The calendar after the Digital Omnibus
The law entered into force on 1 August 2024 and never had a single date. The Article 5 prohibitions and the Article 4 AI literacy duty have applied since 2 February 2025. The rules for general-purpose AI (GPAI) models and the designation of national authorities, since 2 August 2025. On 2 August 2026 came general applicability, with the Article 50 transparency obligations and the start of enforcement.
The Digital Omnibus was proposed by the Commission on 19 November 2025, approved by Parliament on 16 June 2026 by 423 votes to 57 with 174 abstentions, adopted by the Council on 29 June and signed on 8 July. It has been in force since 27 July 2026. It made one big change and one small one.
The big one: Annex III high-risk systems — HR, credit, biometrics, education, essential services — moved from 2 August 2026 to 2 December 2027. Those embedded in regulated products under Annex I moved from August 2027 to 2 August 2028. And these are now fixed dates, no longer conditional on the publication of harmonised technical standards.
The small one: anyone who already had a synthetic content generator on the market before August 2026 got until 2 December 2026 to mark its outputs. Two new prohibitions start on the same date: generating non-consensual intimate imagery and child sexual abuse material.
What did not move is precisely what hits SMBs hardest: transparency, prohibitions and AI literacy. Reading "deferred" and concluding "not my problem until 2027" is this year's expensive mistake.
Who is in scope, even with no office in Europe
Article 2 does not ask where you are. It asks where the system lands. It covers anyone placing an AI system on the EU market, whether established in the Union or in a third country; anyone deploying it while located in the EU; importers, distributors and authorised representatives; and — this is the point for Brazil — providers and deployers based outside the Union where the output produced by the system is used in the Union.
In plain terms: a company in Curitiba running CV screening for a client's German subsidiary is in scope. A Brazilian SaaS whose scoring model feeds a credit decision for a customer in Hamburg is in scope. You do not need a European entity or a server in Ireland.
Your role matters more than your size. A provider develops the system and places it on the market under its own name or trademark. A deployer operates it under its own authority. Most SMBs are deployers — and a deployer of a high-risk system has real duties: use it according to the provider's instructions, assign competent human oversight, keep the logs, and inform affected workers before putting the system to use.
Where your company lands across the four risk tiers
Unacceptable, prohibited since February 2025: social scoring, subliminal manipulation, untargeted scraping of facial images and emotion recognition in the workplace. That last one surprises people most: "team sentiment analysis" tools in a call centre or over recorded meetings land here.
High risk, applicable on 2 December 2027: screening and filtering job applications, targeted job advertising, evaluating candidates, decisions on promotion and termination. Also creditworthiness evaluation and credit scoring of individuals, with an express carve-out for systems used to detect financial fraud. And remote biometric identification, biometric categorisation and emotion recognition outside the workplace.
Limited transparency, applicable since August 2026: customer service chatbots, generators of text, image, audio or video, deepfakes. No audit, no certification. Notice.
Minimal risk: spam filters, product recommendations, autocomplete, stock forecasting. No specific obligation. This covers most of what an SMB actually runs — which is exactly why the inventory comes before the budget.
| Example | Obligation | |
|---|---|---|
| Unacceptable · prohibited since Feb 2025 | Emotion recognition in the workplace | Prohibited, no exception |
| High risk · applicable Dec 2027 | Résumé screening, credit scoring | Documentation, human oversight, logs (Annex III) |
| Limited transparency · since Aug 2026 | Customer-service chatbot, content generator, deepfake | User notice (Art. 50); no audit |
| Minimal risk | Spam filter, product recommendation, autocomplete | No specific obligation |
What "transparency obligations" require in practice
Article 50(1): if the system interacts directly with people, they must know they are talking to an AI, unless that is obvious to a reasonably well-informed person. In practice, a line at the opening of the conversation and a persistent label on the widget. Not a clause buried in the terms of use.
Article 50(2): synthetic outputs — audio, image, video and text — must be marked in a machine-readable format and detectable as artificially generated. That is engineering work, not design work: provenance metadata or technical watermarking, with a solution that is robust and interoperable. A visual badge in the corner of the image does not satisfy the article.
Article 50(3) and 50(4): anyone operating emotion recognition or biometric categorisation informs the people exposed to it. Anyone publishing a deepfake discloses that the content is artificial. AI-generated text published on matters of public interest also requires disclosure, unless it went through human editorial review with an identified person responsible.
