If you run an AI assistant, an AI writing tool, or any AI-powered feature that serves EU users from your own server, August 2, 2026 is a date worth marking. EU institutions reached a provisional political agreement on the Digital Omnibus on AI, which postpones the high-risk compliance deadlines but does not postpone the transparency duties.

What Moved and What Didn't

  • Postponed: obligations for Annex III (use-based) high-risk AI systems move from August 2, 2026 to December 2, 2027. High-risk systems embedded in regulated products under Annex I — medical devices, machinery — move from August 2027 to August 2, 2028.
  • Not postponed: Article 50 transparency obligations remain on the original August 2, 2026 timeline — telling people when they are interacting with an AI system, and labelling AI-generated content.
  • Newly added: a prohibition covering AI-generated non-consensual intimate imagery and child sexual abuse material was introduced into Article 5.

One caveat: these changes only take legal effect once the Omnibus is formally adopted and published in the Official Journal, which is expected before August 2, 2026. The published text governs. This article is not legal advice — consult a qualified lawyer for your specific situation.

Why This Reaches Small Teams and Solo Site Owners

A common assumption is that the AI Act only targets model vendors. In practice, Article 50 speaks to deployers — that is, you. If your site offers AI chat or AI-generated text and images to EU users, you are inside the scope of the transparency duties. And that is precisely the piece that was not delayed.

A Practical Checklist

  • Make the AI visible as AI: state clearly in the first view of the chat widget that users are talking to an AI assistant. Don't dress it up with a human name and photo.
  • Label AI-generated content: articles and images that were generated or substantially rewritten by AI should carry a visible marker on the page.
  • Keep traceable logs: request timestamps, which model was used, whether a human reviewed the output. That is your evidence trail if anything is questioned. Where logs contain personal data, apply GDPR minimisation and retention limits too.
  • Update your privacy policy and terms: spell out which features are AI-powered, where data goes, and whether a third-party model API receives user input.
  • Decide where data lands: for EU-facing services, keeping the application and its logs in an appropriate region cuts the cost of explaining cross-border transfers.

Why Self-Hosting Helps on Compliance

The question that most often stalls a compliance review is: where exactly is user data stored, and who can reach it? With third-party SaaS, that answer usually isn't yours to give. On your own VPS, data location, retention, access control and log format are all yours to define — and easy to answer precisely. SharkCloud offers multiple regions and dedicated instances, so you can place deployments near your target users and turn "where does the data live" into a concrete line you can put in your privacy policy.