EU AI Act Enters a New Phase: What Danish Businesses Need to Know in 2026

bringing a wider set of rules into application and moving AI regulation from preparation toward active enforcement. 

For Danish businesses, this is an important turning point. Companies are increasingly using artificial intelligence for customer service, content creation, recruitment, data analysis, marketing and internal operations. The new regulatory environment means businesses now need to consider not only what AI can do for them, but also what legal responsibilities come with using it. 

At the same time, the picture has changed considerably following the EU's AI Omnibus, which entered into force on 27 July 2026. The changes simplify parts of the original framework and postpone some requirements, particularly those concerning high-risk AI. 

For companies following developments through Lead Roedl and the wider Danish business law landscape, understanding which requirements apply now and which have been postponed is becoming increasingly important. 

The AI Act Is Now Moving Into Enforcement 

The EU AI Act entered into force on 1 August 2024, but its requirements were designed to become applicable gradually. 

Some provisions have therefore already been relevant for some time. Rules concerning prohibited AI practices started applying in February 2025, while governance provisions and obligations concerning general-purpose AI models became applicable in August 2025. 

A much broader milestone arrived on 2 August 2026

From this date, the European Commission's AI Office and national authorities began enforcing applicable provisions of the A The European Union's Artificial Intelligence Act entered a major new phase on 2 August 2026, I Act. Important transparency requirements also started to apply. 

This means 2026 should not simply be viewed as another preparation year. For many businesses, parts of AI compliance have become an operational issue. 

Transparency Becomes a Practical Business Requirement 

One of the most visible changes concerns transparency. 

Under Article 50 of the AI Act, certain businesses providing or deploying AI systems must ensure people understand when AI is involved. 

For example, where an AI system such as a chatbot interacts directly with a person, that person generally needs to be informed that they are interacting with AI unless this is already obvious from the circumstances. 

There are also requirements concerning AI-generated or manipulated material. 

Depending on how AI is being used, businesses may therefore need to consider: 

  • Whether customers know they are communicating with an AI system 
  • Whether AI-generated material needs to be identifiable 
  • Whether deepfake content requires appropriate disclosure 
  • Whether internal procedures clearly identify which AI systems are being used 
  • Whether staff understand their responsibilities when publishing AI-assisted material 

These questions can affect marketing departments, customer service teams, communications departments and technology providers, not just companies developing sophisticated AI models. 

AI-Generated Content Comes Under Greater Scrutiny 

The rules surrounding generated content deserve particular attention. 

Providers of certain generative AI systems are required to make AI-generated or manipulated outputs identifiable in a machine-readable format. 

The AI Omnibus does, however, provide additional time in one specific situation. For relevant systems that were already placed on the market before 2 August 2026, the machine-readable marking requirement applies from 2 December 2026

Businesses should not interpret this transition period as a general postponement of Article 50. Other applicable transparency obligations took effect on 2 August. 

This distinction is important because AI-generated text, images, audio and video are rapidly becoming part of everyday business communications. 

The AI Omnibus Has Changed the High-Risk Timeline 

Perhaps the biggest development for businesses is the change to high-risk AI deadlines. 

The original AI Act timetable placed major high-risk obligations much closer to August 2026 and 2027. The AI Omnibus has now extended those timelines. 

Under the revised framework: 

  • Requirements for high-risk systems falling within Annex III are scheduled to apply from 2 December 2027 
  • Requirements for high-risk AI embedded in certain regulated products under Annex I are scheduled to apply from 2 August 2028 

This provides businesses with additional preparation time. 

However, additional time should not be confused with an absence of future obligations. 

High-risk AI can eventually be subject to significant requirements concerning areas such as risk management, documentation, data quality, record keeping, human oversight, accuracy and cybersecurity. 

Employment AI Deserves Particular Attention 

One area Danish employers should watch closely is AI used in employment. 

AI systems can now help businesses screen applications, assess candidates, rank CVs, manage workers or support employment-related decisions. 

Certain employment-related applications fall within the AI Act's high-risk categories. 

Following the AI Omnibus changes, relevant Annex III high-risk requirements are scheduled to apply from December 2027 rather than August 2026. 

