AI GovernanceAugust 13, 202615 min read

EU AI Act: what changes on December 2, 2026 (checklist)

On 2 December 2026 two new Article 5 prohibitions apply and the machine-readable marking grace period ends. A checklist by role and horizon through 2027 and 2028.

Antonella Serine

Antonella Serine

Founder, KLA

Founder of KLA, building the independent runtime governance control plane for regulated AI agents under the EU AI Act.

2 December 2026

Two new Article 5 prohibitions apply: AI systems that generate child sexual abuse material and systems that generate non-consensual intimate imagery. The machine-readable marking grace period for generative systems already on the market ends the same day.

2 December 2027

Chapter III obligations for stand-alone Annex III high-risk systems classified under Article 6(2), together with Article 27 FRIA and Article 49 registration.

2 August 2028

Chapter III obligations for high-risk AI embedded in Annex I regulated products. Law-firm analyses of the Omnibus also report a Commission delegated act on sectoral-law overlaps due by this date.

Already in force

The obligations that applied on 2 August 2026 stay in force: Article 50 transparency, Article 101 Commission fines on GPAI model providers, Chapter V model duties, and the original Article 5 prohibitions.

On 2 December 2026 two things happen under the EU AI Act as amended by Regulation (EU) 2026/1744, the Digital Omnibus on AI. Two new Article 5 prohibitions start to apply, covering AI systems that generate child sexual abuse material and systems that generate non-consensual intimate imagery of an identifiable person. The four-month transitional period for machine-readable marking of synthetic content ends the same day, so generative systems placed on the market before 2 August 2026 must mark their output from that date. This article turns those two changes, and the deadlines that follow in 2027 and 2028, into a checklist by role and by planning horizon for compliance officers at providers and deployers. Orientation only; not legal advice.

The dates, from December 2026 outward

The Digital Omnibus on AI rewired Article 113, the article that sets when each part of the Act applies. The result is a sequence of fixed calendar dates. The Commission AI framework page confirms the 2 December 2027 date for Annex III systems and 2 August 2028 for product-embedded systems, and describes the December 2026 prohibition on generated non-consensual intimate content.

Everything that applied on 2 August 2026 stays applicable. The August 2026 guide covers that layer in detail: Article 50 transparency for providers and deployers, Article 101 enforcement against general-purpose AI model providers, and the Chapter V model obligations in force since August 2025.

EU AI Act application dates from December 2026, after the Digital Omnibus
DateWhat starts to applyWho carries it
2 December 2026New Article 5 prohibitions: generation of child sexual abuse material and of non-consensual intimate imageryEvery provider and deployer, at every risk tier
2 December 2026End of the machine-readable marking transitional period for generative systems placed on the market before 2 August 2026Providers of generative AI systems
2 August 2027At least one operational AI regulatory sandbox per Member State (Article 57); GPAI models placed on the market before 2 August 2025 must comply by 2 August 2027 under Article 111(3)Member States; legacy GPAI model providers
2 December 2027Chapter III obligations for stand-alone high-risk systems classified under Article 6(2) and Annex III, with Article 27 FRIA and Article 49 registrationProviders and deployers of Annex III systems
2 August 2028Chapter III obligations for high-risk AI that is a safety component of an Annex I regulated product; reported deadline for the Commission delegated act on sectoral-law overlapsProviders of product-embedded AI; the Commission

Change one: two new prohibitions with a penalty ceiling of 7%

The Omnibus added two practices to Article 5, both applicable from 2 December 2026. AI systems that generate or manipulate child sexual abuse material, and AI systems that generate or manipulate realistic sexual or intimate imagery of an identifiable person without their consent, are prohibited. The prohibition reaches a provider where that output is the intended purpose of the system or a reasonably foreseeable and reproducible result without significant technical modification.

Article 5 breaches sit in the top penalty tier of Article 99: up to EUR 35 million or 7% of total worldwide annual turnover, whichever is higher for an undertaking. That tier has applied to the original prohibitions since 2 February 2025; the two new categories join it on 2 December 2026.

The compliance work is concrete. A team shipping image, video, or audio generation needs adversarial test coverage against both categories, refusal behaviour that survives paraphrase and system-prompt pressure, and retained test results. A deployer embedding a third-party generator needs the same assurance in writing from the vendor.

Change two: the marking grace period ends

Article 50(2) requires providers of systems that generate synthetic audio, image, video, or text to mark outputs in a machine-readable format and make them detectable as artificially generated or manipulated, as far as technically feasible. The duty applied on 2 August 2026 for systems placed on the market from that date. Systems already on the market before 2 August 2026 received one transitional period, which ends on 2 December 2026.

