The AI Act after the Digital Omnibus
The AI Act was due to apply in large part from 2 August 2026. Nine days before that date, an amending regulation pushed the requirements for high-risk AI systems back to December 2027 and August 2028. What did take effect are the transparency obligations: chatbots must identify themselves as AI, and generated material must be marked in a machine-readable format.
Transparency obligations apply from 2 August 2026
Article 50 of the AI Act applies from 2 August 2026. Providers must design systems that interact directly with natural persons in such a way that those persons are aware they are dealing with an AI system. Artificially generated or manipulated audio, images, video and text must be marked in a machine-readable format and be detectable as such. Deployers of emotion recognition or biometric categorisation systems must inform the persons exposed to such systems about how the system operates.
The new Article 111(4) eases this for existing systems. Providers of AI systems generating synthetic audio, images, video or text that were placed on the market before 2 August 2026 have until 2 December 2026 to comply with the marking obligation in Article 50(2).
When AI-written text must be disclosed
Paragraph 4 addresses the deployer, and so reaches the party doing the publishing. Anyone who publishes a deepfake must disclose that the material has been artificially generated or manipulated. Anyone who publishes AI-generated or AI-edited text to inform the public on matters of public interest must disclose that as well. That second duty does not apply where the text has undergone a process of human review or editorial control and a natural or legal person bears editorial responsibility for its publication. Under paragraph 5, any such disclosure must be clear and distinguishable no later than the point of first exposure.
High-risk requirements move to 2027 and 2028
The amended Article 113 sets two separate dates. The requirements in Chapter III, Sections 1 to 3 apply from 2 December 2027 to systems classified as high-risk under Article 6(2) and Annex III. For systems falling under Article 6(1) and Annex I, the date becomes 2 August 2028. The postponement is confined to those three Sections. Article 6(5) is expressly carved out and therefore does apply.
The distinction between the two Annexes determines which date applies. Annex III lists standalone applications across eight domains, including recruitment and employee evaluation, creditworthiness assessment, pricing of life and health insurance, education, law enforcement and the administration of justice. Annex I covers AI as a safety component in products already governed by European product legislation, such as machinery and medical devices. The postponement works out differently for each. Annex III systems fell under the general date of 2 August 2026 and are pushed back by sixteen months. Annex I systems were already set at 2 August 2027 in the original Article 113 and gain a further twelve months.
A broader transitional regime applies to systems already in operation. The rewritten Article 111(2) subjects existing high-risk systems to the AI Act only once they undergo significant changes in their designs. Recital 39 clarifies that a single unit lawfully placed on the market suffices: other units of the same type and model may continue to be placed on the market without additional certification, as long as the design remains unchanged. For systems intended to be used by public authorities, a hard deadline of 2 August 2030 applies.
| Date | What becomes applicable |
|---|---|
| 2 February 2025 | Prohibited practices (Article 5) and AI literacy |
| 2 August 2025 | General-purpose AI models, governance, penalties, notified bodies |
| 27 July 2026 | Regulation 2026/1744 enters into force; amendments to other Union legislation (Articles 102 to 110) |
| 2 August 2026 | Transparency obligations (Article 50), supervision and remedies (Chapter IX) |
| 2 December 2026 | New prohibitions on sexual deepfakes; marking obligation for existing generative AI |
| 2 August 2027 | National AI regulatory sandboxes operational |
| 2 December 2027 | Requirements for high-risk systems under Annex III (Article 6(2)), including Article 25 |
| 2 August 2028 | Requirements for high-risk systems under Annex I (Article 6(1)) |
| 2 August 2030 | High-risk systems used by public authorities |
The omnibus also narrows what counts as high-risk
Alongside the postponement, the amending regulation contains a substantive narrowing that has drawn less attention. The concept of a safety component in Article 3(14) has been redefined. A component now performs a safety function only where its intended purpose is to prevent or mitigate risks to the health and safety of persons or property. That intended purpose is determined by the provider.
The new Article 6(1a) spells this out. AI systems used solely for non-safety related aspects of user assistance, performance optimisation, service efficiency, automation, convenience or quality control do not qualify as safety components. Recital 7 adds that the mere fact that an AI system is integrated into a product covered by Union harmonisation legislation does not in itself mean that it performs a safety function.
