Back to BlogIndustry Insight

Digital Omnibus 2026: New AI Act Timeline for Voice Agents

The Digital Omnibus delays high-risk rules, but AI Act Article 50 has applied since 2 August 2026. What your AI phone agent must disclose today

Famulor AI TeamAugust 12, 202614 min read
Digital Omnibus 2026: New AI Act Timeline for Voice Agents

Summarize Content With:

The Digital Omnibus Is Law: What Actually Changes for AI Phone Agents in 2026

The short answer for anyone running or launching an AI phone agent: your disclosure duty was not delayed. Article 50 of the EU AI Act has applied since 2 August 2026. If a machine answers your calls today, the caller must be told – clearly enough that a reasonably attentive person understands it. What was delayed are the obligations for high-risk systems under Annex III, and those moved to 2 December 2027.

The confusion comes from the Digital Omnibus on AI – Regulation (EU) 2026/1744. It was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. Since then, plenty of coverage has been summarised as "the AI Act is delayed." That framing is wrong in general and actively risky for voice operators, because the one article that touches phone agents most directly stayed exactly where it was. This guide sorts out the timeline, translates Article 50 into concrete greetings, and shows what a clinic, law firm, or support line should fix this week.

What the Digital Omnibus is – and what it is not

The Digital Omnibus on AI is not a new law. It is an amending regulation that reaches into the existing AI Act with three stated goals: simplify EU digital rules, ease the burden on smaller providers, and buy time for the most technically demanding obligations. The Commission proposed the package in November 2025; the final text has been on the books since late July 2026.

What the Omnibus does not do: it leaves both the prohibition regime in Article 5 and the transparency duties in Article 50 intact. If anything it tightens things – it adds two further prohibited practices that bite from 2 December 2026. Skimming the headlines and concluding that "nothing happens in 2026" leads to a bad decision.

The revised timeline at a glance

The table below summarises what Regulation (EU) 2026/1744 moved and what it left alone. It is the basis for any realistic compliance plan in the voice space.

ObligationOriginallyAfter Digital OmnibusRelevance for phone agents
Prohibited practices (Art. 5)2 February 2025unchangedHigh – e.g. emotion recognition at work
Transparency (Art. 50)2 August 2026unchangedVery high – applies to every voice agent
Marking of AI content (Art. 50(2)), systems on market before 2 Aug 20262 August 20262 December 2026Medium – narrow grace period for legacy systems
Two new prohibitions (Art. 5)2 December 2026Low for voice, relevant for governance
High-risk under Annex III2 August 20262 December 2027Depends on use case – see below
High-risk under Annex I (embedded)2 August 20272 August 2028Low for pure telephony

The one-liner for your leadership team: transparency now, high-risk later. The extra sixteen months apply to conformity assessment, risk management systems, and technical documentation for Annex III applications – not to whether your caller has to learn they are talking to a machine.

Article 50 on the phone: what exactly must be said

Article 50(1) requires providers of AI systems intended to interact directly with natural persons to design those systems so the person is informed that they are interacting with an AI system – unless this is obvious from the point of view of a reasonably well-informed, observant and circumspect person.

In practice that means: with a voice agent speaking in a natural voice, it is precisely not obvious. Modern text-to-speech is engineered to sound human – that is the product promise. Which is exactly why the exemption rarely applies here. The disclosure belongs at the start of the call, not in your website footer and not four minutes in.

We covered the exact wording options in depth in our guide to Article 50 and what your AI phone agent must say. This piece is about what the Omnibus changed there – which is nothing. Three requirements have emerged in practice:

  • Early: in the first sentence, before the caller explains why they are calling.
  • Clear: no marketing language, no terms that obscure the AI nature of the system.
  • Perceivable: at normal speaking pace, not rattled off like fine print.
AssessmentExample greetingWhy
Defensible"Hello, this is the digital assistant at Becker Dental. I'm an AI and I can book appointments or put you through to the team. How can I help?"AI nature explicit, first sentence, escalation path included
Defensible"Welcome to Hotel Lakeview. You're speaking with our AI assistant for reservations."Short, unambiguous, contextual
Risky"Hi, my name is Lisa from the service team."Implies a real employee – no disclosure at all
Risky"You're being assisted by our intelligent system.""Intelligent system" is not a disclosure in the sense of the article
RiskyNotice given only after collecting name, date of birth and requestToo late – the interaction started long ago

Operationally, you set this greeting once, centrally, and enforce it across every number. In Famulor you maintain the opening line in the prompt editor and then verify in post-call analysis that it actually fired on every single call. That second step is routinely skipped – and it is the part that constitutes your evidence.

What was not delayed – four common misreadings

Misreading 1: "We have until December 2027." That applies only to Annex III high-risk systems. An appointment-booking agent in a clinic typically is not one – its transparency duty has applied since 2 August 2026.

Misreading 2: "The December 2026 date pushes back our greeting." It does not. 2 December 2026 concerns only Article 50(2) – machine-readable marking of AI-generated content – and only for systems placed on the market before 2 August 2026. The direct-interaction disclosure under paragraph 1 has no grace period.

