EU Data & AI Regulation Brief: Issue 1, October 2026
The AI Act's high-risk deadline has moved to December 2027, transparency duties are live, and GDPR enforcement just got sharper. What changed and what governance teams should do about it.
By Ronny K Roy
This month in one minute
The AI Act's high-risk deadline has moved to December 2027, but transparency duties are live and GDPR enforcement just got sharper.
- High-risk AI is delayed, not cancelled. The Digital Omnibus on AI (Regulation (EU) 2026/1744) entered into force on 27 July 2026. Annex III obligations now apply from 2 December 2027.
- Article 50 transparency applies now. Chatbot disclosure and deepfake labelling have applied since 2 August 2026. Generative systems already on the market have until 2 December 2026 to mark their output.
- Two very large GDPR fines in five weeks. The Irish DPC fined Google €403 million over location data. The Dutch AP is reported to have fined Uber about €825 million over automated driver deactivations.
- The GDPR reform is stuck. The data part of the Digital Omnibus has no Council mandate and no Parliament position. The GDPR applies unchanged.
- The ECB is losing patience on risk data. Supervisors say long remediation plans for BCBS 239 gaps will no longer be accepted.
AI Act: more time for high-risk, none for transparency
The Digital Omnibus on AI was published in the Official Journal on 24 July 2026 and entered into force on 27 July. It replaced the 2 August 2026 high-risk deadline with fixed later dates, confirmed by the Commission's AI Act Service Desk.
| Obligation | Applies from |
|---|---|
| Transparency duties (Article 50) | 2 August 2026 |
| Marking of AI output for generative systems already on the market (Article 50(2)) | 2 December 2026 |
| New bans on non-consensual intimate content and CSAM generation | 2 December 2026 |
| High-risk systems listed in Annex III | 2 December 2027 |
| High-risk AI embedded in regulated products (Annex I) | 2 August 2028 |
Transparency guidance is complete. The Commission published the final Code of Practice on AI-generated content on 10 June 2026 and final Article 50 guidelines on 20 July. Both are voluntary or non-binding, but the Commission points to them as the way to show compliance.
Enforcement powers are active. Since 2 August 2026 the AI Office and national authorities can enforce the rules on prohibited practices, transparency and general-purpose AI models.
Why it matters for governance teams. The deferral covers Chapter III only. Data governance under Article 10 is the hardest high-risk requirement to retrofit, so the extra 16 months are best spent on training-data lineage, quality rules and documentation.
GDPR: fines get bigger and more predictable
Enforcement, not reform, is the GDPR story this month.
| Date | Authority | Company | Fine | Issue |
|---|---|---|---|---|
| 21 Sep 2026 | Irish DPC | €403 million | Lawfulness, transparency and retention of location data, 2018 to 2020 | |
| 21 Aug 2026 | Dutch AP | Uber | about €825 million | Automated deactivation of driver accounts without adequate information |
| 11 Sep 2026 | CNIL | EXTIA | €300,000 | Mishandled erasure requests |
The Uber figure comes from press reports based on Reuters and an AP spokesperson; Uber has said it will appeal. Google was also ordered to bring its processing into compliance within six months.
New EDPB fining guidelines. On 21 September the EDPB announced Guidelines 04/2026 on when authorities should impose a fine at all. They set a five-step test and a strong presumption of a fine for any infringement that is not minor. Consultation runs until 13 November 2026. The Board also finalised its guidelines on the interplay between the DSA and the GDPR.
Digital Omnibus on data is stalled. The proposal to amend the GDPR, ePrivacy rules and the Data Act has no Council negotiating mandate, according to Simmons & Simmons. A leaked Presidency text dated 3 September would treat AI development as a possible legitimate interest, as reported by GDPR Local. Nothing has changed in law.
Why it matters for governance teams. The Uber case turns on Article 22 automated decisions and the Google case on retention. Both are controls a data governance function owns: decision inventories with human review points, and retention schedules that are actually enforced.
