is deliberately cautious: because the prohibitions only entered application on 2 February 2025, enforcement rules are “not yet applicable,” and there is “a lack of practical experience,” the report concludes a more substantive evaluation of Article 5 will only be possible “after the prohibitions have applied for at least a year and common challenges or regulatory gaps begin to emerge.” Likewise, evaluating the high-risk rules “will be facilitated once the Commission guidelines on the classification of high-risk AI systems are published and practical experience has been acquired” — explicitly deferring to the 19 May 2026 draft guidelines track S-2026-05-19-eu-ai-office-high-risk-draft. The one substantive issue surfaced is a potential gap on AI systems generating CSAM and non-consensual intimate content (not currently prohibited by Article 5), which the 7 May 2026 AI Omnibus political agreement addresses via a ban on such systems [S-2026-05-22-eu-ai-office-prohibitions-highrisk-review][S-2026-05-07-eu-ai-omnibus-agreement]. The report says the Commission has flagged specific (unnamed on the published page) AI systems for monitoring in subsequent reviews, and positions AI regulatory sandboxes as the mechanism for “regulatory learning and evidence collection.” Practitioner read (not in source): for financial-services firms the report signals that the high-risk/prohibition perimeter is unlikely to shift materially in the near term — the live interpretive instrument remains the high-risk classification guidelines, not this review — so inventory-triage effort is better spent on the 19 May draft guidelines than on anticipating Annex III changes.

Practical Applications

  • Programme planning — Assurance plans should cover both “August 2026 still holds” and “delayed” scenarios; do not stand down high-risk readiness work pending the Digital Omnibus outcome [S-2025-11-19-eu-digital-omnibus].
  • Deployer evidence — Firms deploying GPAI must collect upstream-provider copyright policy and training-data summary, plus Code of Practice alignment evidence, ahead of 2 August 2026 enforcement [S-2026-04-29-eu-ai-office-gpai].
  • High-risk inventory — Maintain a tagged inventory of high-risk AI use cases (Annex III scope) with documentation against Articles 8–15. Maps to the AI Tools Inventory baseline expected under BCBS AI Governance Framework.
  • Re-test inventory triage against the 19 May 2026 worked examples. The Commission’s draft guidelines provide concrete examples of systems that should and should not be classified as high-risk; use them to re-validate existing risk-classification decisions before the consultation closes — now confirmed as 23 July 2026 (extended from 23 June) [S-2026-05-19-eu-ai-office-high-risk-draft][S-2026-07-01-ec-highrisk-consultation-extension-confirmed]. There is a genuine window to submit sector-specific interpretation issues (e.g. credit scoring, fraud/AML) before the 23 July close.
  • Build Article 50 labelling, disclosure and provenance evidence for customer- and public-facing AI workflows (chatbots, document generation, deepfake-prone use cases, emotion-recognition / biometric-categorisation tools) before 2 August 2026 — use the voluntary Code of Practice — published 10 June 2026 — as the compliance-evidence anchor, and evaluate whether signing it (committing to the EU labelling icons and disclosure steps) is the right evidence posture for customer- and public-facing workflows [S-2026-05-08-eu-ai-office-article-50-transparency][S-2026-06-10-eu-ai-office-content-marking-code-final].
  • Respond to or monitor the 3 June 2026 consultation on the draft Article 50 guidelines to surface sector-specific interpretation issues for financial-services workflows [S-2026-05-08-eu-ai-office-article-50-transparency].

