EU AI Act Compliance Status
Client briefing — July 2026
Omilia has built its EU AI Act compliance program ahead of the regulatory curve. This summarises what we have completed to date and the obligations still ahead — what Omilia provides as AI system provider, and what remains a client responsibility as deployer.
Our Governance Foundation
-
CEO-approved AI Governance Framework and Model Risk Governance Process, covering the EU AI Act, GDPR, and internationally recognised standards.
-
Every Omilia product has been classified against the AI Act's risk tiers using a documented, repeatable methodology. No Omilia product or feature falls into the Prohibited category.
-
Independent third-party assurance already in place: ISO/IEC 27001, SOC 2 Type II, PCI-DSS, and HIPAA. ISO/IEC 42001 (AI management systems) certification program xfunderway.
-
A dedicated Corporate Governance, Risk and Compliance function owns this program and reports to the CEO and Board.
What We've Already Done
|
Date |
Milestone |
|
Feb 2025 |
EU AI Act prohibited-practices provisions (Art. 5) entered into force. Confirmed: no Omilia product or feature falls within a prohibited category. |
|
Aug 2025 |
GPAI model and AI literacy obligations entered into force. Governance structures and internal AI literacy program active. |
|
2025 – 2026 |
Company-wide AI risk classification completed across the full product portfolio, using a documented, repeatable methodology aligned to the AI Act's risk tiers. |
|
2026 |
CEO-approved AI Governance Framework and Model Risk Governance Process issued, integrating EU AI Act, GDPR, ISO/IEC 42001, ISO 27001, PCI-DSS, and HIPAA requirements into a single control set. |
|
2026 |
ISO/IEC 42001 gap assessment completed; certification program launched, building on Omilia's existing ISO 27001 and SOC 2 Type II audit program. |
|
May 2026 |
EU AI Act “Digital Omnibus” provisional agreement assessed; Omilia's compliance timeline updated to reflect revised statutory deadlines. |
What's Ahead — Our Roadmap
|
Date |
Obligation |
What it means for clients |
|
2 Aug 2026 |
Art. 50(1): AI interaction disclosure Art. 50(3): biometric / emotion-categorisation disclosure Art. 50(4): synthetic content labelling |
Omilia provides the technical capability for each disclosure. Clients (as deployers) activate and configure the disclosure in their own deployment. |
|
2 Dec 2026 |
Art. 50(2): machine-readable watermarking of AI-generated audio (transitional period for systems already on the market) |
Neural TTS output progressively marked as AI-generated. No client action required beyond not stripping the marking. |
|
2 Dec 2027 |
Full Annex III high-risk obligations: conformity assessment, technical documentation, post-market monitoring, human-oversight procedures, EU database registration |
Applies to Omilia's high-risk product lines. Full compliance documentation package to be issued to affected clients ahead of this date. |
Provider / Deployer responsibility
Omilia acts as Provider for the AI systems we place on the market; clients act as Deployer in their own operations. Provider obligations (technical capability, marking, documentation) sit with Omilia. Deployer obligations (activating disclosures, staff training, logging, DPIAs) sit with the client. Full product-specific documentation is available on http://ocp.ai .
This document provides general information on Omilia's compliance program and does not constitute legal advice. Contact: corporate-grc@omilia.com