The EU AI Act after the Digital Omnibus: why it reaches Zambian businesses and what applies now
The EU AI Act applies beyond Europe. It reaches providers placing AI systems on the Union market and businesses in third countries whose AI output is used in the EU. The high-risk obligations were deferred to December 2027, but transparency obligations took effect on 2 August 2026 and a further deadline falls on 2 December 2026.
Why
a European regulation matters in Lusaka
The
European Union’s Artificial Intelligence Act is not confined to businesses
established in Europe. Article 2 of Regulation (EU) 2024/1689 extends the
regime to providers who place an AI system on the Union market irrespective of
where they are established, and, more broadly still, to providers and deployers
established in a third country where the output produced by the AI system is
used in the Union.
That
second trigger is the one that reaches Zambian businesses, and it sets a lower
threshold than the General Data Protection Regulation. The GDPR requires an element
of targeting, of offering goods or services to people in the Union or
monitoring their behaviour. The AI Act asks only whether the output is used
there. A Zambian software company whose tool scores applicants for a European
employer, a Zambian business unit within a European group, a service provider
whose analytical output is consumed by a client in the Union: each may be
within scope without ever having sold into Europe directly.
The
consequences are not trivial. Penalties for the most serious breaches reach the
higher of thirty-five million euro or seven per cent of worldwide annual
turnover, and a provider established outside the Union placing a high-risk
system on the market must appoint an authorised representative established in
the Union before doing so. For
that reason, the question of what the AI Act now requires, and what was
recently postponed, is a live one for Zambian businesses with European
customers, European group companies or European-facing digital products. The
remainder of this article sets out the current position.
A
deferral is not a pause
On
27 July 2026 the Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into
force, six days before the date on which the EU AI Act high-risk obligations
were due to apply. For eighteen months organisations had been working towards 2
August 2026. That deadline has moved, and the question every board is now
asking is whether the pressure has come off.
It
has not. The Omnibus deferred one part of the regime and left the rest
untouched. Obligations that apply by reference to what an AI system does,
rather than to the risk tier it occupies, took effect on 2 August 2026 exactly
as originally scheduled. A second date falls on 2 December 2026. The
reputational and legal risk in this period is not that firms miss a distant
deadline. It is that they read a headline about delay, stand down a programme,
and fail obligations that are already live.
What
the Omnibus actually changed
The
instrument amends the AI Act, Regulation (EU) 2024/1689, and is the first
formal set of amendments since its adoption. It was approved by the European
Parliament on 16 June 2026, adopted by the Council on 29 June 2026, signed on 8
July 2026, published in the Official Journal on 24 July 2026 and entered into
force on the third day following publication.
The
central change is the deferral of the high-risk obligations. For stand-alone
high-risk systems classified under Annex III, covering use cases in areas
including employment, education, credit scoring, biometrics, critical infrastructure
and law enforcement, the application date moves from 2 August 2026 to 2
December 2027. For AI embedded in products already governed by EU sectoral
safety legislation under Annex I, including medical devices, machinery and
toys, the date moves to 2 August 2028. Providers of high-risk systems intended
for use by public authorities have a further extended period under Chapter III.
Two
features of the new timetable deserve attention. The dates are now fixed rather
than linked to the finalisation of harmonised standards, which removes an
uncertainty that had made programme planning difficult. And the deferral is
expressed as a change of date, not a change of substance: the obligations
themselves, covering risk management, data governance, technical documentation,
human oversight, conformity assessment and registration, are unchanged.
What
applied on 2 August 2026 and did not move
The
transparency obligations in Article 50 were not amended by the Omnibus and took
effect on schedule. They apply according to the function of the system rather
than its risk classification, which means mainstream generative deployments are
squarely within scope notwithstanding the Annex III deferral. From
2 August 2026, providers and deployers must disclose that a person is
interacting with an AI system. Deployers must disclose deepfakes depicting real
persons, places or events. Deployers of emotion recognition and biometric
categorisation systems must inform the individuals exposed to them and must
process personal data in accordance with EU data protection law, subject to
limited exceptions for the detection, prevention and investigation of criminal
offences.
