As of 6 October 2026, a French company that provides or uses an AI system must already comply with three sets of rules under Regulation (EU) 2024/1689. The prohibited practices and AI literacy have applied since 2 February 2025, the obligations for general-purpose AI models since 2 August 2025 and the transparency rules of Article 50 since 2 August 2026. Regulation (EU) 2026/1744, known as the Digital Omnibus on AI, was published in the Official Journal of the EU on 24 July 2026 and entered into force on 27 July. It moved the rest of the timeline: high-risk systems listed in Annex III are only covered from 2 December 2027.
Update of 6 October 2026. This page will be updated whenever a new text is published (French law designating the authorities, guidelines on high-risk systems, harmonised standards). It is based on the text of Regulation 2024/1689 as amended by Regulation 2026/1744, read in its English-language version.
Status at 6 October 2026: who must do what, and since when
The table follows Article 113 of the Regulation, as worded after the omnibus, and the transitional provisions of Article 111. The roles are those of the text: the provider develops the system or has it developed and places it on the market under its own name, while the deployer uses it under its own authority in a professional context.
| Date | Obligation | Who | Article |
|---|---|---|---|
| 2 February 2025 | Eight prohibited practices; AI literacy of staff | All operators; providers and deployers | Art. 5, Art. 4 |
| 2 August 2025 | Obligations for general-purpose AI models; governance; national penalty regime | Model providers; Member States | Chapters V, VII and XII |
| 2 August 2026 | Transparency: chatbots, marking of generated content, deepfakes; Commission fines for general-purpose models | Providers and deployers; model providers | Art. 50, Art. 101 |
| 2 December 2026 | Machine-readable marking for generative systems placed on the market before 2 August 2026; two new prohibitions | Providers of generative systems; providers and deployers | Art. 111(4); Art. 5(1)(ba) and (bb) |
| 2 August 2027 | Compliance of general-purpose models placed on the market before 2 August 2025; national AI regulatory sandbox operational | Model providers; Member States | Art. 111(3), Art. 57 |
| 2 December 2027 | High-risk requirements for Annex III uses (employment, credit, education, biometrics...) | Providers and deployers | Art. 113(c)(i) |
| 2 August 2028 | High-risk requirements for regulated products under Annex I | Providers and manufacturers | Art. 113(c)(ii) |
| 2 August 2030 | High-risk systems used by public authorities, including those already in service | Providers and deployers of systems intended for public authorities | Art. 111(2) |
Where things stand on 6 October 2026
No new obligation started to apply in September or on 6 October. The next deadline falls on 2 December 2026. Providers of generative systems, including general-purpose ones, already on the market before 2 August will then have to mark their outputs, and the prohibitions targeting non-consensual intimate content and child sexual abuse material will become applicable. On the French side, the National Assembly's legislative file on the bill adapting French law to EU law (DDADUE) shows, as of 6 October, five committees seized, four of them for an opinion since 23 April 2026. It lists no report and no text adopted in committee. The Senate's file, updated on 4 September 2026, stops at the transmission of 20 February.
Regulation 2026/1744: three delays, new deadlines and a rewritten Article 4
Adopted after the European Parliament's position of 16 June 2026 and the Council's decision of 29 June, and signed in Strasbourg on 8 July, the omnibus does not remove any category of obligation. Its recital 40 justifies the delay for high-risk systems by "the delayed availability of standards, common specifications, and alternative guidance and the delayed establishment of national competent authorities".
- High risk: Sections 1 to 3 of Chapter III apply on 2 December 2027 for Annex III and on 2 August 2028 for Annex I, instead of 2 August 2026 and 2 August 2027.
- Transparency: a new Article 111(4) gives providers of generative systems placed on the market before 2 August 2026 until 2 December 2026 to comply with Article 50(2). Recital 38 refers to "a transitional period of four months".
- Prohibitions: two points are added to Article 5, applicable on 2 December 2026.
- AI literacy: Article 4 no longer requires operators to "ensure, to their best extent, a sufficient level" of AI literacy, but provides that providers and deployers "shall take measures to support" its development.
- Notified bodies: bodies already notified under the sectoral legislation of Annex I, Section A, remain authorised under conditions, as the 2024 text already provided. They must now apply for designation under the AI Regulation by 28 January 2028 at the latest (Art. 43(3)).
- Sandboxes: the deadline for the national AI regulatory sandbox moves from 2 August 2026 to 2 August 2027.
The text also creates the category of "small mid-cap enterprises" (SMCs), defined by Recommendation (EU) 2025/1099, which, together with SMEs, benefits from a simplified technical documentation form (Art. 11) and reduced fine ceilings. Finally, it moves to a new Article 4a the authorisation to process special categories of personal data under six conditions in order to detect and correct biases, which Article 10 reserved for providers of high-risk systems. Paragraph 2 of that article extends it to deployers of high-risk systems and to other AI systems and models, without creating "any obligation to conduct such bias detection and correction".