There is an exception to this. Article 6(1b) provides that systems whose failure or malfunctioning would endanger health and safety do qualify as safety components. The narrowing therefore turns on the purpose for which a system is deployed, while the consequences of a malfunction remain a separate test.
The AI literacy obligation in Article 4 has also been relaxed. Where the original text required providers and deployers to ensure, as far as possible, a sufficient level of AI literacy, the new text requires only measures to support its development. It adds that the obligation does not entail guaranteeing any particular level of AI literacy. The obligation itself has existed since 2 February 2025 and affects every organisation deploying AI, whatever the risk classification. The relaxed wording applies from 27 July 2026.
Becoming a provider through a substantial modification
Article 25 governs when a customer becomes a provider in its own right, with all the obligations under Article 16. This happens in three cases. The first is putting one's own name or trademark on a system already placed on the market, unless the obligations have been allocated differently by contract. The second is a substantial modification after which the system remains high-risk. The third is modifying the intended purpose of a system, including a general-purpose AI system, so that it becomes high-risk.
The second and third cases can arise without the customer noticing. An organisation that configures a general-purpose language model to screen job applicants brings that model within Annex III and becomes a provider. Under Article 3(23), a substantial modification is a change that the provider did not foresee or plan in the initial conformity assessment and which either affects compliance with the requirements in Chapter III, Section 2 or results in a modification of the intended purpose for which the system was assessed. Article 43(4) requires a fresh conformity assessment in that event, with an exception for systems that continue to learn: changes predetermined by the provider and included in the technical documentation do not count.
Regulation (EU) 2026/1744 has rewritten Article 25(2). The initial provider is no longer regarded as the provider of that system, but acquires an explicit duty to cooperate: technical documentation sufficient to assess compliance with Article 16, information on known limitations and failure modes, and targeted technical access for testing and validation. That duty does not apply where the initial provider has clearly specified that its system is not to be converted into a high-risk system. Paragraph 4 further requires a written agreement with upstream suppliers, with an exception for free and open-source components that are not general-purpose AI models.
New prohibitions on sexual deepfakes apply from December
Article 5(1) now prohibits the placing on the market, the putting into service and the use of AI systems that generate or manipulate realistic images, video or audio of an identifiable person's intimate parts, or of that person engaged in sexually explicit activities, without their freely given, specific, informed and explicit consent. A second prohibition covers material within the meaning of the directive on combating child sexual abuse.
The scope is narrowly drawn. For providers, the prohibition applies only where generating such material is the intended purpose of the system, or where it is a reasonably foreseeable and reproducible outcome without significant technical modification while the system lacks reasonable safeguards. For deployers, it applies only where the system is used for that purpose. Both prohibitions take effect on 2 December 2026 and sit on top of the disclosure duty in paragraph 4: material caught by them may not be generated or used at all, even if it is labelled as artificial. Recital 16 notes that they are without prejudice to the remedies available under national law to protect fundamental rights, including rights to one's image, privacy and human dignity.
Why the postponement arrived nine days before the deadline
Regulation (EU) 2026/1744 of 8 July 2026 amends the AI Act, the aviation safety regulation and the machinery regulation. It was published in the Official Journal on 24 July 2026 and entered into force on the third day thereafter. Article 4 provides for no deferred application: the amendment applies in full from 27 July 2026.
The legislative process took just under eight months. The Commission presented the proposal on 19 November 2025 as COM(2025) 836, part of a broader digital package. Following opinions from the European Central Bank, the European Economic and Social Committee (18 March 2026) and the Committee of the Regions (7 May 2026), the European Parliament adopted its position on 16 June 2026, after which the Council took its decision on 29 June 2026.
Recital 40 gives the reason. Harmonised standards, common specifications and alternative guidance became available too late, and the national competent authorities were designated too late. That combination would drive compliance costs up to a point where, in the legislator's assessment, maintaining the original date could not be justified.
