Pan Innovation House Pan Innovation House
Software Agenda

The 2026 Turn in the EU AI Act: What Moved, What Came Into Force

The Digital Omnibus deferred high-risk obligations to 2 December 2027, while transparency obligations came into force on 2 August 2026.

August 2026 had been marked on the calendar for European AI regulation for a long time. In the final three weeks before the date, two things happened at once: part of the expected obligations were postponed, and part of them genuinely came into force. For a company exporting machinery, products or software from Türkiye to Europe, that split marks the real distance between "this does not concern us" and "we are in trouble tomorrow".

This article sets out what to do on the software side, with the calendar attached. One boundary first: this is not legal advice. Whether your company falls within scope is an assessment for a lawyer. The framework here exists so that you can make that assessment while seeing what waits for you in engineering.

The Short Answer: What Moved, What Applies

The EU Artificial Intelligence Act (Regulation (EU) 2024/1689) enters into application in stages. The amending regulation known as the Digital Omnibus on AI, Regulation (EU) 2026/1744, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. Its most significant change was the deferral of the high-risk obligations.

Subject Previous date Current position
Stand-alone high-risk systems under Annex III 2 August 2026 Deferred to 2 December 2027
High-risk AI embedded in regulated products (Annex I) 2 August 2027 Deferred to 2 August 2028
Transparency obligations (Article 50) 2 August 2026 Not deferred; in force
Prohibited practices (Article 5) 2 February 2025 In force; a newly added prohibition has a transition to 2 December 2026
General-purpose AI model obligations 2 August 2025 In force, unchanged
AI literacy (Article 4) 2 February 2025 In force; wording amended on 27 July 2026

The summary is short: there is now breathing room for the heavy technical compliance file, and none for transparency towards users.

Why the Transparency Obligation Reaches You

Article 50 is the least discussed and most widely applicable part of the Act, because it covers ordinary uses that are not "high risk". Three headings have applied since 2 August 2026:

  1. Disclosure in systems that interact with people. A user must know they are interacting with an AI system. The support chatbot on your website, the automated responder on WhatsApp, the voice assistant in your call centre.
  2. Machine-readable marking of synthetic content. AI-generated audio, image, video or text must be marked so that it is detectable as artificially generated. This goes beyond a visible label: a marking that machines can read is expected in the content itself.
  3. Disclosure for deepfakes and similar content. Generated content that gives the impression of a real person, object or event must be identified as such.

For generative systems already on the market, a limited transition period was granted for the machine-readable marking requirement; it expires on 2 December 2026. So even the one item that requires a product change does not have a long runway.

How a Turkish Exporter Falls Within Scope

The sentence we hear most often is: "We are in Türkiye, so it does not bind us." If your market is Europe, that is not a safe assumption. The Act covers providers placing systems on the European market irrespective of where they are established, and it can apply where the output of a system is used within the Union.

In practice there are three routes:

  • Intelligence embedded in a product. If a machine you sell into Europe contains image processing, automatic adjustment or a component that makes decisions, it is assessed together with product safety legislation. This group's deadline moved to 2 August 2028, which is not far away in a field where building a compliance file from scratch takes two years. For teams working on embedded systems and IoT, starting early means not having to undo design decisions later.
  • A digital surface open to European users. A chatbot, an automated quotation engine or a recommendation system serving your European customers. This group is within the scope of the transparency obligation today.
  • Content produced for the market. If you use AI to produce images, video and copy aimed at the European market, the marking rule applies. In e-export operations that automate content production, this is the item most often missed.

The Engineering Checklist

While the legal assessment runs in parallel, there is concrete work an engineering team can start now.