Article 5: eight prohibitions since 2025, two more on 2 December 2026
Since 2 February 2025, Article 5 has prohibited the placing on the market, putting into service or use of AI systems that:
- deploy subliminal or purposefully manipulative techniques (point (a));
- exploit vulnerabilities due to age, disability or a specific social or economic situation (point (b));
- carry out social scoring (point (c));
- predict the risk of a criminal offence based solely on profiling or personality traits (point (d));
- build facial recognition databases through untargeted scraping (point (e));
- infer emotions in the workplace or in education institutions, except for medical or safety reasons (point (f));
- categorise people on the basis of biometric data to deduce sensitive characteristics (point (g));
- are used for real-time remote biometric identification in publicly accessible spaces for law enforcement purposes, subject to exceptions (point (h), which only covers use).
Point (f) directly concerns employers: an emotion analysis tool applied to call centre employees falls under the prohibition.
The first addition made by the omnibus (point (ba)) targets systems that generate or manipulate realistic images, videos or audio showing the intimate parts of an identifiable person, or that person engaged in sexually explicit activities. The prohibition applies in the absence of that person's "freely-given, specific, informed, unambiguous and explicit consent". The second (point (bb)) targets systems that produce child sexual abuse material within the meaning of Directive 2011/93/EU. Recital 11 cites "nudification" applications. For the provider, the prohibition applies if such production is the intended purpose of the system, or if it is a "reasonably foreseeable and reproducible outcome" of the system in the absence of adequate technical safeguards (paragraph 1a). For the deployer, it only applies if the system is used for that purpose. A publisher of a consumer image generator must therefore be able to show, by 2 December 2026, that its filters reliably prevent these outputs.
Article 50: chatbots, deepfakes and marking, with a reprieve until 2 December
Article 50 has applied since 2 August 2026. It sets four obligations. The provider of a system that interacts directly with people must inform them that they are dealing with an AI, unless this is obvious from the context (paragraph 1). The provider of a system that generates audio, image, video or text must mark the outputs "in a machine-readable format" (paragraph 2). The deployer of an emotion recognition or biometric categorisation system informs the people exposed to it (paragraph 3). The deployer who disseminates a deepfake must disclose it (paragraph 4). The same obligation applies to generated text published to inform the public on matters of public interest, unless it has undergone editorial review under the responsibility of an identified person.
The Commission published its guidelines on Article 50 on 20 July 2026. The code of practice on the transparency of AI-generated content, finalised on 10 June 2026, includes a section for providers (marking and detection) and one for deployers (labelling). According to the Commission, around 190 organisations had signed it by the end of July. Adherence remains voluntary, but the Commission and the AI Board have deemed it adequate to demonstrate compliance; a company that does not sign it will have to prove the adequacy of its own measures before each market surveillance authority. The omnibus rewrote Article 50(7): the Commission, rather than the AI Office, facilitates these codes, and it assesses, taking utmost account of the opinion of the AI Board, whether adherence to them is adequate. The possibility of imposing common rules through an implementing act if the code is not adequate was already in the 2024 text.
A marketing department that disseminates an AI-generated video of an executive is the deployer of a deepfake and must disclose it.
AI literacy: an obligation of means to be documented
Article 4 has applied since 2 February 2025 to all providers and deployers, whatever the risk class of the system. Its new wording specifies that it "does not require" providers or deployers to guarantee any specific level of AI literacy of any individual. The obligation remains: it covers staff and other persons who use the systems on the company's behalf, contractors included, taking into account their knowledge and the context of use.
The Commission's FAQ, updated after the omnibus, states that no certificate is required and that the company may keep an internal record of training and support actions. It confirms that a company whose employees use ChatGPT to draft or translate must inform them of risks such as hallucinations, and that enforcement lies with national market surveillance authorities, not with the AI Office. According to the same page, these authorities have been supervising and enforcing Article 4 since 2 August 2026. For deployers of high-risk systems, Article 26 also maintains the obligation to assign human oversight to people with the necessary training.
High risk: HR, credit, education and biometrics on 2 December 2027
Annex III lists eight areas. For a private company, the most common are employment (recruitment, screening of applications, decisions on promotion or dismissal, performance monitoring) and access to credit (creditworthiness assessment of natural persons, excluding fraud detection). They are joined by pricing in life and health insurance, education and vocational training (admission, assessment, exam proctoring) and biometrics. These systems will have to meet the requirements of Chapter III (risk management, data quality, technical documentation, record-keeping, human oversight, robustness) from 2 December 2027. Products that include AI as a safety component (medical devices, toys, lifts...) move to 2 August 2028. ActuIA has detailed the consequences for HR tools.
Deployers have their own obligations: use in line with the instructions for use, human oversight, retention of logs and, for employers, informing workers' representatives and employees before putting the system into service (Art. 26(7)). Public bodies, private entities providing public services and companies that assess creditworthiness or price life and health insurance must carry out a fundamental rights impact assessment. The omnibus allows them to refer to the GDPR data protection impact assessment or to incorporate its relevant parts. The questionnaire template that the AI Office has been required to provide since 2024 will have to offer this option (Art. 27(4) and (5)). A system placed on the market before the date of application that concerns it is only subject to the Regulation if it subsequently undergoes significant changes in its design (Art. 111(2)).
