Securance logo

The State of the EU AI Act — Q3 2026 Report

  • Advisory
Advisory · Quarterly Regulatory Briefing

EU AI ACT Update.

Enforcement is live. The high-risk regime moved to December 2027. The transparency clock is already running. Our Q3 2026 report tells you exactly what applies today — and where your effort belongs next quarter.

2 Aug 2026Enforcement began at EU and national level
2 Dec 2027New deadline for stand-alone high-risk systems
€35M / 7%Maximum penalty for prohibited practices
Executive summary

A quarter of two speeds

Q3 2026 delivered the two most consequential events since the AI Act entered into force. The Digital Omnibus on AI became law in July, deferring the heavy high-risk regime by sixteen months. Days later, on 2 August, the Act's enforcement machinery switched on across the single market. Less applies today than organisations planned for — but what does apply is now backed by real fines.

The Omnibus is law

In force since 27 July 2026. It amends the AI Act's timeline — not its substance. The high-risk requirements are unchanged; only the date moved.

High-risk moved, not vanished

Stand-alone high-risk systems (Annex III): 2 December 2027. AI embedded in regulated products (Annex I): 2 August 2028.

Transparency stayed on schedule

Article 50 applied on 2 August 2026: disclose chatbots, label deepfakes, notify people exposed to emotion recognition. Article 4 AI literacy remains in force.

Enforcement is real

The AI Office can now fine GPAI providers up to €15M or 3% of turnover, and national authorities hold full market-surveillance and sanction powers.

Free download

Get the Q3 2026 report

Written by Securance Advisory — the same consultants who prepare organisations for SOC 2, ISO 27001, NIS2 and DORA. No fluff, no sales deck. Just the state of the law and what to do about it.

<
What the Digital Omnibus changed

The revised compliance calendar

2 Feb 2025 In force

Prohibitions & AI literacy

Bans on unacceptable-risk practices and the Article 4 AI literacy duty.

2 Aug 2025 In force

GPAI obligations & governance

Duties for general-purpose model providers; EU governance bodies established.

2 Aug 2026 This quarter

Enforcement switches on

Article 50 transparency applies; the AI Office and national authorities gain full enforcement and fining powers.

2 Dec 2026

Watermarking & new prohibitions

Machine-readable marking of synthetic content for legacy systems; new ban on AI-generated NCII and CSAM.

2 Dec 2027 Moved from Aug 2026

Annex III high-risk obligations

Risk management, documentation, human oversight, conformity assessment and EU database registration.

2 Aug 2028 Moved from Aug 2027

Annex I embedded high-risk AI

High-risk obligations for AI embedded in regulated products.

!-- WHAT'S INSIDE -->
Inside the report

Four pages. Zero noise.

01 · Summary

The quarter in one page

The Omnibus, the enforcement start, and the revised calendar — what actually changed and what it means.

02 · Live obligations

What applies today

Prohibitions, AI literacy, Article 50 transparency and GPAI duties — mapped to who they hit and what they require.

03 · Sanctions

The penalty framework

The full fining schedule up to €35M or 7% of worldwide turnover, plus the SME rules and GDPR overlap.

04 · Action

Five moves for Q4 2026

The Dutch supervision landscape and a concrete advisory plan for the sixteen-month runway to December 2027.

Frequently asked questions

Quick answers

Did the August 2026 deadline become irrelevant?

No. The high-risk obligations moved to December 2027, but Article 50 transparency, AI literacy, the prohibitions and GPAI duties are enforceable today — with penalty calculations counting the full duration of non-compliance.

Does the Digital Omnibus soften the high-risk requirements?

No. The requirements — risk management, documentation, human oversight, conformity assessment — are unchanged. Only the application dates moved, to 2 December 2027 (Annex III) and 2 August 2028 (Annex I).

Who supervises the AI Act in the Netherlands?

The Autoriteit Persoonsgegevens coordinates, the RDI covers the technical side, and sector regulators such as the AFM and DNB keep their domains. GPAI model providers fall under the EU AI Office directly.

How does this connect to NIS2, DORA and ISO 27001?

AI Act controls overlap heavily with existing security and governance frameworks. Securance's integrated approach lets you collect evidence once and reuse it across every standard — including AI Act readiness.

Become demonstrably in control of AI.

Talk to an advisor, not a salesperson. Get a free consultation on your AI Act readiness — integrated with your existing compliance frameworks.

Schedule a free consultation

Want the rest of the report?

Fill in your details above and we’ll make sure you have full access — the sanctions breakdown, the Dutch supervision map, and our Q4 2026 action plan.

Fill in the form above

Related articles