That gives employers more time, but businesses may benefit from using it to understand where AI already appears in their HR processes. 

For example, a company might use software supplied by a third party without initially thinking of it as an AI compliance issue. 

An internal review could ask: 

  • Does recruitment software use AI to rank candidates? 
  • Are automated systems involved in employee evaluation? 
  • Who makes the final employment decision? 
  • What information has the technology provider supplied? 
  • Does the company know what employee or applicant data enters the system? 

The answers can help determine where future compliance work may be required. 

Denmark Has Its Own Enforcement Structure 

Although the AI Act is EU legislation, enforcement also has a national dimension. 

In Denmark, the Agency for Digital Government, Digitaliseringsstyrelsen, acts as the national coordinating supervisory authority for implementation of the AI Act. 

Denmark is using a sector-based supervisory structure, meaning different authorities can have roles depending on the relevant field. 

For Danish businesses, this reinforces the need to consider AI regulation alongside existing areas of law rather than treating it as a completely separate subject. 

An AI application could potentially raise questions involving data protection, employment law, intellectual property, consumer rules or sector-specific regulation in addition to the AI Act itself. 

The AI Omnibus Offers Businesses Some Relief 

The 2026 AI Omnibus is not solely about delaying deadlines. 

It was introduced to make implementation more proportionate and reduce unnecessary administrative burdens while maintaining protections relating to safety and fundamental rights. 

Among other changes, the revised framework provides additional support for smaller businesses and extends certain simplified approaches beyond traditional SMEs to qualifying small mid-cap companies. 

It also expands opportunities for testing and regulatory experimentation. 

Regulatory sandboxes are particularly interesting because they can allow businesses to develop and test AI under regulatory supervision. 

The deadline for Member States to establish at least one AI regulatory sandbox has been moved to August 2027, while the revised rules also provide for an EU-level sandbox. 

Non-Compliance Can Be Expensive 

The financial consequences make AI governance difficult to ignore. 

For violations of certain AI Act requirements, penalties can reach substantial amounts. For example, violations of obligations including applicable transparency requirements can potentially result in administrative fines of up to €15 million or 3% of worldwide annual turnover for the preceding financial year, depending on the circumstances. 

The framework also provides for proportionality when fines concern SMEs and small mid-cap companies. 

For businesses, however, compliance is about more than avoiding fines. 

Poorly governed AI can create reputational, employment, privacy and commercial risks. A system that produces misleading content or makes poorly understood decisions can create problems long before a regulator becomes involved. 

What Should Danish Businesses Do Now? 

The most practical first step is to understand how AI is actually being used inside the organisation. 

Businesses can begin by creating an inventory covering AI systems used across HR, marketing, customer service, IT, finance and other departments. 

They can then consider what role the business plays in relation to each system. The AI Act distinguishes between different actors, including providers and deployers, and obligations can differ accordingly. 

Companies should also review: 

  • Customer-facing AI and chatbot disclosures 
  • AI-generated marketing and communications 
  • Third-party AI suppliers and contracts 
  • Recruitment and employee-management tools 
  • Data entering generative AI platforms 
  • Internal responsibility for approving AI tools 
  • Documentation relating to higher-risk applications 

The objective does not need to be eliminating AI from business operations. Instead, companies need a clearer picture of where it is being used and what obligations follow from that use. 

2026 Marks a New Stage for AI Compliance 

The EU AI Act has moved decisively from legislative planning toward practical implementation. 

The AI Omnibus gives companies additional breathing room in important areas, particularly high-risk AI, but transparency requirements and enforcement are already becoming part of the regulatory reality. 

For Danish and international companies operating in Denmark, the next challenge is connecting AI compliance with existing corporate, employment, data protection and commercial responsibilities. 

As businesses following developments through Lead Roedl will recognise, regulatory changes often become much easier to manage when companies identify their exposure early rather than waiting for a compliance deadline. 

The key question for 2026 is therefore no longer simply whether a company uses AI. It is whether the company knows where it uses AI, how it uses it and which legal obligations apply.