The delay leaves fourteen months before the Annex III deadline. The 2024 text already required the Commission to request "without undue delay" standards covering the technical requirements of Chapter III, Section 2. The omnibus adds to Article 40 a request extended to the obligations of providers and deployers in Section 3. The Commission must also adopt, by 1 August 2027 at the latest, guidelines on the interplay with the sectoral legislation of Annex I (Art. 96(1), point (g)). A template for the post-market monitoring plan is expected by 2 September 2027 at the latest (Art. 72).
General-purpose models: the Commission can impose fines since 2 August 2026
The obligations of providers of general-purpose models (technical documentation, copyright compliance policy, public summary of training content, enhanced obligations for models with systemic risk) have applied since 2 August 2025. ActuIA reported on this when they started to apply. Article 101, which allows the Commission to impose fines of up to 15 million euros or 3% of worldwide turnover, had been excluded from that date: it has applied since 2 August 2026. The Commission announced on 31 July that the AI Office and national authorities would start enforcing the Regulation on that date. Models placed on the market before 2 August 2025 have until 2 August 2027.
The omnibus extends the competence of the AI Office (Article 75(1), as amended). The 2024 text already empowered it to supervise systems based on a general-purpose model where the model and the system come from the same provider; it now becomes solely competent for them. It also covers systems that constitute, or are integrated into, a very large online platform or a very large online search engine within the meaning of the DSA. Exceptions remain for Annex I products, critical infrastructure, the judiciary and certain systems of law enforcement, border and financial institutions. A company that integrates a third party's model into its own product, however, remains under the supervision of national authorities.
Penalties and authorities: France awaits its law, Germany has designated the Bundesnetzagentur
The ceilings in Article 99 have not changed:
- prohibited practices (Art. 5): 35 million euros or 7% of total worldwide annual turnover, whichever is higher;
- obligations of providers, authorised representatives, importers, distributors, deployers and notified bodies, and transparency under Article 50: 15 million euros or 3%;
- incorrect, incomplete or misleading information supplied to authorities: 7.5 million euros or 1%.
For SMEs, the lower of the two amounts applies, for all three tiers. The omnibus extends this rule to small mid-cap enterprises for the last two tiers only (new paragraph 6a). Article 4 does not appear in these lists: a breach falls under the regime that each Member State sets under Article 99(1).
In France, this regime and the authorities that will apply it depend on the DDADUE bill. On 17 February 2026, the Senate inserted provisions on the designation of the authorities through government amendments, after Article 24 of the text (votes in plenary), before adopting the bill as a whole on 18 February. The detailed allocation between authorities is set out in a scheme published by the Directorate General for Enterprise (DGE) on 9 September 2025, before the Senate's examination. According to the DGE, this scheme will be implemented "subject to its acceptance by Parliament through a bill". It gives the CNIL most of the prohibited practices and the Annex III high-risk systems: biometrics, employment, education, law enforcement, borders. Vocational training goes to the DGCCRF, which also handles coordination and acts as the single point of contact. Arcom and the DGCCRF share manipulative practices and the exploitation of vulnerabilities. For Article 50, they also share informing people (paragraph 1), the marking of generated content (paragraph 2) and deepfakes (paragraph 4). Arcom alone supervises generated text published to inform the public (paragraph 4), and the CNIL emotion recognition and biometric categorisation (paragraph 3). The ACPR supervises the credit and insurance systems of financial institutions.
Germany has completed this work. The KI-Marktüberwachungs- und Innovationsförderungsgesetz (KI-MIG), passed by the Bundestag on 11 June 2026 and published in the Bundesgesetzblatt on 28 July (BGBl. 2026 I No. 233), has been in force since 29 July. The Bundesnetzagentur becomes the market surveillance authority, point of contact and complaints desk, with existing sectoral authorities retaining their competences. For a company operating on both sides of the Rhine, the German counterpart is identified by law, while the French one is so far only identified by a bill. The obligations of the Regulation, which are directly applicable, nevertheless run in the same way in both countries.
Upcoming deadlines and update log
Three points are to be followed until the next update. The first is the examination of the DDADUE bill by the Economic Affairs Committee of the National Assembly, for which the file shows no date as of 6 October. Next comes 2 December 2026, for the marking of generative systems already on the market and the two new prohibitions, followed by the publication of harmonised standards on high-risk systems. For the context prior to the omnibus, see the countdown to 2 August 2026 and the entry into application of the first measures in February 2025 (in French).
- 6 October 2026: first version. Timeline checked against Regulation 2026/1744 (OJ of 24 July 2026); status of the DDADUE bill checked on the Senate and National Assembly websites; German status checked on the websites of the Federal Ministry for Digital Affairs and the Bundesnetzagentur.