Open Questions

  • Official Journal publication / entry-into-force date of the Digital Omnibus on AI, and the identity of the “two new prohibitions” applying from 2 December 2026 — asserted by a vendor playbook (27 July 2026 entry into force), not yet confirmed from a primary source [S-2026-08-25-credo-eu-omnibus-playbook]. (Partially resolved 2026-09-08 — the Commission’s AI Office page states the amendments “entered into force on 27 July” 2026 and links OJ L 2026/1744, confirming the date on primary footing [S-2026-08-13-ec-ai-office-page-omnibus-in-force]. Still open: what the “two new prohibitions” from 2 December 2026 are — the AI Office page does not mention them; the page already records the CSAM/nudification ban from December 2026 [S-2026-06-29-council-ai-omnibus-final-adoption], so this may be one prohibition, not two. Needs the OJ text.)
  • New (2026-09-08): What is the full DSA VLOSE obligation set ChatGPT must meet by January 2027, does the designation reach enterprise/API deployments used by FS firms, and how will DSA supervision of the service be coordinated with the AI Office’s GPAI supervision of the underlying models? [S-2026-08-31-ec-dsa-chatgpt-vlose-designation]
  • Following the 7 May 2026 political agreement, when will the amended AI Act text be formally adopted and published (political agreement ≠ enacted law)? (Resolved 2026-07-24 — the Council gave final adoption on 29 June 2026 (Omnibus VII); act reported signed 8 July 2026, awaiting Official Journal publication and entering into force the third day after. Residual: the exact OJ publication date [S-2026-06-29-council-ai-omnibus-final-adoption].) [S-2026-05-07-eu-ai-omnibus-agreement]
  • New (2026-07-24): How will the financial-institutions exception to AI Office competence over same-provider GPAI-based systems interact with EBA / national-competent-authority supervision in banking — and does it create a coordination seam between AI Office and NCA oversight? [S-2026-06-29-council-ai-omnibus-final-adoption]
  • New (2026-07-24): Does the shortened 3-month transparency grace period (deadline 2 December 2026) change firms’ Article 50 labelling implementation timelines for customer-facing AI, given the 2 August 2026 applicability date is unchanged? [S-2026-06-29-council-ai-omnibus-final-adoption]
  • Will the Digital Omnibus be enacted before the 2 August 2026 cliff? (Largely overtaken: the high-risk delay is now agreed for Dec 2027 / Aug 2028; the August 2026 cliff only ever applied to GPAI / Article 50, which are unaffected [S-2026-05-07-eu-ai-omnibus-agreement].)
  • How materially will the final Article 6 high-risk classification guidelines change the worked examples from the 19 May 2026 draft? (Confirmed: consultation closes 23 July 2026; final adoption targeted end-2026 — i.e. after the 2 Aug 2026 core-obligations date but before the Dec 2027 high-risk application date [S-2026-07-01-ec-highrisk-consultation-extension-confirmed].) [S-2026-05-19-eu-ai-office-high-risk-draft]
  • Confirm directly: is the consultation deadline 23 June or 23 July 2026? (Resolved 2026-07-01 — primary Commission consultation page confirms extension to 23 July 2026, adoption end-2026 [S-2026-07-01-ec-highrisk-consultation-extension-confirmed].)
  • Will the GPAI Code of Practice harmonised standards (CEN-CENELEC JTC 21) publish before enforcement begins?
  • Whether GPAI fines will be applied during 2026 in practice given enforcement powers only enter into application on 2 August 2026.
  • How will the final Article 50 guidelines differ from the 8 May 2026 draft once consultation feedback (closing 3 June 2026) is incorporated? [S-2026-05-08-eu-ai-office-article-50-transparency]
  • Will the Commission issue separate sectoral guidance for Article 50 in financial services, or rely on competent authorities to translate it into supervisory expectations? [S-2026-05-08-eu-ai-office-article-50-transparency]
  • How will the voluntary Code of Practice on AI-generated content marking interact with industry-side technical standards (C2PA, watermarking)?
  • Now that the final Code is published (10 June 2026), how does its text differ from the 8 May 2026 draft guidelines, and will financial-services competent authorities (EBA, FCA) treat signing it as evidence of Article 50 compliance? [S-2026-06-10-eu-ai-office-content-marking-code-final]
  • Which specific AI systems did the 22 May 2026 Article 112(1) review flag for monitoring in subsequent reviews (named in the report PDF, not retrieved), and could any touch financial-services use cases? [S-2026-05-22-eu-ai-office-prohibitions-highrisk-review]

