EU AI Act: the compliance race
CEO aziende tech globali
The Digital Omnibus defers Annex III to December 2027, but Article 50 transparency obligations kick in August 2. Companies must figure out what applies to them — now
DAMM Scorecard
Health Score
Verdict: Evolving — Annex III deferral confirmed, Art.50 obligations imminent
The facts
The EU AI Act, approved in 2024, is the world's first comprehensive regulatory framework for artificial intelligence. August 2, 2026 is the key date: obligations for AI systems classified as "high-risk" come into force — including systems used in healthcare, finance, human resources, education, critical infrastructure, and many other sectors.
The obligations are substantial: detailed technical documentation, conformity assessments, risk management systems, training data governance, human oversight, user transparency, logging, and traceability. For many companies, this means rebuilding entire AI development processes from scratch.
The penalties are among the most severe ever imposed on the tech sector: up to EUR 35 million or 7% of annual global turnover, whichever is higher. For Big Tech, this can mean billions. The scope is extraterritorial: any AI system that affects EU residents is subject to the regulation, regardless of where the company is headquartered.
But there was a crucial unknown: the "Digital Omnibus" package proposed by the European Commission could postpone the high-risk obligations deadline. The proposal was under discussion between Parliament and Council, with several member states opposing the delay.
July 2026 Update
The breakthrough came on May 7, 2026: the Council, Parliament, and Commission reached a provisional political agreement on the Digital Omnibus. The key changes:
Annex III (stand-alone high-risk systems): deadline deferred from August 2, 2026 to December 2, 2027 — a 16-month extension. This covers systems used in healthcare, finance, human resources, education, and other sensitive sectors.
Annex I (AI embedded in regulated products): deadline deferred to August 2, 2028 — a 24-month extension. This covers AI embedded in machinery, medical devices, vehicles, and other products subject to certification.
Article 50 (transparency obligations): deadline CONFIRMED at August 2, 2026 — no deferral. This means that from August 2, all companies using chatbots, generating AI content (text, images, audio, video), or using biometric recognition systems must comply with transparency obligations. Penalties for Art.50 violations reach EUR 15 million or 3% of global turnover.
New prohibitions: an explicit ban on AI nudifiers (non-consensual intimate imagery generated with AI) and AI-generated child sexual abuse material was added to Article 5.
Transitional period: generative systems already on the market before August 2, 2026 have until December 2, 2026 to implement the machine-readable marking requirement under Art.50(2).
The agreement is political and provisional — it must still be formally adopted and published in the Official Journal. But formal adoption is expected before August 2, 2026.
The dilemma for companies has transformed. Those who gambled on the delay won — for high-risk systems. Those who invested in early compliance still have a competitive and organizational advantage. But everyone must still comply with Art.50 transparency obligations by August 2.
DAMM Analysis
Delimitation (7/10): The situation is now much clearer. The Digital Omnibus has created three distinct, well-defined deadlines: Art.50 on August 2, 2026, Annex III on December 2, 2027, Annex I on August 2, 2028. Companies can now classify their AI systems with much greater precision — knowing exactly what applies when. The score is not higher because classifying systems across the three categories remains complex, and the formal Omnibus adoption has not yet been published.
Asymmetry (6/10): The asymmetry has improved significantly for high-risk systems — the 16-month deferral reduces the risk of immediate penalties and allows time for structured compliance. For Art.50 transparency obligations, the asymmetry remains unfavorable: compliance costs are moderate (disclosure, marking, labeling) but non-compliance penalties (EUR 15M or 3%) are immediate from August 2. The score reflects the mix of both scenarios.
Room to Maneuver (6/10): Room to maneuver has grown enormously for high-risk systems — 16 additional months to implement documentation, audits, and governance. For Art.50 obligations, room is tight but the required actions are less burdensome: add disclosure on chatbots, implement marking on generated content, inform users of biometric systems. The transitional period until December 2026 for machine-readable marking adds further room.
Minimum Move (5/10): The situation now favors those who adopted a modular strategy. The updated minimum move is: implement Art.50 obligations immediately (transparency on chatbots and AI content), then use the 16 months to prepare Annex III compliance in a structured way. Those who invested in early full compliance have an advantage but also spent prematurely. Those who did nothing must now rush at least on Art.50.
DAMM Scenarios
The picture has changed radically with the Omnibus. The question is no longer "invest or wait?" but "how quickly can I implement Art.50 and how strategically can I plan for Annex III?"
Those compliant with Art.50 by August 2 have eliminated the immediate risk of penalties. They then have 16 months for Annex III compliance — enough time for rational planning, not a sprint.
Those who ignore Art.50 risk penalties from August 3, 2026. The Annex III deferral does not cover transparency.
Today's minimum move: implement Art.50 obligations by August 2 (chatbot disclosure, content marking, biometric transparency), then begin a structured Annex III compliance program with intermediate milestones toward December 2027.
Key lesson
The EU AI Act illustrates a fundamental DAMM principle: when the deadline is certain but the context is uncertain, the minimum move is not "do everything" or "do nothing" — it is to segment risk. Classifying your AI systems and acting only on those that are unambiguously high-risk reduces exposure without committing excessive resources. The most common mistake is treating compliance as a binary decision instead of a modular one.
Want to learn the framework? Read the complete book
Related case studies
Kodak: the buried invention
Management Kodak · 1975–2012
Read analysisBlockbuster: the $50 million that cost an empire
John Antioco, CEO Blockbuster · 2000
Read analysisNetflix: from red envelopes to streaming empire
Reed Hastings, CEO Netflix · 2007–2013
Read analysis