The EU AI Act in 2026: what businesses need to do now

The EU AI Act has been amended by the AI Omnibus. Which rules already apply, what has been postponed, and what does it mean for companies using AI in their processes?

The EU Artificial Intelligence Act has been in force since 1 August 2024 and applies in phases. In July 2026 it was amended by the so-called AI Omnibus, which moved some of the deadlines. This article sets out what applies now and what your business practically needs to do.

This article is a general explanation, not legal advice. Consult a lawyer for your specific situation.

The timeline at a glance

Date What
1 August 2024 AI Act enters into force
2 February 2025 Prohibited AI practices and the AI literacy duty apply
2 August 2025 Rules for providers of general-purpose AI models (such as large language models)
2 August 2026 Transparency obligations (Article 50) apply
2 December 2027 Rules for stand-alone high-risk AI systems (Annex III), postponed by the Omnibus
2 August 2028 High-risk AI in regulated products (Annex I), postponed by the Omnibus

The AI Omnibus entered into force on 27 July 2026. Its main effect: the strictest rules for high-risk AI have been postponed by more than a year. The transparency rules were not postponed and have applied since 2 August 2026.

What applies now

Prohibited practices. Some uses of AI are simply not allowed, such as social scoring, manipulative techniques that exploit vulnerabilities and certain forms of emotion recognition in the workplace. For most companies automating processes this is not relevant, but it is worth checking once.

AI literacy. Companies using AI must take measures to support the AI literacy of their staff. The Omnibus softened this slightly: the duty is to support a sufficient level of knowledge, not to guarantee it. In practice: make sure people working with an AI system know what it does, where it can go wrong and when to step in.

Transparency. Since 2 August 2026, people must know when they are dealing with an AI system, for example a chatbot on your website. AI-generated content such as images, audio and video must be recognisable as such.

What comes later: high-risk AI

High-risk AI covers uses with a major impact on people, such as AI that helps decide on job applicants, creditworthiness, access to education or essential services. These systems will face heavy requirements on risk management, data quality, documentation, human oversight and registration.

Because of the Omnibus, these requirements apply to most such systems from 2 December 2027. Postponed is not cancelled. Anyone building or using such systems would do well to get the basics in place now.

What does this mean for process automation?

The good news: most automations in business processes are not high-risk. An AI that reads invoices, sorts email or prepares quotes is usually a limited-risk use. The general rules do apply:

  1. Inventory which AI systems you use, including AI built into existing software.
  2. Classify the risk of each use. In doubt? Have it assessed.
  3. Be transparent with customers when they interact with AI.
  4. Organise human oversight for decisions that affect people.
  5. Train your team so they know what the system does and when to step in.
  6. Document what the system does, with which data and who is responsible.

Fines

The AI Act carries significant fines. Using prohibited AI practices can cost up to 35 million euros or 7 percent of global annual turnover. For most companies the risk is mainly practical: customers, partners and tenders increasingly ask you to show that you use AI responsibly.

How we help

For every automation Nuraghi Cloud builds, we carry out a risk classification under the AI Act up front and deliver the matching documentation. So you know exactly where you stand, even as the rules are filled in further over the coming years. Questions? Get in touch.

Sources