Two
other bodies of obligation also remain on their original timetable. The
prohibited practices in Article 5 have applied since February 2025. The
obligations on providers of general-purpose AI models, including transparency,
documentation and systemic risk requirements for the largest models, have
applied since August 2025 and were not touched.
The
date that most firms will miss: 2 December 2026
Article
50(2) requires providers of systems generating synthetic audio, image, video or
text to mark outputs in a machine-readable and detectable format. The Omnibus
granted a limited transitional period, but only for systems already on the
market. A generative system placed on the EU market before 2 August 2026 must
comply with the marking obligation by 2 December 2026. A system placed on the
market on or after 2 August 2026 must comply from that date. This
is a four-month grace period, shorter than the six months originally proposed,
and it is the single most commonly misunderstood element of the current
position. Firms that read the Omnibus as a general delay will treat
watermarking as a 2027 problem. It is not. For legacy generative systems it is
a December 2026 problem, and machine-readable marking is an engineering change
rather than a policy document.
Two
new prohibited practices from 2 December 2026
The
Omnibus adds prohibitions directed at AI systems used to create non-consensual
intimate imagery and child sexual abuse material. The prohibition reaches the
placing of such systems on the EU market for that purpose, and also the placing
on the market of systems without reasonable safety measures to prevent such
creation. It applies from 2 December 2026. For
providers of general-purpose generative systems this is a design and safeguards
question rather than a disclosure question, and the obligation to have taken
reasonable preventive measures cannot be satisfied retrospectively after a
system is already in the market.
The
wider Digital Omnibus Package is not law
The
AI Omnibus is the artificial intelligence strand of a broader package published
by the Commission on 19 November 2025. The remainder of that package, which
proposes amendments to the General Data Protection Regulation, the ePrivacy
Directive, the NIS2 Directive and the Data Act, remains subject to negotiation
in the Parliament and the Council and has not been adopted. This
distinction matters commercially. Advisers and vendors have begun to describe
the package as though it were a single enacted reform. It is not. Only the AI
strand is in force. Any compliance decision taken on the assumption that NIS2
or GDPR obligations have been simplified is being taken on a proposal, and the
negotiating history of the AI strand shows how much can change between proposal
and adoption.
Where
this meets DORA, NIS2 and existing supervisory expectations
For
regulated financial entities the AI Act does not arrive in isolation. DORA has
applied since 17 January 2025 and is now in its first genuine supervisory
cycle. NIS2 obligations continue to bite through national transposing law. An
AI system that fails inside a regulated firm can engage ICT incident reporting
under DORA, cybersecurity incident notification under national NIS2 rules,
personal data breach notification under the GDPR and, depending on the system,
AI Act obligations at the same time.
Supervisors
have already signalled that they expect this to be governed as one problem. In
their first annual report on major ICT-related incidents, published on 3 June
2026, the European Supervisory Authorities noted that the evolution of highly
capable AI-driven tools should encourage financial entities to strengthen
cybersecurity measures. The practical consequence is that AI governance is not
a separate workstream that can wait until December 2027. It sits inside the ICT
risk, incident and third-party frameworks that regulated firms are already
required to operate.
A
sensible engagement sequence
The
right starting point is a paid legal and regulatory assessment that establishes
which systems the organisation actually provides and deploys, how each is
classified, which obligations are live today, and what falls due on 2 December
2026. Only after that diagnostic can a remediation or implementation programme
be scoped and priced responsibly. OIKONOMAKIS LAW performs the legal and
regulatory workstream; F SOCIETY provides the operational readiness,
governance, controls and evidence workstream, with specialist technical
providers used where required.
