The European Commission announced that the AI Omnibus entered into force across the EU on July 27. The official page describes extended timelines and administrative simplification while preserving safeguards for safety and fundamental rights. It also describes support for innovation, including extending some measures to small mid-cap companies and expanding access to regulatory sandboxes and testing.
For an exporter or software supplier serving Europe, the unsafe shortcut is to interpret “simplification” or “extended timelines” as a universal pause for every AI use. The applicable position still depends on the system, purpose, organizational role, market, and date. Those elements need a controlled inventory and a review process.
Inventory the system before assigning the role
One company can occupy different roles across different uses. It may deploy a third-party customer-service tool, supply software that includes an AI capability, and use a generative tool to prepare marketing content. A website assistant, recruitment screen, visual quality check, quotation recommendation, and internal knowledge search should not be grouped under one vague “AI system” record.
An inventory should record the system and supplier, model or service version, input data, output purpose, affected people, deployment countries, direct interaction, connection to human decisions, and accountable reviewer. The role assessment should remain pending until someone has evaluated the actual deployment. A vendor's general documentation can support that assessment, but it does not automatically settle the company's obligations in a specific use.
The inventory should also state whether the system is experimental, internal production, customer-facing, or embedded in a delivered product. A controlled pilot should not silently become a public workflow because a marketing or sales user found it convenient.
Connect dates to evidence and change control
A compliance calendar is more than a list of regulatory dates. Each entry should connect the applicability assessment, evidence record, owner, internal preparation date, external effective date, and review trigger. Changes to the model, supplier terms, use, input data, target country, or affected people may require reassessment.
Teams should keep three categories distinct: legal requirement, vendor commitment, and internal control. They can support one another but are not substitutes. A vendor statement does not by itself replace deployment-level transparency, staff training, recordkeeping, or human oversight where those are applicable.
Where the legal position is uncertain, the company should maintain a written question list and obtain advice from qualified professionals for the specific product, role, and jurisdiction. The operating team should not resolve ambiguity through an unsupported website claim.
What this means for Chinese exporters
The business value of an AI compliance calendar is controlled deployment. Management can see which systems have been assessed, which remain limited to internal experiments, which can be customer-facing, where human review is mandatory, and which date requires the next action.
Public communication should remain evidence-based. A company can describe its actual process and current controls. It should not claim a certification or complete compliance without supporting evidence. Website notices, AI interaction disclosures, content labels, privacy information, and contract language should match the production deployment.
The calendar should include owners outside legal or compliance. Product owns intended behavior, technology owns configuration and logs, operations owns use, marketing owns public representation, and management owns acceptance of residual risk. Clear ownership prevents a policy document from becoming disconnected from the live system. Each owner should know the evidence they must maintain and the event that requires another review.
This article provides an operating framework and does not replace legal advice for a particular AI system, role, country, or transaction.
Action checklist
1. Inventory AI systems in the website, marketing, sales, recruitment, production, and support functions. 2. Record provider, deployer, or pending role assessment for each system rather than one company-wide label. 3. Track applicability, internal preparation date, external date, evidence location, owner, and review trigger. 4. Separate internal experiments from customer-facing production and prevent unreviewed scope expansion. 5. Reassess after changes to vendor, model version, purpose, data, affected people, or deployment country. 6. Align website notices, interaction disclosures, content labels, and contract language with the actual system. 7. Describe only verifiable controls in public statements and avoid unsupported certification language. 8. Escalate unresolved legal questions in writing to qualified professionals with the full deployment context.
Sources
- European Commission, “AI Omnibus enters into force,” published July 27, 2026: https://digital-strategy.ec.europa.eu/en/news/ai-omnibus-enters-force

