The AI Act timeline after the digital omnibus: what applies and what slipped
High-risk obligations have moved to December 2027 and August 2028, but transparency duties and AI literacy are already in play. A dated guide for fashion teams.

KEY TAKEAWAYS Summary by the editors
- The Digital Omnibus on AI, Regulation (EU) 2026/1744, was published in the Official Journal on 24 July 2026 and moved stand-alone high-risk obligations from 2 August 2026 to 2 December 2027.
- High-risk AI embedded in regulated products moved to 2 August 2028, while the Article 50 transparency obligations still began to apply on 2 August 2026.
- Providers whose generative systems were on the market before 2 August 2026 have until 2 December 2026 to meet the machine-readable marking duty in Article 50(2).
- The prohibitions and the AI literacy duty have applied since 2 February 2025, and the omnibus softens literacy into a duty to support staff literacy rather than ensure it.
- Most fashion use cases such as forecasting, merchandising and product content are not high-risk, so the transparency and literacy duties matter more to them than the delayed high-risk dates.
The AI Act's high-risk rules have slipped, but much of the Act already applies. Under the Digital Omnibus on AI, stand-alone high-risk obligations now apply from 2 December 2027 and those for AI built into regulated products from 2 August 2028, while prohibitions, AI literacy and, since 2 August 2026, the transparency duties of Article 50 are in force. For most fashion companies, the dates that matter first are the transparency ones.
What did the digital omnibus change in the AI Act timeline?
A provisional political agreement on the AI omnibus was reached on 6 May 2026, according to law-firm analysis, and Member State representatives confirmed it on 13 May. The final act, Regulation (EU) 2026/1744 of 8 July 2026, was published in the Official Journal on 24 July 2026 and is reported to have entered into force three days later. The practical effect was to postpone the application of the high-risk regime before the original 2 August 2026 date arrived.
The main changes reported by law firms are the new application dates for high-risk systems, a transitional period for the marking of AI-generated content, a softened AI literacy duty and a new prohibition on systems that generate non-consensual intimate imagery and child sexual abuse material. National regulatory sandboxes must be available in each Member State by 2 August 2027.
| Date | What applies | Relevance for fashion |
|---|---|---|
| 2 February 2025 | Prohibited practices and AI literacy | Emotion inference at work is banned (with exceptions); literacy measures expected |
| 2 August 2025 | Rules for general-purpose AI models | Mainly model providers, but affects supplier choice |
| 2 August 2026 | General application, including Article 50 transparency | Chatbot disclosure, deepfake labelling, marking of synthetic content |
| 2 December 2026 | Marking grace period ends for older generative systems; new prohibition on intimate-image and abuse-material generators | Check generative image tools placed on the market before August 2026 |
| 2 August 2027 | General-purpose models placed on the market before August 2025 must comply; sandboxes due | Vendor contracts and model documentation |
| 2 December 2027 | Stand-alone high-risk systems (Annex III) | HR, recruitment and worker-management tools |
| 2 August 2028 | High-risk AI in regulated products (Annex I) | Rarely relevant to apparel, more to connected products |
| 2 August 2030 | High-risk systems used by public authorities | Little direct relevance |
What already applies to fashion companies today?
Three layers are already live. First, the prohibitions: Article 5 bans, among other things, the use of AI to infer the emotions of a person in the workplace and in education, except for medical or safety reasons. Second, AI literacy: Article 4 now asks providers and deployers to take measures to support the AI literacy of their staff and other people operating AI on their behalf, taking into account their knowledge, experience and context, without guaranteeing a specific level for any individual. Third, since 2 August 2026, the Article 50 transparency rules.
Article 50 is the layer most visible to fashion teams. Providers of systems that interact directly with people must design them so people know they are dealing with a machine, unless this is obvious to a reasonably well-informed person. Providers of systems that generate synthetic audio, image, video or text must mark outputs in a machine-readable format. Deployers must disclose deepfakes, with lighter disclosure for evidently artistic, creative, satirical or fictional works. Information must be given at the latest at the first interaction or exposure, in a clear and distinguishable way.

