By November 2025 it was clear the EU AI Act rollout wasn't keeping pace: too many technical standards and delegated acts that the high-risk rules depend on were still missing. The Commission tabled the Digital Omnibus, a package that adjusts several digital laws at once. For the AI Act it comes down to one thing. The sharpest obligations arrive later.
If you already know the risk classes, the entry point into AI readiness and data strategy is here. If you're starting fresh, the short version is below.
What changed
The original plan set the high-risk obligations from 2 August 2026 (Annex III) and from 2 August 2027 for AI embedded in regulated products (Annex I). The Omnibus replaces the previously discussed conditional trigger with fixed dates and pushes both back:
- Annex III (stand-alone high-risk systems): from 2 December 2027.
- Annex I (high-risk AI in regulated products): from 2 August 2028.
There's also a substantive addition: a new Article 5 prohibition on AI-generated non-consensual intimate imagery and abuse material. It doesn't touch marketing analytics directly, but it belongs in the full picture.
What stays the same
The high-risk part moved. The rest holds.
- Prohibited practices have been banned since February 2025. Social scoring, manipulative subliminal techniques, real-time biometrics in public spaces. Penalties up to €35 million or 7 percent of global annual turnover.
- General-Purpose AI has carried its own obligations since August 2025. Distinguish model-provider duties from the duties of system providers and deployers. Using a third-party model does not automatically make a marketing team its provider.
- Transparency obligations under Article 50 have applied since 2 August 2026. Chatbots, AI copy and synthetic media have to be recognisable to users. The German authority is the Bundesnetzagentur, with fines up to €15M or 3 percent. For systems that were already running, machine-readable labelling of AI-generated content kicks in on 2 December 2026. That is the next real deadline, and it hits every GenAI content workflow that was live before August.
The new timeline at a glance
The Digital Omnibus moves only the high-risk part. Prohibitions, GPAI and transparency obligations stay in force.
- Feb 2025In force
Prohibited practices
In force. Social scoring, manipulative techniques, real-time biometrics. Penalties up to €35M or 7%.
- Aug 2025In force
General-Purpose AI
In force. GPT, Claude, Gemini in tools or products fall under the GPAI obligations.
- Aug 2026In force
Transparency obligations, Article 50
In force since 2 August 2026. Chatbots, AI copy and synthetic media must be recognisable. German authority: Bundesnetzagentur. Fines up to €15M or 3%.
- Dec 2026Deadline running
Marking duty for existing systems
From 2 December 2026, machine-readable marking of AI-generated content also covers systems already running before 2 August 2026.
- Dec 2027was Aug 2026Deferred
High-risk, Annex III
Deferred. Stand-alone high-risk systems: mandatory documentation, conformity assessment, EU registration.
- Aug 2028was Aug 2027Deferred
High-risk, Annex I
Deferred. High-risk AI embedded in regulated products.
As of August 2026. Regulation (EU) 2026/1744, published in the Official Journal on 24 July, in force since 27 July 2026.
What it means for marketing teams
Deferred, not dropped. The extra time is lead time, not a reason to table the topic. If you run Smart Bidding, predictive audiences, lookalike audiences or attribution models, you operate AI systems in the sense of the Act. Risk classification decides which obligations apply, and the delay doesn't change that.
Click or tab through the tiers for marketing examples and obligations.
Limited risk
Obligation
Transparency obligation: users must know they're interacting with AI. AI-generated content must be labelled.
Marketing examples
- AI chatbot on the website
- GenAI blog or ad copy
- AI-generated images / deepfakes
2026 status
Transparency obligations in force since 2 August 2026, marking of existing systems from 2 December 2026. German authority: Bundesnetzagentur.
Three things are worth doing now, regardless of the moved deadlines:
- AI inventory. Which AI components sit in the marketing stack, including the invisible ones like Smart Bidding or HubSpot AI?
- Risk classification per use case. Most marketing setups land in Minimal or Limited Risk. Establishing that is cheap and ends the speculation.
- Transparency and documentation obligations. These apply today and are the most common blind spot in an audit.
The AI Act guide for marketing analytics explains which marketing use cases to examine.
