
Regulation Watch: AI Act, October 2026 - what applies, what moved, what is open
Was the AI Act delayed or not? The short answer: partly, and by binding law. Here is the timeline as it stands at the start of October 2026.
The Digital Omnibus on AI is law, not a proposal
Regulation (EU) 2026/1744 of 8 July 2026, the Digital Omnibus on AI, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It is adopted, binding law that amends the AI Act.
Do not confuse it with the separate Digital Omnibus on data, GDPR and cookies. That file is still a proposal: as of 24 September 2026 there was no Council negotiating mandate, Parliament's committees were working through more than 1,750 amendments and trilogues had not started.
What applies now
Since 2 February 2025: the prohibited practices (Article 5) and the AI literacy duty (Article 4). The omnibus reworded Article 4: providers and deployers must take measures to support staff AI literacy, with no duty to guarantee a specific level.
Since 2 August 2025: obligations for general-purpose AI (GPAI) models, the governance chapter and the penalties chapter.
Since 2 August 2026: the Article 50 transparency duties and the Commission's supervision and fining powers over GPAI model providers. On 1 September 2026 the Commission confirmed that the AI Office had sent its first requests for information to more than 30 AI providers.
What moved
Stand-alone high-risk systems (Annex III), for example in employment, education or essential services: 2 December 2027, previously 2 August 2026.
High-risk AI in products (Annex I): 2 August 2028, previously 2 August 2027.
National regulatory sandboxes: operational by 2 August 2027, previously 2 August 2026.
This is not a pause on the whole Act. Fines reach up to EUR 35m or 7% of worldwide turnover for prohibited practices and EUR 15m or 3% for most other obligations, including Article 50.
What comes next
2 December 2026: two new prohibitions apply, covering AI systems that generate non-consensual intimate imagery of identifiable persons or child sexual abuse material. On the same day the grace period ends for generative systems placed on the market before 2 August 2026: they must meet the Article 50(2) machine-readable marking duty.
2 August 2027: GPAI models placed on the market before 2 August 2025 must be compliant.
2 August 2030: high-risk systems intended for use by public authorities must comply, including legacy systems.
What is still open
High-risk classification guidelines. Draft published on 19 May 2026, consultation closed on 23 July 2026, final adoption announced for the end of 2026. Not adopted at the time of writing.
Harmonised standards. EN 18286:2026, the quality management standard supporting Article 17, was published in July 2026. Its reference is not yet cited in the Official Journal, so it gives no presumption of conformity yet.
Serious incident reporting. Draft guidance on Article 73 dates from 26 September 2025. We have found no final version.
National authorities. As of 17 June 2026 an independent tracker counted 9 Member States with clear designations of competent authorities, 12 with partial clarity and 6 unclear.
What to do now
Re-plan high-risk programmes against December 2027 and August 2028. Use the extra time for inventory, classification and quality management rather than stopping work.
Treat Article 50 as live: check every chatbot, voice agent and content generator, and close the legacy marking gap before 2 December 2026.
Ask your model vendors whether they have signed the GPAI Code of Practice.
Keep the open items on a watch list and revisit the plan once the classification guidelines are final.
Sources
This is information, not legal advice.