What slipped, and why does it matter less for fashion?
The high-risk regime slipped. Annex III covers areas such as recruitment, selection and decisions about work-related relationships, including task allocation based on behaviour and the monitoring and evaluation of workers. Annex I covers AI built into products that are already regulated under EU product legislation. Demand planning, assortment optimisation, product tagging, image generation and pricing support are generally not on these lists.
That does not make the delay irrelevant. Human resources software, tools that score or monitor staff, and systems used to manage supplier workforces can fall under Annex III. Companies that adopt such tools in 2026 will be bound by the high-risk rules when they apply, and procurement contracts signed now will still be in force then.
Did the omnibus change the penalties or the scope?
The reporting reviewed for this article does not describe changes to the penalty ceilings in Article 99, which remain up to EUR 35 million or 7 per cent of worldwide annual turnover for prohibited practices, and up to EUR 15 million or 3 per cent for most other operator obligations, including Article 26 and Article 50, whichever is higher. For small and medium-sized enterprises the lower of the two figures applies. Scope under Article 2 still reaches non-EU providers and deployers whose AI output is used in the Union.
How should a fashion company plan around the new dates?
A staged approach fits the calendar. The items below follow the order in which obligations bite:
- Now: confirm AI literacy measures exist for teams using generative and analytical tools, and that no workplace emotion-inference tools are in use.
- Now: review customer-facing chatbots, virtual assistants and AI-generated imagery for Article 50 disclosure and marking, and ask suppliers how they will mark outputs.
- By 2 December 2026: check any generative system placed on the market before 2 August 2026 against the marking grace period, and confirm that no tool generates intimate imagery or abuse material.
- 2027: inventory HR, recruitment and workforce tools, and plan for the December 2027 high-risk date with suppliers.
- Ongoing: keep a register of AI systems with provider, deployer and risk classification.

What should executives take from the delay?
The delay is breathing space for the high-risk regime, not a pause on the Act. Transparency, literacy and the prohibitions are in operation, supervisory authorities are being built up, and customers and retail partners will increasingly ask how AI is used and disclosed. Companies that treat 2027 as the starting line will find that their suppliers, contracts and disclosures needed attention earlier.
Frequently asked questions
When do the AI Act high-risk rules apply now?
Stand-alone high-risk systems listed in Annex III apply from 2 December 2027, and high-risk AI embedded in regulated products under Annex I from 2 August 2028, following the Digital Omnibus on AI, Regulation (EU) 2026/1744.
Do the AI Act transparency rules already apply?
Yes. Article 50 began to apply on 2 August 2026. Providers of generative systems placed on the market before that date have until 2 December 2026 to meet the machine-readable marking duty in Article 50(2).
Is AI literacy still required?
Yes. Article 4 has applied since 2 February 2025 and now asks providers and deployers to take measures to support the AI literacy of their staff, rather than to ensure a sufficient level.
Did the omnibus remove any AI Act obligations for fashion companies?
It postponed the high-risk obligations and softened AI literacy, but transparency duties still began on 2 August 2026 and the prohibitions remain. It also added a ban on systems generating non-consensual intimate imagery and child sexual abuse material.
One edition every weekday morning. Read in five minutes. Free for industry professionals.
SOURCES
- AI Act Service Desk (artificialintelligenceact.eu): Implementation timeline
- Cuatrecasas: Digital Omnibus on AI has been published
- Gibson Dunn: EU AI Act Omnibus Agreement, Postponed High-Risk Deadlines and Other Key Changes
- AI Act Service Desk (artificialintelligenceact.eu): Article 50, Transparency obligations
- AI Act Service Desk (artificialintelligenceact.eu): Annex III, High-risk AI systems




