What changed for AI compliance in 2026

Sergiy Barbashyn Managing Partner at Barbashyn Law Firm
9 September, 2026 5 minutes to read
9 September, 2026 5 minutes to read

On 27 July 2026, Regulation (EU) 2026/1744 – the AI Omnibus – entered into force. It had long been anticipated by the legal and compliance teams of companies subject to the AI Act. One of its key changes is the postponement of the deadlines for applying certain requirements to high-risk AI systems.

For businesses, this raised a practical question: does the postponement of the high-risk deadlines mean that active preparations for the AI Act can be put on hold until 2027? That would be a mistake.

The AI Omnibus postponed the deadlines for a specific set of high-risk requirements, but it did not suspend the application of the AI Act as a whole. Some requirements are already applicable, including those relating to transparency, GPAI models and AI literacy.

For businesses, therefore, 2026 is not a pause in compliance. It is a period in which to determine which requirements already apply and which ones require preparation well in advance.

What the AI Omnibus actually changed — and what it left unchanged

The main change introduced by the AI Omnibus is the new timeline for high-risk AI. For high-risk systems in specified areas, including recruitment, credit scoring, biometrics and critical infrastructure, the relevant requirements will begin to apply on 2 December 2027. For high-risk AI used in regulated products, they will apply from 2 August 2028.

But this does not mean that the AI Act can be disregarded until those dates. Other requirements are already applicable.

  • Transparency. The requirements of Article 50 apply from 2 August 2026. Depending on how AI is used, users must be informed when they are interacting with AI or when content has been generated or modified using AI. For certain generative AI systems that were already on the market before that date, a transitional period applies until 2 December 2026.
  • GPAI models. The rules for providers of general-purpose AI models have applied since 2 August 2025. From 2 August 2026, the Commission may monitor compliance and take the measures provided for under the AI Act. For models that were already on the market before 2 August 2025, a transitional period applies until 2 August 2027.
  • AI literacy. The AI literacy requirements also continue to apply. Providers and deployers must take measures to ensure an appropriate level of knowledge and skills among individuals working with AI systems, taking into account their experience, technical knowledge and the context in which AI is used. Following the Omnibus, this requirement has become more flexible: companies are no longer expected to guarantee a specific level of AI literacy for every individual employee.
  • Prohibited practices. The main prohibitions under the AI Act have applied since 2 February 2025. The AI Omnibus introduced additional prohibitions concerning the creation or manipulation, using AI, of realistic intimate images, videos or audio of a person without their consent, as well as child sexual abuse material. These new prohibitions will apply from 2 December 2026.

The postponement of the AI Act deadlines also does not affect other legal frameworks. Where AI processes personal data, works with content, is used in relation to employees or interacts with consumers, the GDPR, IP, employment and consumer protection laws may apply in parallel.

At the same time, the Commission is gradually providing more detail on how these rules should be applied in practice. The final Guidelines on transparency obligations under Article 50 have already been published, while the Guidelines on the classification of high-risk systems remain in draft as of August 2026.

In other words, the AI Omnibus has given businesses more time to prepare for the high-risk regime. But it has not created a period in which AI compliance can simply be put on hold.

¹ Regulation (EU) 2026/1744, signed on 8 July 2026, published on 24 July 2026 and entering into force on 27 July 2026: Regulation (EU) 2026/1744

² Commission Guidelines on Article 50, published on 20 July 2026: Commission Guidelines on Article 50

Where AI compliance begins: understanding where your company uses AI

The most common situation we encounter in practice is that a company knows its employees use ChatGPT, Claude or other AI tools, but does not have a complete picture of where they are used, for which tasks and with what data.

AI is now embedded in far more places than it may seem. A CRM with predictive scoring. An HR platform that ranks candidates. A marketing tool that generates A/B tests. A meeting transcription service that processes client negotiations. An in-house SaaS product that integrates a GPAI model via API. All of these may involve AI functionality, and each one requires a closer look.

Scenario 1. Employees use generative AI for everyday tasks

The team uploads contracts for analysis, candidate CVs and client briefs to ChatGPT or another generative AI tool. Before deciding whether to prohibit or allow such use, several questions need to be answered: What data is being entered? Does it include personal data or confidential client information? What are the provider’s terms regarding training the model on input data? Who reviews the AI output before it is used? Without answers to these questions, any AI policy remains merely a declaration.

The minimum set of information to collect for each AI tool includes: the tool and its provider; the purpose of use; who in the company uses it; what data is submitted; and how the output is used in practice. This is not a bureaucratic requirement. It is what enables a company to answer questions from its legal team, auditors, regulators or a client asking about its AI practices as part of due diligence.

An AI inventory or register is a practical governance tool, not a mandatory document for every company without exception. But even a basic lack of understanding of where AI is being used is already a risk, regardless of whether the company is a provider or a deployer.

Classification: high-risk is only the beginning of the legal analysis

The first mistake in approaching AI compliance is to reduce the analysis to a single question: “Is it high-risk or not?” A “no” answer does not mean that no obligations apply.

A full analysis of a particular AI system involves several questions in sequence. What exactly are we dealing with — an AI system, a GPAI model or a system built on GPAI? What is the company’s role or roles under the AI Act: provider, deployer or, where applicable, downstream provider? What is the intended purpose, and does the AI Act apply territorially? Do the transparency requirements under Article 50 apply? Only then should the question of whether the high-risk regime may apply be considered.

Other legal frameworks may apply alongside the AI Act. The GDPR — if the system processes personal data. Copyright and IP law — if third-party content is used or new content is generated. Employment law and anti-discrimination rules — if AI is used in HR. Consumer protection law — if the system interacts with end users. Cybersecurity requirements — depending on the sector and type of data.