- art-50-1Art. 50(1) — disclose it is an AI in direct interaction (chatbots)high
- art-50-2Art. 50(2) — mark synthetic output (audio, image, video, text) in a machine-readable wayhigh
- art-50-3Art. 50(3) — inform anyone exposed to emotion recognition or biometric categorisationmed
- art-50-4Art. 50(4) — disclose deepfakes and AI text on matters of public interestmed
The notice must be clear and arrive at first contact. Breaching this costs up to EUR 15 million or 3% of total worldwide annual turnover, whichever is higher. A prohibited practice costs up to EUR 35 million or 7%. Incorrect information to authorities, up to EUR 7.5 million or 1%. For SMEs and start-ups the ceiling is the lower of the two figures, not the higher — the only size concession the law makes on fines.
90 days, five deliverables
Days 1 to 15, inventory. One spreadsheet covering every AI in use: tool, vendor, who uses it, what decision it supports, what data goes in, whether the output reaches anyone in the Union. Include what IT did not buy — the sales team's browser extension and the assistant inside the CRM count.
Days 16 to 30, classification. Every row gets a risk tier and a two-sentence justification. Almost everything lands in minimal or limited transparency. Whatever lands in high risk is your real worklist, and it usually holds three or four items, not thirty.
Days 31 to 55, documentation. For each high-risk item: purpose, training and test data, performance metrics, known limitations, the human oversight point and a risk management plan. SMEs may use the simplified technical documentation form provided for Annex IV. You do not need to reproduce a multinational's format.
Days 56 to 75, contracts. In agreements with AI vendors, require: a written risk classification, instructions for use, a serious-incident notification deadline, a documentary audit right and a commitment to mark synthetic content. This is the clause you paste into the European customer's compliance questionnaire — and it is what unblocks the sale.
Days 76 to 90, logging. Record inputs, outputs, model version and who approved the decision, with a defined retention period. Logs are the evidence that turns policy into compliance. They are also the item missing from nearly every SMB that has already written the policy.
- 01Days 1–15 · Inventory
Spreadsheet covering every AI in use: tool, vendor, who uses it, what decision it supports, what data goes in, whether the output reaches the Union.
- 02Days 16–30 · Classification
Every row gets a risk tier and a two-sentence justification. Whatever lands in high risk usually holds three or four items, not thirty.
- 03Days 31–55 · Documentation
For each high-risk item: purpose, data, metrics, limitations, human oversight and a risk plan — the simplified Annex IV form.
- 04Days 56–75 · Contracts
Require from the vendor: written risk classification, instructions for use, incident deadline, audit right, synthetic content marking.
- 05Days 76–90 · Logging
Record inputs, outputs, model version and who approved the decision, with a defined retention period.
Where not to spend — and what Brazil will do
Do not buy high-risk certification for a FAQ chatbot. Do not stand up an ethics committee with monthly meetings before the inventory exists. Do not pay for an external audit before December 2027 if nothing you run is Annex III. And do not wait for the perfect harmonised standard to start: the deadlines are fixed now and no longer depend on it.
Use what the law reserves for small companies. Article 62 guarantees priority, free-of-charge access to regulatory sandboxes, conformity assessment fees reduced in proportion to size, and dedicated channels with national authorities for questions. Member States have until 2 August 2027 to have at least one sandbox operational.
In Brazil, bill PL 2338/2023 passed the Senate on 10 December 2024 and remains in the Chamber's special committee, awaiting the rapporteur's report; the vote was pushed past the October 2026 elections. The text copies the European risk-tier logic and sets fines of up to BRL 50 million per infringement. Organise for the EU now and you arrive ready for the Brazilian framework. The reverse does not work.
And much of the work is already paid for. System inventory, legal basis, records of processing and access logs are things LGPD and GDPR have demanded for years. The AI Act adds two: classify by risk and mark the output. If you already have the first set standing, you start the race halfway down the track.
- AGO · 2024Entry into force (1 Aug)
- FEV · 2025Article 5 prohibitions and AI literacy
- AGO · 2025GPAI, national authorities and penalty regime
- AGO · 2026General applicability: transparency (Art. 50) and enforcement
- SET · 2026Today
- DEZ · 2026Marking of legacy synthetic content and new prohibitions
- DEZ · 2027Annex III high risk (deferred by the Digital Omnibus)
- AGO · 2028High risk embedded in products (Annex I)