Misreading 3: "We're only a deployer, not a provider." The AI Act addresses providers and deployers separately, but it addresses both. If you run a voice agent under your own name for your customers, obligations attach to you regardless of who built the technology. Agencies and IT service providers reselling white-label agents should nail down the role split contractually.

Misreading 4: "This is an enterprise problem." The penalty provisions have no headcount threshold. For SMEs the only concession is that the lower of the two amounts applies – a cap, not an exemption.

Is an AI phone assistant a high-risk system?

In the large majority of cases: no. An agent that books appointments, answers opening-hours questions, takes callback requests, or reads out order status is a transparency case, not a high-risk case. It becomes high-risk only when the application reaches into one of the Annex III areas. Four constellations matter for telephony:

  • Employment: screening or evaluating candidates in a recruitment process.
  • Creditworthiness: assessing the credit standing of natural persons during the call.
  • Essential private and public services: for example triage decisions affecting access to emergency or social services.
  • Emotion recognition: here the Article 5 prohibition additionally applies in workplace and education contexts.

A recruitment agent that pre-qualifies candidates by phone and produces a ranking is therefore a different animal from an AI phone assistant in healthcare that only coordinates appointments. Operators in the first category should spend the extra runway to December 2027 rather than let it lapse: risk management, data quality, logging and human oversight cannot be retrofitted in four weeks.

New: the "small mid-cap" category

One of the most practically relevant changes in the Omnibus is a new size class. Until now, relief was reserved for SMEs. The Omnibus adds "small mid-cap" enterprises – companies that no longer qualify as SMEs but employ fewer than 750 people and have either an annual turnover of at most €150 million or a balance sheet total of at most €129 million.

Relief measurePreviouslyAfter the Omnibus
Simplified technical documentation (Annex IV)SMEs onlySMEs + small mid-caps
More proportionate quality-management expectationsSMEs onlySMEs + small mid-caps
Priority access to regulatory sandboxesSMEs onlySMEs + small mid-caps
Tailored penalty capsSMEs onlySMEs + small mid-caps

For the typical Famulor customer – a clinic group with 40 sites, a trades business with 120 staff, a mid-sized e-commerce operation – this means you almost always land in a relieved class. It does not release you from Article 50, but it materially lowers the documentation burden if your use case ever does tip into high-risk territory.

GDPR keeps running independently

The AI Act replaces nothing in data protection law. A phone call with an AI agent almost always processes personal data – name, phone number, the request itself, and in healthcare contexts potentially Article 9 special-category data. You still need:

  • a lawful basis for the processing and, where you record, for the recording itself,
  • a data processing agreement with your platform provider,
  • an entry in your record of processing activities,
  • retention limits for transcripts and recordings,
  • a workable way to answer data subject requests.

In practice, the AI Act notice and the data protection notice fit into one sentence without making the call feel heavy: "I'm the AI assistant at Weber Legal. This call is logged so we can handle your request." Details belong in your privacy policy, not the greeting. If you record audio rather than just store transcripts, several EU jurisdictions impose additional requirements on recording spoken conversations; treat that as its own workstream and do not fold it into the AI disclosure.

Penalties: what is at stake

Sanctions follow Article 99 of the AI Act and are tiered. Breaches of the Article 50 transparency duties sit in the middle tier.

BreachCapShare of annual turnover
Prohibited practices (Art. 5)€35 million7%
Transparency duties (Art. 50) and most other obligations€15 million3%
Incorrect or incomplete information to authorities€7.5 million1%

For companies the higher amount applies; for SMEs and start-ups, the lower one. Enforcement sits with national market surveillance authorities. Realistically, though, a fine is not the first risk a mid-sized operator faces – complaints from data subjects, competitor challenges, and reputational damage arrive faster than a formal proceeding.

Compliance cost: build it yourself or use a platform

The disclosure itself is one sentence. The effort sits in the evidence: six months from now, can you demonstrate the greeting fired on every call? This is where in-house builds and platforms diverge.

TaskIn-house on raw APIsPlatform such as Famulor
Version the greeting centrallyneeds your own prompt managementin the prompt editor, per agent
Per-call evidenceyour own logging and analysiscall history and post-call analysis
Retention limitsimplement yourselfplatform configuration
Data processing agreementone per sub-processorone agreement with the provider
Provider/deployer role splitentirely on youcontractually pre-structured

Once you price in the evidence layer, in-house builds routinely come out well above the expected total cost. To sanity-check how that maps to your current call volume:

ROI Calculator

Estimate your ROI from automating calls

See how much your business could save by switching to AI-powered voice agents.

Number of human agents40
5200
Hours worked per day6
412
Average hourly wage€22
1260

ROI Result

ROI 0%

Minutes needed288,000
Recommended planAgency
Total human agent cost
€105,600/month
AI agent cost
€36,051/month
Estimated savings
€69,549/month
Get started

No credit card required

Implementation in seven steps

  1. Build an inventory. List every number, agent, and chat channel where AI speaks to humans – including test numbers that are accidentally reachable.
  2. Determine your role. Are you a deployer, a provider, or both? For resellers this is the single most important question.
  3. Write the greeting. One sentence, AI named explicitly, company name, escalation path to a human.
  4. Roll it out. Apply it to every agent, including rarely used outbound campaigns.
  5. Sample your calls. Listen to twenty real calls from this week or read the transcripts. Did the greeting fire every time?
  6. Document it. A short memo: which system, which role, which greeting, since when, who owns it, where the evidence lives.
  7. Set reminders. Two dates: 2 December 2026 for the new prohibitions and the marking duty for legacy systems, 2 December 2027 for Annex III.