Step What to do Why now
1. Inventory List every point where AI is used in your products and digital surfaces Scope cannot be assessed without an inventory
2. Transparency Disclosure in chat interfaces, machine-readable marking on generated content The obligation is already in force
3. Classification Determine the risk category for each use, with your lawyer Everything downstream depends on this split
4. Logging and traceability Infrastructure that records inputs, outputs, versions and decisions It cannot be reconstructed retroactively
5. Supply chain Ask your model provider in writing which documents they supply Half of your compliance file comes from there

The fourth item is the weakest link in most companies. Without a record showing which version of a system produced what output, from what input and on what date, both the compliance file and any defence against a complaint stand on nothing. This is ordinary audit and compliance infrastructure, and it is worth building regardless of AI.

Is the Deferral a Relief or a Trap?

Reading the deferral as "the subject is closed" is risky for two reasons.

First, the item that moved is the longest part of compliance. Technical documentation, data governance, a risk management system and conformity assessment are not a single quarter's work. For a company starting from zero, seventeen extra months is not a comfortable schedule; it is a reasonable one.

Second, the item that did not move is the visible one. A chatbot disclosing itself to users is not hidden inside a compliance file; it is something everyone can see. It is also the first place a European corporate buyer will look during a supplier audit.

AI is not a standalone heading for a manufacturer selling into Europe either. In the same period, on the product safety side, the Cyber Resilience Act's reporting obligation comes into effect. What both regulations have in common is that they treat software as a product: something with a version, a component list, records and an owner.

Where "High Risk" Actually Appears for a Manufacturer

High-risk classification is narrower than most manufacturers assume, but it arrives from an unexpected direction. Three possibilities come up most often on the shop floor:

  • Recruitment and worker management. Systems used in candidate screening, task allocation, performance evaluation or decisions affecting the continuation of employment fall under this heading. If a model is to produce decisions in timekeeping and incentive pay, the distinction must be agreed at the outset. Our own preference is to leave the decision to rules rather than to a model, and to use the model only for preparatory work.
  • Components tied to critical infrastructure safety. Systems performing a safety function in energy and comparable infrastructure.
  • Decisions on access to essential services. Uses that determine financial access, such as creditworthiness assessment. A system that automatically sets dealer credit limits brings the topic within reach of a manufacturer.

Most uses outside these three headings are not in the high-risk category; they are in the transparency heading. Starting compliance work without making that distinction produces unnecessary cost.

Three Common Questions

"We do not develop our own system, we use a ready-made AI tool. Are we still in scope?" The Act addresses not only the developer but also the party deploying the system. The most visible obligations on the deployer side are transparency and AI literacy among staff. If you are the one placing the generated content on the market, the marking responsibility reaches you as well.

"Our product carries the CE mark. Is that not enough?" Product safety conformity and AI obligations are not the same thing. Where a high-risk component is embedded in a product, the scope of the conformity assessment widens and the technical file grows with it.

"What happens if we do not comply?" The regulation provides for administrative fines with upper limits tied to turnover. In practice, though, the pressure we see in the field is commercial rather than punitive: European corporate buyers have started adding these headings to supplier audit checklists. The question usually arrives as "will we lose the order if we cannot complete this form?"

The Turkish Side: KVKK Is a Separate Heading

European compliance does not replace obligations in Türkiye. Any AI use that processes personal data is separately assessed under KVKK; notice, legal basis, cross-border transfer and retention periods are independent topics. Where the two regimes overlap, a single technical foundation can serve both, but only if it is designed that way from the start. That overlap, collected into one record-keeping discipline, is exactly what we build in KVKK and GDPR compliance work.

Conclusion

The August 2026 turn changed the tempo of European AI regulation: heavy technical compliance moved forward, transparency towards users came into force. For a company exporting from Türkiye to Europe, the correct reading is this. Build the inventory now, complete disclosure and marking on visible surfaces this year, and plan the technical file against the 2027 and 2028 dates.

To map where AI actually runs in your products and digital surfaces, and to see what is missing on the software side, get in touch. The inventory usually takes about a week, and in most companies the length of the list is the first surprise.

Related reading:

All articles

Related articles

Let us work together

Share this article with your team, then call us for real results.

Call Free strategy call