Tensions / Contradictions

On the high-risk classification guidelines consultation deadline (23 June vs 23 July 2026):

  • The Commission’s high-risk guidelines policy page, directly retrieved 26 June 2026 (primary), states the consultation is “open until 23 June 2026” — but the page’s own “Last update” is 19 May 2026 [S-2026-06-26-ec-high-risk-guidelines-page].
  • Secondary reporting (16 June 2026) states the deadline was extended to 23 July 2026, with final adoption targeted end-2026 [S-2026-06-16-eu-ai-office-highrisk-consultation-status].
  • Where they actually disagreed: only on whether an extension occurred after 19 May.
  • Status: RESOLVED (2026-07-01) — direct retrieval of the primary Commission consultation page (distinct from the policy page above) confirms the extension: “originally open… until 23 June… the deadline was extended to 23 July 2026”, Closing 23 July, final guidelines end-2026 [S-2026-07-01-ec-highrisk-consultation-extension-confirmed]. The 23 June date on the policy page was the originally-set deadline. Both prior sources are preserved above; the extension is now the confirmed position.

On the 2 August 2026 deadline:

  • Sources within the corpus consistently flag both possibilities: that 2 August 2026 will hold (e.g. captures dated 4/21 [S-2026-04-29-eu-ai-office-gpai]) and that the Digital Omnibus may push to Dec 2027 / Aug 2028 (e.g. capture dated 5/10 [S-2025-11-19-eu-digital-omnibus]).
  • Where they actually disagree: only on whether the delay will materialise — both sides agree the 2 August 2026 transparency / GPAI obligations are not in scope of the delay.
  • Status: partially superseded (2026-06-01). The 7 May 2026 political agreement [S-2026-05-07-eu-ai-omnibus-agreement] confirms the high-risk delay (2 Dec 2027 / 2 Aug 2028), so the “will the delay materialise?” disagreement is largely resolved for the high-risk track; the August 2026 GPAI / transparency track is unchanged. Residual uncertainty is now timing of formal adoption, not whether the delay happens. Paul’s “plan for both scenarios” synthesis S-2026-05-06-paul-ai-data-pathway is preserved but narrows to the GPAI / transparency cliff.

On secondary claims that “August 2026” is the effective high-risk deadline (added 2026-07-07):

  • Tanium’s agentic-AI analysis, as summarised by AIGI [S-2026-06-28-tanium-agentic-default-tiers] (low), states the Digital Omnibus “postpones high-risk AI system requirements by 16 months, setting August 2026 as the operative planning deadline”, and AIGI’s weekly recap repeats “August 2026 the effective compliance deadline for high-risk AI systems”.
  • The primary-source position on this page [S-2026-05-07-eu-ai-omnibus-agreement][S-2026-06-24-ec-ai-act-overview-page] (high) is that the high-risk track was postponed to 2 Dec 2027 (stand-alone Annex III) / 2 Aug 2028 (product-embedded), while 2 Aug 2026 applies to the GPAI / Article 50 transparency track.
  • Where they actually disagree: what the August 2026 date governs — the secondary sources appear to conflate the GPAI/transparency milestone (or an internal planning heuristic) with the high-risk compliance deadline; “16 months” is also arithmetically inconsistent with either primary date.
  • Status: contested — primary sources prevail. The Tanium/AIGI deadline framing is recorded, not adopted; the durable content of that source (default-tier agentic delivery) lives on Model Risk Management and Agentic AI.
  • Recurrence noted 2026-08-15 (Open Brain sync): three Open Brain vendor captures of 10–11 Aug 2026 repeat the conflation — the Earnix capture (10 Aug) states insurance AI “is Annex III high-risk under the EU AI Act, whose obligations took effect 2 August 2026”; the Daon capture (10 Aug) states “Annex III now in force since 2 Aug 2026”; a BigID capture (11 Aug) refers to “EU AI Act high-risk obligations (enforcement from 2 August 2026…)“. Open Brain’s own regulatory scan record (captures of 3–5 Aug 2026) states the opposite: “high-risk obligations remain phased to 2 Dec 2027 (Annex III use-cases) and 2 Aug 2028 (Annex I embedded products) under the AI Omnibus”. Note the vault’s Source pages did not propagate the error — e.g. S-2026-08-04-earnix-mgaa-governance already marks the Annex III read-across as [inference]. Resolution: the primary-source position above ([S-2026-05-07-eu-ai-omnibus-agreement][S-2026-06-29-council-ai-omnibus-final-adoption], high) continues to prevail; per sync policy Open Brain’s best-sourced scan record and the wiki agree, and the misstatements are recorded here rather than adopted or deleted.

