Back to Guides
Guide16 September 2026

What are the key changes in the EU AI regulations for 2026?

Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.

In this guide
  1. Key takeaways
  2. What new transparency obligations take effect on 2 Aug 2026?
  3. How does the Digital Omnibus change requirements for general - purpose AI models?
  4. Which new AI applications are now prohibited?
  5. When do high - risk AI obligations start for stand - alone and embedded systems?
  6. How has the AI - literacy duty been modified?
  7. What clarification was added to the definition of a safety component?
  8. How are sector - specific AI obligations being aligned?
  9. What new provision helps with bias detection using special - category data?
  10. How are SMEs and small - mid - cap companies affected?
  11. What is the impact of the unified technical standards requirement?
  12. How does the AI Office’s enforcement power change?
  13. What timeline shift occurs for regulatory sandboxes?
  14. How does the grace period for pre - existing AI - generated content work?
  15. What should providers do next?
  16. Where can I find more detailed guidance?

Key takeaways

What new transparency obligations take effect on 2 Aug 2026?

AI systems that interact with users must now display a clear notice that the interaction is with AI, and deep - fake content must carry a label. Providers must also embed a machine - readable watermark in synthetic audio, image, video or text. Systems already on the market before 2 Aug 2026 have until 2 Dec 2026 to add the watermark.

How does the Digital Omnibus change requirements for general - purpose AI models?

From 2 Aug 2026, providers of foundation models must produce technical documentation, a public summary of training - data sources, a copyright - compliance policy, risk - management processes, incident - reporting, and for very large models, additional cybersecurity and systemic - risk checks. The European AI Office can now supervise these providers and impose fines.

Which new AI applications are now prohibited?

The amended Article 5 adds two bans that become enforceable on 2 Dec 2026: AI that creates non - consensual intimate imagery (often called “nudifier” apps) and AI that generates child sexual - abuse material. Violations can attract fines up to €35 million or 7 % of global turnover.

When do high - risk AI obligations start for stand - alone and embedded systems?

Stand - alone high - risk AI listed in Annex III must comply from 2 Dec 2027, while AI that is a safety component of products covered by sectoral legislation (Annex I) must comply from 2 Aug 2028. This gives providers an extra 16 - month and 12 - month window respectively to implement conformity - assessment, risk - management and post - market - surveillance.

How has the AI - literacy duty been modified?

The wording now requires providers and deployers to “take measures to support the development of AI literacy” rather than guaranteeing a sufficient level of competence. Documentation of training or awareness activities remains mandatory, but the burden of proving individual competence is reduced.

What clarification was added to the definition of a safety component?

AI is considered a safety component only when its intended purpose is to prevent or mitigate risks to health and safety. Uses that are purely for convenience, optimisation, or quality - control are excluded unless their failure would endanger health or safety, narrowing the scope of high - risk classification.

How are sector - specific AI obligations being aligned?

AI requirements for machinery are moved to the Machinery Regulation (EU 2023/1230) and will be integrated via delegated acts by 2 Aug 2028. This avoids duplicate conformity - assessment for AI - enabled machinery and other products.

What new provision helps with bias detection using special - category data?

Processing of special - category data is now allowed for bias detection and correction under a strict - necessity test, with mandatory safeguards such as pseudonymisation, use of synthetic data first, limited sharing, and timely deletion.

How are SMEs and small - mid - cap companies affected?

The simplified compliance regime now also covers small - mid - cap companies (≤ 750 employees, ≤ €150 million revenue). Documentation and technical - file requirements are proportionally reduced, lowering compliance costs for a larger set of innovators.

What is the impact of the unified technical standards requirement?

The Commission must commission single harmonised standards that satisfy both the AI Act and relevant sectoral legislation. The first such standard, EN 18286 on Quality - Management Systems, was published in July 2026, allowing one conformity - assessment process for high - risk AI that also meets product - safety rules.

How does the AI Office’s enforcement power change?

From 2 Aug 2026 the AI Office has exclusive supervision of GPAI model providers and can also supervise AI systems embedded in very large online platforms regulated by the DSA. It can request documentation, conduct on - site inspections, order corrective measures and impose fines.

What timeline shift occurs for regulatory sandboxes?

The deadline for national sandboxes moves from 2 Aug 2026 to 2 Aug 2027, and an EU - level sandbox may be created for high - risk AI, giving innovators more time to test borderline AI under supervised conditions.

How does the grace period for pre - existing AI - generated content work?

AI systems placed on the market before 2 Aug 2026 must implement the machine - readable watermark by 2 Dec 2026, providing a limited retro - fit window to avoid immediate disruption.

What should providers do next?

  1. Audit your AI systems for user - notice and watermark capabilities and implement them before the 2 Aug 2026 deadline.
  2. Compile the required technical documentation for any foundation models you provide.
  3. Review your product catalog for the newly prohibited uses and remove any non - compliant features.
  4. Adjust your high - risk compliance roadmap to the new 2027/2028 deadlines.
  5. Document AI - literacy activities and verify eligibility for SME/SMC simplifications.
  6. Monitor the rollout of EN 18286 and align your quality - management processes accordingly.

Where can I find more detailed guidance?

The European Commission’s digital strategy page and the cited law - firm briefs provide the official text and interpretive guidance. For practical implementation steps, consult the EU AI Act amendment summaries linked in the evidence table.

Free security scan

See what's actually exposed on your site.

Decloak's free scan runs in about 15 seconds, no account required, and covers:

  • HTTP/TLS security posture
  • JavaScript CVEs
  • Exposed Supabase/Lovable/Base44 misconfigurations
  • AI-written executive summary