13.08.2026

Introduction – changes resulting from the AI Act and the Digital Omnibus on AI

The adoption of the so-called Digital Omnibus on AI, amending Regulation (EU) 2024/1689 of the European Parliament and of the Council on artificial intelligence (the “AI Act”), has shifted the deadlines for the application of key obligations in the field of artificial intelligence. From a business perspective, this means a gradual roll-out of new requirements – in… View Article

The adoption of the so-called Digital Omnibus on AI, amending Regulation (EU) 2024/1689 of the European Parliament and of the Council on artificial intelligence (the “AI Act”), has shifted the deadlines for the application of key obligations in the field of artificial intelligence. From a business perspective, this means a gradual roll-out of new requirements – in particular the provisions concerning systems classified as high-risk systems. In this article we show how the AI Act (as amended by the Digital Omnibus on AI) is changing the legal environment for entities developing and using artificial intelligence – from the ban on the riskiest practices, through new transparency requirements, to the extensive legal regime governing requirements for high-risk systems.

AI Act application timeline – key dates for business

Below are the most important pieces of information regarding the deadlines for the application of the individual provisions of the AI Act:

  • From 2 February 2025, the general provisions of the AI Act began to apply, including those on prohibited AI practices. These include, among others, the ban on so-called social scoring and on the use of AI systems to infer the emotions of a natural person in the workplace, except in specific situations related to, for example, medicine or safety.
  • From 2 August 2025, obligations for providers of general-purpose AI models came into force, among others – these are models capable of competently performing a wide range of distinct tasks and that can be integrated into various downstream systems or applications. Providers of such models are required, among other things, to draw up technical documentation for the model, including its training and testing process, to put in place a policy on copyright and related rights, and to draw up and make publicly available a sufficiently detailed summary of the content used to train the given general-purpose AI model.
    From this date, provisions on notifying authorities and notified bodies also apply, aimed at preparing the governance and conformity assessment system.
  • From 2 August 2026, most of the provisions of the AI Act apply, including the transparency provisions, as well as the provisions empowering the Commission to impose fines on providers of general-purpose AI models.
  • From 2 August 2027, Member States will be required to ensure at least one national-level regulatory sandbox.
  • From 2 December 2027, most of the obligations relating to high-risk systems will start to apply, in particular systems using biometrics and systems used in critical infrastructure, education, employment, and the provision of essential services.
  • From 2 August 2028, the provisions on high-risk systems covered by EU harmonisation legislation (e.g. machinery, toys, medical devices) will start to apply.

Transparency obligations – labelling AI-generated content

A key element of the AI Act is the transparency obligations concerning content created or modified using AI systems.

Where an AI system is used to generate or manipulate image, audio, or video content in a way that resembles real people or events (a deepfake), there is an obligation to clearly disclose that the content has been artificially generated or manipulated. An exception applies where the deepfake forms part of a work that is evidently artistic, creative, satirical, fictional, or of a similarly evident nature – in that case, the transparency obligation is limited to a simple disclosure of the existence of generated or manipulated content, in a manner that does not hamper the display or enjoyment of the work.

Where an AI system is used to generate or modify text published for the purpose of informing the public on matters of public interest, there is likewise an obligation to disclose that the text has been artificially generated or manipulated. This rule is softened by exceptions, in particular where the content has undergone human review or editorial control, and where a natural or legal person holds editorial responsibility for the publication of the content. The labelling obligation therefore does not apply to standard proofreading, quality improvements, or other editorial actions that do not result in new, generated content.

Information that content has been AI-generated or AI-manipulated must be provided:

  • clearly and distinguishably – not hidden in “small print”, terms and conditions, or footnotes;
  • at the latest at the time of first interaction or exposure, so that the user is immediately made aware of the nature of the content;
  • in a manner that meets accessibility requirements, i.e. understandable and accessible to persons with disabilities (e.g. appropriate contrast, compatibility with screen readers, absence of language barriers).

Examples:

  • An app lets a user “swap” their face for someone else’s (e.g. a celebrity’s) in a video – the user must be explicitly informed that the effect is the result of AI.
  • A comedy series uses AI to “de-age” an actor in several scenes – a note in the opening credits or description is sufficient: “This series uses generative artificial intelligence techniques.”
  • An employee edits photos from a company event, cropping them in a program that uses artificial intelligence, without any further alteration of the content of the photos – in this case, no labelling is required.

Transitional regime for content-generating systems

The transitional period for part of the transparency obligations applicable to providers of AI systems generating synthetic audio, image, video, or text content ends on 2 December 2026. These providers should ensure that the output of the AI system is marked in a machine-readable format and detectable as artificially generated or manipulated. The transitional period applies to systems placed on the market before 2 August 2026.

New guidelines and regulatory positions, and the Polish AI Act

Alongside the entry into force of the AI Act and related regulations, new rules, guidelines, and positions are being adopted to facilitate the practical application of these provisions, in particular:

  • On 19 May 2026, the Commission published a draft guidelines on the classification of high-risk systems (available here).
  • On 20 July 2026, guidelines on transparency obligations for providers and deployers of certain AI systems were published (available here).
  • On 31 July 2026, the EBA, EIOPA, and ESMA published a joint position on adopting a consistent, risk-based approach to information and communication technology risks arising from the use of advanced AI models (available here).

In addition, on 11 August 2026, the Polish act on artificial intelligence systems enters into force, regulating oversight of the use of AI and establishing a national supervisory authority – the Commission for the Development and Safety of Artificial Intelligence. This act constitutes an important complement to the EU regime and sets out the national framework for monitoring compliance with the AI Act (the text of the act is available here).

As shown by the timeline outlined at the beginning of this article, a significant part of the AI Act – namely the provisions on high-risk systems – is not yet in application. The Digital Omnibus on AI has postponed the start of application of these provisions, giving entities that use or develop AI systems more time to ensure compliance. This upcoming period should therefore be used to carry out an internal analysis of the classification of the systems used from a high-risk perspective, taking into account the latest guidelines, and to plan adaptation measures – implementing a quality management system, preparing the necessary documentation, and taking the other steps required by the AI-related legislation.

At Identt, we are actively preparing ourselves and our clients for the new obligations relating to the use of artificial intelligence. We review and classify the AI systems in use from a high-risk perspective, implement the required transparency and content-labelling measures, and further develop the quality management systems and technical documentation required by the new legal regime.

Our goal is to ensure full compliance of every solution we deliver before the relevant obligations start to apply, which protects both our clients’ legal position and their reputation. Compliance with the law is an integral part of how we work, not something addressed at the last minute.

Need a custom solution? We’re ready for it.

IDENTT specializes in crafting customized KYC solutions to perfectly match your unique requirements. Get the precise level of verification and compliance you need to enhance security and streamline your onboarding process.

Book a demo