Key takeaways

For months, one date sat in the back of every executive's mind: August 2, 2026, the day the EU AI Act was meant to apply "in full". Twelve days out, the Union has just changed the calendar. The text that does this, the Digital Omnibus on AI, was signed on July 8, 2026. For an SME, the real question is not what got postponed, but what remains.

What the Digital Omnibus actually changed

The Digital Omnibus on AI is a simplification package proposed by the European Commission on November 19, 2025, then confirmed by a political agreement between the Parliament and the Council in early May 2026 (Council of the EU). The final text was signed on July 8, 2026 and is awaiting publication in the Union's Official Journal, a few days before the August 2 deadline.

Its main effect is a shift in the calendar. The AI Act's heaviest obligations, the ones that bear on so-called "high-risk" AI systems, are pushed back: to December 2, 2027 for the stand-alone systems listed in Annex III (CV screening, credit scoring, biometrics), and to August 2, 2028 for AI embedded in already-regulated products (Gibson Dunn). The duty to mark AI-generated content slips to December 2, 2026. The text also adds a new ban on non-consensual sexual content produced by AI.

This delay answers a recurring complaint: the "high-risk" regime asked companies for heavy technical documentation while the technical standards and guidance were not ready. By moving the deadline back sixteen months, Brussels buys time to publish those standards. But a delay is not a cancellation, and it touches only part of the regulation.

What does this change for a European SME?

For the vast majority of SMEs, the answer fits in one sentence: almost nothing that got postponed applied to you in the first place. The "high-risk" regime targets specific uses, software that screens job applications, decides on credit, or runs a medical device. A company of ten to a hundred employees using a CRM, a writing assistant, or a support chatbot is, in the overwhelming majority of cases, not a "provider" of a high-risk system. It is a "deployer", meaning simply a user.

And it is precisely the deployer that the obligation which does apply on August 2, 2026 is aimed at: the transparency duty in Article 50. The Digital Omnibus left it on its original date (Sidley). In other words, the date you were bracing for still arrives, but it does not cover what you imagined. It does not demand a thirty-page compliance file; it asks you to be clear about your use of AI toward your customers.

The distinction between provider and deployer is the point to remember. It changes the burden entirely: a provider of a high-risk system must prove its model complies, with documentation, risk management, and assessments; a deployer mainly has to inform and train. For an SME that buys its tools off the market rather than building them, you are almost always in the second case.

What still applies on August 2, 2026

Article 50 of the AI Act sets out four transparency obligations, all concrete (European Commission). First, disclosing that someone is talking to a machine: if you put a chatbot on your site, the visitor must know they are dealing with an AI, unless it is obvious. Second, marking synthetic content: images, audio, video, or text generated by AI must be detectable as such, in a machine-readable format. Third, flagging deepfakes: content that makes a real person say or do something must be presented as artificial. Fourth, informing people when emotion recognition or biometric categorisation is used.

On top of that sits an obligation already in force, and often forgotten: AI literacy. Since February 2, 2025, Article 4 requires any company using AI systems to ensure its staff have a sufficient level of understanding of those tools. No specific fine is attached to it, but the signal is clear: training your teams is no longer optional.

The penalty framework sets the scale. Prohibited practices can cost up to €35 million or 7% of global annual turnover; other breaches, including transparency, up to €15 million or 3%. These ceilings target large players first, but they mark how seriously the obligation is taken.

These rules feel less abstract once you build the tools they cover. On my own site, the page where you can chat with my assistant states upfront that it is an AI; that is exactly what Article 50 will require from August 2. Adding that notice takes a few minutes; skipping it leaves a blind spot on a point that will become verifiable.

The right reflex: neither panic nor indifference

For an SME, the short-term risk is not legal; it is commercial. As each AI Act deadline approaches, "compliance" offers bloom, often oversized against the real need of a company that merely uses off-the-shelf tools. Paying for a "high-risk" compliance audit when you deploy a plain chatbot is insuring against a risk you do not run. This is where judgment beats an invoice.

The right reflex comes down to three moves, all doable without a vendor. Map where AI touches your customers: chatbot, generated content, automated emails. Add the transparency notices where they are needed. Spend an hour explaining to your teams what the tool they use does, and does not, do. That is the core of what August 2, 2026 asks of an SME. The "high-risk" regime will only concern you if you one day put into service an automated decision system on sensitive matters, and you will then have until late 2027 to prepare.

August 2, 2026 is no longer the hard cutoff it was billed as. For an SME, it mainly marks the moment when saying "this is an AI" becomes an obligation, not a courtesy. Real preparation is not a compliance dossier: it is knowing exactly where AI speaks to your customers in your name.

Frequently asked questions

Does my company need to comply with the EU AI Act on August 2, 2026?

If you use AI as a tool (chatbot, content generation, assistant), your main obligation on August 2, 2026 is the transparency duty in Article 50: telling customers when they interact with an AI or view AI-generated content. The far heavier "high-risk" regime targets specific uses only and has been pushed to late 2027 by the Digital Omnibus.

What did the Digital Omnibus on AI change?

Signed on July 8, 2026, it postpones the AI Act's "high-risk" obligations from August 2, 2026 to December 2, 2027 for stand-alone systems, and to August 2, 2028 for AI embedded in products. It also delays the marking of AI-generated content to December 2, 2026. The Article 50 transparency obligations remain applicable on August 2, 2026.

What is the difference between a "provider" and a "deployer" of an AI system?

A provider develops or places an AI system on the market; a deployer uses it in the course of its business. An SME using an off-the-shelf CRM or chatbot is almost always a deployer, not a provider. This distinction is decisive: the heavy "high-risk" obligations fall mostly on providers, while deployers mainly owe transparency and training duties.