From 2 December 2026 the distinction between old and new systems disappears for this duty. Non-compliance sits in the Article 99(4)(g) tier: up to EUR 15 million or 3% of worldwide annual turnover, whichever is higher. The Article 50 checklist covers the full transparency control set, including the disclosure and deepfake-labelling duties that carried no grace period at all.

Provider checklist: this quarter (before 2 December 2026)

Work items for the provider role, ordered so that the items with hard December dates come first.

  • Close out machine-readable marking on every generative system placed on the market before 2 August 2026. Verify the marking survives your real output paths: API responses, file exports, embedded viewers.
  • Red-team the two new prohibitions. Run structured adversarial tests for CSAM and non-consensual intimate imagery generation on every model and system you place on the market. Keep the test plans and results.
  • Re-check Article 50(1) disclosure on interactive systems: informed no later than first interaction, clear and distinguishable, in each language the surface serves.
  • Record the evidence. For each control, keep a record that it ran: marking applied per output pipeline, disclosure served per surface, refusal behaviour per test cycle.
  • Confirm your classification position. Record the Article 6 reasoning for each system, including any position that a system is out of Annex III scope. The risk classifier walks the Annex III logic.

Deployer checklist: this quarter (before 2 December 2026)

A deployer runs an AI system under its own authority. Most enterprises hold this role for most of their AI estate.

  • Inventory generative surfaces. List every place your organisation publishes or distributes AI-generated media, including marketing assets produced with third-party tools.
  • Get vendor commitments in writing for the 2 December 2026 marking close-out on any generative product that shipped before 2 August 2026, and for refusal behaviour on the two new prohibited categories.
  • Keep the deepfake and public-interest text disclosures running. These deployer duties under Article 50(4) have applied since 2 August 2026 and continue unchanged; tie each disclosure to a release-time regression check.
  • Check internal tooling. An internal image tool that can produce intimate imagery of an identifiable person is in scope of the new prohibitions even when no output is published.
  • Log that controls fired. A record written at the time of the interaction answers a supervisor faster than a policy document.

Provider checklist: 2027 (to 2 December 2027)

Chapter III arrives for stand-alone Annex III systems on 2 December 2027, with the same substance it always carried: risk management (Article 9), data governance (Article 10), technical documentation (Article 11), logging (Article 12), transparency to deployers (Article 13), human oversight design (Article 14), accuracy and robustness (Article 15), and the Article 17 quality management system. The Omnibus deadline guide lists every date that moved.

  • H1 2027: operate risk management and data governance with evidence, and make Article 12 logging capture the fields the Annex IV technical file will need.
  • H1 2027: design human oversight into the product. Article 14 asks for a person who can interpret output, override it, and stop the system; that takes an interface and a record.
  • H2 2027: assemble the Annex IV file and run the Article 17 QMS with internal audit evidence. Small mid-caps can use the simplified documentation forms the Omnibus extended to them.
  • H2 2027: choose the conformity assessment route and, where a notified body is required, book it. Capacity does not grow with the deadline.
  • By 2 December 2027: register under Article 49, including systems self-assessed as not high-risk under Article 6(3) with the reduced Annex VIII payload, and sign the declaration of conformity.

Deployer checklist: 2027 (to 2 December 2027)

The deployer duties in Article 26 and the Article 27 fundamental rights impact assessment follow the Annex III date.

  • Classify your deployments against Annex III and record the reasoning. Creditworthiness assessment, insurance risk pricing for life and health, employment decisions, and essential-service access are the common enterprise triggers.
  • Draft FRIAs early for in-scope systems. The assessment describes the deployment process, affected people, specific risks, oversight measures, and remedies; most of that content exists only once the oversight model is decided.
  • Assign oversight owners per high-risk system, with authority to suspend use, and log their interventions.
  • Verify vendor readiness. Ask each provider for its conformity assessment plan, instructions for use, and logging interface; Article 26 duties assume those inputs exist.
  • Use existing DPIAs. Article 27(4) lets a GDPR data protection impact assessment be complemented rather than duplicated.

2028: product-embedded AI and the sectoral-overlap question

High-risk AI that is a safety component of a product covered by the Annex I harmonisation legislation, such as machinery, medical devices, or lifts, follows the sectoral conformity assessment already required for that product. Chapter III applies to those systems from 2 August 2028.

The Omnibus also addressed the overlap between the AI Act and sectoral product law. Analyses by Orrick, Gibson Dunn, and Cooley report that the Commission is empowered to limit AI Act requirements where sectoral legislation imposes equivalent obligations, with a delegated act on those overlaps due by 2 August 2028, and that AI systems covered by the Machinery Regulation are largely taken out of parallel AI Act scope. Those firms also report a deferral to 2 August 2030 for certain high-risk systems used by public authorities. Confirm the exact scope of each carve-out against the Official Journal text before relying on it.

