EU AI Act Omnibus: Six Days to Transparency, Nudifiers Out
Six days. That is the runway EU generative AI providers have left before the transparency obligations in the freshly adopted AI Act Omnibus start biting, and every so-called "nudifier" app on the market has until Dece…
EU AI Act Omnibus: Six Days to Transparency, Nudifiers Out
Six days. That is the runway EU generative AI providers have left before the transparency obligations in the freshly adopted AI Act Omnibus start biting, and every so-called “nudifier” app on the market has until December to disappear from EU distribution channels. Boards that spent Q2 treating the AI Act as a 2027 problem now own a Q3 problem.
What the Omnibus actually changes
The Omnibus package folds transparency, provenance, and prohibited-use rules into one enforceable instrument, tightening what the European Commission’s AI Office supervises directly. Providers of general-purpose AI models must publish training-data summaries, mark synthetic outputs in a machine-readable way under Article 50, and give downstream deployers the technical documentation needed to run their own risk assessments.
The nudifier ban lands under the prohibited-use annex. Any app whose primary function is generating non-consensual intimate imagery must be delisted from EU app stores and blocked at the distribution layer by December. Platforms that keep them live face fines calibrated to the 7% global-turnover ceiling in Article 99.
Executive teams asking “does this apply to us?” should walk the classification tree before drafting exemption memos. Our Lexnomia regulatory practice covers the four-tier assessment; the consulting practice runs the same walkthrough in a compliance sprint.
# transparency-flag.yaml — minimum viable disclosure config
provider: acme-genai
model_family: acme-image-v4
outputs:
watermark: c2pa
ai_disclosure_label: true
training_data_summary_url: https://acme.example/tds/v4
downstream_docs:
hosted_at: https://acme.example/docs/deployer-pack.pdf
updated: 2026-07-24
contact: ai-office-liaison@acme.example
What a compliant six-day sprint looks like
Six days does not leave room for elegant architecture. It leaves room for a triage list: which models ship outputs into the EU, which of those outputs are synthetic media, who holds the C2PA signing keys, and which app-store listings need pulling before enforcement discretion evaporates. ENISA’s provenance work is the reference the AI Office will lean on when adjudicating disputes.
The CAI position
Most “AI Act readiness” decks treat transparency as a documentation exercise. It is not. It is a supply-chain problem: your watermark is only as trustworthy as the key custody around it, and your training-data summary is only as defensible as the retention log behind it. Compliance teams that outsource watermark signing to a SaaS vendor without a key-escrow clause will discover in Q1 2027 that they cannot prove provenance when a regulator asks. Build the escrow now, not after the first enforcement letter.
Talk to us before the six-day clock resets your Q3 plan — start with the consulting compliance sprint.