Earlier view

  • Until 2026-07-30 the wiki’s Article 50 transparency-track content stopped at the 8 May 2026 draft guidelines / consultation [S-2026-05-08-eu-ai-office-article-50-transparency] and the 10 June 2026 voluntary content-marking Code. This is advanced by the Commission’s final published Guidelines on Article 50 transparency obligations (20 July 2026) [S-2026-07-20-eu-ai-office-transparency-guidelines], which clarify the scope of the provider and deployer duties ahead of the 2 August 2026 applicability date. The draft-stage entry is retained here per the no-delete rule; the final Guidelines are now the current position for scope.
  • Until 2026-07-24 the wiki recorded the national AI regulatory-sandbox deadline as 2 August 2026 [S-2025-11-19-eu-digital-omnibus]. This was superseded by the adopted Digital Omnibus, which postpones the sandbox establishment deadline to 2 August 2027 [S-2026-06-29-council-ai-omnibus-final-adoption]. The original date is retained here per the no-delete rule.
  • Until 2026-05-29 the wiki recorded the Digital Omnibus high-risk delay as “proposed but not yet law”, with practitioner posture to “plan for both scenarios” (August 2026 holds vs. delay to Dec 2027 / Aug 2028) [S-2025-11-19-eu-digital-omnibus]. This was superseded for the high-risk track by the 7 May 2026 political agreement confirming the Dec 2027 / Aug 2028 dates [S-2026-05-07-eu-ai-omnibus-agreement]. The earlier view is retained here because the amended text is not yet formally adopted, so the “not yet enacted law” caveat still applies in a narrower form.

