Key takeaways
- The Digital Omnibus on AI entered into force on 27 July 2026.
- High-risk duties for Annex III systems now apply from 2 December 2027; for AI in Annex I regulated products, from 2 August 2028.
- Article 50 transparency obligations still applied from 2 August 2026 — with a watermarking grace period to 2 December 2026 for systems already on the market.
- Prohibited practices and general-purpose AI model obligations were already in force and were not reopened.
The timeline at a glance
The gold marker shows where we are today. Filled markers have already passed.
Regulation (EU) 2024/1689 becomes law, with obligations phased in over the following years.
Bans on unacceptable-risk practices apply, together with the Article 4 AI-literacy provision.
Obligations for providers of general-purpose AI models apply, alongside governance and penalty provisions.
Published in the Official Journal on 24 July and in force on 27 July, deferring the high-risk timetable.
Disclosure duties for AI that interacts with people and for certain AI-generated content apply as originally scheduled.
The end of the four-month grace period for marking AI-generated content from systems already on the market.
Obligations for stand-alone high-risk systems — including those used in employment, essential services and the administration of justice.
Obligations for AI embedded in products already covered by EU product-safety legislation.
What the Digital Omnibus actually changed — and why
The European Commission proposed the Digital Omnibus on AI on 19 November 2025. Its reasoning was practical: neither industry nor the European standardisation bodies (CEN and CENELEC) were likely to be ready, and the conformity-assessment infrastructure the Act assumes had not matured in time.
The result is a deferral, not a cancellation. The substance of the high-risk regime remains. What moved is when it bites. For advisers, the most common error in autumn 2026 is telling clients “the AI Act was delayed” without distinguishing the parts that were not.
The Omnibus also revisited some supporting provisions, including how the AI-literacy duty is framed. Check the consolidated text for the current wording before relying on any summary — including this one.
Who it applies to (it may include you)
The Act uses roles rather than industries. The two that matter most for lawyers are:
- Providers — those who develop an AI system, or have it developed, and place it on the market under their own name.
- Deployers — those who use an AI system under their authority in a professional capacity. A law firm using an AI tool is a deployer.
Its reach is extraterritorial. It covers deployers located in the EU, and providers and deployers outside the EU where the output of the AI system is used in the EU. A firm in London, Dubai, Lahore or New York serving EU clients should not assume it is out of scope.
The four risk tiers, briefly
| Tier | What it covers | Status |
|---|---|---|
| Unacceptable risk | Prohibited practices, such as social scoring and certain manipulative or exploitative systems | Banned since 2 February 2025 |
| High risk | Annex III uses (e.g. employment, credit, essential services, law enforcement, migration, administration of justice) and Annex I product-safety uses | Deferred to 2 December 2027 / 2 August 2028 |
| Transparency risk | Chatbots and systems generating synthetic content that must be disclosed or marked | Applies from 2 August 2026 |
| Minimal risk | Most other AI, such as spam filters or ordinary productivity tools | No specific obligations; voluntary codes encouraged |
Penalties are significant: up to €35 million or 7% of worldwide annual turnover for prohibited practices, up to €15 million or 3% for most other infringements, and up to €7.5 million or 1% for supplying incorrect information to authorities.
What it means for your own law firm
For most firms, day-to-day legal AI — drafting, summarising, research assistance — is not itself high-risk. But being a deployer still brings responsibilities and, just as importantly, client expectations. A sensible firm programme looks like this:
- Inventory the AI tools in use, including those individual lawyers adopted on their own.
- Classify each use. HR screening tools, for example, can fall into high-risk employment categories.
- Review vendor terms for data use, security certifications and the vendor’s own AI Act position.
- Be transparent where clients or the public interact with AI, such as website chatbots.
- Train people. Whatever the final framing of the literacy duty, competent use is also a professional-conduct obligation.
AI for Lawyers 2026
The EU AI Act and professional-responsibility duties alongside the tools and 100 practical prompts.
See it on AmazonAdvising clients: the questions to ask
Clients building or buying AI will ask what the delay means for them. Start with these questions:
- Are you a provider, a deployer, or both — for each system?
- Is any output of the system used in the EU?
- Does any use fall within an Annex III area? If so, is a compliance plan in place for December 2027?
- Do any systems interact with people or generate content that triggers Article 50 disclosure now?
- Do your contracts allocate AI Act responsibilities between vendor and customer?
Much of that work ends up in documents: AI-use policies, transparency notices, vendor and customer terms. For technology businesses, TECHLAWG prepares AI governance policies, disclosures and contracts, and its free policy checker is a useful first look at documentation gaps.
Outside the EU: the professional-conduct baseline
Even where the AI Act does not apply, professional rules do. In the United States, ABA Formal Opinion 512 (29 July 2024) applies existing Model Rules to generative AI across six areas: competence, confidentiality, communication with clients, candour toward the tribunal, supervision, and reasonable fees. Regulators and bar bodies elsewhere have issued comparable guidance. The practical overlap with the AI Act is large: understand your tools, protect data, tell people what they need to know, and keep a human responsible.
The most visible failure of that baseline is fabricated citations — see AI hallucinations in court for the cases and a verification checklist.
Frequently asked questions
Was the August 2026 AI Act deadline delayed?
Partly. High-risk obligations moved to 2 December 2027 (Annex III) and 2 August 2028 (Annex I). Article 50 transparency obligations still applied from 2 August 2026, with a watermarking grace period to 2 December 2026 for systems already on the market.
Does the AI Act apply to firms outside the EU?
It can, where a provider places systems on the EU market or where the output of an AI system is used in the EU.
Is using ChatGPT or Claude in a law firm “high-risk”?
Ordinary drafting and summarising generally is not. Specific uses can be, such as AI for recruitment decisions, or AI intended to assist judicial authorities in researching and applying the law.
What should a firm do first?
Inventory the AI in use, classify each use, review vendor terms, write a short policy and train people. Organisational training can cover the last step.
Brief your whole team in one session
We deliver EU AI Act and AI-ethics sessions for firms, chambers and bar associations.
Sources
- Gibson Dunn — EU AI Act Omnibus agreement: postponed high-risk deadlines and other key changes
- ComplianceHub — The EU AI Act’s August 2, 2026 deadline just moved
- Travers Smith — EU agrees to delay key AI Act compliance deadlines
- Cloud Security Alliance — High-risk deadline: deferred, not cancelled
- UNC Law Library — ABA Formal Opinion 512