Guides

EU AI Act Compliance Status

EU AI Act Compliance Status

Client briefing — July 2026

Omilia has built its EU AI Act compliance program ahead of the regulatory curve. This summarises what we have completed to date and the obligations still ahead — what Omilia provides as AI system provider, and what remains a client responsibility as deployer.

Our Governance Foundation

  • CEO-approved AI Governance Framework and Model Risk Governance Process, covering the EU AI Act, GDPR, and internationally recognised standards.

  • Every Omilia product has been classified against the AI Act's risk tiers using a documented, repeatable methodology. No Omilia product or feature falls into the Prohibited category.

  • Independent third-party assurance already in place: ISO/IEC 27001, SOC 2 Type II, PCI-DSS, and HIPAA. ISO/IEC 42001 (AI management systems) certification program xfunderway.

  • A dedicated Corporate Governance, Risk and Compliance function owns this program and reports to the CEO and Board.

What We've Already Done

Date

Milestone

Feb 2025

EU AI Act prohibited-practices provisions (Art. 5) entered into force. Confirmed: no Omilia product or feature falls within a prohibited category.

Aug 2025

GPAI model and AI literacy obligations entered into force. Governance structures and internal AI literacy program active.

2025 – 2026

Company-wide AI risk classification completed across the full product portfolio, using a documented, repeatable methodology aligned to the AI Act's risk tiers.

2026

CEO-approved AI Governance Framework and Model Risk Governance Process issued, integrating EU AI Act, GDPR, ISO/IEC 42001, ISO 27001, PCI-DSS, and HIPAA requirements into a single control set.

2026

ISO/IEC 42001 gap assessment completed; certification program launched, building on Omilia's existing ISO 27001 and SOC 2 Type II audit program.

May 2026

EU AI Act “Digital Omnibus” provisional agreement assessed; Omilia's compliance timeline updated to reflect revised statutory deadlines.

What's Ahead — Our Roadmap

Date

Obligation

What it means for clients

2 Aug 2026

Art. 50(1): AI interaction disclosure

Art. 50(3): biometric / emotion-categorisation disclosure

Art. 50(4): synthetic content labelling

Omilia provides the technical capability for each disclosure. 

Clients (as deployers) activate and configure the disclosure in their own deployment.

2 Dec 2026

Art. 50(2): machine-readable watermarking of AI-generated audio (transitional period for systems already on the market)

Neural TTS output progressively marked as AI-generated. No client action required beyond not stripping the marking.

2 Dec 2027

Full Annex III high-risk obligations: conformity assessment, technical documentation, post-market monitoring, human-oversight procedures, EU database registration

Applies to Omilia's high-risk product lines. Full compliance documentation package to be issued to affected clients ahead of this date.

Provider / Deployer responsibility

Omilia acts as Provider for the AI systems we place on the market; clients act as Deployer in their own operations. Provider obligations (technical capability, marking, documentation) sit with Omilia. Deployer obligations (activating disclosures, staff training, logging, DPIAs) sit with the client. Full product-specific documentation is available on http://ocp.ai .

This document provides general information on Omilia's compliance program and does not constitute legal advice. Contact: corporate-grc@omilia.com