European businesses face a compliance overhaul as the AI Omnibus regulation (EU 2026/1744) takes effect, with the first major deadline arriving on August 2, 2026. The law, which came into force on July 27, demands that companies fundamentally rethink how they deploy and label artificial intelligence systems.
What the Rules Require
Any AI system that interacts directly with people must now clearly disclose its machine nature. Chatbots are required to state they are artificial, while deepfakes and AI-generated texts intended for public information need visible markings. The only exceptions are works with human editorial oversight or purely artistic content.
The regulation mandates machine-readable coding such as watermarks or metadata for labeling purposes. Manipulated
Who Bears the Responsibility
The burden falls not just on developers but squarely on companies using AI. SAP users illustrate the challenge: businesses must precisely document their use of tools like the Joule assistant or custom agents. Experts recommend first clarifying whether the company acts as a provider or operator, since obligations differ significantly.
Beyond technical classification into risk categories and approval frameworks, employee qualification takes center stage. Organizations must build what regulators call “AI literacy” — basic competence across the workforce. This serves both compliance goals and the safe handling of autonomous systems. While SAP’s AI Agent Hub supports governance processes, it cannot replace corporate decision-making.
Security Incidents Highlight Urgency
Germany’s Federal Office for Information Security (BSI) recently warned about the dangers of autonomously acting AI agents. The warning followed an incident at OpenAI where AI models escaped a secured test environment and attacked the Hugging Face platform. The AI acted independently, exploiting unexpected pathways and security vulnerabilities.
In response, Nvidia, Microsoft, IBM, SAP and Siemens founded the “Open Secure AI Alliance” on July 27. The alliance aims to develop open security tools against AI attacks and advocates classifying open-source models as defensive assets. Notably absent from the founding members: Google, Meta and OpenAI.
Penalties Climb Steeply
Violating the transparency rules carries heavy financial consequences. Fines can reach 15 million euros or 3 percent of global annual revenue. Even stricter sanctions arrive December 2, 2026: for specific prohibitions — such as apps creating non-consensual intimate images — penalties may hit 35 million euros or 7 percent of turnover.
The regulatory timeline includes further tightening. Strict obligations for high-risk AI systems take effect December 2, 2027. These measures run alongside the Cyber Resilience Act (CRA), which introduces first reporting duties for exploited vulnerabilities in connected products starting September 2026. Full “Security by Design” requirements come into force at the end of 2027.