Deeper
analysis and implementation
Transparency applies by function, not by risk tier
The
most consequential structural point in the current position is that Article 50
does not depend on the Annex III classification. An organisation can conclude,
correctly, that none of its systems is high risk, and still be fully within the
transparency regime because it deploys a customer-facing chat interface,
generates marketing copy or images with a generative tool, or uses synthetic
voice in a service channel.
This
is where the deferral does most damage if it is misread. A classification
exercise that stops at the high-risk question, concludes that nothing is in
scope and closes the file will produce a compliant-looking record and a
non-compliant organisation. The classification must run twice: once against
Annex III, and once against the functional triggers in Article 50. Article
50 also contains an editorial control element for AI-assisted content that
undergoes human review before publication. The scope of that carve-out should
be assessed against the actual editorial workflow rather than assumed, because
a review process that is nominal will not support it.
The deferral changes the deadline, not the build time
Conformity
assessment, technical documentation under Annex IV, risk management, data
governance, human oversight and post-market monitoring are not documentation
exercises that can be produced in the final quarter before a deadline. They
describe how a system is designed, tested, recorded and supervised across its
lifecycle. An organisation that stands down its high-risk programme in August
2026 and restarts in mid-2027 will have lost the interval in which the
underlying capability could have been built, and will be assembling evidence
about a period during which nothing was recorded. Standards
and Commission guidance are expected to continue developing through the
deferral period. Firms that maintain their programme will be able to align to
those instruments as they emerge. Firms that stopped will be reading them for
the first time under time pressure.
Governance, evidence and the supervisory record
The
organisation should be able to produce, on request, an inventory of AI systems
provided and deployed, the classification decision for each with the reasoning
and the person accountable for it, the transparency measures implemented and
the date they took effect, and the change-control process that determines when
a system is reassessed. Classification decisions should carry an owner, a date,
a source and a statement of what change would require the decision to be
revisited.
The
same discipline that DORA supervision has begun to apply to the Register of
Information will be applied here in due course: a defensible record is one in
which an independent reviewer can trace the path from obligation to decision to
implementation, and in which the gaps that were identified were owned and
managed rather than silently left open.
Frequently
asked questions
Has the EU AI Act been delayed? Only in part. The Digital
Omnibus on AI deferred the high-risk obligations for stand-alone Annex III
systems to 2 December 2027 and for Annex I embedded systems to 2 August 2028.
The transparency obligations in Article 50, the prohibited practices in Article
5 and the general-purpose AI model obligations were not deferred.
What applied from 2 August 2026? Disclosure that a person
is interacting with an AI system; disclosure of deepfakes depicting real
persons, places or events; and notification obligations for emotion recognition
and biometric categorisation systems. These apply by reference to what the
system does, not to its risk tier.
When must AI-generated content be watermarked? Systems
placed on the EU market on or after 2 August 2026 must comply from that date.
Generative systems already on the market before 2 August 2026 have until 2
December 2026. Machine-readable marking is an engineering change and should not
be left to the final weeks.
We have concluded that none of our systems is high risk.
Are we outside the regime? Not necessarily. Article 50 applies according to
system function rather than classification. A classification exercise that
tests only against Annex III and closes will miss live obligations. The
assessment should run against both.
Do the GDPR and NIS2 changes in the Digital Omnibus
apply? No. Only the AI strand has been adopted and is in force. The proposed
amendments to the GDPR, the ePrivacy Directive, NIS2 and the Data Act remain in
negotiation and are not law.
Should we stand down our high-risk programme until 2027?
We would not advise it. The obligations are unchanged; only the date moved.
Conformity assessment, technical documentation and post-market monitoring
describe how a system is built and supervised over time, and cannot be
reconstructed for a period during which nothing was recorded.
Does the AI Act apply to a business established in
Zambia? It
can. Article 2 reaches providers placing an AI system on the Union market
wherever they are established, and providers and deployers in a third country
where the output produced by the system is used in the Union. A Zambian
business with European customers, a European parent or subsidiary, or a product
whose output is consumed in Europe should assess its position rather than
assume it is outside the regime.