  • Providers of embedded AI: align the Chapter III work with the sectoral conformity cycle for the host product, and reuse the Annex IV structure across both files.
  • Deployers buying regulated products with AI inside: ask which regime the vendor treats as leading, and get the 2028 plan in the contract.
  • Both roles: track the sectoral-overlap delegated act; it determines how much duplicated documentation the 2028 wave actually requires.

Supervision and the small mid-cap category

Two structural Omnibus changes shape who you will deal with and under what regime. The Commission describes reinforced AI Office powers and centralised oversight of systems built on general-purpose AI models. Law-firm analyses add detail: the AI Office holds exclusive supervisory competence over AI systems built on a general-purpose model where the same provider or group supplies both, and over AI systems integrated into very large online platforms and search engines designated under the Digital Services Act, with powers that include investigations, inspections, binding commitments, and fines. For a GPAI-based system, the supervisory conversation moves to Brussels.

The Omnibus also extended the simplifications previously reserved for SMEs to small mid-caps. Orrick reports the thresholds as fewer than 750 employees and up to EUR 150 million turnover or EUR 129 million balance sheet total, drawing on Commission Recommendation (EU) 2025/1099, with simplified documentation templates, proportionate quality management, priority sandbox access, and proportionate penalties. An organisation near those thresholds should establish its status now, because it changes the Article 17 and Annex IV workload for 2027.

Evidence is the common thread

Each checklist item above ends the same way: show that the control ran on the day it mattered. The marking pipeline, the disclosure, the refusal, the oversight decision, and the classification reasoning all need a record produced while the work happened.

That is the layer KLA operates. The KLA Policy Engine evaluates a Decision Request before a governed agent action runs, Decision Desk holds the require_approval outcomes for a named human, and Evidence Room produces a Sealed Evidence Bundle a third party can verify offline. Building that layer during the December 2026 transparency work means the 2027 high-risk evidence exists as a by-product of operating, and the EU AI Act hub maps each obligation to the control that produces its record.

Frequently Asked Questions

What changes on 2 December 2026 under the EU AI Act?

Two new Article 5 prohibitions start to apply, covering AI systems that generate child sexual abuse material and systems that generate non-consensual intimate imagery of an identifiable person. The same day, the transitional period ends for machine-readable marking of synthetic content by generative systems placed on the market before 2 August 2026.

Are the December 2026 changes affected by the high-risk delay?

No. The Digital Omnibus moved the high-risk dates to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I products, and itself created the two December 2026 obligations. Both apply regardless of any system’s risk classification.

What penalties attach to the new prohibitions?

Article 5 breaches sit in the top Article 99 tier: up to EUR 35 million or 7% of total worldwide annual turnover, whichever is higher for an undertaking. Missing the machine-readable marking duty sits in the Article 99(4) tier of EUR 15 million or 3%. Article 99(6) caps fines for SMEs at the lower of the two amounts.

Do the obligations that applied in August 2026 change?

They stay in force unchanged: the Article 50 transparency duties, the Article 101 Commission fining power over general-purpose AI model providers, the Chapter V model obligations, and the original Article 5 prohibitions. December 2026 adds obligations on top of that layer.

What is a small mid-cap under the amended AI Act?

The Omnibus extended SME simplifications to small mid-caps. Orrick reports the thresholds as fewer than 750 employees and up to EUR 150 million turnover or EUR 129 million balance sheet total, referencing Commission Recommendation (EU) 2025/1099, with simplified documentation, proportionate quality management, sandbox priority, and proportionate penalties. Confirm status against the recommendation’s criteria.

When do high-risk obligations finally apply?

2 December 2027 for stand-alone high-risk systems classified under Article 6(2) and Annex III, including the Article 27 FRIA and Article 49 registration. 2 August 2028 for high-risk AI embedded in Annex I regulated products. Law-firm analyses also report 2 August 2030 for certain public-authority systems.

Key Takeaways

December 2026 is a compact delivery window with two hard items: refusal controls for the new Article 5 prohibitions and machine-readable marking on every generative system, old or new. The 2027 and 2028 waves are larger and reward starting from the December work, because the inventory, classification records, and evidence capture built this quarter feed the Annex IV file, the FRIA, and the registration payload directly. Classify your own systems against the Annex III logic with the free risk classifier. This article is general information and not legal advice; confirm your obligations with qualified counsel and check the Official Journal text before relying on any date.

See It In Action

Ready to automate your compliance evidence?

Book a 20-minute demo to see how KLA helps you prove human oversight and export audit-ready Annex IV documentation.

EU AI Act: what changes on December 2, 2026 (checklist) | KLA Blog