AI Act Round-Up: Recent Developments

The EU AI Act has continued its transition from legislative framework to practical regulatory regime, with important developments in recent weeks at both EU and national level. This briefing highlights the key milestones since our last round-up, and what these updates mean for organisations in scope.

Digital Omnibus on AI

The Digital Omnibus on AI (which amends the EU AI Act) came into effect on 27 July 2026, following its publication in the Official Journal on 24 July 2026. Key practical impacts include:

  • Postponed timelines for certain high-risk AI obligations: rules for stand-alone high-risk systems will apply from 2 December 2027, and those embedded in safety-regulated products will apply from 2 August 2028.
  • Watermarking requirements under Article 50(2) of the EU AI Act are postponed until 2 December 2026.
  • An outright ban on AI tools that generate non-consensual sexually explicit content or child sexual abuse material, with compliance required by 2 December 2026.

Overlaps with product safety laws are addressed, limited processing of special category personal data is permitted with safeguards, certain exemptions are extended to small mid-cap enterprises, and general-purpose AI enforcement is centralised in the EU's AI Office.

Key AI Act Provisions Now in Effect

From 2 August 2026, key provisions of the EU AI Act have come into effect, with the European Commission's AI Office, national competent authorities and the European Data Protection Supervisor now empowered to commence enforcement in relation to: the bulk of the Article 50 transparency obligations, prohibited AI practices and certain rules governing general-purpose AI (GPAI) models. GPAI model operators should now be live to the possibility of related regulatory requests for information. Further information relating to the transparency compliance requirements can be found below.

Transparency under Article 50

On 20 July 2026, the European Commission published its final guidelines on transparency obligations for providers and deployers of certain AI systems under Article 50. The guidelines define the scope of the transparency obligations and clarify which providers and deployers must comply, including obligations in respect of marking and labelling AI-generated content such as deepfakes and AI-generated or manipulated content. They also address transparency requirements for interactive AI systems (e.g. chatbots), emotion recognition systems, and biometric categorisation systems.

As mentioned above, the Article 50 obligations (with the exception of the provider marking and detection of AI-generated or manipulated content requirements, which take effect on 2 December 2026) became applicable on 2 August 2026. The European Commission has confirmed that approximately 190 organisations had signed the Code of Practice on Transparency of AI-generated Content ahead of this deadline.

For further information on the requirements under Article 50 of the EU AI Act, read our two-part series of briefings on the Article 50 guidelines here and here.

Ireland’s Regulation of Artificial Intelligence Act

The Regulation of AI Act 2026 came into operation on 31 July 2026, with that date also appointed as the establishment day for the Act under related commencement and establishment orders. A further designation amendment instrument updates the market surveillance authority designations under the 2025 designation regulations, also with effect from 31 July 2026.

AI Office of Ireland

On 30 July 2026, the Department of Enterprise, Trade and Employment (DETE) announced the establishment of Oifig IS na hÉireann (the AI Office of Ireland) under the Regulation of Artificial Intelligence Act 2026, together with the appointment of Paul Byrne as its first Chief Executive Officer, and subsequently appointed members to its Board.

The AI Office of Ireland operates as the effective “AI regulator” of Ireland and is appointed, pursuant to the Regulation of Artificial Intelligence Act 2026, to:

  • Operate as the Single Point of Contact for the EU AI Act for the European Commission, national sectoral regulators and the public;
  • Develop a consistent regulatory framework for the implementation of the EU AI Act, and the Regulation of Artificial Intelligence Act 2026;
  • Facilitate centralised access to technical expertise for other competent authorities, as required; and
  • Drive AI innovation and adoption.

Complaints channel for GPAI Downstream Providers

On 31 July 2026, the European Commission published a complaints channel for downstream providers using general purpose AI (“GPAI”) models. The channel is notable because it recognises the practical position of downstream providers, who may depend on information and co-operation from GPAI model providers in order to understand and comply with their own obligations under the EU AI Act.  Downstream providers integrating or building on GPAI models should consider whether the channel may be relevant where they encounter issues in obtaining the information needed to assess, document or manage their EU AI Act compliance obligations.

Expert Findings – Frontier AI

On 15 July 2026, the EU AI Office published a report of expert recommendations on strengthening Europe’s frontier AI capabilities, with a focus on competitiveness, sovereignty and security. The report notes that developers of frontier AI models are predominantly based outside the EU and calls for a coordinated European strategy covering investment, talent, compute infrastructure and regulatory clarity. The report signals a broader EU policy shift beyond risk regulation towards supporting competitive European AI capabilities. Its recommendations may inform future EU funding, public procurement and the regulatory framework for GPAI models.

Cybersecurity and AI Action Plan

On 7 July 2026, the European Commission published an Action Plan on the cybersecurity risks and opportunities arising from advanced AI. The plan seeks to strengthen EU resilience against AI-enabled cyber threats through closer co-operation between Member States, industry and EU bodies, including measures to evaluate advanced AI models, support secure access to AI systems for cybersecurity purposes, test AI applications in critical sectors, and promote European AI cybersecurity solutions.

How Can McCann FitzGerald Help?

For further information or assistance, please reach out to one of the key contacts below, or your usual contact at McCann FitzGerald LLP.

 

This content has been prepared by McCann FitzGerald LLP for general guidance only and should not be regarded as a substitute for professional advice. Such advice should always be taken before acting on any of the matters discussed.

Key Contacts