Sources

  • [S-2026-05-07-eu-ai-omnibus-agreement] → S-2026-05-07-eu-ai-omnibus-agreement
  • [S-2025-11-19-eu-digital-omnibus] → S-2025-11-19-eu-digital-omnibus
  • [S-2026-04-29-eu-ai-office-gpai] → S-2026-04-29-eu-ai-office-gpai
  • [S-2026-05-08-eu-ai-office-article-50-transparency] → S-2026-05-08-eu-ai-office-article-50-transparency
  • [S-2026-05-19-eu-ai-office-high-risk-draft] → S-2026-05-19-eu-ai-office-high-risk-draft
  • [S-2026-05-22-eu-ai-office-prohibitions-highrisk-review] → S-2026-05-22-eu-ai-office-prohibitions-highrisk-review
  • [S-2026-06-11-eu-ai-office-content-marking-code] → S-2026-06-11-eu-ai-office-content-marking-code
  • [S-2026-06-10-eu-ai-office-content-marking-code-final] → S-2026-06-10-eu-ai-office-content-marking-code-final
  • [S-2026-06-16-eu-ai-office-highrisk-consultation-status] → S-2026-06-16-eu-ai-office-highrisk-consultation-status
  • [S-2026-06-24-ec-ai-act-overview-page] → S-2026-06-24-ec-ai-act-overview-page — primary-source corroboration of the post-Omnibus high-risk timeline (2 Dec 2027 / 2 Aug 2028) and the 2 Aug 2026 GPAI/Article 50 track
  • [S-2026-06-26-ec-high-risk-guidelines-page] → S-2026-06-26-ec-high-risk-guidelines-page — primary retrieval of the high-risk classification guidelines page; bears on the 23 June vs 23 July consultation-deadline question (with a 19 May “last update” staleness caveat)
  • [S-2026-07-01-ec-highrisk-consultation-extension-confirmed] → S-2026-07-01-ec-highrisk-consultation-extension-confirmed — primary retrieval of the Commission consultation page; confirms the deadline extension to 23 July 2026 and end-2026 adoption, resolving the standing tension
  • [S-2026-06-28-tanium-agentic-default-tiers] → S-2026-06-28-tanium-agentic-default-tiers — Tanium/AIGI secondary analysis (low authority); source of the contested “August 2026 high-risk deadline” claim recorded under Tensions
  • [S-2026-07-07-ec-ai-cybersecurity-action-plan] → S-2026-07-07-ec-ai-cybersecurity-action-plan — Commission Action Plan on Cybersecurity and AI (high authority); operationalises the Act’s advanced-model evaluation requirement via an EU evaluation capacity and ENISA/JRC testing platform
  • [S-2026-06-29-council-ai-omnibus-final-adoption] → S-2026-06-29-council-ai-omnibus-final-adoption — Council of the EU press release (high authority, primary); final adoption of the Digital Omnibus on AI (Omnibus VII) on 29 June 2026; resolves the formal-adoption question and supersedes the 2 Aug 2026 sandbox deadline (now 2 Aug 2027), adds the 2 Dec 2026 transparency deadline and the financial-institutions AI Office competence carve-out
  • [S-2026-07-20-eu-ai-office-transparency-guidelines] → S-2026-07-20-eu-ai-office-transparency-guidelines — Commission news item / Guidelines (high authority, primary); final published Guidelines clarifying the scope of the Article 50 transparency obligations for providers and deployers, 20 July 2026, ahead of the 2 Aug 2026 applicability date; advances the 8 May 2026 draft-stage transparency entry
  • [S-2026-07-31-ec-ai-act-enforcement-begins] → S-2026-07-31-ec-ai-act-enforcement-begins — Commission press release (high authority, primary), 31 July 2026; confirms AI Office + national-authority enforcement and Article 50 transparency obligations commenced 2 August 2026, with interactive-AI disclosure, deep-fake labelling and machine-readable marking now live, and 180+ signatories to the voluntary content-transparency Code of Practice
  • [S-2026-08-25-credo-eu-omnibus-playbook] → S-2026-08-25-credo-eu-omnibus-playbook — vendor (Credo AI) Omnibus playbook; low authority; entry-into-force date now confirmed by S-2026-08-13-ec-ai-office-page-omnibus-in-force; prohibitions claim still unverified
  • [S-2026-08-13-ec-ai-office-page-omnibus-in-force] → S-2026-08-13-ec-ai-office-page-omnibus-in-force — Commission European AI Office policy page (high authority, primary; page last updated 13 Aug 2026, retrieved 8 Sep 2026); states the AI Omnibus entered into force 27 July 2026 (OJ L 2026/1744) and that the AI Office is recruiting ~40 enforcement staff
  • [S-2026-08-31-ec-dsa-chatgpt-vlose-designation] → S-2026-08-31-ec-dsa-chatgpt-vlose-designation — Commission press release / news item (high authority, primary; narrow scope), 31 Aug 2026; ChatGPT designated a VLOSE under the DSA (Reddit, Roblox VLOPs), compliance by January 2027; DSA measure, recorded here for regulatory layering on GPAI-based services