The Netherlands has yet to adopt its implementing act
The AI Act applies directly, but supervision has to be organised nationally. Article 70(2) required Member States to make public by 2 August 2025 how the competent authorities can be contacted. Article 99(1) required them to lay down rules on penalties by that same date and notify them to the Commission, with maximum fines of €35 million or 7% of worldwide annual turnover for prohibited practices and €15 million or 3% for other infringements.
The Dutch bill is still in preparation. The AI Act Implementation Act (Uitvoeringswet AI-verordening) was open for public consultation from 20 April to 1 June 2026 and drew thirty responses. It designates ten existing market surveillance authorities, with the Dutch Data Protection Authority (AP) and the Dutch Authority for Digital Infrastructure (RDI) as coordinators and a single point of contact. Until that act enters into force, the obligations apply but the national framework enabling an authority to enforce them is absent.
What does this mean for businesses operating in the Netherlands?
Any organisation deploying a chatbot or publishing generated content has fallen under Article 50 since 2 August 2026. This affects considerably more organisations than the high-risk regime, and the obligation is concrete enough to check now. Does the system identify itself as AI, and is generated material marked in a machine-readable format? Anyone publishing AI-assisted text that informs the public would do well to record the human review and the editorial responsibility, because the exception in paragraph 4 rests on both.
For high-risk applications it is worth continuing the inventory rather than suspending it, and to test that inventory against the new definition of a safety component. Systems previously caught by Annex I because they formed part of a regulated product may now fall outside it. The transitional regime in Article 111(2) also rewards placing a system on the market in good time and catches systems as soon as the design changes significantly.
One point of overlap remains unresolved. The right to an explanation of individual decision-making in Article 86 sits in Chapter IX and was left untouched by the amending regulation. It applies from 2 August 2026, whereas the classification provision it refers to only becomes applicable in December 2027. Whether an affected person can invoke that right in the intervening period will have to be settled in proceedings. There is no Dutch case law on the AI Act yet: what exists on automated decision-making runs through the GDPR, such as the Uber and Ola rulings handed down by the Amsterdam Court of Appeal on 4 April 2023.
When it comes to contracting, the postponement is no reason to wait. Article 25 takes effect on 2 December 2027, while multi-year contracts concluded now run straight through that date. The AI Act leaves three points to be settled by contract: the exception for name and trademark in paragraph 1, the statement by which a supplier excludes conversion into a high-risk system in paragraph 2, and the content of the written agreement in paragraph 4. The postponement shifts the dates, but the choices now fixed in design, documentation and contracts determine where an organisation stands in December 2027.
Frequently asked questions
Does the AI Act apply from 2 August 2026 or not?
It applies, but not in full. The transparency obligations in Article 50 and the provisions on supervision and remedies apply from that date. The requirements for high-risk systems have moved to 2 December 2027 and 2 August 2028, depending on the basis for the classification.
Must a chatbot disclose that it is an AI system?
Yes. Article 50(1) requires providers to ensure that persons interacting directly with an AI system are informed of this, unless it is obvious from the point of view of a reasonably well-informed, observant and circumspect person. That obligation applies from 2 August 2026 and there is no transitional period for existing systems.
Must you disclose that a text was written with AI?
Only where the text is published to inform the public on matters of public interest. Article 50(4) provides an exception: no disclosure is required where the text has undergone a process of human review or editorial control and a natural or legal person bears editorial responsibility for its publication.
Can modifying an AI system make you its provider?
It can. Article 25 treats a party that makes a substantial modification, or alters the intended purpose so that the system becomes high-risk, as the provider, with the obligations under Article 16. A change the original provider foresaw and recorded in the technical documentation does not count.
Cited case law
Courts of appeal
- Court of Appeal of Amsterdam 4 April 2023, ECLI:NL:GHAMS:2023:796 — scope of the right to information under Article 15(1)(h) GDPR where automated decision-making within the meaning of Article 22 GDPR is at issue, applied to Uber's batched matching and upfront pricing systems and to the calculation of average ratings.
- Court of Appeal of Amsterdam 4 April 2023, ECLI:NL:GHAMS:2023:804 — the same right to information applied to Ola's fraud probability score, its earning profile and the allocation of rides to drivers.