Scenario 2. Customer-facing chatbot or SaaS using GPAI via API

The company launches a customer service chatbot or integrates a third-party GPAI model into its SaaS. From 2 August 2026, Article 50 applies. If the company is a provider of a system intended for direct interaction with people, users must be informed that they are interacting with AI, unless this is obvious to a reasonably well-informed, observant and circumspect person. At the same time, questions arise about the company’s role, what customer data is transmitted to the model and on what terms, and what the provider’s terms say about training on input data. Each of these questions needs to be answered before launch.

Scenario 3. AI in recruitment or personnel management

The company uses AI for initial CV screening, candidate assessment or employee performance evaluation. These are among the scenarios that the AI Act potentially classifies as high-risk. But not every AI-enabled HR tool is automatically high-risk — what matters is the system’s intended purpose and how it affects decisions concerning a candidate or employee. Employment and anti-discrimination laws must also be considered separately, as they apply regardless of the system’s classification under the AI Act.

What AI governance looks like inside a company

AI compliance is not a folder of documents. It is about answering a fundamental question: who decides which AI is used, how it is used and by whom?

In most companies, there is no clear process for making these decisions. Individual employees connect new tools, upload work materials and generate outputs without any review. This is “shadow AI” — a typical risk for organisations without a clear framework.

Basic AI governance involves several elements. First, rules of use: what is permitted, what is prohibited, which data may be shared with AI systems and which may not. Second, a process for approving new tools and new use cases. Third, an appropriate level of human review depending on the consequences: an AI recommendation for an internal report and an AI-generated decision affecting a client or employee require different levels of scrutiny. Fourth, a clear allocation of responsibility: who in the company is responsible for AI compliance — legal/compliance, privacy/DPO, IT, HR or product? The answer “everyone together” usually means “no one”.

AI literacy is not a single lecture for everyone. Following the Omnibus, Article 4 of the AI Act requires providers and deployers to “take measures to support the development of AI literacy”, taking into account the technical knowledge, experience and context of the individuals concerned. For a lawyer using AI to analyse contracts, this means one level of knowledge and skills. For a product manager integrating GPAI via API, it means another.

Documentation is a separate issue. Depending on the system and the company’s role, an AI register, AI Use Policy, classification/risk assessment, vendor due diligence, transparency notice, DPIA or FRIA, AI literacy records and incident handling procedures may be needed. But not every one of these documents is a mandatory legal requirement for every AI system. Some are expressly required by law only in specific circumstances; others are compliance practices that reduce risk and make future audits easier.

Compliance does not end once AI is launched

AI compliance should not be treated as a one-off project. Conducting an audit, preparing documentation and establishing internal rules is not enough if the system, the way it is used or the applicable regulatory requirements subsequently change.

A reassessment may be necessary, for example, if the AI system’s intended purpose or use case changes, the underlying model or provider is replaced, new functionality or an integration is added, or data flows or the level of human review change. Incidents, complaints, data breaches, changes to provider terms or new regulatory requirements are also important triggers for review.

The Commission has already launched several tools to support the practical application of the AI Act. The AI Act Service Desk provides information and guidance on applying the AI Act, the Single Information Platform brings official materials together in one place, and the EU AI Act Compliance Checker helps conduct an initial assessment of applicable requirements. As of August 2026, the Compliance Checker is available in beta, and its results are informational and do not constitute an official assessment of a specific AI system.

Alongside official tools, professional approaches to AI governance and auditing are also developing. In particular, AIEI (AI Ethics and Integrity International Association) is developing principles, assessment tools and AI audit methodologies that may complement companies’ internal compliance processes where regulatory requirements have not yet been fully detailed.

AI governance therefore requires not only an initial classification and the preparation of documents, but also regular reviews of how AI is actually used within the company and which requirements apply to it.

What to do in 2026–2027: a practical roadmap

Below are several practical steps businesses can take to begin preparing now.

  • Conduct an AI inventory: identify which AI systems and AI functionalities are actually being used across the company — including AI embedded in SaaS, CRM and HR tools, not just obvious generative AI applications.
  • Determine the company’s role in relation to each system: whether it acts as a provider or deployer, or, where applicable, a downstream provider, and conduct an initial classification under the AI Act.
  • Check compliance with requirements that already apply, including transparency obligations, personal data and confidentiality rules, IP requirements and the terms of contracts with AI providers.
  • Establish internal rules: who approves new AI tools, what data may be shared with AI, and what level of human review is required depending on how the system is used and the potential consequences.
  • Allocate responsibility: define specific roles for legal/compliance, privacy, IT and business functions, depending on the company’s structure.
  • Start preparing early for potentially high-risk systems: determine which requirements will apply to the specific system and the company’s role, conduct a gap assessment, and plan the necessary changes to processes and documentation. For high-risk systems listed in Annex III, the relevant requirements will begin to apply on 2 December 2027.
  • Plan for regular reviews: reassess AI systems when their intended purpose, functionality, model, provider, data flows or regulatory requirements change.

The biggest mistake after the AI Omnibus would be to interpret the postponement of the high-risk deadlines as permission to do nothing until 2027. That is not the case. Some requirements already apply. Others require preparation, with less than a year and four months remaining before the relevant deadline.

AI compliance is not a box-ticking exercise of “high-risk / not high-risk”. It is a system through which a company knows what AI it uses, who is responsible for it, which rules apply — and can demonstrate this. Building such a system now is considerably easier than doing so under regulatory pressure.

 

Published in Yurydychna Praktyka.

Article link

Share

  • Facebook
  • Twitter
  • LinkedIn

We use cookies to improve the performance of the site and enhance your user experience.

More information can be found in our Privacy Notice