X OX-00 OX-00 guides ← OX-00 home
OX-00 guide · EU AI Act deadlines

Every EU AI Act deadline agencies actually face (post-Omnibus, verified August 2026)

Published August 2026 · Written for EU digital-agency owners · Verified against Regulation (EU) 2024/1689 as amended by the Digital Omnibus, Regulation (EU) 2026/1744

Quick status check for anyone planning Q4 2026:

The myth this page corrects

For months, agency forums have run two contradictory lines: “the AI Act got postponed across the board” and “the heavy deadlines already hit.” Both are wrong, and each costs money in opposite directions — one produces panic re-planning around dates that moved, the other false comfort around dates that didn’t.

The facts, verifiable against the regulation itself (Regulation (EU) 2024/1689, Art. 113 application schedule, as amended by the Digital Omnibus, Regulation (EU) 2026/1744):

Deadlines by obligation — who each binds, current status

“Who it binds” matters more than the calendar. The Act distinguishes providers (who develop or place systems on the market) from deployers (who use systems under their own authority). Most agencies sit in the deployer seat for chatbots, generative tools, and published AI content — unless they white-label an AI system under their own brand, which can shift you toward provider duties for that product. Where you act “to the extent” as a provider or deployer, that partial role follows the same dates as the full one.

ObligationApplies / bitesBindsStatus · Aug 2026
Art. 5 — prohibited practices (manipulation, social scoring, untargeted facial scraping…) 2 Feb 2025 Everyone supplying, using, or importing such systems Live
Art. 4 — AI literacy: staff-level understanding of the AI tools your business uses 2 Feb 2025 Providers & deployers In force · enforcement activated 2 Aug 2026
Art. 50(1) — tell people when they’re talking to an AI system (chatbots, voice agents) 2 Aug 2026 Providers & deployers Live
Art. 50(4) — disclose AI-generated or manipulated image/audio/video constituting deep fakes; parallel disclosure for public-interest text 2 Aug 2026 Deployers publishing or circulating such content Live
Art. 50(3) — inform people exposed to emotion-recognition or biometric-categorisation systems 2 Aug 2026 Deployers of such systems Live
Art. 50(2) — mark synthetic content in machine-readable form (automated detection tooling) 2 Dec 2026 Providers of generative systems Grace period ends
Annex III high-risk regime (biometrics, critical infrastructure, employment screening, credit scoring…) 2 Dec 2027 Providers & deployers of listed systems Deferred — not yet binding
High-risk AI embedded in regulated products (machinery, toys, medical devices…) 2 Aug 2028 Providers & deployers Deferred — not yet binding

What is live versus deferred — and why agencies should care about the split

The Omnibus deferral bought time only for the heavy compliance regimes: Annex III high-risk conformity work, and the embedded-products wave behind it. Nothing about chatbot disclosure, synthetic-content labeling, or staff AI literacy moved. If your agency runs client chatbots, publishes AI-assisted images or video, or briefs journalists and newsletters with generated copy, your exposure dates are already here — not in 2027.

Live today (no further transition)

Still deferred

One date sits between the two groups: Art. 50(2) machine-readable marking, whose transition ends 2 Dec 2026. It binds providers of generative systems — but agencies selecting vendors should already ask those vendors how they comply, because your clients may ask you the same question.

Common misinformation, corrected

  1. “The Omnibus postponed everything.” No. Regulation (EU) 2026/1744 deferred specific regimes (Annex III high-risk to Dec 2027; embedded high-risk to Aug 2028). Arts. 4, 5, and 50 kept their original dates: Feb 2025 and Aug 2026 respectively.

  2. “Chatbot disclosure is a 2027 problem.” No. Art. 50(1) has been live since 2 August 2026. A client-facing chatbot without AI disclosure is a present-tense gap, not a future one.

  3. “AI literacy was quietly cancelled.” No. Art. 4 still applies, and its enforcement was activated on 2 August 2026. It is one of the cheapest obligations to satisfy — documented staff training on the tools you actually use.

  4. “High-risk rules already apply to HR-tech clients.” Not yet: Annex III obligations bite at 2 Dec 2027. Planning should start now for affected clients, but no Annex III duty is enforceable today.

  5. “Machine-readable watermarking was dropped.” No. Art. 50(2) stands, with its own transition ending 2 December 2026. Visible labels alone do not discharge the marking expectation.

  6. “SMEs are exempt.” No exemption exists from these duties. What exists is a proportionality principle and a lower penalty cap for SMEs and small mid-cap enterprises — lighter sanctions, identical obligations.

What to do with this list

Not sure where your agency actually stands?

Run the free OX-00 self-score: ten questions, two minutes, and you get a readiness rating mapped to the exact dates above — plus pointers on the gaps that matter before 2 Dec 2026. When you want the gaps turned into a prioritized fix list with evidence templates, that's the paid packet.

Take the free AI-readiness self-score →

Prefer a done-for-you version? Our AI Act Ready packet delivers checklists, gap lists, and templates within 72 hours.