Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.
In this guide
- Key takeaways
- What new transparency obligations take effect on 2 Aug 2026?
- How does the Digital Omnibus change requirements for general - purpose AI models?
- Which new AI applications are now prohibited?
- When do high - risk AI obligations start for stand - alone and embedded systems?
- How has the AI - literacy duty been modified?
- What clarification was added to the definition of a safety component?
- How are sector - specific AI obligations being aligned?
- What new provision helps with bias detection using special - category data?
- How are SMEs and small - mid - cap companies affected?
- What is the impact of the unified technical standards requirement?
- How does the AI Office’s enforcement power change?
- What timeline shift occurs for regulatory sandboxes?
- How does the grace period for pre - existing AI - generated content work?
- What should providers do next?
- Where can I find more detailed guidance?
Key takeaways
- Mandatory user notice and machine - readable watermark for AI - generated content start 2 Aug 2026 (grace period until 2 Dec 2026 for existing systems).
- General - purpose AI models face full documentation, risk - management and cybersecurity duties from 2 Aug 2026.
- New prohibited practices ban non - consensual intimate imagery and AI - generated CSAM, enforceable 2 Dec 2026.
- High - risk AI compliance deadlines are pushed to late 2027 and 2028, giving providers extra time.
- AI - literacy duty is softened, SME/SMC relief expanded, and a single harmonised standard pathway introduced.
What new transparency obligations take effect on 2 Aug 2026?
AI systems that interact with users must now display a clear notice that the interaction is with AI, and deep - fake content must carry a label. Providers must also embed a machine - readable watermark in synthetic audio, image, video or text. Systems already on the market before 2 Aug 2026 have until 2 Dec 2026 to add the watermark.
How does the Digital Omnibus change requirements for general - purpose AI models?
From 2 Aug 2026, providers of foundation models must produce technical documentation, a public summary of training - data sources, a copyright - compliance policy, risk - management processes, incident - reporting, and for very large models, additional cybersecurity and systemic - risk checks. The European AI Office can now supervise these providers and impose fines.
Which new AI applications are now prohibited?
The amended Article 5 adds two bans that become enforceable on 2 Dec 2026: AI that creates non - consensual intimate imagery (often called “nudifier” apps) and AI that generates child sexual - abuse material. Violations can attract fines up to €35 million or 7 % of global turnover.
When do high - risk AI obligations start for stand - alone and embedded systems?
Stand - alone high - risk AI listed in Annex III must comply from 2 Dec 2027, while AI that is a safety component of products covered by sectoral legislation (Annex I) must comply from 2 Aug 2028. This gives providers an extra 16 - month and 12 - month window respectively to implement conformity - assessment, risk - management and post - market - surveillance.
How has the AI - literacy duty been modified?
The wording now requires providers and deployers to “take measures to support the development of AI literacy” rather than guaranteeing a sufficient level of competence. Documentation of training or awareness activities remains mandatory, but the burden of proving individual competence is reduced.
What clarification was added to the definition of a safety component?
AI is considered a safety component only when its intended purpose is to prevent or mitigate risks to health and safety. Uses that are purely for convenience, optimisation, or quality - control are excluded unless their failure would endanger health or safety, narrowing the scope of high - risk classification.
How are sector - specific AI obligations being aligned?
AI requirements for machinery are moved to the Machinery Regulation (EU 2023/1230) and will be integrated via delegated acts by 2 Aug 2028. This avoids duplicate conformity - assessment for AI - enabled machinery and other products.
What new provision helps with bias detection using special - category data?
Processing of special - category data is now allowed for bias detection and correction under a strict - necessity test, with mandatory safeguards such as pseudonymisation, use of synthetic data first, limited sharing, and timely deletion.
How are SMEs and small - mid - cap companies affected?
The simplified compliance regime now also covers small - mid - cap companies (≤ 750 employees, ≤ €150 million revenue). Documentation and technical - file requirements are proportionally reduced, lowering compliance costs for a larger set of innovators.
What is the impact of the unified technical standards requirement?
The Commission must commission single harmonised standards that satisfy both the AI Act and relevant sectoral legislation. The first such standard, EN 18286 on Quality - Management Systems, was published in July 2026, allowing one conformity - assessment process for high - risk AI that also meets product - safety rules.
How does the AI Office’s enforcement power change?
From 2 Aug 2026 the AI Office has exclusive supervision of GPAI model providers and can also supervise AI systems embedded in very large online platforms regulated by the DSA. It can request documentation, conduct on - site inspections, order corrective measures and impose fines.
What timeline shift occurs for regulatory sandboxes?
The deadline for national sandboxes moves from 2 Aug 2026 to 2 Aug 2027, and an EU - level sandbox may be created for high - risk AI, giving innovators more time to test borderline AI under supervised conditions.
How does the grace period for pre - existing AI - generated content work?
AI systems placed on the market before 2 Aug 2026 must implement the machine - readable watermark by 2 Dec 2026, providing a limited retro - fit window to avoid immediate disruption.
What should providers do next?
- Audit your AI systems for user - notice and watermark capabilities and implement them before the 2 Aug 2026 deadline.
- Compile the required technical documentation for any foundation models you provide.
- Review your product catalog for the newly prohibited uses and remove any non - compliant features.
- Adjust your high - risk compliance roadmap to the new 2027/2028 deadlines.
- Document AI - literacy activities and verify eligibility for SME/SMC simplifications.
- Monitor the rollout of EN 18286 and align your quality - management processes accordingly.
Where can I find more detailed guidance?
The European Commission’s digital strategy page and the cited law - firm briefs provide the official text and interpretive guidance. For practical implementation steps, consult the EU AI Act amendment summaries linked in the evidence table.
Related guides
What is NIST in cybersecurity and why should you care?
NIST is the U.S. agency that creates the Cybersecurity Framework and a suite of standards like SP 800 - 53 that guide risk management for both government and private organizations.
Which NIST Cybersecurity Standards Should My Organization Adopt in 2024 - 2025?
Learn the core NIST publications that form a practical, layered security program, how they map together, and concrete steps to start using them today.
Does the EU AI Act apply to U.S. companies?
Yes - the EU AI Act has extraterritorial reach and can bind U.S. AI providers, deployers, importers or distributors whenever their systems are placed on the EU market, used by an EU entity, or produce output that is used in the Union.