Three industry examples

Becker Dental, 14 staff, two locations. The agent answers calls between noon and 2pm and in the evenings, books check-ups, and escalates pain cases immediately. Not a high-risk case. To do: greeting with AI disclosure and a transfer option, review the data processing agreement, set transcript retention to 90 days. Effort: half a day.

Krüger Plumbing, 38 staff. The agent qualifies emergency callouts and creates jobs. Not a high-risk case. To do: apply the greeting to the emergency extension as well – the classic blind spot, because that number was configured separately.

A staffing firm with 220 employees. The agent calls candidates, runs a structured short interview, and produces a shortlist. That can fall into the Annex III employment area. To do: greeting immediately, and in parallel build risk management, logging, and human final decision-making by December 2027. As a small mid-cap the company can use the simplified technical documentation. For structuring and governing cases like this, the enterprise track is the right entry point.

Common mistakes

  • Greeting only on the main number. Secondary numbers, outbound campaigns, and the web widget get forgotten.
  • Greeting in the prompt but never verified. A model can skip the opening if the caller speaks immediately. Without sampling you will never notice.
  • Obscuring personas. A human first name with no AI disclosure is exactly the situation Article 50 targets.
  • Conflating GDPR and the AI Act. You need both, but they are separate records resting on separate legal bases.
  • Reading the delay as a free pass. Let sixteen months lapse and you face the same project in late 2027, only with more legacy baggage.

Conclusion

The Digital Omnibus bought breathing room where it was technically needed – conformity assessment and documentation for high-risk systems. For an ordinary AI phone assistant in a clinic, law firm, hotel, or trades business it changes very little: the disclosure duty has applied since 2 August 2026, and meeting it is genuinely manageable. A well-written first sentence, evidence pulled from call analysis, and a two-page memo cover the core.

Your concrete next step: pull twenty calls from this week and check whether your AI identified itself as AI in every one of them. If the greeting is missing on even one channel, fix it today rather than in December. And if you are setting the agent up right now anyway, configure the greeting, the transfer path, and the logging in a single pass.

🎯 Live Demo

Try our AI Assistant

Experience how natural our AI phone assistant sounds.

Enter your details and receive a call from our AI agent within seconds.

Agent is trained to discuss Famulor services and book appointments.

✓ 24/7 Availability✓ Natural conversations✓ GDPR compliant
Demo AI agent
Demo AI agent

Famulor representative

🇺🇸English

The call will automatically end after 5 minutes

SLIDE TO CALL

Slide the button to the right

📱 You will receive an SMS verification code

FAQ

Was the EU AI Act delayed by the Digital Omnibus?

Only partly. High-risk obligations under Annex III moved to 2 December 2027 and those under Annex I to 2 August 2028. The Article 50 transparency duties have applied unchanged since 2 August 2026.

Does my AI phone agent have to say it is an AI?

Yes, in nearly all cases. Article 50 requires users to be informed they are interacting with an AI system unless that is obvious. With natural-sounding voices, it is not obvious.

When exactly does the disclosure have to happen?

At the start of the interaction, before the caller explains their request. A notice mid-call, or only in the privacy policy, is not sufficient.

What does the 2 December 2026 deadline cover?

Two things: the new Article 5 prohibitions, and the marking duty for AI-generated content under Article 50(2) for systems on the market before 2 August 2026. Direct-interaction disclosure has no grace period.

Is an appointment-booking agent a high-risk system?

Normally not. High-risk status attaches to Annex III applications such as candidate screening, creditworthiness assessment, or access to essential services.

What penalties apply for missing disclosure?

Article 50 breaches fall into the tier of up to €15 million or 3% of worldwide annual turnover. For SMEs and start-ups the lower of the two amounts applies.

What is a small mid-cap?

A company that is no longer an SME but has fewer than 750 employees and either up to €150 million turnover or up to €129 million balance sheet total. These firms now receive the same relief measures as SMEs.

Does the AI Act replace the GDPR?

No. Both apply in parallel. You still need a lawful basis, a data processing agreement, retention limits, and the ability to respond to data subject requests.

Does this apply to outbound calls too?

Yes. The duty attaches to direct interaction, not to call direction. Outbound campaigns are the most commonly overlooked channel in practice.

How do I evidence compliance?

Through your call records. Sample calls regularly to confirm the greeting actually fired, and keep a short written note of the result.

FA
Famulor AI Team

Writer at Famulor

AI Phone Assistant

Everything in one plan. try Famulor

Voice AI, workflows, and integrations in one platform.

Famulor AI incoming call on a smartphone
Newsletter

Answer first. Grow fast.

Subscribe to receive latest news, product updates and curated AI content.