Data Act: access by design is now mandatory
Since 12 September 2026, connected products and related services placed on the EU market must be designed so users can reach their data directly. This is Article 3(1) of the Data Act, which has otherwise applied since 12 September 2025.
- What the design duty requires. Product and related-service data, with the metadata needed to interpret it, must be accessible by default, securely, free of charge and in a machine-readable format.
- Contract tools. The Commission lists non-binding model contractual terms and standard cloud clauses for data sharing and cloud switching. A final adoption date is not yet confirmed.
- Consolidation is proposed, not law. The stalled Digital Omnibus would fold the Data Governance Act, the free flow of non-personal data regulation and the Open Data Directive into the Data Act, as Heuking summarises. No conclusion is expected before 2027.
Why it matters for governance teams. IoT and product data now needs the same catalogue entries, ownership and access rules as customer data. Metadata that lets a user interpret the data is a legal requirement, not a nice-to-have.
Financial services corner: the ECB turns up the pressure on risk data
ECB supervisors said twice in September that slow BCBS 239 remediation will now trigger escalation.
- Board-level accountability. In a 30 September interview, ECB Banking Supervision said boards must treat data quality as a core risk-management issue, not an IT project. It expects tangible progress instead of multi-year plans with limited results.
- AI depends on data foundations. A 22 September ECB speech reported that more than 90% of directly supervised banks use AI and 85% use generative AI. It added that new technology cannot compensate for poor underlying data.
- Priorities unchanged. Remediating risk data aggregation and reporting gaps remains part of the 2026 to 2028 supervisory priorities, alongside DORA implementation.
- DORA oversight is running. The supervisory authorities designated 19 critical ICT providers in November 2025, and the list is updated annually.
Why it matters for governance teams. Banks can use the supervisor's own words to fund lineage and data quality work. The same foundations serve BCBS 239, DORA registers and AI Act Article 10.
What to do this month
- Check every chatbot and generative AI use case against Article 50, and confirm which legacy systems rely on the 2 December 2026 grace period.
- Re-baseline the AI Act programme to 2 December 2027, keeping the AI inventory and risk classification on the original schedule.
- Inventory automated decisions with legal or similar effect, and record the human review point for each.
- Test whether retention schedules for location and behavioural data are enforced in systems, not only written in policy.
- Add connected-product and related-service data to the data catalogue, with an owner and an access route for users.
- For banks: put the ECB's September statements on risk data in front of the board with a dated remediation plan.
- Decide whether to respond to the EDPB fining guidelines consultation.
Dates to watch
| Date | What happens |
|---|---|
| 15 October 2026 | Parliament's IMCO committee is due to vote on its Digital Omnibus opinion, per CENTR |
| 13 November 2026 | EDPB consultation on fining guidelines 04/2026 closes |
| 2 December 2026 | Article 50(2) marking deadline for generative systems already on the market; new AI Act prohibitions apply |
| 2 February 2027 | Watermark-detection interoperability commitment under the Code of Practice, per DLA Piper |
| 2 December 2027 | High-risk obligations apply to Annex III systems |
| 2 August 2028 | High-risk obligations apply to AI embedded in regulated products |
Sources and method
This brief is compiled from primary sources where they exist, with secondary sources named in the text. It is a practitioner's summary, not legal advice.
- AI Act Service Desk: when does enforcement start?
- European Parliament Legislative Train: Digital Omnibus on AI
- European Commission: Code of Practice on marking and labelling AI-generated content
- EDPB: fining methodology and DSA-GDPR guidelines
- EDPB: Irish DPC fines Google €403 million
- EUR-Lex: Data Act, Regulation (EU) 2023/2854
- ECB Banking Supervision: interview, 30 September 2026
- ECB supervisory priorities 2026 to 2028
- ESMA: designation of critical ICT third-party providers